Cloudflare · OFFICIAL ARTICLE

推出 Precursor:通过持续客户端信号检测代理行为

Precursor 是我们面向 Bot 管理推出的全新持续行为验证引擎,可洞察人类与机器人在完整用户旅程中的实际交互方式。它将会话级行为转化为 Bot 检测信号,识别高级自动化……

来源:Cloudflare
ORIGINAL · 官方原文

Introducing Precursor: detecting agentic behavior with continuous client-side signals

详细说明

Blog AI Bot Management Cybersecurity +4 Show 4 more tags

7 Tags Show 7 tags

JavaScript Precursor Product News Turnstile

AI Bot Management Cybersecurity JavaScript Precursor Product News Turnstile

July 13, 2026

  • Selected Tags
  • AI Bot Management Cybersecurity JavaScript Precursor Product News Turnstile
  • All tags
  • Matching tags
  • No tags found
  • 1.1.1.1
  • 2FA
  • Abuse
  • Access
  • Access Control Lists (ACLs)
  • Accessibility
  • Account Takeover
  • Acquisitions
  • Addressing
  • Advanced Certificate Manager
  • Advanced DDoS
  • Advertising
  • Aegis
  • Africa
  • Afroflare
  • Agent Readiness
  • Agents
  • Agents Week
  • AI
  • AI Bots
  • AI Gateway
  • AI Search
  • AI-SPM
  • AI WAF
  • AI Week
  • Alertmanager
  • Always Online
  • AMD
  • AMP
  • Analytics
  • Anonymous
  • Anti Malware
  • Anycast
  • API
  • API Gateway
  • API Security
  • API Shield
  • APJC
  • Apple
  • Application Security
  • Application Services
  • Area 1 Security
  • Argo Smart Routing
  • ASCII
  • Asia
  • Athenian Project
  • Atlassian
  • Attacks
  • Audit Logs
  • Austin
  • Australia
  • Authentication
  • Authy
  • Automatic HTTPS
  • Automatic Platform Optimization
  • Automation
  • AutoMinify
  • Auto Rag
  • Awards
  • AWS
  • Baidu
  • Bandwidth Alliance
  • Bandwidth Costs
  • Best Practices
  • Beta
  • Better Internet
  • BGP
  • Birthday Week
  • Blackbird
  • Black Friday
  • Bot Fight Mode
  • Bot Management
  • Botnet
  • Bots
  • BPF
  • Brand
  • Brand Protection
  • Brazil
  • Browser Insights
  • Browser Rendering
  • Browser Run
  • Bug Bounty
  • Bugs
  • BYOIP
  • Cache
  • Cache Purge
  • Cache Reserve
  • Cache Rules
  • California
  • Canada
  • Cap'n Proto
  • CAPTCHA
  • Careers
  • CASB
  • Categories
  • CDN
  • CDNJS
  • Certificate Authority
  • Certificate Pinning
  • Certificate Transparency
  • Certification
  • CFSSL
  • Challenge Page
  • ChatGPT
  • China
  • China Network
  • Christmas
  • Chrome
  • CIO Week
  • CISA
  • Claire
  • CLI
  • ClickHouse
  • Clientless
  • Clientless Web Isolation
  • Cloud Connector
  • Cloud Email Security
  • Cloudflare Access
  • Cloudflare Apps
  • Cloudflare Area 1
  • Cloudflare Calls
  • Cloudflare Email Service
  • Cloudflare for Campaigns
  • Cloudflare for SaaS
  • Cloudflare for Startups
  • Cloudflare Gateway
  • Cloudflare History
  • Cloudflare Images
  • Cloudflare Media Platform
  • Cloudflare Meetups
  • Cloudflare Network
  • Cloudflare One
  • Cloudflare One Client
  • Cloudflare One User Risk Score
  • Cloudflare One Week
  • Cloudflare Pages
  • Cloudflare Polish
  • Cloudflare Queues
  • Cloudflare Realtime
  • Cloudflare Stream
  • Cloudflare Tunnel
  • Cloudflare TV
  • Cloudflare Workers
  • Cloudflare Workers KV
  • Cloudflare Workers KV (ES)
  • Cloudflare Workers (PT)
