Rules decisive alone

Each of these eleven is enough, on its own, to call a visit a bot.

Eleven of Loghound’s 26 rules carry 80 points or more. Eighty is the bot threshold, so each of these is a claim that this one piece of evidence is enough to call a visit a bot.

The bold name is the label the panel shows; the code below it is what a filter URL and the stored data carry. The other fifteen rules are on Rules that stack.

01 · The eleven rules
Automation marker 100 points

The page exposed a driver artefact: the webdriver flag, a chromedriver global, or a Puppeteer, Playwright or Selenium hook. Browsers do not have these; drivers do. A page cannot acquire them by accident.

Code
automation_marker
Declared crawler 100 points

It said it was a bot and it was telling the truth. Verdict bot, threat none. Honest crawlers explains why these are kept apart.

Code
ua_declared_bot
Not a browser 100 points

The User-Agent is neither a browser a person uses nor a declared crawler: an empty header, a bare Mozilla/5.0, WordPress/6.4.3, a home-made client. The browser list covers desktop, mobile, regional, in-app, text-mode, TV, console and feature-phone browsers, and it errs towards “browser”. A log format that does not record the User-Agent is never judged by it.

Code
ua_not_a_browser
rDNS claim failed 95 points

It declared itself a major search crawler and forward-confirmed reverse DNS did not back that up. This is impersonation, checked the way the search engines themselves document.

Code
rdns_claim_failed
Headless renderer 90 points

WebGL reported a software renderer (SwiftShader, llvmpipe, Mesa OffScreen or Microsoft Basic Render), which is what you get when there is no screen. Not 100, because a virtual machine or a remote desktop can land here too.

Code
headless_renderer
Forged beacon timing 90 points

The time on page the beacon claimed is impossible against the moment its own token was issued, by more than five seconds. Within that margin the number is quietly corrected, because a busy browser can overshoot honestly. The lie is kept as evidence.

Code
beacon_forged
UA claim failed 85 points

The browser engine lacks a feature that shipped in the version the User-Agent claims, or has one that shipped after it, with two versions of grace either way. iOS browsers are skipped. A spoofed User-Agent cannot change what the engine can do. Browser claim probes.

Code
ua_claim_failed
Exploit probe 85 points

The visit asked for something no browser requests by accident: a sensitive file, a command injection, a JNDI lookup, a server-side fetch or cloud metadata address, a known exploit path, program code as a path, a scanner User-Agent, a crawler impersonation, or one of your attack patterns. Noisier patterns are shown on the Attacks view but are not a verdict alone.

Code
hostile_probe
Refused attack 85 points

Your site answered a request that matched an attack pattern with a 403 or a 406: its own defences refused it and the detector names it a probe. Sign-in requests do not count, because a person can be refused at a login form.

Code
refused_attack
Proxy fleet fingerprint 80 points

Five or more different addresses shared this exact header fingerprint within 24 hours, not on mobile networks, and it is not a crawler that passed its reverse DNS check. One client, many exits.

Code
fp_cluster_proxy_fleet
Never served anything 80 points

Your site refused every request this client made and served it nothing: no page, no redirect, not one byte of body. Sign-in challenges (401, 407) and rate limits (429) alone do not count.

Code
never_served
Two lower rules also convict alone

Sec-CH-UA mismatch (75) and Platform mismatch (70) are weighted below 80, but a User-Agent its own client hints contradict always makes the verdict bot. They are on Rules that stack.

Scoring

Loghound is open source and MIT licensed. Questions about the Opensolr half — the account, the indexes, the plan — go to opensolr.com/contact; questions about the software itself belong on GitHub.

Loghound Documentation