# Gcore WAAP > Protect websites, web applications, and APIs against application-layer attacks, bots, API abuse, and vulnerabilities using Gcore WAAP with real-time traffic inspection, WAF policies, behavioral analysis, rate limiting, bot management, API discovery, IP allowlists/denylists, and threat intelligence. - [Overview](https://docs.gcore.com/waap/overview.md): Protect websites, web applications, and APIs against application-layer attacks, bots, API abuse, and vulnerabilities using Gcore WAAP with real-time traffic inspection, WAF policies, behavioral analysis, rate limiting, bot management, API discovery, IP allowlists/denylists, and threat intelligence. ## Getting started - [Configure WAAP for a new domain](https://docs.gcore.com/waap/getting-started/configure-waap-for-a-domain.md): Create a Gcore CDN resource with WAAP enabled by specifying domain name, origin server IP or hostname, origin authentication type, and custom port settings, then update DNS records with the generated CNAME to route traffic through WAAP for Layer 7 DDoS protection and web application security, or use the REST API to list WAAP domains and manage their protection mode. - [Manage domains protected with WAAP](https://docs.gcore.com/waap/getting-started/manage-domains.md): Manage WAAP-protected domains by checking status, disabling WAAP via CDN settings, and deleting inactive domains via Customer Portal or REST API. - [Billing](https://docs.gcore.com/waap/getting-started/billing.md): Configure WAAP billing plans (Free, Start, Pro, Enterprise) with feature availability for IP Firewall, Default Rules, Custom Rules, Bot Management, Threat Intelligence, and API Security; manage Domain/Zone billing units representing CDN resources with single WAAP configurations. ## Analytics - [WAAP Analytics](https://docs.gcore.com/waap/analytics/waap-analytics.md): Monitor WAAP-protected domains and APIs with Analytics Dashboard, Events investigation, and Domains coverage views displaying security posture, attack detection, mitigation actions, and traffic patterns in UTC timezone. - [Dashboard](https://docs.gcore.com/waap/analytics/dashboard.md): Monitor WAAP traffic across account-level and domain-level scopes using Dashboard metrics including total requests, detected attacks, prevented attacks, passed requests, traffic timeline, and top activity indicators by source country, attacker, target, and triggered rules. - [Events](https://docs.gcore.com/waap/analytics/events.md): Investigate HTTP requests and security events in WAAP via Customer Portal using filters for time range, event type, decision, optional action, country, IP address, path, HTTP method, and request identifiers, or via REST API using the analytics requests endpoint. - [Domains](https://docs.gcore.com/waap/analytics/domains.md): Manage protected assets in WAAP by selecting domains to isolate analytics, security events, and incident investigation for specific applications, APIs, and services across production, staging, and multi-tenant environments. ## Firewall - [Access control](https://docs.gcore.com/waap/firewall/access-control.md): Configure WAAP Firewall allowed and blocked IP lists to permit or deny traffic from specific IPv4, IPv6 addresses, or IP ranges before requests reach your application. - [IP allowlist and blocklist](https://docs.gcore.com/waap/firewall/ip-allowlist-and-blocklist.md): Manage WAAP Firewall IP allowlist and blocklist rules to permit or deny traffic from specific IPv4 and IPv6 addresses or IP ranges via Customer Portal or via REST API. - [IP Reputation](https://docs.gcore.com/waap/firewall/ip-reputation.md): Configure IP Reputation policies in Gcore WAAP via Customer Portal or REST API to block or challenge traffic from TOR networks, proxy networks, hosting services, VPNs, malicious bots, suspicious NAT ranges, external reputation block lists, and CDN infrastructure. - [Check IP](https://docs.gcore.com/waap/firewall/check-ip.md): Check IP reputation tags and detection activity in WAAP Firewall, viewing local and global reputation tags (suspectedautomation, rapidbehaviour, ipinjectedfastclient, lowriskip) assigned to detected IP addresses with timestamps and associated domains. - [L7 DDoS protection](https://docs.gcore.com/waap/ddos-protection.md): Detect and mitigate Layer 7 DDoS attacks on web