WAF Detector
Category: Web
Sends crafted probes and inspects headers/bodies/behavior to fingerprint Cloudflare, Akamai, AWS WAF, Imperva, F5, and other common WAFs.
Inputs
HTTP(S) URL.
How to run it
- Open Security tools → WAF Detector.
- Enter target URL → run.
- Note product + confidence before planning a full scan.
Output
Detected product name(s), evidence headers/cookies, confidence.
Notes
- A WAF does not mean 'safe' — it changes payload strategy. Authenticated scans still matter.
Related
- /tools/subdomain-finder/
- /scans/web-app-scan/
← Back to Security tools overview