<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Divinelab.io</title>
    <description>The latest articles on DEV Community by Divinelab.io (@divinelab).</description>
    <link>https://dev.to/divinelab</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4164185%2F988b8a49-76e7-451d-88f6-6439ace462d7.png</url>
      <title>DEV Community: Divinelab.io</title>
      <link>https://dev.to/divinelab</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/divinelab"/>
    <language>en</language>
    <item>
      <title>How to Block OWASP Top 10 Attacks (Without Breaking Legitimate Traffic)</title>
      <dc:creator>Divinelab.io</dc:creator>
      <pubDate>Mon, 05 Oct 2026 15:11:51 +0000</pubDate>
      <link>https://dev.to/divinelab/how-to-block-owasp-top-10-attacks-without-breaking-legitimate-traffic-2lf6</link>
      <guid>https://dev.to/divinelab/how-to-block-owasp-top-10-attacks-without-breaking-legitimate-traffic-2lf6</guid>
      <description>&lt;p&gt;Most developers turn off Web Application Firewalls (WAFs) within their first week of deployment. &lt;/p&gt;

&lt;p&gt;The reason is almost always the same: &lt;strong&gt;false positives&lt;/strong&gt;. &lt;/p&gt;

&lt;p&gt;Traditional WAFs rely on crude single-regex pattern matching. If a user submits a blog comment containing a single quote, a search query with the word &lt;code&gt;OR&lt;/code&gt;, or an admin saves rich HTML inside a CMS, an overly aggressive WAF will immediately drop the request with a &lt;code&gt;403 Forbidden&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;In this tutorial, we are going to use &lt;a href="https://github.com/divinelabio/aegis" rel="noopener noreferrer"&gt;Aegis&lt;/a&gt;—an open-source, self-hosted Web Application Firewall (WAF) and reverse proxy—to block OWASP Top 10 attacks using &lt;strong&gt;cumulative anomaly scoring&lt;/strong&gt;. We will walk through the exact steps to baseline your traffic, configure paranoia levels, test exploit detection, and surgically tune false alarms.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F35561pozdp09609tw1uu.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F35561pozdp09609tw1uu.png" alt="Aegis WAF Dashboard" width="800" height="403"&gt;&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  What Attacks Does OWASP CRS Cover?
&lt;/h2&gt;

&lt;p&gt;Under the hood, Aegis pairs the Go-native &lt;strong&gt;Coraza engine&lt;/strong&gt; with the &lt;strong&gt;OWASP Core Rule Set (CRS v4)&lt;/strong&gt; to protect against the most common web exploit vectors:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;SQL Injection (SQLi):&lt;/strong&gt; Malicious SQL syntax inserted into parameters to extract or destroy database records.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Cross-Site Scripting (XSS):&lt;/strong&gt; Injected client-side scripts that hijack user sessions or steal credentials.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Remote Code Execution (RCE):&lt;/strong&gt; Shell commands or payload injections targeting underlying server interpreters.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Local File Inclusion (LFI) &amp;amp; Path Traversal:&lt;/strong&gt; Directory traversal attempts (e.g., &lt;code&gt;../../etc/passwd&lt;/code&gt;) targeting internal system files.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Server-Side Request Forgery (SSRF):&lt;/strong&gt; Forged internal requests querying cloud metadata services (&lt;code&gt;169.254.169.254&lt;/code&gt;).&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  How Cumulative Anomaly Scoring Prevents False Positives
&lt;/h2&gt;

&lt;p&gt;Instead of immediately blocking on the first keyword match, Aegis calculates a cumulative threat score across every rule an HTTP request triggers:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Notice:&lt;/strong&gt; &lt;code&gt;2 points&lt;/code&gt; (slightly irregular character set or header).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Warning:&lt;/strong&gt; &lt;code&gt;3 points&lt;/code&gt; (unusual query structure).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Error:&lt;/strong&gt; &lt;code&gt;4 points&lt;/code&gt; (suspicious payload pattern).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Critical:&lt;/strong&gt; &lt;code&gt;5 points&lt;/code&gt; (clear, deterministic attack signature, such as &lt;code&gt;' OR 1=1--&lt;/code&gt;).&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Aegis compares the total points against the &lt;strong&gt;Inbound Anomaly Threshold&lt;/strong&gt; (default: &lt;code&gt;5&lt;/code&gt;). &lt;/p&gt;

