Killed a login brute-force attack at the edge in fifteen minutes
Traffic analysis showed /wp-login.php taking about 46% of every request hitting the origin. We put a Cloudflare Managed Challenge in front of it with a skip rule for the admin IP, watched the drop, and confirmed real admin access still worked.
The more useful finding was that the attack was not making the site slow. The server was sitting at 7.5% CPU. That stopped the client spending money on a bigger server to fix a problem they did not have.
- Time to resolution
- 15 minutes from diagnosis to verified live
- Tooling
- Cloudflare WAF, Managed Challenge, IP allowlisting, server log analysis