An intelligent bot management platform that detects and blocks
bots and automated attacks

Run four-layer verification, AI threat analysis, and active defense from a single console —
identifying web scraping, unauthorized crawling, and account takeover based on access environment and behavior patterns, then detecting and blocking them according to policy.

BotManager

BotManager is an AI-based bot management platform that analyzes access environments and behavior patterns in real time to detect and block malicious bots and macros.

THE PROBLEM

The era when bots outnumber humans

In 2026, the center of gravity of threats has shifted from 'breaking in' to 'logging in.'

Bots overtake humans

More than half of all web traffic is bots. Humans are just 47% — automated requests now rule half the internet.

The era of weaponized AI

AI-driven bot attacks surged 12.5× year over year, and agentic AI traffic exploded +7,851%. Attacks grow cheaper while approaching human-level sophistication.

Login itself is the threat

94% of login attempts are bots, and 60% of auth requests use leaked credentials. The real threat is 'logging in,' not 'breaking in.'

See live traffic at a glance

From total requests to per-stage blocking, threat index, TPS, and top IPs·ASNs·countries — visualized in real time.
Spot attack signals instantly and respond right away.

Real-time monitoring
Threat score
TPS
Real-time BotManager dashboard — per-category counts, threat-assessment index, Defense Stream, stage-by-stage request trends, TPS, and requests vs. the previous day

The four-step verification pipeline at
a glance

Every request passes through four sequential steps: firewall (IP·country·ASN) → bot category → filter → policy.

Review blocking results (request count·block rate) and the Top 5 insights per step on one screen.

Four-step verification
Blocking results
Top 5 insights
Four-stage verification pipeline dashboard — domain info, BotManager verification stages, and the Top 5 key insights

Identify suspicious users
by their behavior

Suspicious user detection3Auser_a3f7Login IDHighSsess_91ceSession IDMediumIP203.0.113.42IP-levelPassedPolicy block/pass trendLast 24 hoursBlockedPassed

Track traffic by login ID, session ID, and IP, with risk level (high/medium) alongside policy block·pass trends. Quickly single out abnormal users.

  • Behavior-based detection
  • Risk level

From violated policies to
RPM trends

user_a3f7Bot 94%RPM trend↑ 312%3 policy violationsLast hour

Deep-dive into a specific identifier's block·detect·pass counts, violated policies, bot detection rate, and RPM trends. Pinpoint a single user's attack pattern with precision.

  • Violated policies
  • Bot detection rate
  • RPM trends

Auto-interpret traffic and
recommend actions

AI automatically organizes traffic summaries, risk assessment, RPM analysis, violated policies, and URL analysis,

and even suggests recommended actions such as applying CAPTCHA, blocking sessions, and adjusting thresholds.

AI-powered analysis
Recommended actions
Risk assessment
AI auto-interpretationLIVETraffic risk73/100Policy violations3casesRPM3,240+312%URL analysis12EndpointsRecommended action generatedRecommended action3Apply CAPTCHAVerify suspicious trafficBlock sessionsess_91ce · 1hAdjust thresholdRPM 600 → 450

A security copilot
that analyzes on demand

Ask in natural language like "show me recently blocked IPs" and get instant answers — blocked IP lookups, detection policy analysis, member-ID block history, and more. Get insights fast, with no complex menu navigation.

Natural-language queries · Recommended actions · Risk assessment
Security copilot search — look up blocked IPs, analyze detection-policy status, review member-ID block history, and run AI analysisSecurity copilot response — natural-language query analysis result (sequential speech-bubble streaming animation)

Manage both regular and AI crawlers
by type

Classify conversational search bots such as ChatGPT·Claude·Perplexity and AI training crawlers such as GPTBot·ClaudeBot as benign·suspicious·malicious. Configure allow/detect/block granularly per bot.

  • AI crawler management
  • Benign · Suspicious · Malicious
  • Allow · Detect · Block

Build your own
detection rules

Combine conditions such as IP·User-Agent·JA3/JA4 fingerprints·HTTP headers to create custom filters. Implement rules that fit your business exactly, in detect or block mode.

  • Custom rules
  • JA3 · JA4 fingerprints
  • Detect · Block

Automation·access environment·frequency·pattern,
all at once

Apply and operate proven recommended policies — blocking browser automation tools, detecting multiple IP·session issuance, excessive URL requests, and scraping — with a single toggle.

  • Recommended policies
  • Automation · Frequency · Pattern
  • Toggle controls

Data-driven
threshold recommendations

Analyze the last 7 days of traffic to automatically recommend the optimal threshold per policy every day. Presented with a confidence score, so you can apply or reject it in a single click.

  • Automatic optimization
  • Threshold recommendations

Credential stuffing·password spraying
blocking

Detect and block automation attacks that occur during login authentication.

Defend against Credential Stuffing and Password Spraying based on failure rate·number of attempted accounts·login count.

Credential Stuffing
Password Spraying
Credential-stuffing block policy — edit thresholds, target scope, and additional optionsPassword-spray block policy — number of attempted accounts, time window, and alert settings

Defend against direct API calls and unauthorized crawling
with dynamic URLs

Legitimate userBrowser requestPer-session URL/__bm=a1b2c3ProcessedUse a dynamic URL instead of the original addressBot · macroAttack toolDirect original URL call/reserve403 blockedUnknown dynamic URL → original address blockedForged or reused URLs are blocked by validation

Block attacks that target the API directly. With BotManager's dynamic URL feature, direct calls, replay, session hijacking, and parameter tampering are all blocked.

  • Block direct calls (403 on the original API URL)
  • Replay and tampering protection (timestamp expiry validation)
  • Session binding (prevents cross-session URL reuse)

Pick only what to protect and
apply it with ease

Protected URL pattern registration — recommended presets and key-set rotation interval settings

Register the URL patterns to protect and the exception URLs, then adjust the key-set rotation cycle·request validity period via a recommended preset or manually. Defend against scraping·automation without operational burden.

  • Recommended preset

Hide agent scripts
from bots

Protect frontend code with a four-layer approach: variable obfuscation·string encoding·function Hex conversion·compression.

Keep bot-detection logic from being identified·blocked while minimizing performance impact.

Four layers
Code protection
Control attacker resources via cost-inflating patterns
4-stage code obfuscationSame behavior, harder to analyze ↑Variable obfuscationbuyTicket()e()String encoding"/api/tickets"_0xd(3)Function Hex conversiongoDetail()_0x1a3f()Code compressionMulti-line codea=()=>{...}93%Pattern coverage

Brand-aligned
blocking and CAPTCHA screens

Support block screens and CAPTCHA from no-code setup to full code-based customization.
Freely configure background·logo·text·fonts to filter out only bots without hurting the user experience.

No-code customization
Branding
Brand-aligned blocking and CAPTCHA screens — demo of toggling per-language settings in the no-code console

Frequently Asked Questions

Common questions before getting started. Reach out anytime to learn more.

BotManager is a bot management solution that analyzes traffic coming into websites and applications to distinguish real users from malicious bots and macros, and then allows, detects, challenges, or blocks them according to policy. Across multiple layers—client-side, server-side, and CDN—it analyzes signs of automation-tool usage, the access environment, behavioral patterns, and more to identify automated traffic that approaches like a real user. AI-based capabilities are also used for risk analysis and policy recommendations.

써 보는게 가장 빠릅니다.

서비스 환경 변화 없이 원하는 방식에 따라 빠르게 테스트 및 적용 가능합니다

(Server Side 에이전트의 경우 별도 적용 요청 필요)