An intelligent bot management platform that detects and blocks bots and automated attacks
Run four-layer verification, AI threat analysis, and active defense from a single console — identifying web scraping, unauthorized crawling, and account takeover based on access environment and behavior patterns, then detecting and blocking them according to policy.
BotManager is an AI-based bot management solution that analyzes access environments and behavior patterns in real time to detect and block malicious bots and macros.
THE PROBLEM
The era when bots outnumber humans
In 2026, the center of gravity of threats has shifted from 'breaking in' to 'logging in.'
Bots overtake humans
More than half of all web traffic is bots. Humans are just 47% — automated requests now rule half the internet.
The era of weaponized AI
AI-driven bot attacks surged 12.5× year over year, and agentic AI traffic exploded +7,851%. Attacks grow cheaper while approaching human-level sophistication.
Login itself is the threat
94% of login attempts are bots, and 60% of auth requests use leaked credentials. The real threat is 'logging in,' not 'breaking in.'
Humans47%
A shrinking share of real users
Bots53%+
An era where automated traffic has overtaken human traffic
See live traffic at a glance
Visualize in real time everything from total request counts to per-stage blocking status, threat-assessment score, TPS, and top IPs, ASNs, and countries. Spot attack signals the moment they appear and respond immediately.
Real-time monitoring
Threat score
TPS
The four-step verification pipeline at a glance
Every request passes through four stages in order: firewall (IP, country, ASN) → bot category → filter → policy.
One screen shows blocking results (request counts and block rates) and the top 5 blocked items per stage.
Four-step verification
Blocking results
Top 5 insights
Identify suspicious users by their behavior
Suspicious user detection3Auser_a3f7Login IDHighSsess_91ceSession IDMediumIP203.0.113.42IP-levelPassedPolicy block/pass trendLast 24 hoursBlockedPassed
Track traffic by login ID, session ID, or IP, with risk level (high or medium) and block/pass trends per policy. Suspicious users stand out fast.
Drill into one identifier: block, detect, and pass counts, policies violated, bot score, and RPM over time. Pinpoint how a single user is attacking you.
Violated policies
Bot detection rate
RPM trends
Auto-interpret traffic and recommend actions
AI automatically summarizes traffic, assesses risk, and analyzes RPM, policy violations, and URLs—then recommends applying CAPTCHA, blocking sessions, or adjusting thresholds.
A security copilot that analyzes whatever you ask.
Ask natural-language questions like "Show me recently blocked IPs" to instantly retrieve blocked IPs, analyze detection policies, and review account blocking history. Get fast insights without navigating complex menus.
Classify conversational search bots (ChatGPT, Claude, Perplexity) and AI training crawlers (GPTBot, ClaudeBot) as benign, suspicious, or malicious. Set allow, detect, or block policies for each bot.
AI crawler management
Benign · Suspicious · Malicious
Allow · Detect · Block
Build your own detection rules
Create custom filters by combining conditions like IPs, User-Agents, JA3/JA4 fingerprints, and HTTP headers. Implement tailored rules in detect or block mode.
Custom rules
JA3 · JA4 fingerprints
Detect · Block
Automation·access environment·frequency·pattern, all at once
Apply proven security policies with a single toggle. Instantly block browser automation tools, and detect multiple IPs/sessions, excessive URL requests, and scraping.
Every day, BotManager analyzes the past 7 days of traffic to automatically recommend optimal thresholds for each policy. Backed by a confidence score, each recommendation can be applied or dismissed with a single click.
Automatic optimization
Threshold recommendations
New recommendations (pending)12+2 vs yesterdayApplied this month6-Rejected this month1-
Credential stuffing·password spraying blocking
Detect and block automated threats in your login flow. Prevent credential stuffing and password spraying by analyzing failure rates, targeted accounts, and total login attempts.
Credential stuffing
Password spraying
Defend against direct API calls and unauthorized crawling with dynamic URLs
Legitimate userBrowser requestPer-session URL/__bm=a1b2c3ProcessedUse a dynamic URL instead of the original addressBot · macroAttack toolDirect original URL call/reserve403blockedUnknown dynamic URL → original address blockedForged or reused URLs are blocked by validation
Block direct API attacks. Use BotManager's dynamic URLs to prevent direct calls, replay attacks, session hijacking, and parameter tampering.
Block direct calls (Returns 403 Forbidden on original API URL access)
Replay and tampering protection (timestamp expiry validation)
Register protected URL patterns and exclusion paths, then adjust key rotation and request validity using recommended presets or manual settings. Block scraping and automated attacks while minimizing operational overhead.
Recommended preset
Hide agent scripts from bots
Secure your frontend code with a 4-layer defense: obfuscated variables, encoded strings, hex-encoded functions, and compressed code. This keeps your bot detection logic hidden and unblockable with minimal performance impact.
Four layers
Code protection
Increase attacker resource cost through analysis-resistance patterns
Customize block and CAPTCHA screens—from no-code settings to full code-level control. Configure backgrounds, logos, copy, and fonts to accurately filter out bots without disrupting the user experience.
No-code customization
Branding
Frequently Asked Questions
Common questions before getting started. Reach out anytime to learn more.
BotManager is an advanced bot management solution that analyzes inbound web and application traffic to distinguish real users from malicious bots and macros. It allows, detects, challenges, or blocks requests based on your policies. Operating across multiple layers—client-side, server-side, and CDN—it evaluates automation signals, access environments, and behavioral patterns to identify sophisticated bots mimicking human behavior. Furthermore, BotManager leverages AI to power risk analysis and automated policy recommendations.
BotManager does not judge whether something is a bot from a single piece of information; it analyzes many signals together. Beyond various access information, it comprehensively analyzes traces of automation-tool usage, user interaction, abnormally short dwell times, repetitive URL-access patterns, whether browser attributes have been manipulated, and more. It also analyzes request patterns by login ID, session ID, and IP to reveal the risk level and the basis for its judgment.
A WAF (Web Application Firewall) generally focuses on defending against attacks that target web application vulnerabilities or against known attack patterns. BotManager focuses on identifying and controlling bot and macro traffic that looks like normal web requests but uses automation tools, scripts, or abnormal behavioral patterns. So rather than being an interchangeable replacement that plays exactly the same role, a WAF and BotManager complement each other—one for web-attack defense and the other for identifying and controlling automated traffic.
Yes. BotManager can detect and control automated attacks such as automated scraping, macros, direct API calls, and credential stuffing according to policy. For scraping, it comprehensively analyzes patterns such as sequentially crawling URLs, the absence of user interaction, abnormal dwell times, and traces of Headless Browser or Stealth tool usage. In login areas, it identifies automated login attempts to respond to attacks such as credential stuffing. It also provides capabilities—using a Server-Side Agent along with dynamic URLs and obfuscation—to respond to direct API calls that bypass the browser and to automated data collection.
No. Rather than blocking all bot traffic uniformly, BotManager can classify it into categories such as malicious bots, suspicious bots, and good bots, and apply different policies to each type. Because allow, detect, and block policies can be set individually for each bot category, you can allow the automated traffic your service operations require while restricting automated traffic used for unauthorized scraping or abuse.
The fastest way to try it.
Test and deploy the way you want, with no changes to your service environment.
(Server-side agents require a separate setup request.)