  • Cloudflare Zero Trust
  • Cloudforce One
  • Cloudy
  • Code Orange
  • Coinbase
  • Colombia
  • Community
  • Compliance
  • Compression
  • Config Rules
  • Configuration Management
  • Congestion Control
  • Connectivity
  • Connectivity Cloud
  • Consumer Services
  • Containers
  • Content Independence Day
  • Content Scanning
  • Context
  • Core
  • COVID-19
  • Crawler Hints
  • CrowdStrike
  • Cryptography
  • Crypto Week
  • CSAM Reporting
  • Customers
  • Customer Success
  • Customer Zero
  • CVE
  • CVE-2023-50387
  • Cyber Readiness
  • Cybersecurity
  • D1
  • Dashboard
  • Data
  • Database
  • Data Catalog
  • Data Center
  • Data Localization
  • Data Localization Suite
  • Data Loss
  • Data Loss Prevention
  • Data Platform
  • Data Privacy Day
  • Data Protection
  • Data Sovereignty
  • Data Transfer Bucket
  • DDoS
  • DDoS Alerts
  • DDoS Reports
  • Debugging
  • Deep Dive
  • Descaler
  • Design
  • Deskope
  • Developer Documentation
  • Developer Platform
  • Developers
  • Developer Spotlight
  • Developers Storage
  • Developer Week
  • Device Security
  • DevOps
  • DEX
  • Digital Experience Monitoring
  • Digital Forensics
  • Disrupt
  • Distributed
  • Distributed Systems
  • Distributed Web
  • Diversity
  • DLP
  • DMARC
  • DNS
  • DNS Filtering
  • DNS Flood
  • DNSSEC
  • DNS Security
  • Dogfooding
  • DoH
  • Domain Rankings
  • Domain Scoped Roles
  • dosd
  • Drupal
  • Due Process
  • Durable Execution
  • Durable Objects
  • Early Hints
  • Earth Day
  • eBPF
  • EC2
  • eCommerce
  • Edge
  • Edge Computing
  • Edge Database
  • Edge Rules
  • Education
  • Egress
  • Elastic
  • Elections
  • Election Security
  • Elliptic Curves
  • Email
  • Email Routing
  • Email Security
  • Email Workers
  • EmDash
  • Emissions
  • Employee Resource Groups
  • Encrypted SNI
  • Encryption
  • Engineering
  • Enterprise
  • Entropy
  • EPYC
  • Ethereum
  • Europe
  • European Union
  • Events
  • Exploit
  • Facebook
  • Fancy Bear
  • Fast Fonts
  • FCC
  • Feature Flags
  • FedRAMP
  • FedRAMP High
  • FedRAMP Moderate
  • Firefox
  • Firewall
  • Firmware
  • Florida
  • Football
  • Formal Methods
  • Forrester
  • Fortran
  • Foundation DNS
  • Founders' Letter
  • France
  • Fraud
  • Free
  • Freedom of Speech
  • Front End
  • Full Stack
  • Full Stack Week
  • Fun
  • Gartner
  • Gatebot
  • GA Week
  • GDPR
  • General Availability
  • Generative AI
  • Gen X
  • Geo Key Manager
  • Germany
  • GitHub
  • Go
  • Google
  • Google Analytics
  • Google Cloud
  • Google Workspace
  • Government Innovation
  • Grace Hopper
  • Grafana
  • GraphQL
  • Green
  • Grinch
  • Growth
  • gRPC
  • Guest Post
  • Hackathon
  • Halloween
  • Hardware
  • HashiCorp
  • Hertzbleed
  • Heuristics
  • History
  • Holidays
  • Holocaust
  • Hong Kong
  • Hosting Con
  • Hostnames
  • HTTP2
  • HTTP3
  • HTTPS
  • Human Rights
  • Hurricane
  • Hybrid Cloud
  • Hyperdrive
  • IBM
  • ICANN
  • iCloud Private Relay
  • Identity
  • IETF
  • IL4
  • Image Optimization
  • Image Recognition
  • Image Resizing
  • Image Storage
  • Impact
