Is a denial-of-service tool so convenient for you?
When I was getting into nodejs a few years back I wrote DoS script to kill a site that was scraping content from one of my sites and posing it as their own. I made it just for shits n giggles in about 5 minutes and I was surprised when it actually worked, their website just went down.
DoS is and always will be easy.
It could be as simple as a modest global rate limit on repeated GET requests to the same URL. We could start with 250 msec and see how that goes.
Or it could be as simple as limiting F5 reloads to once per keydown. Let users work for their accidental DoS attacks. :-)