&lt;p&gt;A casual anomaly alone won't trigger a block, but a real attack string immediately reaches the threshold and gets rejected.&lt;/p&gt;




&lt;h2&gt;
  
  
  Step 1: Start in "Detection Only" Mode (Safe Baselining)
&lt;/h2&gt;

&lt;p&gt;When introducing a WAF to production, you should never turn on hard blocking immediately.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Open your Aegis Admin Console at &lt;code&gt;http://localhost:8081&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;In the sidebar under &lt;strong&gt;Configuration&lt;/strong&gt;, select &lt;strong&gt;WAF Core &amp;gt; Overview&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Set the &lt;strong&gt;Enforcement Mode&lt;/strong&gt; to &lt;strong&gt;Detection Only&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;Save Changes&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fklng9albntqbqvb2j8pa.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fklng9albntqbqvb2j8pa.png" alt="Aegis WAF Rulesets" width="800" height="395"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Why this matters:&lt;/strong&gt; In Detection Only mode, Aegis analyzes every incoming request and logs all detected signatures to the &lt;strong&gt;Threat Inspection Log&lt;/strong&gt;, but &lt;strong&gt;never blocks users&lt;/strong&gt;. This lets you observe normal customer traffic for 24–48 hours to confirm zero false alarms before turning on active mitigation.&lt;/p&gt;




&lt;h2&gt;
  
  
  Step 2: Choose the Right Paranoia Level
&lt;/h2&gt;

&lt;p&gt;On the same &lt;strong&gt;Overview&lt;/strong&gt; page, adjust the &lt;strong&gt;Paranoia Level&lt;/strong&gt; slider to match your risk profile:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Paranoia Level 1 (Default - Recommended):&lt;/strong&gt; Applies high-confidence rules designed to catch obvious attacks with virtually zero false positives. Best for standard websites, APIs, and blogs.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Paranoia Level 2:&lt;/strong&gt; Adds stricter validation on input lengths and special characters. Recommended for user portals and e-commerce checkouts.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Paranoia Level 3 &amp;amp; 4:&lt;/strong&gt; Rigorous payload inspection and strict character encoding rules. Best for high-security banking, healthcare, or government environments where you have dedicated engineering time to tune exceptions.&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Step 3: Switch to "Active Blocking"
&lt;/h2&gt;

&lt;p&gt;Once you verify that legitimate traffic passes through without anomaly warnings:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Change the &lt;strong&gt;Enforcement Mode&lt;/strong&gt; switch to &lt;strong&gt;Active Blocking&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;Save Changes&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Aegis reloads the security policy dynamically in memory with zero downtime—no proxy restarts required.&lt;/p&gt;




&lt;h2&gt;
  
  
  Step 4: Verify Exploit Mitigation with curl
&lt;/h2&gt;

&lt;p&gt;Now verify that real attack payloads are dropped at the network edge before reaching your origin servers.&lt;/p&gt;

&lt;h3&gt;
  
  
  Test A: SQL Injection (SQLi)
&lt;/h3&gt;

&lt;p&gt;Send an injection attempt in the query string:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="nt"&gt;-i&lt;/span&gt; &lt;span class="s2"&gt;"http://localhost:8080/?id=1%27%20OR%201=1--"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Response:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight http"&gt;&lt;code&gt;&lt;span class="k"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;403&lt;/span&gt; &lt;span class="ne"&gt;Forbidden&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s"&gt;text/html; charset=utf-8&lt;/span&gt;
&lt;span class="na"&gt;X-WAF-Rule-ID&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s"&gt;942100&lt;/span&gt;

Access denied: This request was rejected by the application security layer.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Aegis matches rule &lt;code&gt;942100&lt;/code&gt; (SQLi attack), calculates a critical anomaly score of 5, and immediately returns a &lt;code&gt;403 Forbidden&lt;/code&gt;.&lt;/p&gt;

