Bot management · Reblaze (Check Point)

Reblaze

Difficulty 4/5

A dedicated cloud perimeter — WAF, DDoS and bot management in one, deployed inside the customer’s own cloud tenancy.

  • TLS fingerprinting
  • JS challenge required
  • Behavioural scoring
  • IP reputation weight: high

How it decides

  • An `rbzid` cookie minted after a browser-verification challenge.

  • Fingerprinting plus behavioural profiling per session.

  • Per-customer isolated deployment, so rules vary far more between sites than with a shared-SaaS vendor.

What you see when it stops you

  • `rbzid` or `rbzsessionid` cookies
  • A short JS verification interstitial before first paint

Signatures the detector matches

Publicly observable artefacts Reblaze sends to every visitor. Paste a response into the analyser and these are what it looks for.

WhereSignalWeight
Cookierbzid cookie75
Cookierbzsessionid cookie70
Headerx-rbz-id header60

What actually gets through

  • Real browser plus residential exits.

  • Hold the `rbzid` cookie and the address together for the whole session.

  • Test per target: because deployments are isolated, findings from one Reblaze site rarely transfer to another.

Not sure this is what
is blocking you?

Paste the response you actually got. The detector names the vendor from its own headers, cookies and challenge markup — no account, nothing uploaded.