Protecting the web with open source Web Application Firewalls

Open source Web Application Firewalls (WAFs) protect millions of applications across the Internet. Yet the ecosystem is fragmented across projects, rulesets, integrations, and communities.

OWASP brings them together.

As the world’s leading open community for application security, OWASP provides a neutral home where WAF projects, rule authors, researchers, vendors, and users can collaborate to improve the security of the entire ecosystem. From detection rules and testing methodologies to documentation, benchmarks, and best practices, this initiative aims to connect the people and projects shaping the future of open source WAFs.

Whether you’re building a WAF, maintaining rules, integrating security into your platform, or deploying protection in production, you’re part of the community.

Welcome to the Open Source WAF initiative at OWASP.

map[class:object-cover object-center src:images/home/hero/waf-security.png]

ModSecurity

Industry-leading WAF engine

Coraza

Next-gen Go-based WAF

Core Rule Set

Comprehensive detection rules

Open Community

Global collaboration

One Mission, Three Major and Many Smaller Projects

The OWASP WAF family is the place for existing and new application firewall projects. The community is united by a common goal of protecting web applications from attacks.

map[class:aspect-square object-contain object-center w-[75%] src:images/home/features/crs.png]

The Intelligence

Generic Attack Detection

OWASP CRS: The Rule Set That Powers Protection

The OWASP CRS (formerly OWASP ModSecurity Core Rule Set) provides generic, enterprise-grade attack detection rules that work seamlessly with ModSecurity, Coraza and compatible commercial engines. Maintained by a global community of security experts, CRS protects against security risks as decribed by the OWASP Top 10 and many other attack vectors. With continuous updates and extensive coverage, CRS is the dominant rule set in the industry.
CRS is an OWASP flagship project.
https://coreruleset.org

map[class:aspect-square object-contain object-center w-[75%] src:images/home/features/modsecurity.png]

The Original

Industry Standard WAF Engine

ModSecurity: The Original Open Source WAF

ModSecurity is the original open-source Web Application Firewall that has been protecting web applications since 2002. It is known for its robustness and extensive deployments on Apache and Nginx worldwide, ModSecurity provides a powerful rule-based engine for rules in its SecRule domain specific language. It’s the foundation that started the open-source WAF movement and continues to be a trusted solution for organizations of all sizes.
ModSecurity is an OWASP production level project.
https://modsecurity.org

map[class:aspect-square object-contain object-center w-[75%] src:images/home/features/coraza.png]

The New Generation

Modern, Fast, and Cloud-Native

Coraza: Built for Modern Infrastructure

Coraza is a next-generation Web Application Firewall built from the ground up in Go, designed for modern cloud-native environments. With near-full ModSecurity compatibility, Coraza offers strong performance, easier deployment, and better integration with contemporary web architectures. It brings the power of ModSecurity to cloud-native applications.
Coraza is an OWASP production level project.
https://coraza.io

map[class:aspect-square object-contain object-center w-[75%] src:images/home/features/coraza.png]

The Dashboard

Ambitious attempt to bring a GUI to WAF management

WAFControl: Managing Your WAF

OWASP WAFControl provides an open source web-based dashboard that simplifies the deployment, configuration, monitoring, and management of ModSecurity and the OWASP Core Rule Set.
WAFControl is an OWASP incubator level project.
https://wafcontrol.org/

map[class:aspect-square object-contain object-center w-[75%] src:images/home/features/coraza.png]

Rules Optimization

Rebalancing the rules to improve performance

WARM (WAF Advanced Rule Set Management): Optimizing Your WAF

OWASP WARM tries to apply machine learning and automation to improve the accuracy, tuning, and operational management of WAF rule sets. The project is based on a series of scholarly articles and promises to deliver to OSS.
WARM is an OWASP incubator level project.
https://owasp.org/www-project-waf-advanced-ruleset-management/

map[class:aspect-square object-contain object-center w-[75%] src:images/home/features/coraza.png]

Analysis

What a WAF needs to cover

WAFEC (WAF Evaluation Criteria): Picking the right WAF

OWASP WAFEC is an OWASP project that defines a vendor-neutral framework for evaluating, testing, and comparing the capabilities and effectiveness of Web Application Firewalls. Truth be told it has not seen an update in many years and could be with a few enthusiasts breathing new life into it.
WAFEC is an OWASP incubator level project.
https://owasp.org/www-project-wafec/

map[class:aspect-square object-contain object-center w-[75%] src:images/home/features/coraza.png]

Fuzzying

Mutating the payloads to find bypasses

WAF-A-MoLE: Fuzzying payloads for fun and profit

OWASP WAF-A-MoLE is a security testing tool that uses guided mutation fuzzing to discover WAF detection bypasses and assess the robustness of Web Application Firewalls against evasive attacks.
WAF-A-MoLE is an OWASP incubator level project.
https://owasp.org/www-project-waf-a-mole/

OWASP

OWASP, the Open Worldwide Application Security Project (formerly Open Web Application Security Project), is an online community that publishes open-source information and resources on IoT, system software and web application security. It is led by a non-profit called The OWASP Foundation spanning across the globe via hundreds of chapters and dozens of active projects.

SecRule Rule Range Reservation

OWASP CRS rules follow the convention, that rule IDs be unique. We are thus maintaining the official Rule ID reservation repository