Web Application Firewall

Web Application Firewall.

Collect and correlate WAF telemetry today. Automated WAF response arrives with Fabric Action in MVP2.

Collect WAF telemetry today

WAF logs are ingested now, on MVP1. The Universal Log Parser is vendor-agnostic, so WAF syslog is normalised to OCSF v1.3 and enters the same detection pipeline as your firewall, endpoint, and identity telemetry. No separate WAF module, no waiting.

  • --Any WAF that emits syslog, including UBIKA WAAP
  • --OCSF v1.3 normalisation for WAF block and alert events
  • --PII scrubbed on-premise before anything leaves your network
  • --Write a custom parser for an unrecognised WAF format in minutes

Correlated web attack detection

WAF verdicts are not read in isolation. Sigma correlates them against endpoint, network, and authentication telemetry, so a blocked request that precedes a successful login becomes one incident rather than two disconnected alerts.

  • --OWASP Top 10 patterns mapped to MITRE ATT&CK
  • --SQL injection, XSS, and path traversal surfaced from WAF events
  • --Correlated with authentication events to catch credential stuffing
  • --G-Score contribution weighted by verdict volume and severity

Automated WAF response: Fabric Action, MVP2

What is not live yet is autonomous response on the WAF itself. That arrives with Fabric Action in MVP2, where the UBIKA Web Application Firewall is one of four response components alongside the Stormshield firewall, the HAProxy load balancer, and Wallix privileged access management.

  • --Stormshield Firewall: response driver live today
  • --HAProxy Load Balancer: MVP2
  • --UBIKA Web Application Firewall: MVP2
  • --Wallix Privileged Access Management: MVP2
See how it all fits together →

Reclaim your security data.

60-day full-platform trial. No credit card. No inbound firewall changes. Live in under an hour.

Start Free TrialTalk to Sales →
Chat with us