# Gcore WAAP > Protect websites, web applications, and APIs against application-layer attacks, bots, API abuse, and vulnerabilities using Gcore WAAP with real-time traffic inspection, WAF policies, behavioral analysis, rate limiting, bot management, API discovery, IP allowlists denylists, and threat intelligence. - [Overview](https://docs.gcore.com/waap/overview.md): Protect websites, web applications, and APIs against application-layer attacks, bots, API abuse, and vulnerabilities using Gcore WAAP with real-time traffic inspection, WAF policies, behavioral analysis, rate limiting, bot management, API discovery, IP allowlists denylists, and threat intelligence. ## Getting started - [Configure WAAP for a new domain](https://docs.gcore.com/waap/getting-started/configure-waap-for-a-domain.md): Add a domain to Gcore WAAP protection from the WAAP Domains page or by enabling WAAP on a CDN resource, then configure DNS, verify traffic in Monitoring mode, allow admin IPs and known bots, and switch to Protection mode via Customer Portal or REST API. - [Manage domains protected with WAAP](https://docs.gcore.com/waap/getting-started/manage-domains.md): Manage WAAP-protected domains by checking status, disabling WAAP via CDN settings, and deleting inactive domains via Customer Portal or REST API. - [Billing](https://docs.gcore.com/waap/getting-started/billing.md): Compare WAAP Free, Start, Pro, and Enterprise plans, manage self-serve plan changes and add-ons, and learn about Managed WAAP and Detection and Response professional services. ## Analytics - [WAAP Analytics](https://docs.gcore.com/waap/analytics/waap-analytics.md): Monitor WAAP-protected domains and APIs with Analytics Dashboard, Events investigation, and Domains coverage views displaying security posture, attack detection, mitigation actions, and traffic patterns in UTC timezone. - [Dashboard](https://docs.gcore.com/waap/analytics/dashboard.md): Monitor WAAP traffic across account-level and domain-level scopes using Dashboard metrics including total requests, detected attacks, prevented attacks, passed requests, traffic timeline, and top activity indicators by source country, attacker, target, and triggered rules. - [Events](https://docs.gcore.com/waap/analytics/events.md): Investigate HTTP requests and security events in WAAP via Customer Portal using filters for time range, event type, decision, optional action, country, IP address, path, HTTP method, and request identifiers, or via REST API using the analytics requests endpoint. - [Domains](https://docs.gcore.com/waap/analytics/domains.md): Manage protected assets in WAAP by selecting domains to isolate analytics, security events, and incident investigation for specific applications, APIs, and services across production, staging, and multi-tenant environments. ## Firewall - [Access control](https://docs.gcore.com/waap/firewall/access-control.md): Configure WAAP Firewall allowed and blocked IP lists to permit or deny traffic from specific IPv4, IPv6 addresses, or IP ranges before requests reach your application. - [IP allowlist and blocklist](https://docs.gcore.com/waap/firewall/ip-allowlist-and-blocklist.md): Manage WAAP Firewall IP allowlist and blocklist rules to permit or deny traffic from specific IPv4 and IPv6 addresses or IP ranges via Customer Portal or via REST API. - [IP Reputation](https://docs.gcore.com/waap/firewall/ip-reputation.md): Configure IP Reputation policies in Gcore WAAP via Customer Portal or REST API to block or challenge traffic from TOR networks, proxy networks, hosting services, VPNs, malicious bots, suspicious NAT ranges, external reputation block lists, and CDN infrastructure. - [Check IP](https://docs.gcore.com/waap/firewall/check-ip.md): Check IP reputation tags and detection activity in WAAP Firewall, viewing local and global reputation tags (suspectedautomation, rapidbehaviour, ipinjectedfastclient, lowriskip) assigned to detected IP addresses with timestamps and associated domains. - [L7 DDoS protection](https://docs.gcore.com/waap/ddos-protection.md): Detect and mitigate Layer 7 DDoS attacks on web applications, websites, and APIs using WAAP Monitoring and Protection modes with automatic DDoS mode activation based