hi @alexbjorlig , just confirming - is this for 21risk?
the most immediate thing if a user has reached out about this is to create a firewall bypass rule to let your user through WAF System Bypass Rules
I’ve looked through the logs of botid from your project and I can see some sessions being flagged by our partner Kasada as bots. Can you give me a rough time stamp of when the classification happened? will help narrow down the exact session and reason
Not hostname because it’d bypass more than just that user, if that user only accesses your site from a certain ip, or ASN or user agent, you should bypass that
Dug deeper and figured it out - that user is using ZScalar, and it’s acting like a reverse proxy and obscuring signals we rely on for bot protection.
I’m working with the security team to detect usage of VPN’s and not block ZScalar users - but this is a problem with any reverse proxy or zero trust proxy in front.