vigie-waf
A high-performance web application firewall built with Rust
High-performance Forwarding
P95 latency is only 6.92ms at 200 concurrent connections, 125.18ms at 500, and 410.16ms at 1000.
Low Resource Overhead
Memory usage is about 20m to 500m, and CPU usage is about 0.35% to 1.5%, suitable for long-running edge deployment.
Dynamic Crawler Defense
Blocks forged search engine crawlers, supports configurable blacklist duration, and allows verified crawlers through for SEO.
Blockchain Proof of Work
Requires browsers to complete an adjustable computation challenge on access, increasing the cost of large-scale real-browser attacks.
Custom Defense Scripts
Supports advanced custom policies that combine business traits, request paths, and risk conditions into field-specific defense rules.
Route Management
Configure multiple routes per site to provide unified entry-point protection for upstream services, static directories, and 301 / 302 redirects.
Certificate Management
Mainstream free SSL certificates usually expire in 90 days; automatic issuance, renewal, and deployment reduce manual misses and keep HTTPS available.
Blacklist and Whitelist
Configure blacklist and whitelist entries with validity periods by IP or domain to quickly allow trusted sources or block risky traffic.
Web Attack Defense
Covers SQL injection, XSS, code injection, command injection, path traversal, SSRF, XXE, backdoors, RCE, CRLF injection, LDAP / XPATH injection, and other common web attacks to reduce probing and exploitation risk at the business entry point.