on global traffic thresholds and attack pattern analysis. ## Default Rules - [WAAP policies](https://docs.gcore.com/waap/waap-policies.md): Configure WAAP policy groups to block malicious traffic, common attack patterns, data breaches, unauthorized access, suspicious IPs, and bot traffic by enabling or disabling specific policies. - [OWASP threats](https://docs.gcore.com/waap/waap-policies/waf-and-owasp-top-threats.md): Configure OWASP Threats policies in Gcore WAAP via Customer Portal or REST API, including CSRF behavior when www and non-www hostnames differ. - [Behavioral WAF](https://docs.gcore.com/waap/waap-policies/behavioral-waf.md): Configure Behavioral WAF policies in Gcore WAAP via Customer Portal or REST API to enable or disable brute-force, probing, obfuscated attack, and repeated violations protection for a domain. - [CMS protection](https://docs.gcore.com/waap/waap-policies/cms-protection.md): Configure CMS Protection policies in Gcore WAAP via Customer Portal or REST API to allow CMS admin sessions and block WordPress exploits, or allowlist admin IP addresses using firewall rules. ## Custom Rules - [WAAP rules](https://docs.gcore.com/waap/waap-rules.md): Create WAAP firewall rules, custom rules, and advanced rules to inspect web requests by IP address, country, request length, strings, SQL injection patterns, XSS payloads, and predefined tags, then apply actions like block, allow, or CAPTCHA challenge. - [Custom Rules](https://docs.gcore.com/waap/waap-rules/custom-rules.md): Create and manage WAAP custom rules and actions via Customer Portal or REST API, including how Allow skips all security checks. - [Rate-Limiting](https://docs.gcore.com/waap/waap-rules/advanced-rules/advanced-rate-limiting-rules.md): Configure rate-limiting rules in WAAP using the request.limit_rate method to control request counts by time window, IP origin, URL patterns, request methods, response status codes, aggregation scope, and tags via REST API or Python and Go SDKs. ## Advanced rules - [Advanced Rules](https://docs.gcore.com/waap/waap-rules/advanced-rules.md): Create and manage WAAP advanced rules using Common Expression Language (CEL) syntax via REST API or Python and Go SDKs, with If Then conditions, source field objects, and actions including allow, block, captcha, handshake, and tag. - [Advanced rule objects and attributes](https://docs.gcore.com/waap/waap-rules/advanced-rules/advanced-rule-objects.md): Configure advanced rule objects and attributes including client_data fingerprint, request rate_limit with content_type interval ip_list method_list requests scope status_list url parameters, and response headers status for WAAP rule conditions. - [Source field objects in advanced rule expressions](https://docs.gcore.com/waap/waap-rules/advanced-rules/source-field-objects.md): Configure advanced rule expressions using source field objects (request.headers, request.ip, request.uri, request.path, request.method, request.origin_ip, request.ja3, request.ja4) with single-quoted string values in WAAP rule conditions. ## Tag rules - [Tag rules](https://docs.gcore.com/waap/waap-rules/custom-rules/tag-rules.md): Create tag-based and tag-generating rules in WAAP custom rules to filter incoming traffic using predefined tags, user-defined tags, request headers, and cookies for blocking or allowing requests to domains. - [Reserved tags](https://docs.gcore.com/waap/waap-rules/custom-rules/tag-rules/reserved-tags.md): Configure reserved tags in WAAP custom rules to trigger specific actions - general tags (Registered, Logged In, Paid, Monitor, Login Page, Malicious Activity, Item Added to Cart, LLM Trigger) and API protection tags (API Privileged Access, API Admin Access, Auth Endpoint, Ignore Email Address Detection) using conditions like IP address, session cookies, or HTTP response headers. - [Predefined tags and their descriptions](https://docs.gcore.com/waap/waap-rules/custom-rules/tag-rules/predefined-tags.md): Configure tag-based rules in WAAP using predefined behavioral tags including abnormaldynamicrequests, ajaxscraper, botnetclient, bruteforceattempt, captchafarmbotfp, automationdriver, and 40+ additional tags generated by heuristics and AI models to filter