Guides

Plain-English WAF explainers for campus and agency teams. Start with count mode, then operate without breaking forms.

Getting started

Concepts & decisions

Operations & false positives

Campus DDoS response: keep .edu sites up under flood
Campus DDoS response for .edu and agency sites — first-hour playbook, origin IP lock-down, count→promote during recovery, and status/comms when the flood hits.
Hide your origin IP behind a WAF (and allowlist edge IPs only)
Origin IP bypass DDoS walks around your edge. Hide the origin IP behind a WAF and allowlist edge IPs only — the durable fix for campus and agency sites.
WAF false positives on forms: stop blocking legitimate POSTs
Why WAFs block registration, admissions, and government forms — multipart uploads, CSRF tokens, odd field names, payment callbacks — and how count-first stopping of false positives works.
WAF bot management for campus and agency sites
WAF bot management for campuses and agencies — stop scrapers, admissions form spam, and credential stuffing without day-one false positives. Count → promote.
Virtual patching websites with a managed WAF
Virtual patching at the edge buys time before CMS updates land. Managed WAF rules start in count; promote what's safe to block — Copilot explains, you click.
Emergency virtual patching when a CMS CVE drops
Friday CMS CVE? Put an emergency virtual patch at the edge in count first, then promote what's safe while WordPress and Drupal teams patch. Copilot explains — you click.
What a WAF 403 page means (and why you start in count)
A branded 403 is what visitors see after you promote a rule to block. Count mode comes first. Promote Copilot explains what's safe — you still click once.

Platforms

Public sector

Security basics