Pentestas / help

WAF Detector

WAF Detector — Identify web application firewalls and edge security products.
WAF Detector in the Pentestas Security tools UI.

Category: Web

Sends crafted probes and inspects headers/bodies/behavior to fingerprint Cloudflare, Akamai, AWS WAF, Imperva, F5, and other common WAFs.

Inputs

HTTP(S) URL.

How to run it

  1. Open Security tools → WAF Detector.
  2. Enter target URL → run.
  3. Note product + confidence before planning a full scan.

Output

Detected product name(s), evidence headers/cookies, confidence.

Notes

  • A WAF does not mean 'safe' — it changes payload strategy. Authenticated scans still matter.
  • /tools/subdomain-finder/
  • /scans/web-app-scan/

← Back to Security tools overview