WAF Analysis Framework for Evasive Recognition. Detect and fingerprint protective layers.
WAFER is a practical security tool designed to detect and fingerprint Web Application Firewalls by analyzing response behavior and enforcement patterns. Instead of relying solely on static signatures, WAFER actively probes the target application and observes how requests are filtered, blocked, or modified. The goal of WAFER is to help security engineers, penetration testers, and researchers quickly understand what protective layer stands in front of a web application and how it behaves under different request patterns.
Identifies the presence of a Web Application Firewall by analyzing request and response behavior rather than relying only on static fingerprints.
Attempts to recognize the WAF vendor or implementation based on response patterns, headers, and blocking behavior.
Uses active probing techniques to observe how the target reacts to different payloads and request variations.
Builds and runs on Linux, macOS, and Windows with support for multiple architectures.
Optimized for speed and low resource usage, suitable for integration into automated pipelines.
WAFER is built with passion and offered for free. If it saves you time or makes your workflow better, consider showing your support. Every contribution helps keep this project alive and growing.