Cloudflare Docs
DDoS Protection
Visit DDoS Protection on GitHub
Set theme to dark (⇧+D)

Rule categories

Rules in the HTTP DDoS Attack Protection managed ruleset belong to the following categories (also known as tags):

NameDescription
botnetsRules for requests from known botnets, with very high accuracy and low risk of false positives. It is recommended that you keep these rules enabled.
unusual-requestsRules for requests with suspicious characteristics that are not usually seen in legitimate traffic.
advancedRules related to features available to Advanced DDoS Protection customers, such as Adaptive DDoS Protection.
genericRules for detecting and mitigating floods of requests. These rules are useful for mitigating attacks that have no known signatures, but they may also trigger on unusually high volumes of legitimate traffic. To reduce the risk of false positives, their request per second (rps) activation threshold is higher. These rules either rate-limit or challenge traffic by default, but you can override them to block traffic if necessary.