Open source Web Application Firewalls (WAFs) protect millions of applications across the Internet. Yet the ecosystem is fragmented across projects, rulesets, integrations, and communities.
OWASP brings them together.
As the world’s leading open community for application security, OWASP provides a neutral home where WAF projects, rule authors, researchers, vendors, and users can collaborate to improve the security of the entire ecosystem. From detection rules and testing methodologies to documentation, benchmarks, and best practices, this initiative aims to connect the people and projects shaping the future of open source WAFs.
Whether you’re building a WAF, maintaining rules, integrating security into your platform, or deploying protection in production, you’re part of the community.
Welcome to the Open Source WAF initiative at OWASP.
![map[class:object-cover object-center src:images/home/hero/waf-security.png]](https://waf.owasp.org/images/home/hero/waf-security.png)
Industry-leading WAF engine
Next-gen Go-based WAF
Comprehensive detection rules
Global collaboration
The OWASP WAF family is the place for existing and new application firewall projects. The community is united by a common goal of protecting web applications from attacks.
![map[class:aspect-square object-contain object-center w-[75%] src:images/home/features/crs.png]](https://waf.owasp.org/images/home/features/crs.png)
Generic Attack Detection
The OWASP CRS (formerly OWASP ModSecurity Core Rule Set) provides generic, enterprise-grade attack detection rules that work seamlessly with ModSecurity, Coraza and compatible commercial engines. Maintained by a global community of security experts, CRS protects against security risks as decribed by the OWASP Top 10 and many other attack vectors. With continuous updates and extensive coverage, CRS is the dominant rule set in the industry.
CRS is an OWASP flagship project.
https://coreruleset.org
![map[class:aspect-square object-contain object-center w-[75%] src:images/home/features/modsecurity.png]](https://waf.owasp.org/images/home/features/modsecurity.png)
Industry Standard WAF Engine
ModSecurity is the original open-source Web Application Firewall that has been protecting web applications since 2002. It is known for its robustness and extensive deployments on Apache and Nginx worldwide, ModSecurity provides a powerful rule-based engine for rules in its SecRule domain specific language. It’s the foundation that started the open-source WAF movement and continues to be a trusted solution for organizations of all sizes.
ModSecurity is an OWASP production level project.
https://modsecurity.org
![map[class:aspect-square object-contain object-center w-[75%] src:images/home/features/coraza.png]](https://waf.owasp.org/images/home/features/coraza.png)
Modern, Fast, and Cloud-Native
Coraza is a next-generation Web Application Firewall built from the ground up in Go, designed for modern cloud-native environments. With near-full ModSecurity compatibility, Coraza offers strong performance, easier deployment, and better integration with contemporary web architectures. It brings the power of ModSecurity to cloud-native applications.
Coraza is an OWASP production level project.
https://coraza.io
![map[class:aspect-square object-contain object-center w-[75%] src:images/home/features/coraza.png]](https://waf.owasp.org/images/home/features/coraza.png)
Ambitious attempt to bring a GUI to WAF management
OWASP WAFControl provides an open source web-based dashboard that simplifies the deployment, configuration, monitoring, and management of ModSecurity and the OWASP Core Rule Set.
WAFControl is an OWASP incubator level project.
https://wafcontrol.org/
![map[class:aspect-square object-contain object-center w-[75%] src:images/home/features/coraza.png]](https://waf.owasp.org/images/home/features/coraza.png)
Rebalancing the rules to improve performance
OWASP WARM tries to apply machine learning and automation to improve the accuracy, tuning, and operational management of WAF rule sets. The project is based on a series of scholarly articles and promises to deliver to OSS.
WARM is an OWASP incubator level project.
https://owasp.org/www-project-waf-advanced-ruleset-management/
![map[class:aspect-square object-contain object-center w-[75%] src:images/home/features/coraza.png]](https://waf.owasp.org/images/home/features/coraza.png)
What a WAF needs to cover
OWASP WAFEC is an OWASP project that defines a vendor-neutral framework for evaluating, testing, and comparing the capabilities and effectiveness of Web Application Firewalls. Truth be told it has not seen an update in many years and could be with a few enthusiasts breathing new life into it.
WAFEC is an OWASP incubator level project.
https://owasp.org/www-project-wafec/
![map[class:aspect-square object-contain object-center w-[75%] src:images/home/features/coraza.png]](https://waf.owasp.org/images/home/features/coraza.png)
Mutating the payloads to find bypasses
OWASP WAF-A-MoLE is a security testing tool that uses guided mutation fuzzing to discover WAF detection bypasses and assess the robustness of Web Application Firewalls against evasive attacks.
WAF-A-MoLE is an OWASP incubator level project.
https://owasp.org/www-project-waf-a-mole/
OWASP, the Open Worldwide Application Security Project (formerly Open Web Application Security Project), is an online community that publishes open-source information and resources on IoT, system software and web application security. It is led by a non-profit called The OWASP Foundation spanning across the globe via hundreds of chapters and dozens of active projects.
OWASP CRS rules follow the convention, that rule IDs be unique. We are thus maintaining the official Rule ID reservation repository