Azure WAF operations
Read WAF blocks in KQL, qualify false positives, then add targeted OWASP/CRS exclusions or custom rules with evidence.
From noisy blocks to defensible WAF changes.
- 01 Azure WAF: read Application Gateway blocks with KQL without chasing every layer
- 02 WAF and KQL: identify a false positive before creating an exclusion
- 03 Azure WAF: add an OWASP/CRS exclusion without weakening all protection
- 04 Azure WAF: when to use custom rules before managed OWASP rules
- 05 Azure WAF: frame an emergency custom rule without losing evidence
- 06 Azure WAF: move a policy from Detection to Prevention without breaking traffic
- 07 Azure WAF: prepare an evidence pack before a policy PR
- 08 Azure WAF: diagnose rate limiting before increasing the threshold
- 09 Azure WAF: validate a managed rule upgrade before switching to Prevention
- 10 Azure WAF: diagnose a file upload before raising size limits
- 11 Azure WAF Bot Manager: qualify a bot before adding an allow rule
- 12 Azure WAF: diagnose inconsistent policy enforcement after deployment