Bot management · F5 Networks

F5 (Shape / BIG-IP ASM)

Difficulty 5/5

Shape Security under the F5 badge. Common in banking, airlines and telco, where the tolerance for false negatives is close to zero.

  • TLS fingerprinting
  • JS challenge required
  • Behavioural scoring
  • IP reputation weight: high

How it decides

  • A heavily obfuscated telemetry payload posted to the origin, encrypted per session.

  • Deep device fingerprinting joined against F5’s cross-customer view of credential-stuffing traffic.

  • BIG-IP ASM in front of it contributes classic WAF rules and the `TS*` cookie family.

  • Deployments are frequently tuned to observe first and block later, so early success is not proof of anything.

What you see when it stops you

  • “The requested URL was rejected. Please consult with your administrator.” plus a support id
  • `TS01xxxxxx` or `BIGipServer*` cookies
  • A large opaque JS bundle posted back on every navigation
  • Blocks that appear only after hours of apparently fine traffic

Signatures the detector matches

Publicly observable artefacts F5 (Shape / BIG-IP ASM) sends to every visitor. Paste a response into the analyser and these are what it looks for.

WhereSignalWeight
Page markupBIG-IP ASM rejection page75
CookieBIGipServer* persistence cookie55
CookieTS01* ASM cookie50
Headerx-distil-cs header (legacy Distil)65
Page markupDistil challenge markup65
Headerserver: BigIP45
Status403 rejection10

What actually gets through

  • Real browsers only, and expect per-target work — F5 deployments are individually tuned.

  • Residential or ISP exits depending on the vertical; banking deployments weigh ASN heavily.

  • Very low concurrency per identity. This product is built around credential-stuffing patterns, and burst traffic looks exactly like that.

  • Assume delayed enforcement when you test, and measure over days rather than minutes.

Hosts on record running it

From the detector's curated database. Observed, not live — stacks change, and large sites often run different protection per market.

Not sure this is what
is blocking you?

Paste the response you actually got. The detector names the vendor from its own headers, cookies and challenge markup — no account, nothing uploaded.