  • Impact Week
  • I'm Under Attack Mode
  • Incident Report
  • Incident Response
  • India
  • Indicators of Compromise
  • Indonesian
  • Infrastructure
  • Infrastructure as Code
  • Insights
  • Intel
  • Interconnection
  • Internal DNS
  • Internet Performance
  • Internet Quality
  • Internet Regulation
  • Internet Shutdown
  • Internet Summit
  • Internet Traffic
  • Internet Trends
  • Internship Experience
  • Intrusion Detection
  • Investors
  • IoCs
  • iOS
  • IoT
  • IPFS
  • IPsec
  • IPv4
  • IPv6
  • IRAP
  • Israel
  • Italy
  • IWD
  • JAMstack
  • Japan
  • JavaScript
  • Jengo
  • Jengo Policy
  • Joomla
  • Judeoflare
  • Kafka
  • Kernel
  • Keyless SSL
  • KeyTrap
  • Key Value
  • Killnet
  • Korea
  • Kubernetes
  • LangChain
  • Latency
  • Latin America
  • Latinflare
  • LavaRand
  • Lazarus group
  • Leaked Credential Checks
  • Legal
  • Legal Patents Sable
  • LGBTQIA+
  • Life at Cloudflare
  • Linux
  • Lisbon
  • Live Streaming
  • Llama
  • LLM
  • Load Balancing
  • Localization
  • Log4J
  • Log4Shell
  • Logging
  • Log Push
  • Logs
  • LUA
  • Machine Learning
  • Magecart
  • Magic Firewall
  • Magic Network Monitoring
  • Magic Transit
  • Magic WAN
  • Magic WAN Connector
  • Malicious JavaScript
  • Malware
  • Managed Components
  • Managed Rules
  • March of Cloudflare
  • MASQUE
  • MCP
  • Meerkat
  • MeetUp
  • Meris
  • Message Protocol
  • Mexico
  • Micro-frontends
  • Microsoft
  • Microsoft 365
  • Microsoft Azure
  • Middle East
  • Migration Hub
  • Milestones
  • Miniflare
  • Mirage
  • Mirai
  • Mitel
  • Mitigation
  • Mixed Content Errors
  • MLops
  • Mobile
  • Mobile SDK
  • Model Context Protocol
  • Moldova
  • Monitoring
  • Multi-Cloud
  • Multi-User
  • MySQL
  • NaaS
  • Net Neutrality
  • Network
  • Networking
  • Network Interconnect
  • Network Performance Update
  • Network Protection
  • Network Services
  • New Year
  • NGINX
  • Ninjas
  • NIST
  • Node.js
  • North America
  • Notebooks
  • Notifications
  • NSEC3
  • OAuth
  • Observability
  • Oceania
  • OCSP
  • Offices
  • Okta
  • Olympics
  • Onboarding
  • OpenAI
  • Open API
  • OpenBMC
  • OpenDNS
  • Open Source
  • OpenSSL
  • OpenTelemetry
  • Optimization
  • Origin Rules
  • Outage
  • Oxy
  • Pacific Northwest
  • Page Rules
  • Page Shield
  • Parallels
  • Partners
  • Partnership
  • Password-reuse
  • Passwords
  • Passwords (PT)
  • Patents
  • PAYGO
  • Payments
  • Pay Per Crawl
  • PCI Certified
  • Peering
  • Performance
  • Phishing
  • php
  • Phython
  • Pingora
  • Pipelines
  • PlanetScale
  • Plans
  • Platform Engineering
  • Platform Week
  • Plesk
  • Policy & Legal
  • Politics
  • Portugal
  • Postgres
  • Post Mortem
  • Post-Quantum
  • Precursor
  • Prepared Statements
  • Prisma
  • Privacy
  • Privacy Pass
  • Privacy Week
  • Private IP
  • Private Network
  • Product Design
  • Product News
  • Programming
  • Programming (PT)
  • Project Fair Shot
  • Project Galileo
  • Project Honey Pot
  • Project Pangea
  • Project Safekeeping
  • Project Turpentine
  • Prometheus
  • Protocols
