# 0xInfection/Awesome-WAF

Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

Repository: https://github.com/0xInfection/Awesome-WAF
Canonical: https://ross.abutalabs.com/products/awesome-waf
Language: Python
License: Apache-2.0
License Family: permissive
Topics: waf, web-application-firewall, firewall, awesome-list, awesome, waf-bypass, waf-detection, waf-test, waf-testing, waf-fingerprints, bypass-waf, infosec, security
Last push: 2026-08-26T12:48:34+00:00

## Health v2 (maintenance only)
Score: 77/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 99, release rhythm 35, longevity 100
- inputs: {"age_days": 2794, "days_push": 7, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 7592, forks 1176 (observed 2026-08-28T04:10:01.835880+00:00)

## What it is
A curated awesome-list collecting everything about Web Application Firewalls (WAFs) from a security perspective, including how they work, detection and fingerprinting techniques, evasion methods, known bypasses, and related tools, papers, and writeups. It is aimed at penetration testers and security researchers rather than being a runnable tool itself.

## Use cases
- learn how web application firewalls work
- find tools to detect and fingerprint WAFs
- research WAF bypass and evasion techniques
- prepare for pentesting a web app behind a WAF
- find papers and talks on WAF security
- build a WAF testing methodology

## When to choose
- you are a pentester or researcher needing a comprehensive WAF reference
- you want a curated starting point for WAF detection, fingerprinting, or bypass research
- you need links to tools, papers, and writeups about WAFs in one place

## When to avoid
- you need an actual WAF product to deploy and protect an application
- you want runnable software rather than a curated list of resources
- you need guaranteed up-to-date bypasses for a specific WAF vendor

## Facets
- artifact type: learning-resource
- maturity: active
- function: security, penetration-testing, vulnerability-scanning, developer-tools
- domain: security, penetration-testing, web-development, awesome-lists
- platform: cross-platform
- tags: awesome-list, waf, web-application-firewall, waf-bypass, waf-detection, evasion-techniques, infosec, curated-resources

## Member repositories
- 0xInfection/Awesome-WAF (main) score 77

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:10:01.835880+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:36:53.016545+00:00, confidence not recorded.
  - readme: https://github.com/0xInfection/Awesome-WAF (fetched 2026-08-28T04:10:01.835880+00:00, sha 5b922b4e77ef)
- Data as of 2026-08-30T08:39:29.467469+00:00.
