What to do when you are under attack

When the last few minutes look like credential stuffing, a flood of one path, a scan, or a handful of addresses, Tuning says so. You choose a narrow response. It expires. Copilot still says Promote, Hold, or Needs allowlist.

What you see

The look uses this site's WAF logs for the last 15 minutes and compares them with the previous day. When Analytics has a short request series, a volume surge has to agree with that series. A missing series is not treated as zero. A scan of many probe paths can still be called from the logs.

The card names the path, the masked addresses, the country mix when one country dominates, and the rate versus that site's usual 15 minutes. Logs do not include a network name, so the card does not invent one.

The same card is on the site page, above Tuning. The sites list repeats a fresh headline. The email, Slack, and webhook use the attack-spike switch and wait out that switch's cooldown. An agency admin with alerts on gets the same email. A client viewer can see the card and cannot click it.

A marketing launch across many pages, a steady cron, or a log that is too short stays quiet. Thin evidence is not emailed as an attack.

What you can click

When Copilot says Promote, Apply installs one narrow rule for 2 hours: a rate limit on the login family or on one exact path, a block or challenge of the few addresses that account for the surge, or a block of the exact probe paths that were requested. The rule sits behind Always allow, and it does not match a verified crawler or a webhook client.

Hold means the surge overlaps checkout, a crawler, or an Always-allow address, or a rate limit would not separate attackers from a person signing in. Needs allowlist means a callback should be added to Always allow before any block. Those cards have no Apply button.

The card shows the time left. Undo reads the firewall afterward and records the removal. Keep in count leaves the same scope in count until the end time. Make it a reviewed rule removes the expiry and adds a count rule Promote Copilot can look at later. A reviewed rate uses at least 100 requests per 5 minutes, the same floor as other custom rate rules. That conversion does not promote it.

Change history records the apply, the undo, the count change, the conversion, and the expiry. Addresses in that history are masked.

What this will not do

It will not apply a rule without a click, widen a rule past the paths or addresses in the evidence, or leave a block on after the end time. It will not block checkout, a payment callback, a verified crawler, or an Always-allow address. It does not change price, and it does not require locking the origin to CloudFront.

You still click Promote. Nothing is blocked automatically. A temporary response does not make the rest of Promote Copilot less cautious. Managed rules still start in count, and a reviewed surge rule starts in count too.

Answers

Will the WAF block the surge by itself?

No. The note and the card are a recommendation. A temporary rate limit, block, or challenge is installed only after you click. It expires on its own.

What if the surge is my checkout or a webhook?

Copilot says Hold or Needs allowlist. Checkout, payment callbacks, verified crawlers, and Always-allow addresses are not the target of a temporary block.

Related guides

More in this section