&lt;h3&gt;
  
  
  Test B: Reflected Cross-Site Scripting (XSS)
&lt;/h3&gt;

&lt;p&gt;Send a script tag in a POST body:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="nt"&gt;-i&lt;/span&gt; &lt;span class="nt"&gt;-X&lt;/span&gt; POST http://localhost:8080/submit &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-H&lt;/span&gt; &lt;span class="s2"&gt;"Content-Type: application/x-www-form-urlencoded"&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-d&lt;/span&gt; &lt;span class="s2"&gt;"comment=&amp;lt;script&amp;gt;alert('xss')&amp;lt;/script&amp;gt;"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Response:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight http"&gt;&lt;code&gt;&lt;span class="k"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;403&lt;/span&gt; &lt;span class="ne"&gt;Forbidden&lt;/span&gt;
&lt;span class="na"&gt;X-WAF-Rule-ID&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s"&gt;941100&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The XSS payload is dropped at the ingress layer.&lt;/p&gt;




&lt;h2&gt;
  
  
  Resources
&lt;/h2&gt;

&lt;p&gt;The Community Edition is free to self-host for your own homelabs and production servers:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Aegis GitHub Repository:&lt;/strong&gt; &lt;a href="https://github.com/divinelabio/aegis" rel="noopener noreferrer"&gt;https://github.com/divinelabio/aegis&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Documentation:&lt;/strong&gt; &lt;a href="https://divinelab.io/products/aegis/docs/waf-core/overview" rel="noopener noreferrer"&gt;https://divinelab.io/products/aegis/docs/waf-core/overview&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>devops</category>
      <category>go</category>
      <category>opensource</category>
      <category>security</category>
    </item>
    <item>
      <title>How to Stop API Floods and Rate Limit Endpoints in Under 5 Minutes</title>
      <dc:creator>Divinelab.io</dc:creator>
      <pubDate>Mon, 05 Oct 2026 15:07:22 +0000</pubDate>
      <link>https://dev.to/divinelab/how-to-stop-api-floods-and-rate-limit-endpoints-in-under-5-minutes-2c9j</link>
      <guid>https://dev.to/divinelab/how-to-stop-api-floods-and-rate-limit-endpoints-in-under-5-minutes-2c9j</guid>
      <description>&lt;p&gt;Exposing an API or web application to the public internet means dealing with credential stuffing, scraping bots, and sudden volumetric request surges.&lt;/p&gt;

&lt;p&gt;If you don't enforce rate limits and connection thresholds at the network edge, an attacker can easily exhaust your database connection pools or CPU resources.&lt;/p&gt;

&lt;p&gt;In this guide, we'll configure &lt;a href="https://github.com/divinelabio/aegis" rel="noopener noreferrer"&gt;Aegis&lt;/a&gt;—an open-source, self-hosted edge reverse proxy and WAF—to rate limit abusive clients and prevent Layer 7 denial-of-service attacks directly from its web console.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fltlck686a2jycwtqfl6m.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fltlck686a2jycwtqfl6m.png" alt="Aegis Traffic Control &amp;amp; Rate Limiting" width="800" height="500"&gt;&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  1. Configure Global Flood Protection
&lt;/h2&gt;

&lt;p&gt;In the Aegis Admin Console (&lt;code&gt;http://localhost:8081&lt;/code&gt;), navigate to &lt;strong&gt;Traffic Control &amp;gt; Application Flood&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Aegis tracks request velocity and active socket concurrency per client IP in real time:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;HTTP Flood Threshold:&lt;/strong&gt; Sets the maximum requests per second allowed per IP (e.g., &lt;code&gt;100 req/s&lt;/code&gt;).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;In-Flight Connection Ceiling:&lt;/strong&gt; Caps simultaneous concurrent TCP sockets per IP (e.g., &lt;code&gt;50 in-flight&lt;/code&gt;). This defends origin services against connection exhaustion attacks like Slowloris.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Burst Multiplier:&lt;/strong&gt; Allows short traffic spikes (e.g., &lt;code&gt;2.0x&lt;/code&gt;) before throttling begins.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Temporary Ban:&lt;/strong&gt; Automatically blacklists repeated threshold abusers for a set duration (e.g., 60 minutes).&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;When you click &lt;strong&gt;Save&lt;/strong&gt;, Aegis applies the rules directly in memory with zero downtime—no proxy reloads or dropped connections.&lt;/p&gt;




