Solutions
Threats CloudFilt stops
Bad bots scrape your content, take over accounts, flood your forms and skew your analytics. CloudFilt blocks them in real time and lets your real users through.
Solutions
Bad bots scrape your content, take over accounts, flood your forms and skew your analytics. CloudFilt blocks them in real time and lets your real users through.
Scripts and headless browsers that crawl, copy and flood your site at a pace no human keeps.
Bot traffic is non-human traffic to a website/webapp or API. While some bot traffic is beneficial (GoogleBot, Bingbot, SemrushBot...), abusive and bad bot traffic can be very dangerous.
Learn moreBot Mitigation is the process of identifying, analyzing, and taking action to prevent malicious bots from harming your website or application.
Learn moreWeb scraping, web harvesting, or web data extraction is data scraping used for extracting, stealing or monitoring content and data from websites.
Learn moreAI bots adapt, learn from data and mimic human behavior to scrape content, take over accounts or bypass CAPTCHAs.
Learn moreAutomated Threat or OAT, is an automated threat is a type of computer security threat to a computer network or web application, characterised by the malicious use of automated tools such as Internet bots.
Learn moreBots that fill your forms, create fake accounts and try stolen passwords on your login page.
Spam Submissions or Spambots Attack is computer programs that execute repetitive tasks and post spam in various places like contact page, registration page, comments, reviews...
Learn moreFake account creation is an automated bot threat that cybercriminals use to commit fraudulent acts like reputation manipulation, fake reviews, spreading disinformation through fake posts/news, or theft through account sign-up bonuses or discounts.
Learn moreAccount Takeover or ATO is an automated bot threat that cybercriminals use to brute force entry to an account. Credential Stuffing attacks crawl lists of leaked usernames/emails and passwords, using bots to continually test combinations on multiple sites until they are successful.
Learn moreAutomated abuse of your business: card testing, hoarded carts, fake clicks and polluted metrics.
Web Fraud is any unusual behavior on your website or web application. Based on the browsing history of other users, we are able to identify risky behavior like click fraud, Ad Fraud...
Learn moreCarding Fraud robots tries to use pirated cards, this results in chargebacks and unnecessarily declined transactions.
Learn moreBusiness Logic Attacks or BATs/BLBs pollutes data and site metrics, making it hard to understand who your actual customers are.
Learn moreInventory Hoarding or Denial of inventory is an automated bot threat that cybercriminals use to repeatedly places an e-commerce product or service in the shopping cart, without ever completing the transaction.
Learn moreMarketing Fraud mimics human behavior when visiting websites, clicking on ads, filling out forms and surveys, skewing results and wasting ad spend.
Learn moreWhere a visitor comes from says a lot: anonymizing networks, IPs with a bad record, countries you do not serve.
Tor traffic is visitors passing through the TOR network. Very used by hackers it will prevent you from automated attacks.
Learn moreProxy traffic is visitors passing through the Proxy network. Very used by hackers it will prevent you from automated attacks and phishing proxies.
Learn moreIP reputation can be used to block large scale hackers, scanners and spammers from infected or malicious sources based on shared blacklists with our partners.
Learn moreIP Risk Score can be used to block large scale hackers, scanners and spammers from infected or malicious sources by analysing historical behavior. A behavior considered normal on a site can be dangerous on another.
Learn moreGeneral Data Protection Regulation, is regulation of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and on the free movement of such data.
Learn moreVerified crawlers
Declared crawlers that make your site visible: let them in, cap them or keep them out. Search engines and the crawlers of AI assistants are verified and let through by default, so your site stays visible in search results and AI answers.
Whatever the threat, every request goes through the same path, and only real users reach your server.
Visitor
A browser, a script or a bot sends a request to your website or API.
Nearest point of presence
The CDN WAF, or your plugin, hands the request to the closest point of presence.
Signals
IP reputation, behaviour, rate, country and your own rules, weighed in real time.
Verdict
The signals behind each verdict: front, back and your own rules.
Every IP is checked against 15 reputation lists: our honeypots, StopForumSpam, CleanTalk, AlienVault OTX, Blocklist.de, Binary Defense.
Known Tor exit nodes, refreshed automatically, are challenged or blocked before they reach your pages.
Open proxies and datacenter networks, where most bots run, weigh on the risk score of the visitor.
The front script spots automation: headless Chrome, WebDriver, browsers that never run JavaScript.
Anti-flood thresholds per IP and per URL stop request bursts, credential stuffing and aggressive crawlers.
Crawlers harvesting your catalog or your prices hit the pages-per-minute threshold of your site.
Block or allow whole countries or continents, for GDPR, fraud or business reasons.
Give your login, checkout or API paths their own rules, stricter than the rest of the site.
Googlebot, Bingbot and the other search crawlers are verified by reverse DNS and let through: your SEO is safe.
GPTBot, ClaudeBot, PerplexityBot: let declared AI crawlers read your content, or keep them out.
Doubtful visitors get a captcha instead of a hard block: real humans are through in seconds.
Every verdict is logged with its reason, IP, country and rule: you always know why.