Attack Console

Fire common web attacks at the protected app and watch the WAF respond

← Back to app

Each button sends a real HTTP request to this same origin — so it passes through the WAF before it could ever reach the backend. BLOCKED (403) means Coraza + OWASP CRS stopped it. ALLOWED (200) means it reached the app.

0 blocked
0 allowed
0 total sent

Malicious traffic

These should all be blocked while the site is in blocking mode.

Legitimate traffic

The WAF must let real users through. The last one is the analyst false positive.

Activity log

Newest first. Cross-reference these in the platform's Logs view.