applications, websites, and APIs using WAAP Monitoring and Protection modes with automatic DDoS mode activation based on global traffic thresholds and attack pattern analysis. ## Default Rules - [WAAP policies](https://docs.gcore.com/waap/waap-policies.md): Configure WAAP policy groups to block malicious traffic, common attack patterns, data breaches, unauthorized access, suspicious IPs, and bot traffic by enabling or disabling specific policies. - [OWASP threats](https://docs.gcore.com/waap/waap-policies/waf-and-owasp-top-threats.md): Configure OWASP Threats policies in Gcore WAAP via Customer Portal toggles or REST API to view and enable or disable individual WAF security rules for a domain. - [Behavioral WAF](https://docs.gcore.com/waap/waap-policies/behavioral-waf.md): Configure Behavioral WAF policies in Gcore WAAP via Customer Portal or REST API to enable or disable brute-force, probing, obfuscated attack, and repeated violations protection for a domain. - [CMS protection](https://docs.gcore.com/waap/waap-policies/cms-protection.md): Configure CMS Protection policies in Gcore WAAP via Customer Portal or REST API to allow CMS admin sessions and block WordPress exploits, or allowlist admin IP addresses using firewall rules. ## Custom Rules - [WAAP rules](https://docs.gcore.com/waap/waap-rules.md): Create WAAP firewall rules, custom rules, and advanced rules to inspect web requests by IP address, country, request length, strings, SQL injection patterns, XSS payloads, and predefined tags, then apply actions like block, allow, or CAPTCHA challenge. - [Custom Rules](https://docs.gcore.com/waap/waap-rules/custom-rules.md): Create and manage WAAP custom rules to filter requests by IP, country, URL, and user agent via Customer Portal or REST API. - [Rate-Limiting](https://docs.gcore.com/waap/waap-rules/advanced-rules/advanced-rate-limiting-rules.md): Configure rate-limiting rules in WAAP using the request.limit_rate method to control request counts by time window, IP origin, URL patterns, request methods, response status codes, aggregation scope, and tags via REST API or Python and Go SDKs. ## Advanced rules - [Advanced Rules](https://docs.gcore.com/waap/waap-rules/advanced-rules.md): Create and manage WAAP advanced rules using Common Expression Language (CEL) syntax via REST API or Python and Go SDKs, with If/Then conditions, source field objects, and actions including allow, block, captcha, handshake, and tag. - [Advanced rule objects and attributes](https://docs.gcore.com/waap/waap-rules/advanced-rules/advanced-rule-objects.md): Configure advanced rule objects and attributes including client_data fingerprint, request rate_limit with content_type/interval/ip_list/method_list/requests/scope/status_list/url parameters, and response headers/status for WAAP rule conditions. - [Source field objects in advanced rule expressions](https://docs.gcore.com/waap/waap-rules/advanced-rules/source-field-objects.md): Configure advanced rule expressions using source field objects (request.headers, request.ip, request.uri, request.path, request.method, request.origin_ip, request.ja3, request.ja4) with single-quoted string values in WAAP rule conditions. ## Tag rules - [Tag rules](https://docs.gcore.com/waap/waap-rules/custom-rules/tag-rules.md): Create tag-based and tag-generating rules in WAAP custom rules to filter incoming traffic using predefined tags, user-defined tags, request headers, and cookies for blocking or allowing requests to domains. - [Reserved tags](https://docs.gcore.com/waap/waap-rules/custom-rules/tag-rules/reserved-tags.md): Configure reserved tags in WAAP custom rules to trigger specific actions - general tags (Registered, Logged In, Paid, Monitor, Login Page, Malicious Activity, Item Added to Cart) and API protection tags (API Privileged Access, API Admin Access, Auth Endpoint, Ignore Email Address Detection) using conditions like IP address, session cookies, or HTTP response headers. - [Predefined tags and their descriptions](https://docs.gcore.com/waap/waap-rules/custom-rules/tag-rules/predefined-tags.md): Configure tag-based rules in WAAP using predefined behavioral tags including abnormaldynamicrequests, ajaxscraper, botnetclient, bruteforceattempt, captchafarmbotfp, automationdriver, and 40+ additional tags generated by heuristics and AI models