Detected attacks

Surface suspicious or automated activity against your site.

Attack detection flags suspicious behaviour — automated/bot activity, injection-style payloads and other anomalous patterns — so you can investigate. Enable it in Settings → Features and review on the Attacks screen.

Detected attacks

What you'll see

  • A total count and a trend chart of detections over time.
  • A table of flagged sessions with device, browser, country and timestamp.
  • A detail panel with the classification/reason and a link to the session replay for review.

How to use it

  • Correlate spikes with error logs — automated traffic often triggers errors too.
  • Review replays of flagged sessions to confirm whether activity is malicious or benign.
  • Use findings to inform your WAF/rate-limiting and security response.
Attack detection is a signal for investigation, not a replacement for a dedicated WAF or security stack. It observes what reaches your pages; it does not block anything.

Put this to work on your own site.

Heatmaps, session replays, funnels and experiments in one platform. Set it up in minutes, no credit card needed, and early-access members earn exclusive rewards.