Bot management · Reblaze (Check Point)
Reblaze
Difficulty 4/5
A dedicated cloud perimeter — WAF, DDoS and bot management in one, deployed inside the customer’s own cloud tenancy.
- TLS fingerprinting
- JS challenge required
- Behavioural scoring
- IP reputation weight: high
How it decides
-
An `rbzid` cookie minted after a browser-verification challenge.
-
Fingerprinting plus behavioural profiling per session.
-
Per-customer isolated deployment, so rules vary far more between sites than with a shared-SaaS vendor.
What you see when it stops you
- `rbzid` or `rbzsessionid` cookies
- A short JS verification interstitial before first paint
Signatures the detector matches
Publicly observable artefacts Reblaze sends to every visitor. Paste a response into the analyser and these are what it looks for.
| Where | Signal | Weight |
|---|---|---|
| Cookie | rbzid cookie | 75 |
| Cookie | rbzsessionid cookie | 70 |
| Header | x-rbz-id header | 60 |
What actually gets through
-
Real browser plus residential exits.
-
Hold the `rbzid` cookie and the address together for the whole session.
-
Test per target: because deployments are isolated, findings from one Reblaze site rarely transfer to another.
Not sure this is what
is blocking you?
Paste the response you actually got. The detector names the vendor from its own headers, cookies and challenge markup — no account, nothing uploaded.