Writing
How these attacks actually work, and why this product is built the way it is. No keyword filler — each piece answers a question someone asked us before buying.
6 min read
How a hotel booking page gets cloned, step by step
The attack takes about twenty minutes and needs no access to your systems at all. Here is the whole sequence, and the two points where it can be caught.
Read4 min read
Why we refuse to block anything
The most common question we get is whether we can stop the attacks we detect. We can. We will not, and the reason is arithmetic.
Read5 min read
How to read one of our alerts
Every alert carries a score, a confidence figure, and the reasoning that produced both. Here is what each part means and when to ignore one.
Read6 min read
What is a website honeypot, and does your site need one?
A honeypot is a door that exists for nobody. Anyone who opens it has announced themselves. Here is how the idea works on an ordinary business website, and what it catches that filters cannot.
Read7 min read
How to tell if your website has been cloned
Copies of booking pages take real deposits from real guests. The operator usually finds out from an angry phone call. Here are the signals that surface a clone earlier, and what to do the day you find one.
Read6 min read
Credential stuffing and password spraying, explained for site owners
Two attacks your login form cannot see from any single request, why per-IP rate limits miss both, and the three patterns that give them away.
Read