  • Proudflare
  • Proxying
  • Public Sector
  • Python
  • Queues
  • QUIC
  • QUICHE
  • Quicksilver
  • R2
  • R2 Super Slurper
  • Radar
  • Radar Alerts
  • Radar API
  • Radar Maps
  • Railgun
  • Randomness
  • Ransom Attacks
  • Rapid Reset
  • Raspberry Pi
  • Rate Limiting
  • RC4
  • RDDoS
  • React
  • Reading List
  • Real-time
  • Recruiting
  • Regional Services
  • Registrar
  • Reliability
  • Remote Browser Isolation
  • Remote Desktop Protocol
  • Remote Work
  • Replication
  • Research
  • Resolver
  • Restreaming
  • Retreat
  • Reverse Engineering
  • REvil
  • Risk Management
  • Road to Zero Trust
  • Rocket Loader
  • RocksDB
  • Routing
  • Routing Security
  • RPKI
  • RRDNS
  • RSA
  • Russia
  • Rust
  • Rust Workers
  • SaaS
  • SAAS Security
  • Sable
  • Salt
  • Sampling
  • Sandbox
  • SASE
  • Save The Web
  • SDK
  • Search Engine
  • Secrets Store
  • Secure Web Gateway
  • Security
  • Security Analytics
  • Security Center
  • Security Posture
  • Security Posture Management
  • Security Service Edge
  • security.txt
  • Security Week
  • SEO
  • Serverless
  • Serverless AI
  • Serverless (PT)
  • Serverless Week
  • Server Push
  • Servers
  • SIEM
  • Signed Exchanges (SXG)
  • SIM
  • Singapore
  • Single Sign On (SSO)
  • Smart Placement
  • Smart Shield
  • Snippets
  • SOC as a Service
  • South Africa
  • South America
  • Spain
  • spdy
  • Spectrum
  • Speed
  • Speed Brain
  • Speed & Reliability
  • Speed Week
  • Spoofing
  • Sports
  • SQL
  • SRE
  • SSE
  • SSH
  • SSL
  • Standards
  • Startup Enterprise Plan
  • Statistics
  • StopTheHacker
  • Storage
  • Sumo Logic
  • Super Bowl
  • Supercloud
  • Supply Chain Attacks
  • Support
  • Sustainability
  • SWAG
  • SWG
  • Swift
  • Switzerland
  • SXSW
  • SYN
  • SYN Flood
  • Syria
  • TCP
  • Team
  • Teams Dashboard
  • TechCrunch
  • Technical Writing
  • Tech Talks
  • Terraform
  • Testimonials
  • Testing
  • Texas
  • Thanksgiving
  • The Serverlist Newsletter
  • Threat Data
  • Threat Feeds
  • Threat Intelligence
  • Threat Operations
  • Threats
  • Tiered Cache
  • TikTok
  • TLS
  • TLS 1.3
  • Tools
  • Tor
  • Tracing
  • Traffic
  • Transform Rules
  • Transparency
  • Trends
  • Trust & Safety
  • TTFB
  • TTL
  • TURN
  • TURN Server
  • Turnstile
  • TypeScript
  • UDP
  • Ukraine
  • United Kingdom
  • Universal SSL
  • URL Scanner
  • USA
  • User Research
  • VDI
  • Vectorize
  • Vetflare
  • Video
  • Visibility
  • Vite
  • VoIP
  • VPC
  • VPN
  • Vulnerabilities
  • WAF
  • WAF Attack Score
  • WAF Rules
  • Waiting Room
  • WARP
  • WARP Connector
  • WASM
  • Web3
  • Web Application Firewall
  • WebAssembly
  • Web Asset Discovery
  • Webinars
  • WebP
  • WebRTC
  • WebSockets
  • Wildebeest
  • Womenflare
  • WordPress
  • Workers AI
  • Workers Launchpad
  • Workers Logs
  • Workers Observability
  • Workers Sites
  • Workers Unbound
  • Workers VPC
  • Workflows
  • World IPv6 Day
  • Wrangler
  • x402
  • Year in Review
  • Z3
  • Zaraz
  • Zero Day Threats
  • Zero Trust
  • Zero Trust Week
  • Zone Versioning

