@ArneBab @vampirdaddy @BlumeEvolution
That reminds me, I still have to do some forensics work.
Turns out most of the requests in the spikes weren't done by clients identifying as GPTBot. There still is some correlation on the time axis I need to look at, but more importantly, I'll have to bin requests to subnets to see if I can attribute the attacks with some modicum of certainty.
Already started writing a little log analyzer for that, maybe it'll grow into something I can actually release.