vigie-waf

A high-performance web application firewall built with Rust

Get StartedCustom LUA Scripts

High-performance Forwarding

P95 latency is only 6.92ms at 200 concurrent connections, 125.18ms at 500, and 410.16ms at 1000.

Low Resource Overhead

Memory usage is about 20m to 500m, and CPU usage is about 0.35% to 1.5%, suitable for long-running edge deployment.

Dynamic Crawler Defense

Blocks forged search engine crawlers, supports configurable blacklist duration, and allows verified crawlers through for SEO.

Blockchain Proof of Work

Requires browsers to complete an adjustable computation challenge on access, increasing the cost of large-scale real-browser attacks.

Custom Defense Scripts

Supports advanced custom policies that combine business traits, request paths, and risk conditions into field-specific defense rules.

Route Management

Configure multiple routes per site to provide unified entry-point protection for upstream services, static directories, and 301 / 302 redirects.

Certificate Management

Mainstream free SSL certificates usually expire in 90 days; automatic issuance, renewal, and deployment reduce manual misses and keep HTTPS available.

Blacklist and Whitelist

Configure blacklist and whitelist entries with validity periods by IP or domain to quickly allow trusted sources or block risky traffic.

Web Attack Defense

Covers SQL injection, XSS, code injection, command injection, path traversal, SSRF, XXE, backdoors, RCE, CRLF injection, LDAP / XPATH injection, and other common web attacks to reduce probing and exploitation risk at the business entry point.