Web application firewalls (WAFs) secure web applications by inspecting HTTP traffic and blocking malicious requests before they reach backend services. They help protect applications from attacks such as SQL injection, cross-site scripting (XSS), path traversal, command injection, and other threats covered by the OWASP Core Rule Set (CRS).

Coraza is an open source WAF engine written in Go that provides ModSecurity-compatible rule processing and supports the OWASP CRS. It integrates with reverse proxies, web servers, and application frameworks to inspect HTTP traffic and enforce security rules before it reaches an application. Wazuh complements Coraza by collecting and analyzing WAF audit events, correlating them with other security telemetry, and generating events for malicious requests and configuration changes.