&lt;h2&gt;
  
  
  2. Scope Tighter Limits on Sensitive Routes
&lt;/h2&gt;

&lt;p&gt;Global rate limits are often too permissive for authentication endpoints. While &lt;code&gt;100 req/s&lt;/code&gt; makes sense for browsing a product catalog, allowing that on &lt;code&gt;/api/login&lt;/code&gt; leaves you vulnerable to brute-force attacks.&lt;/p&gt;

&lt;p&gt;In the &lt;strong&gt;Protected HTTP Objects&lt;/strong&gt; panel:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Click &lt;strong&gt;+ Add Object&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Specify the path: &lt;code&gt;/api/v1/auth/login&lt;/code&gt; (Method: &lt;code&gt;POST&lt;/code&gt;).&lt;/li&gt;
&lt;li&gt;Set a strict limit: &lt;code&gt;5 req/s&lt;/code&gt; with a max concurrency of &lt;code&gt;2&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Choose the response action: &lt;strong&gt;HTTP 429 Too Many Requests&lt;/strong&gt; or &lt;strong&gt;Browser Challenge&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;




&lt;h2&gt;
  
  
  3. Test the Rate Limiter
&lt;/h2&gt;

&lt;p&gt;Send a burst of rapid requests to test edge enforcement:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="k"&gt;for &lt;/span&gt;i &lt;span class="k"&gt;in&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;1..20&lt;span class="o"&gt;}&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="k"&gt;do
  &lt;/span&gt;curl &lt;span class="nt"&gt;-s&lt;/span&gt; &lt;span class="nt"&gt;-o&lt;/span&gt; /dev/null &lt;span class="nt"&gt;-w&lt;/span&gt; &lt;span class="s2"&gt;"%{http_code}&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; http://localhost:8080/api/v1/auth/login &lt;span class="nt"&gt;-X&lt;/span&gt; POST
&lt;span class="k"&gt;done&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Output:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;200
200
200
200
200
429
429
429
...
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Once the threshold is exceeded, Aegis drops excess requests at the edge with &lt;code&gt;429 Too Many Requests&lt;/code&gt; before they ever reach your origin database.&lt;/p&gt;




&lt;h2&gt;
  
  
  Resources
&lt;/h2&gt;

&lt;p&gt;Aegis Community Edition is free and open-source under BSL 1.1:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;GitHub:&lt;/strong&gt; &lt;a href="https://github.com/divinelabio/aegis" rel="noopener noreferrer"&gt;https://github.com/divinelabio/aegis&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Docs:&lt;/strong&gt; &lt;a href="https://divinelab.io/products/aegis/docs/traffic-control/application-flood" rel="noopener noreferrer"&gt;https://divinelab.io/products/aegis/docs/traffic-control/application-flood&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>cybersecurity</category>
      <category>waf</category>
      <category>webdev</category>
      <category>docker</category>
    </item>
    <item>
      <title>How to set up a self-hosted WAF for Webapps in 2 minutes ?</title>
      <dc:creator>Divinelab.io</dc:creator>
      <pubDate>Mon, 05 Oct 2026 14:51:41 +0000</pubDate>
      <link>https://dev.to/divinelab/how-to-set-up-a-self-hosted-waf-for-webapps-in-2-minutes--17k7</link>
      <guid>https://dev.to/divinelab/how-to-set-up-a-self-hosted-waf-for-webapps-in-2-minutes--17k7</guid>
      <description>&lt;p&gt;Securing a web application usually means either routing private traffic through a third-party cloud CDN or wrestling with complex Nginx configurations.&lt;/p&gt;

&lt;p&gt;Here is how to set up &lt;a href="https://github.com/divinelabio/aegis" rel="noopener noreferrer"&gt;Aegis&lt;/a&gt;—an open-source, self-hosted Web Application Firewall (WAF) and reverse proxy—in under two minutes.&lt;/p&gt;




