WAF
Web Application Firewall
appseceasy
A WAF sits in front of a web application and inspects HTTP traffic, blocking requests that match attack patterns like SQL injection or cross-site scripting. It protects applications in production, buying teams time to fix underlying vulnerabilities in code. A WAF is a compensating control rather than a cure, since determined attackers can often find bypasses for rule-based filtering.
Sources
More in appsec
Go deeper
Tools worth considering
- Sucuri → Cloud WAF, malware scanning, and hacked-site cleanup for CMS-run websites. A filter in front of your site, not a substitute for patching.
Affiliate links: the site may earn a commission at no extra cost to you (how this works). No single tool is a silver bullet; treat each as one layer of coverage.