GRE for DDoS attack detection
Do you know that GRE protocol can be used to deliver port mirror / SPAN packets to remote monitoring location?
It offers plenty of benefits such us ability to send it over L3 without creating L2 tunnel between router and collector.
It's very nice protocol for DDoS attack detection as it offers great visibility without delays added by other traffic telemetry protocols such as jFlow, Netflow or IPFIX.