&lt;h2&gt;
  
  
  1. Install &amp;amp; Deploy Aegis
&lt;/h2&gt;

&lt;p&gt;Choose either the quick installation script or Docker:&lt;/p&gt;

&lt;h3&gt;
  
  
  Option A: Install via Script (Linux)
&lt;/h3&gt;

&lt;p&gt;Clone the repository and run the automated installer:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git clone https://github.com/divinelabio/aegis.git
&lt;span class="nb"&gt;cd &lt;/span&gt;aegis
&lt;span class="nb"&gt;sudo &lt;/span&gt;bash install.sh
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Verify the systemd service is active:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nb"&gt;sudo &lt;/span&gt;systemctl status aegis
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  Option B: Deploy via Docker
&lt;/h3&gt;

&lt;p&gt;Run the self-contained container with persistent data storage:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;docker run &lt;span class="nt"&gt;-d&lt;/span&gt; &lt;span class="nt"&gt;--name&lt;/span&gt; aegis_server &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;--restart&lt;/span&gt; unless-stopped &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-p&lt;/span&gt; 8080:8080 &lt;span class="nt"&gt;-p&lt;/span&gt; 8081:8081 &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-v&lt;/span&gt; aegis_data:/var/lib/aegis/data &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-e&lt;/span&gt; &lt;span class="nv"&gt;AEGIS_ADMIN_PASSWORD&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;"ChooseStrongAdminPassword123!"&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
  ghcr.io/divinelabio/aegis:latest
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Port 8080:&lt;/strong&gt; Public Ingress Proxy (sits in front of your applications).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Port 8081:&lt;/strong&gt; Web Dashboard for traffic monitoring and policy tuning.&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  2. Test WAF Attack Blocking
&lt;/h2&gt;

&lt;p&gt;Aegis inspects incoming requests and blocks common web exploits (SQL Injection, XSS, Remote Code Execution) out of the box.&lt;/p&gt;

&lt;p&gt;Test it by sending a simulated SQL Injection payload to the proxy:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="nt"&gt;-i&lt;/span&gt; &lt;span class="s2"&gt;"http://localhost:8080/?id=1%27%20OR%201=1--"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Aegis intercepts the attack and returns &lt;code&gt;HTTP 403 Forbidden&lt;/code&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight http"&gt;&lt;code&gt;&lt;span class="k"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;403&lt;/span&gt; &lt;span class="ne"&gt;Forbidden&lt;/span&gt;
&lt;span class="na"&gt;X-WAF-Rule-ID&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s"&gt;942100&lt;/span&gt;

Access denied: This request was rejected by the application security layer.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The attack is dropped at the edge and never reaches your backend servers.&lt;/p&gt;




&lt;h2&gt;
  
  
  3. Manage Routes in the Web Dashboard
&lt;/h2&gt;

&lt;p&gt;Open &lt;code&gt;http://localhost:8081&lt;/code&gt; in your browser.&lt;/p&gt;

&lt;p&gt;From the dashboard, you can:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Route incoming traffic to your backend origin servers.&lt;/li&gt;
&lt;li&gt;View blocked attacks and threat telemetry in real time.&lt;/li&gt;
&lt;li&gt;Adjust Layer 7 rate limits, toggle Geo-IP blocking, and manage SSL certificates.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;All policy updates reload dynamically in memory with zero downtime—no proxy restarts required.&lt;/p&gt;




&lt;h2&gt;
  
  
  Resources
&lt;/h2&gt;

&lt;p&gt;The Community Edition is free to self-host on your own servers and homelabs:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;GitHub:&lt;/strong&gt; &lt;a href="https://github.com/divinelabio/aegis" rel="noopener noreferrer"&gt;https://github.com/divinelabio/aegis&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Documentation:&lt;/strong&gt; &lt;a href="https://divinelab.io/products/aegis/docs" rel="noopener noreferrer"&gt;https://divinelab.io/products/aegis/docs&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>opensource</category>
      <category>security</category>
      <category>cybersecurity</category>
      <category>waf</category>
    </item>
  </channel>
</rss>
