Azure WAF operations
Read WAF blocks in KQL, qualify false positives, then add targeted OWASP/CRS exclusions or custom rules with evidence.
From noisy blocks to defensible WAF changes.
- 01 Azure WAF: read Application Gateway blocks with KQL without chasing every layer
- 02 WAF and KQL: identify a false positive before creating an exclusion
- 03 Azure WAF: add an OWASP/CRS exclusion without weakening all protection
- 04 Azure WAF: when to use custom rules before managed OWASP rules
- 05 Azure WAF: frame an emergency custom rule without losing evidence
- 06 Azure WAF: move a policy from Detection to Prevention without breaking traffic
- 07 Azure WAF: prepare an evidence pack before a policy PR
- 08 Azure WAF: diagnose rate limiting before increasing the threshold
- 09 Azure WAF: validate a managed rule upgrade before switching to Prevention