We will be thinking of implementing Google Enterprise Recaptcha in our application to prevent this.
We are deciding approach to validate the token by siteverify API and depending on the score (score-based key) we will validate the request by human or bot and take action.
Which is a good approach to validate tokens by siteverify API or creating an assessment in C#?
"Does the number of payload requests sent by BurpSuite count towards the billing for Google reCAPTCHA Enterprise when using a Score-based sitekey?"