Behavior Patterns
Beyond single-session scoring, ShieldLabs tracks multi-session patterns — repeated anomalies linked to the same device, visitor, or user across time.What patterns track
Patterns are detected on three entity types:| Entity Type | Tracks | Use case |
|---|---|---|
device_id | Same hardware fingerprint | Multi-accounting from one device |
visitor_id | Same browser profile | Account farming from one browser |
user_hid | Same hashed user identifier | Compromised account re-use |
webrtc_ip | Same WebRTC-detected IP | IP-based velocity |
Pattern levels
Each pattern can escalate through two levels:| Level | Description |
|---|---|
suspicious | Anomaly detected — elevated risk, monitor |
dangerous | Confirmed threat — high confidence, action required |
Viewing patterns
Patterns are available in the dashboard under Sessions → Patterns, or via the API:Rate limiting
ShieldLabs automatically rate-limits devices exceeding 10 requests per minute. The device is flagged withDeviceID: "-1" and subsequent checks return: