Security Controls Assessment (SCA)
Purpose: Evaluate WAF’s ability to detect and mitigate known attack techniques.
Tests Include:
-
Signature effectiveness (XSS, SQLi, RCE, etc.)
-
Custom payload detection
-
Evasion technique handling
-
Entity-level protection (parameters, headers)
-
Policy tuning gaps
Outcome: Risk Mitigation Score (RMS) for control coverage.
Bot Protection Assessment
Purpose: Evaluate how WAF handles automated threats.
Tests Include:
-
OWASP Automated Threats (carding, scraping, credential stuffing)
-
Bot client simulation (headless browsers, replay tools)
-
CAPTCHA and JS challenge handling
Outcome: Bot defense score and bypass feasibility.
Policy Configuration Analysis
Purpose: Validate WAF policy logic and alignment to application behavior.
Tests Include:
-
Policy enforcement review
-
Positive security model checks
-
Custom rules review (regex, IP, Geo)
Outcome: Policy quality score and hardening recommendations.
Custom Use Case Simulation
Purpose: Validate WAF in real-world incident scenarios.
Tests Include:
-
Simulated red team campaigns
-
Attack chain testing (multi-step exploit)
-
Application-specific threat modeling
Outcome: Application-aware mitigation score.
