<ul data-eligibleForWebStory="true">Cloudflare's Under Attack Mode is a blunt-force approach that can frustrate real users and slow down legitimate traffic.Default Cloudflare protections may not be sufficient to stop credential stuffing attacks.Attackers can mimic normal user behavior to evade automated defenses.Proactive defenses against brute-force and credential stuffing attacks include setting up specific rules and WAF expressions.It's important not to set thresholds too low to avoid blocking legitimate login attempts.Automating early-warning systems can help react to threats before users are impacted.Under Attack Mode should be a last resort, with rate limiting, bot management, and WAF rules being more proactive defenses.Tuning Cloudflare setup is crucial as attackers do not wait for manual reactions.