Introducing Precursor: detecting agentic behavior with continuous client-side signals

Marina Elmore and Benedikt Wolters

7 minute read

COPY URL

Bot mitigation is an adversarial game: attackers adapt, defenders respond, and the cycle continues. At Cloudflare, we stay ahead by combining visibility across our global network with signals from the client-side environment. At the network level, we analyze over 1 trillion requests per day to understand reputation, patterns, and anomalies across more than 20% of the web. On the client side, we’ve pushed detection deeper with Cloudflare Turnstile , which has evolved from a CAPTCHA replacement to a risk-based managed challenge that adapts the amount of friction needed to verify the user is authentic.

Today, Turnstile runs nearly 3 billion times per day on some of the most sensitive endpoints on the Internet, helping verify users at key moments like login, signup, and checkout. This improves protection on the most important areas of customer applications, but still leaves limited visibility into the rest of the application — how humans and bots actually interact across the full user journey.

This is the visibility gap we’re closing today with our launch of Precursor .

Introducing Precursor

Precursor is a client-side, session-based verification system, built with privacy in mind, that uses dynamically injected JavaScript to continuously collect behavioral signals as visitors interact with your application. These signals are processed and incorporated into Cloudflare’s bot protection in real time, allowing us to continuously distinguish human traffic from automated or agentic traffic.

This extends the client-side detections offered by a Challenge to your entire web application. Precursor is an optional complement to Turnstile — both are features of our Enterprise Bot Management. This user-journey-based detection is powerful because modern automation is increasingly capable of appearing legitimate in short bursts. Bots can execute JavaScript, use real browser environments, and pass individual CAPTCHAs without raising suspicion. What remains difficult to replicate is consistent human behavior over time.

Precursor is built to capture that layer of interaction, turning behavior itself into a reliable signal for detecting fraud and abuse. By evaluating behavior across an entire session, Precursor adds significantly more signal to each decision. This improves detection precision, making it easier to distinguish real users from automation without relying on aggressive Challenges. For legitimate users, Precursor means fewer unnecessary interruptions. For bot developers, it raises the cost of operating automation by requiring them to simulate a full session. This is significantly harder to build, more expensive to maintain, and far less reliable to operate at scale.

To err is human

When a bot developer tries to make a mouse movement look human, they usually add Gaussian noise or uniform random delays. But human movement isn't just "noisy," it is also constrained by physics:

Bots, by contrast, often behave in ways that give them away. They move in linear interpolations or mathematically ideal Bézier curves. They click with a precision that humans could never replicate. And even when they do manage to simulate human error, there is a rhythm to human movements that can only be seen by examining an entire session.

Mouse movement is just one example of the signals Precursor evaluates, but it illustrates the difference clearly. Below is an example of a mouse automation library interacting with a site. You can see how the mouse moves in perfectly straight lines, always returns to an origin, and reacts with the same velocity.

Now, contrast that with a human navigating the same site: you see irregular paths, small corrections and overshoots, and variations in speed, timing, and direction.

Individually, these interactions might look plausible. But over the course of a session, these patterns diverge in ways that are difficult to fake. Precursor is designed to capture and evaluate these behavioral signatures as they develop over a visitor’s interaction with an application.

