Your Web Application Firewall can now make decisions based on who a request comes from, not just what it looks like. A new reputation condition scores every client IP against a continuously updated database of malicious, abusive and suspicious networks.
Requests from known-bad networks are blocked at the edge before they ever reach your origin — no rule tuning, no maintaining your own IP lists. At the same time, verified good bots such as search-engine crawlers and uptime monitors are allowlisted and always take precedence over block rules, so legitimate automation keeps working.
Reputation matching stacks with the rest of your custom WAF rules, so you can combine "who" with "what" — for example, challenge low-reputation IPs only on your login endpoint.
Curious how attackers hide inside normal-looking traffic? See What is a Layer 7 DDoS attack?