and sanction web requests via Customer Portal or API. ## Bot Management - [Bot Protection](https://docs.gcore.com/waap/troubleshooting/enable-troubleshoot-bot-protection.md): Enable Gcore WAAP bot protection using User-Agent detection, traffic source analysis, behavioral analysis, and headless browser detection to block unauthorized vulnerability scans; manage Known Bots allowlist and configure Lets Encrypt policy via Bot Management portal. - [Known Bots](https://docs.gcore.com/waap/waap-policies/known-bots.md): Configure Known Bots policies in Gcore WAAP via Customer Portal or REST API, setting each verified bot to Allow or Policy-based by intent category. - [Anti-automation and bot protection](https://docs.gcore.com/waap/waap-policies/anti-automation-and-bot-protection.md): Configure Anti-automation and Bot Protection policies in Gcore WAAP via Customer Portal or REST API to enable or disable anti-spam, traffic anomaly, automated clients, headless browser, anti-scraping, and vulnerability scanner defenses. - [Invalid user agent and Unknown user agent](https://docs.gcore.com/waap/waap-policies/invalid-user-agent-and-unknown-user-agent.md): Configure Invalid user agent and Unknown user agent WAAP policies to block or challenge requests with missing or non-standard user-agent headers via Customer Portal or REST API. ## Threat Intelligence ## Security Insights - [Security Insights](https://docs.gcore.com/waap/threat-intelligence/security-insights/security-insights.md): Enable Security Insights notifications in WAAP to identify domain misconfigurations, rule mismanagement, and security vulnerabilities with system-generated recommendations for Enterprise plan domains. - [View and investigate insights](https://docs.gcore.com/waap/threat-intelligence/security-insights/view-insights.md): View and investigate WAAP Security Insights including Attack on disabled policy and Allowed high-risk IP insight types, filtered by status (Unread, Read, Closed) and displayed with description, recommendation, IP address or Policy ID, and alert timestamps in the Gcore Customer Portal. - [Manage insight status](https://docs.gcore.com/waap/threat-intelligence/security-insights/manage-insights.md): Manage WAAP security insight status via Customer Portal or REST API - mark as read, close, reopen insights, and create silence rules to suppress notifications. - [Manage Silence Rules](https://docs.gcore.com/waap/threat-intelligence/security-insights/manage-silence-rules.md): Update and delete WAAP security insight silence rules via Customer Portal or REST API to change expiry, comment, or re-enable suppressed notifications. - [TLS fingerprinting with JA3 and JA4](https://docs.gcore.com/waap/threat-intelligence/tls-fingerprinting.md): Use JA3 and JA4 TLS fingerprinting in WAAP to identify bots by network stack, view fingerprints in events, and create advanced rules to block botnets by TLS client identity via Customer Portal or REST API. - [IP Spotlight](https://docs.gcore.com/waap/ip-security/ip-spotlight.md): Analyze IP addresses using IP Spotlight threat analytics to retrieve risk assessment scores, global and domain activity, WHOIS data, botnet involvement, and threat tags (SQL injection, DDoS, headless browsers) for WAAP policy configuration and WAF rule creation. ## API Protection - [API discovery and protection](https://docs.gcore.com/waap/api-discovery-and-protection.md): Configure Gcore WAAP API Discovery, API base paths, and reserved tags to detect API endpoints, specify protection rules, and control access by user role. - [API discovery](https://docs.gcore.com/waap/api-discovery-and-protection/api-discovery.md): Manage REST API endpoints in WAAP domains via Customer Portal or REST API - add, update, and delete API paths, and configure API Discovery scan settings. - [Configure API Protection policies using reserved tags](https://docs.gcore.com/waap/api-discovery-and-protection/configure-api-access-with-reserved-tags.md): Configure API protection reserved tags for API-level authorization, Auth token protection, and Sensitive data exposure via Customer Portal or Gcore API. - [Manually add endpoints to the API base path](https://docs.gcore.com/waap/api-discovery-and-protection/configure-api-base-path.md): Configure