
Completed hands-on test
Coraza Caddy Docker Test: CRS 4.25.0 Results
Hands-on Coraza and Caddy Docker test with pinned versions, OWASP CRS 4.25.0, ten clean and attack-like requests, HTTP results, logs, and build constraints.
Open lab noteOriginal WAFWiki labs
Reproduce version-pinned ModSecurity and Coraza tests, inspect HTTP 200/403 results, and separate observed evidence from methodology.

Completed hands-on test
Hands-on Coraza and Caddy Docker test with pinned versions, OWASP CRS 4.25.0, ten clean and attack-like requests, HTTP results, logs, and build constraints.
Open lab note
Completed hands-on test
Original ModSecurity vs Coraza Docker comparison using the same OWASP CRS 4.25.0, upstream, and 20 HTTP decisions across clean, SQLi, XSS, query, and JSON cases.
Open lab note
Completed hands-on test
Hands-on JSON request-body test showing how ModSecurity and Coraza handled one clean body plus controlled SQLi-like and XSS-like fields under OWASP CRS 4.25.0.
Open lab note
Completed hands-on test
Clean-traffic regression test for ModSecurity and Coraza with 12 HTTP 200 decisions, six input patterns, zero blocking mismatches, and one repeatable numeric Host warning.
Open lab note
Completed hands-on test
Local Docker response-time baseline with 40 sequential requests per path for a direct upstream, ModSecurity NGINX, and Coraza Caddy, plus memory snapshots and limits.
Open lab note
Completed smoke test
A reproducible local smoke test for OWASP CRS with ModSecurity and NGINX, covering clean traffic, a SQLi-like lab request, evidence logs, and rollout caveats.
Open lab note
Methodology
A vendor-neutral WAF workflow diagram explaining client traffic, inspection, decision logic, allowed upstream traffic, blocked requests, and evidence capture.
Open lab note
Methodology
A visual comparison of self-hosted WAF ownership versus managed cloud or edge WAF ownership, focused on traffic path, operations, logging, and rollback.
Open lab note