Heuristic layer evaluation (request scoring layer runs in engine)

Feature

Heuristic layer evaluation (request scoring layer runs in engine)

Description

Scoring layer beyond signatures.

How it works

AegisWAF applies this capability inside the WAF Rules module. The engine evaluates configuration, applies matching (path/method/tokens/counters/providers), then records evidence into the event log and executes the configured enforcement action when conditions are met.

How to access / Enable or disable

  • Access: AegisWAF → WAF Settings (Rules section)
  • Enable/Disable: Use the module toggle/switch on this screen (or the relevant category toggle) to enable/disable.

Recommended setting

Start conservative (LOG or Challenge) for new deployments; tighten to Block once you confirm low false positives.