the WAAP API base path to mark domain endpoints as API traffic via the Customer Portal or REST API. - [Advanced API protection](https://docs.gcore.com/waap/waap-policies/advanced-api-protection.md): Configure Advanced API Protection policies in Gcore WAAP via Customer Portal or REST API to enable auth token protection, sensitive data exposure blocking, invalid API traffic filtering, API-level authorization, and non-baselined request blocking for Enterprise plan domains. - [Protocol validation](https://docs.gcore.com/waap/waap-policies/protocol-validation.md): Configure Protocol Validation policies in Gcore WAAP via Customer Portal or REST API to block clients that tamper with service calls or send malformed HTTP requests that violate RFC standards. ## Response pages - [Response pages](https://docs.gcore.com/waap/response-pages.md): Configure WAAP response pages including Browser validation, Enable cookies, Enable JavaScript, Captcha, Block, and Block CSRF pages triggered by WAAP policies and custom rules, with customizable priority order and corporate branding options. - [Create custom response pages](https://docs.gcore.com/waap/response-pages/create-custom-response-pages.md): Create custom WAAP response pages for Block, Block CSRF, Captcha, Enable cookies, Browser validation, and Enable javascript page types via Customer Portal or REST API, configuring browser title, page title, and message per page type. - [Manage custom response pages](https://docs.gcore.com/waap/response-pages/manage-custom-response-pages.md): Manage custom response pages in Gcore WAAP - view, update, and delete page sets and assign them to domains via the Customer Portal or via REST API. - [View WAAP statistics in Grafana](https://docs.gcore.com/waap/view-waap-statistics-in-grafana.md): Install the Gcore Platform-EN Grafana plugin and visualize WAAP total requests and total bytes metrics in dashboards. ## Terraform - [Manage WAAP via Terraform v0](https://docs.gcore.com/waap/manage-waap-via-terraform.md): Create and manage Gcore WAAP domains, policies, custom, advanced, and firewall rules, API paths, response pages, and insight silences via Terraform v0. ## FAQs - [Frequently asked questions](https://docs.gcore.com/waap/frequently-asked-questions.md): Configure WAAP JavaScript injection, required cookies, and storage variables for bot detection and session management. - [How does WAAP JavaScript injection work?](https://docs.gcore.com/waap/frequently-asked-questions/javascript-injection.md): Configure WAAP JavaScript injection to collect client fingerprint, browser-type signature, and GUI interaction data via cookie-based tracking and sbbi endpoint requests for bot detection and malicious traffic filtering. - [What are the required cookies used by WAAP?](https://docs.gcore.com/waap/frequently-asked-questions/waap-cookies.md): Configure Gcore WAAP cookies for session management, CSRF protection, CAPTCHA validation, DDoS protection, and load balancing using Set-Cookie response headers with HttpOnly, SameSite, and path attributes. - [What storage variables does WAAP use?](https://docs.gcore.com/waap/frequently-asked-questions/storage-variables.md): Configure WAAP local storage variables including cnv, csr, otr, and altutgv2 for CAPTCHA validation, shell mouse script tracking, and user tag token management in web browsers. - [Troubleshooting](https://docs.gcore.com/waap/troubleshooting.md): Troubleshoot Gcore WAAP bot protection enablement, blocked user access, and 5xx server errors with root cause analysis and resolution steps. - [Troubleshoot blocked users](https://docs.gcore.com/waap/troubleshooting/troubleshoot-blocked-users.md): Troubleshoot WAAP blocked users by searching Events requests table with Reference ID, IP address, and date-time metadata to inspect triggered policies, custom rules, HTTP method, client IP, country of origin, and user agent details in the Customer Portal. - [Troubleshoot 5xx errors](https://docs.gcore.com/waap/troubleshooting/troubleshoot-5xx-errors.md): Diagnose WAAP 5xx server errors including 543 errors caused by origin server downtime, firewall blocks, connection timeouts, and incorrect configuration settings.