WAF rule language

Reference for writing and reviewing WAF rulesets, for custom rules and Cloud rulesets alike.

Use this reference when writing rules in Firewall → Custom rules or reviewing a Cloud ruleset. Write custom WAF rules covers editing, testing and publishing the unsigned local ruleset. Cloud releases use the same rule language inside a signed envelope.

  1. Ruleset format defines the JSON document, profiles and rule metadata.
  2. Rule flow explains conditions, field scope, captures and operands.
  3. Targets lists selectable request, message and response fields.
  4. Facts and limits lists parser facts and bounded work settings.
  5. Transformations lists value normalization steps.
  6. Operators lists comparisons and detection operations.
  7. Detectors and patterns explains lists, lexicons and token patterns.
  8. Tokenizers lists grammar classes, token fields, contexts and options.
  9. Scoring and integrity tests explains score attribution and release checks.
  10. Feature versions gives the minimum Clearplane version for each construct.
  11. Examples shows tested seed fragments, a challenge rule and an exclusion ruleset.