This paper presents a rigorous wavelet-based time–frequency anomaly detection framework designed to address volumetric User Datagram Protocol (UDP) flooding attacks in 5G networks within a Zero Trust Architecture (ZTA) context. By leveraging the Discrete Wavelet Transform (DWT) with the Daubechies db4 wavelet family, the proposed Multiscale Adaptive Zero Trust Anomaly Detection (MAZAD) framework decomposes user-plane packet-rate telemetry into multiple resolution levels, enabling the detection of both high-frequency traffic bursts and long-term congestion trends. The framework operates exclusively on metadata-based telemetry at the User Plane Function (UPF) and N6 interface, that is, the user-plane reference point between the UPF and external data networks in the 5G System, ensuring compatibility with fully encrypted 5G traffic environments. The paper uses classical DWT/MRA theory as the signal-processing foundation and contributes a task-specific MAZAD framework that combines db4-based multiscale packet-rate decomposition, scale-wise energy persistence, robust anomaly scoring, and bounded Zero Trust risk translation for metadata-only UDP flooding detection in 5G-inspired user-plane environments. A weighted multiscale anomaly scoring function is introduced to fuse information across frequency bands, capturing subtle deviations that are typically missed by single-scale approaches. Unlike conventional wavelet-based anomaly detectors that produce standalone alerts, MAZAD treats multiscale traffic deviations as policy-actionable risk evidence by converting scale-wise anomaly scores into bounded Zero Trust risk tiers for adaptive enforcement logic. The novelty of MAZAD lies not in the individual use of DWT, entropy, kurtosis, robust normalization, or sigmoid mapping, but in their task-specific integration into a lightweight, multiscale anomaly-scoring and Zero Trust risk-translation framework for metadata-only detection of 5G user-plane UDP flooding. Experimental evaluation using the Center for Applied Internet Data Analysis (CAIDA) DDoS Attack 2007 dataset demonstrates strong detection performance, achieving true positive rates (TPR) ranging from 92.1% to 100%, with false positive rates (FPR) as low as 1.4%–3.9%, and mean detection delays between 0.6 and 1.8 seconds. Comparative analysis shows consistent improvement over entropy-based methods, CUSUM, Isolation Forest, and short-time Fourier transform (STFT)-based approaches. The computational complexity of the framework is O(W) per analysis window, with an observed throughput of 2,439 windows per second, indicating promising suitability for real-time-oriented, metadata-based anomaly detection in 5G-inspired edge monitoring environments. However, further validation on live UPF telemetry and operational Zero Trust enforcement infrastructure remains necessary.