  • Wrist pivot: A human mouse movement is often an arc, limited by the range of the wrist and the rotation of the forearm.
  • Cognitive load: There is a measurable delay between a human seeing a checkbox and clicking it.
  • Hand tremor: Even the steadiest human hand oscillates at a physiological tremor frequency.

How Precursor works

To evaluate behavior over time, Precursor continuously collects interaction data on the client and builds a session-level view of activity for that site.

When Precursor is enabled on your application, Cloudflare automatically injects a lightweight script into HTML responses from your site as they pass through our network, with no additional configuration, network connections, or third-party embedding required. The injected Precursor bundle is compact, obfuscated, and assembled dynamically for each response. The bundle is designed to not interfere with any additional page logic of the hosted web application.

The script attaches lightweight event listeners to capture interaction signals such as pointer movement, keyboard activity, focus changes, and visibility. These events are serialized into a compact format and buffered in memory. At regular intervals, the buffered data is sent back to the evaluation layer for analysis.

On the edge server, incoming Precursor payloads are deserialized into behavioral inputs. A dispatcher runs a roster of evaluators on the input data. Each evaluator reads the Precursor streams it cares about and can raise signals into the shared detection registry.

Evaluators are designed to cross-reference data. For example, they confirm that pointer activity correlates with page visibility duration, or that keyboard events only fire when a text field is focused. This stream of information is then consolidated into individual signals that are used for weighting detections.

Precursor data is session-scoped, meaning it accumulates throughout a session. Session scoping is important because it means a bot cannot reset its behavioral signature by refreshing the page or starting over with a new challenge. The system also feeds session metadata into downstream detection layers for additional shadow-mode heuristics and session analysis, predicted vs. actual completion, and session delinquency heuristics. These edge-side observations are logged for detection improvement purposes and to adjust the bot score of a session.

Precursor was designed to collect signals that help to distinguish human patterns from automated and abusive patterns. The event listeners capture the minimum information needed to be a useful signal for detecting automation and abuse. For example, keyboard activity is captured as timing and rhythm, not as the actual keys pressed. In addition, behavioral signals are evaluated as aggregate patterns rather than individual actions and are consumed internally by Cloudflare's bot detection systems; they are not exposed to customer dashboards or tied to user accounts, login identities, or persistent profiles.

Taken together, this allows Precursor to maintain a continuously evolving evaluation of behavior, maximizing precision while minimizing the friction on good users.

  • Injection and collection layer
  • Evaluation layer
  • Session integration
  • Privacy by design

Per-session analytics

To support this new layer of detection, we are introducing session-based views in Security Analytics. These dashboards shift the perspective from individual requests to full visitor journeys. You can now answer questions like:

These analytics now capture information that per-request analytics can’t — especially the behavior that occurs between requests. Precursor feeds directly into existing systems like bot score, challenge decisions, and security rules, so you benefit from this added context immediately.

  • What does a typical session look like on my site?
  • Where do sessions diverge from expected behavior?
  • Which sessions show signs of automation over time?

What’s next

Precursor is the foundation for extending bot detection across the entire application. We are continuing to expand the range and depth of behavioral signals for security, how session-level insights influence our bot management protections, and new ways to visualize and act on session data. As bots evolve, detection needs to move beyond isolated checkpoints and into the full flow of user activity.

Get started

Precursor is rolling out now and can be enabled directly from your Cloudflare dashboard. Precursor will be free to use until our GA release later this year. Getting started is simple: turn Precursor on for your zone and choose how strictly you want to verify sessions. You can run it in a low-friction mode to observe behavior in the background, or require a fully verified session by enforcing Challenges if a session doesn’t already exist.

Once enabled, Precursor begins enhancing your existing bot defenses immediately, with no changes required to your application. If you're already using Bot Management or Turnstile, Precursor extends those protections beyond Challenges and into the rest of the session. Enable Precursor to extend detection across the full user session, including the activity between moments you already protect.

Related tags

AI Bot Management Cybersecurity JavaScript Precursor Product News Turnstile

Follow on Social Media

  • Cloudflare
  • Benedikt Wolters