titansec / OpenWAF

Web security protection system based on openresty
Apache License 2.0
749 stars 236 forks source link

OpenWaf crs, import export rules from owasp crs #34

Open bsiara opened 2 years ago

bsiara commented 2 years ago

Hi, I'm new in OpenWAF and I have few questions:

  1. Where I can find all rules in OpenWAF git repo and on which conditions there are defined? I found this rules https://github.com/titansec/OpenWAF/tree/master/lib/twaf/inc/knowledge_db/twrules but ther is only a few rules?
  2. What is the standard of definition rules?
  3. How and where I can define my own rules and exceptions
  4. It is posible to import rules from owasp-crs https://github.com/coreruleset/coreruleset? Thanks in advance
bsiara commented 2 years ago

Somebody can answer?