How-to

Reading the Offenders Page

How to interpret the ASN table and drill into a suspicious network.

4 min readLast updated 12 August 2026
Jump to section

Summary strip

At the top of the page, a summary strip reads: "N ASNs · X requests (Y% of total) · Z open alerts" -- giving you an instant sense of scale for the current filter set.

Filter bar

Five dropdown filters sit below the summary:

  • ASN Country -- filter by the ASN's headquarters country (where the network is registered, not where its traffic originates)
  • Bypass tier -- High (≥80%), Elevated (≥50%), or Normal (below 50%)
  • Alerts -- filter to ASNs that have / don't have open alerts
  • Type -- ISP, Cloud, VPN-Proxy, Transit, or Unknown
  • Firewall -- filter by firewall action (see below)

Firewall filter pills

The Firewall dropdown surfaces what the edge actually did with each ASN's traffic. Five options:

PillMatches
Any mitigationASNs where ≥1 request was blocked, challenged, or connection-closed
BlockedASNs with at least one block action
ChallengedASNs hitting any of the challenge variants
Conn. closedASNs with a connection-close action (rare — anti-DDoS reset)
Monitor mode onlyASNs where log/allow rules fired but no mitigating action ever did

The "Monitor mode only" pill is the inverse of "Any mitigation": rules fire but don't enforce. These are the ASNs worth auditing — either the rule should be promoted to a block/challenge, or it should be removed if it's noise. A residential ISP showing 100% log matches is usually a stale rule that hasn't been reviewed.

The pills only render when there are ASNs to populate them.

"Traffic from" chip

When you click a country on the Overview world map, or click through from a status code or cache status row, a "Traffic from" chip appears in the filter bar. This filters by the geographic origin of the requests, which is different from the ASN Country filter (based on the network's headquarters). For example, "Traffic from: Vietnam" shows all ASNs whose requests originate in Vietnam, even if those ASNs are headquartered elsewhere.

A search box lets you filter by AS number or organisation name. Type "45899" or "VNPT" to find a specific network. Organisation names are kept current from a live directory, so newer hosting and VPN networks resolve to real names rather than numbers.

Table columns

Each row in the Offenders table shows:

ColumnDescription
ASNAS number with organisation name, country flag, alert badge (if open alerts exist), and a bgp.tools link icon
RequestsTotal request count with a proportional magnitude bar
% of totalThis ASN's share of all traffic
TrendA sparkline showing the traffic pattern over the selected window
BytesTotal egress bytes
BPRBytes per request -- a low BPR (e.g. <1 KB) combined with high volume is a scraper signal
499 ratePercentage of requests where the client closed the connection
Hit rateCache hit ratio for this ASN. Renders "—" when cache outcomes are mostly unknown (typical of ASNs blocked at the edge before a cache decision), rather than a misleadingly healthy number
Bypass rateThree-tier colouring: red at ≥80%, amber at ≥50%, normal below 50%

All columns are sortable -- click any column header to sort ascending/descending.

Pin and Ignore

  • Pin an ASN to float it to the top of the table, regardless of sort order. Useful for watching a suspect network.
  • Ignore an ASN to hide it from the table. Ignored ASNs are hidden behind a "Show N ignored" toggle at the bottom.

Pins and ignores are saved to your workspace and shared with your whole team: when you pin an ASN, your colleagues see it pinned too, on every device.

CSV export

Click the Export CSV button to download the current filtered view as a CSV file.

Drilling into an ASN

Click any row to open the ASN detail page: stat tiles, stacked timeseries with site-wide baseline overlay, cache breakdown, status codes, firewall actions, top paths, top IPs, UA families, alert history, and a Suggest rule button that drafts an eCDN rule for this network on demand.

Still stuck? Email support or open the support widget in the bottom-right.