This is why I’ve started using honeypots. Set up dummy login pages or forms that only bots fill out. Anyone hitting those is auto-blocked.
Works surprisingly well, and legit users never even see it.
For larger scale, maybe look into AWS Shield if you’re on AWS? It’s pricey but handles a lot of the ip abuse stuff automatically.
Works surprisingly well, and legit users never even see it.
For larger scale, maybe look into AWS Shield if you’re on AWS? It’s pricey but handles a lot of the ip abuse stuff automatically.
