A demo app sitting behind the WAF Management Platform
Analysts search this library for attack signatures and payloads. Every request first passes through the WAF โ including the search below.
Try a normal query, then try pasting a payload an analyst might look up.
This form sends GET /library?term=โฆ through the WAF. A legitimate analyst
query that looks like an attack โ e.g. searching for a
powershell -enc indicator โ trips a CRS rule. That's the false positive
we fix live with a scoped exclusion, without weakening protection elsewhere.
Open the attack console and fire common web attacks at this app.
Open Attack Console โ