Site quality · Site security

WAF rules tuning

We set up and fine-tune WAF rules (Web Application Firewall) — a filter in front of the site that cuts off typical attacks: injections, XSS patterns, brute-forcing, known exploits. So that malicious requests are blocked before they reach the application. Honestly upfront: a WAF filters KNOWN attack patterns and reduces risk, but it is a SHIELD OVER holes, not their elimination — the vulnerabilities in the code still need fixing, and a WAF requires ongoing tuning.

Price
$3,000
Duration
usually 3–6 business days

WAF rules tuning — overview

WAF rules tuning — price, timeline & scope

WAF rules tuning is the configuration and fine-tuning of a filter in front of your site (a cloud or server WAF): we enable and calibrate rule sets against typical attacks (SQL injections, XSS patterns, brute-forcing, scanners, known CMS/plugin exploits), set up the reaction (block/challenge/log), and cut off false positives on your real traffic. Honestly about the role, this is key: a WAF is a SHIELD that filters known malicious patterns IN FRONT OF the application, reducing risk and noise. But it does NOT eliminate the cause: if there is a vulnerability in the code, a WAF only complicates its exploitation, it does not close it — real holes must be fixed separately (validation 762, parameterization 753, XSS protection 752). A WAF buys time and cuts mass attacks, but you cannot rely on it alone. Honestly about accuracy: a WAF balances between false positives (blocking legitimate requests — breaking work) and false negatives (new/bypassing attacks get through) — so the rules are tuned for your traffic and periodically re-tuned. Honestly about maintenance: new attacks and CVEs appear — the rules must be updated, it is not 'set and forget'. Honestly about the cost: if the WAF is cloud-based (Cloudflare, etc.) — its plan/subscription is paid separately; our work is rule setup. Honestly about DDoS: a WAF/CDN helps against some attacks, but full anti-DDoS protection is a separate topic. Honestly about access: access to the WAF/server is needed. An important boundary: this is WAF rule tuning (a filter), while fixing code vulnerabilities is separate. Picture this: instead of 'malicious requests reach the application directly' — typical attacks are cut off at the filter, and you gain time to fix things. The base price starts from 15,000 ₽ (excluding the cloud WAF subscription cost); it depends on the platform and traffic.

Problems we solve

  • Malicious requests reach the application without filtering.
  • Mass scanners and brute-forcing load the site.
  • A WAF is on, but on default rules — many false positives or holes.
  • Known CMS/plugin exploits get through unhindered.

What's included in the WAF rules tuning service

  • Connecting/checking the WAF (cloud or server)
  • Calibrating rule sets for typical attacks and your stack
  • Setting up the reaction (block/challenge/log)
  • Cutting off false positives on real traffic
  • Indicating boundaries (a WAF is a shield, not a replacement for fixing vulnerabilities)
  • Recommendations on rule updates
  • Verification on real scenarios
  • Handover and review with you

What you get

  • Typical attacks are cut off in front of the application
  • Less noise from scanners and brute-forcing
  • Rules calibrated without blocking legitimate requests
  • A shield that buys time (fixing vulnerabilities — separate)

How the work goes: steps

  • We check the WAF and the traffic profile; collect access
  • We calibrate rules and the reaction, cut false positives
  • We verify on scenarios, give an update plan, review boundaries with you

Why PDV Expert

  • Fixed price and timeline — no surprises on the invoice.
  • Report and recommendations in plain language — clear without a technical background.
  • In touch at every step and answering questions about the result.

FAQ

  • With a WAF is the site already protected and the code can be left alone?

    No, that is a dangerous misconception. A WAF is a shield in front of the application: it filters known patterns and complicates exploitation, but does not eliminate the vulnerability itself. If there is a hole in the code, it still needs fixing (validation, parameterization, XSS protection). A WAF buys time and cuts mass attacks, but does not replace fixing the code.

  • Won't the WAF block ordinary users?

    On default rules — it can: typical sets give false positives on non-standard but legitimate traffic. So we calibrate the rules for your real traffic and cut false positives, balancing between 'not missing an attack' and 'not bothering people'. This requires observation and periodic re-tuning.

  • Is the WAF cost included in the price?

    If the WAF is cloud-based (e.g. Cloudflare), its plan/subscription is paid separately — our price is for rule setup. If the WAF is server-based (e.g. ModSecurity) — there is no separate subscription, but server access is needed. We will honestly advise what fits your budget and stack.

About the provider

The «WAF rules tuning» service is provided by PDV Expert — a team specialising in «Site quality». We work under contract and deliver a written report with recommendations.

Prepared by PDV Expert · updated