to filter and sanction web requests via Customer Portal or API. ## Bot Management - [Bot Protection](https://docs.gcore.com/waap/troubleshooting/enable-troubleshoot-bot-protection.md): Enable Gcore WAAP bot protection using User-Agent detection, traffic source analysis, behavioral analysis, and headless browser detection to block unauthorized vulnerability scans; manage Known Bots allowlist and configure Lets Encrypt policy via Bot Management portal. - [Known Bots](https://docs.gcore.com/waap/waap-policies/known-bots.md): Configure Known Bots policies in Gcore WAAP via Customer Portal or REST API to set Allow or Policy-based mode for search engine crawlers, monitoring tools, and payment processor bots. - [Anti-automation and bot protection](https://docs.gcore.com/waap/waap-policies/anti-automation-and-bot-protection.md): Configure Anti-automation and Bot Protection policies in Gcore WAAP via Customer Portal or REST API to enable or disable anti-spam, traffic anomaly, automated clients, headless browser, anti-scraping, and vulnerability scanner defenses. - [Invalid user agent and Unknown user agent](https://docs.gcore.com/waap/waap-policies/invalid-user-agent-and-unknown-user-agent.md): Configure Invalid user agent and Unknown user agent WAAP policies to block or challenge requests with missing or non-standard user-agent headers via Customer Portal or REST API. ## Threat Intelligence ## Security Insights - [Security Insights](https://docs.gcore.com/waap/threat-intelligence/security-insights/security-insights.md): Enable Security Insights notifications in WAAP to identify domain misconfigurations, rule mismanagement, and security vulnerabilities with system-generated recommendations for Enterprise plan domains. - [View and investigate insights](https://docs.gcore.com/waap/threat-intelligence/security-insights/view-insights.md): View and investigate WAAP Security Insights including Attack on disabled policy and Allowed high-risk IP insight types, filtered by status (Unread, Read, Closed) and displayed with description, recommendation, IP address or Policy ID, and alert timestamps in the Gcore Customer Portal. - [Manage insight status](https://docs.gcore.com/waap/threat-intelligence/security-insights/manage-insights.md): Manage WAAP security insight status via Customer Portal or REST API - mark as read, close, reopen insights, and create silence rules to suppress notifications. - [Manage Silence Rules](https://docs.gcore.com/waap/threat-intelligence/security-insights/manage-silence-rules.md): Update and delete WAAP security insight silence rules via Customer Portal or REST API to change expiry, comment, or re-enable suppressed notifications. - [TLS fingerprinting with JA3 and JA4](https://docs.gcore.com/waap/threat-intelligence/tls-fingerprinting.md): Use JA3 and JA4 TLS fingerprinting in WAAP to identify bots by network stack, view fingerprints in events, and create advanced rules to block botnets by TLS client identity via Customer Portal or REST API. - [IP Spotlight](https://docs.gcore.com/waap/ip-security/ip-spotlight.md): Analyze IP addresses using IP Spotlight threat analytics to retrieve risk assessment scores, global and domain activity, WHOIS data, botnet involvement, and threat tags (SQL injection, DDoS, headless browsers) for WAAP policy configuration and WAF rule creation. ## API Protection - [API discovery and protection](https://docs.gcore.com/waap/api-discovery-and-protection.md): Configure Gcore WAAP API Discovery, API base paths, and reserved tags to detect API endpoints, specify protection rules, and control access by user role. - [API discovery](https://docs.gcore.com/waap/api-discovery-and-protection/api-discovery.md): Manage REST API endpoints in WAAP domains via Customer Portal or REST API - add, update, and delete API paths, and configure API Discovery scan settings. - [Configure API access and protection with reserved tags](https://docs.gcore.com/waap/api-discovery-and-protection/configure-api-access-with-reserved-tags.md): Configure API protection with reserved tags (API Privileged Access, API Admin Access, Indicate API Privileged User, Indicate API Admin User, Auth Endpoint, Ignore Email Address Detection, Ignore Phone Number Detection, Ignore CCN Detection, Ignore SSN Detection) via API Discovery or custom rules to categorize