Bot Control gives you visibility and control over common and pervasive bot traffic that can consume resources, skew metrics, cause downtime, and perform other undesired activities. Bot Control checks various header fields and request properties against known bot signatures to detect and categorize automated bots, such as scrapers, scanners, and crawlers.
Account Takeover Prevention (ATP) gives you visibility and control over anomalous login attempts from bad actors using compromised credentials, helping you prevent against unauthorized access that may lead to fraudulent activity. ATP is used to protect your application’s login page.
Bot Control and ATP can be used independently of each other or used together. As with Bot Control managed rule groups, you can use ATP’s default rule action to block matching requests, or you can customize the behavior of ATP using AWS WAF mitigation functionality.