How CoreWAF works

Real-time dashboard

The dashboard shows requests, blocks, unique IPs, visit type and Under Attack status. Everything filterable by 24 hours, 7 days, 30 days or a custom range.

Spot traffic spikes, ongoing attacks and the mix of legitimate users, bots, search engines and AIs hitting your site.

Every block, one row

Review the latest blocked requests with date, IP, country, method, URL and reason. Spot a pattern? Add the IP or range to your blacklist in one click.

The log lets you audit what CoreWAF blocks and fine-tune your rules without guessing.

Bots and AIs under control

We classify every visit: search engines, LLMs, scrapers, crawlers and generic bots. See which AI and bot brands consume your bandwidth and how many requests you block.

Decide which bots can enter and what stays out. Even scrapers from OpenAI, Anthropic and Amazon are broken down.

Rules your way

Create rules by IP, CIDR range, country, brand, catalog, User-Agent and URL. Exact operators: contains, starts, ends and exact. No complex regex.

Whitelist has absolute priority: anything you mark as legitimate is never blocked, no matter what.

Under Attack: full block in one click

When under attack, enable Under Attack mode. CoreWAF challenges every visit with a JS challenge before letting it through, except your whitelist.

Turn it on when the storm hits and off when it passes. No individual rule changes, no restarts.

Try it on your domain. Free trial.

No credit card, no commitment. If it doesn't convince you, close the account and that's it.