and manage API endpoint access by authorization level. - [Manually add endpoints to the API base path](https://docs.gcore.com/waap/api-discovery-and-protection/configure-api-base-path.md): Configure API base path endpoints in WAAP domains by manually adding recursive paths to define communication routes for API request protection, with support for domain-wide API settings or specific endpoint paths via the Customer Portal or API. - [Advanced API protection](https://docs.gcore.com/waap/waap-policies/advanced-api-protection.md): Configure Advanced API Protection policies in Gcore WAAP via Customer Portal or REST API to enable auth token protection, sensitive data exposure blocking, invalid API traffic filtering, API-level authorization, and non-baselined request blocking for Enterprise plan domains. - [Protocol validation](https://docs.gcore.com/waap/waap-policies/protocol-validation.md): Configure Protocol Validation policies in Gcore WAAP via Customer Portal or REST API to block clients that tamper with service calls or send malformed HTTP requests that violate RFC standards. ## Response pages - [Response pages](https://docs.gcore.com/waap/response-pages.md): Configure WAAP response pages including Browser validation, Enable cookies, Enable JavaScript, Captcha, Block, and Block CSRF pages triggered by WAAP policies and custom rules, with customizable priority order and corporate branding options. - [Create custom response pages](https://docs.gcore.com/waap/response-pages/create-custom-response-pages.md): Create custom WAAP response pages for Block, Block CSRF, Captcha, Enable cookies, Browser validation, and Enable javascript page types via Customer Portal or REST API, configuring browser title, page title, and message per page type. - [Manage custom response pages](https://docs.gcore.com/waap/response-pages/manage-custom-response-pages.md): Manage custom response pages in Gcore WAAP - view, update, and delete page sets and assign them to domains via the Customer Portal or via REST API. - [View WAAP statistics in Grafana](https://docs.gcore.com/waap/view-waap-statistics-in-grafana.md): Install and configure the Gcore WAAP datasource plugin in Grafana to visualize total requests and total bytes metrics for WAAP-protected domains with hourly or daily granularity. ## FAQs - [Frequently asked questions](https://docs.gcore.com/waap/frequently-asked-questions.md): Configure WAAP JavaScript injection, required cookies, and storage variables for bot detection and session management. - [How does WAAP JavaScript injection work?](https://docs.gcore.com/waap/frequently-asked-questions/javascript-injection.md): Configure WAAP JavaScript injection to collect client fingerprint, browser-type signature, and GUI interaction data via cookie-based tracking and /sbbi/ endpoint requests for bot detection and malicious traffic filtering. - [What are the required cookies used by WAAP?](https://docs.gcore.com/waap/frequently-asked-questions/waap-cookies.md): Configure Gcore WAAP cookies for session management, CSRF protection, CAPTCHA validation, DDoS protection, and load balancing using Set-Cookie response headers with HttpOnly, SameSite, and path attributes. - [What storage variables does WAAP use?](https://docs.gcore.com/waap/frequently-asked-questions/storage-variables.md): Configure WAAP local storage variables including cnv, csr, otr, and altutgv2 for CAPTCHA validation, shell mouse script tracking, and user tag token management in web browsers. - [Troubleshooting](https://docs.gcore.com/waap/troubleshooting.md): Troubleshoot Gcore WAAP bot protection enablement, blocked user access, and 5xx server errors with root cause analysis and resolution steps. - [Troubleshoot blocked users](https://docs.gcore.com/waap/troubleshooting/troubleshoot-blocked-users.md): Troubleshoot WAAP blocked users by searching Events requests table with Reference ID, IP address, and date-time metadata to inspect triggered policies, custom rules, HTTP method, client IP, country of origin, and user agent details in the Customer Portal. - [Troubleshoot 5xx errors](https://docs.gcore.com/waap/troubleshooting/troubleshoot-5xx-errors.md): Diagnose WAAP 5xx server errors including 543 errors caused by origin server downtime, firewall blocks, connection timeouts, and incorrect configuration settings.