zcrWAF
Web Application Firewall
zcrWAF brings Thai-developed web application firewall protection into the zcr suite. It screens traffic before it reaches the origin server.
Web application firewall for websites and APIs
Web traffic reaches origin too easily
Public websites and APIs face OWASP Top 10 attacks, bots, automated scripts, flood attempts, brute-force patterns, and abnormal traffic that can be hard to separate from real users.
Web Application Firewall

Sources, controls, workflow, and outcomes
zcrWAF connects the operating layer around the product: what it reads, what it does, and what the team gets back.
Protection Coverage
Websites · Web Apps · APIs · Origin Servers
Core zcrWAF Capabilities
OWASP Top 10 and common web attack protection · Rate limiting and abnormal traffic control · Bot and automated script traffic protection
zcrWAF Outcomes
Application-Layer Protection · Traffic Control · Human Verification · Operational Visibility
zcrWAF Outcomes
01
Application-Layer Protection
Block common web attacks and OWASP Top 10 patterns before they reach production systems.
02
Traffic Control
Limit abnormal traffic, flood attempts, and brute-force behavior without blocking real users blindly.
03
Human Verification
Use CAPTCHA and authentication challenges on high-risk pages or suspicious sessions.
04
Operational Visibility
Review security logs, attacks, dashboards, and rule activity in real time.
Core zcrWAF Capabilities
- OWASP Top 10 and common web attack protection
- Rate limiting and abnormal traffic control
- Bot and automated script traffic protection
- CAPTCHA and authentication challenges
- Dynamic HTML/JavaScript protection
- Real-time monitoring, security logs, and virtual patch rule updates
Best For
Protection Coverage
Application & API Shield
Place a security decision point in front of every public application, API, and origin server.
- 1Inspect websites, web apps, APIs, and origin servers for OWASP Top 10 and common attack patterns.
- 2Apply a security policy before suspicious traffic reaches production infrastructure.
- 3Start with the live demo's WAF, DDoS, filtering, SSL/TLS, analytics, and forensic security story.
- 4Keep the origin focused on the application while zcrWAF absorbs and filters hostile traffic at the edge.
Protect the public edge first
Put the public API or web application behind zcrWAF before an incident forces a rushed origin-side fix.
Bot & DDoS Defense
Separate legitimate users from automated, abusive, and volumetric traffic without treating every request the same.
- 1Use rate limits to slow abusive request patterns before they exhaust application resources.
- 2Challenge suspicious sessions with CAPTCHA or authentication instead of blocking legitimate users blindly.
- 3Reduce bot, script, brute-force, flood, and DDoS pressure at the public edge.
Protect availability without punishing customers
When login, checkout, or an API endpoint is targeted, tune the response to the session risk instead of shutting down the whole service.
Virtual Patching
Buy the application team time by putting a targeted protection rule in front of a vulnerable path.
- 1Apply and tune WAF rules while the permanent code fix moves through the delivery process.
- 2Protect exposed paths without waiting for every dependency or release window to align.
- 3Use real-time activity and security logs to decide when a temporary rule can be relaxed or removed.
Reduce exposure between discovery and remediation
When an application defect cannot be released immediately, use a policy layer to reduce exploitability while engineering completes the repair.
Security Visibility
Make traffic decisions explainable with real-time analytics, security logs, and forensic evidence.
- 1Monitor attack activity and security logs in real time for operations and policy tuning.
- 2Use detailed audit trails to investigate what was challenged, blocked, or allowed at the edge.
- 3Share a clear operational story with application owners and security stakeholders.
Defend every decision
Use the activity trail to explain the protection decision, confirm the effect, and make the next tuning change with confidence.
zcrWAF Deployment Options
Thai-Developed WAF Operations — zcrWAF is positioned for organizations in Thailand that need flexible WAF deployment, real-time security logs, local 8x5 support, maintenance, and security policy tuning.
zcrWAF FAQ
- What deployment options are available?zcrWAF is listed in three deployment options: Cloud/SaaS, Virtual Appliance, and ICT Appliance for on-premise deployment.
- What is the public pricing?The public storefront currently lists 0.00 ฿ for Cloud/SaaS, Virtual Appliance, and ICT Appliance. Final pricing should be handled as a contact-sales quote based on sizing, term, and support needs.
- What protections are included?Core protections include OWASP Top 10 coverage, rate limiting, bot and automated traffic protection, CAPTCHA or authentication challenges, dynamic HTML/JavaScript protection, real-time monitoring, logs, and virtual patch rule updates.
Protect web traffic before it reaches origin
Talk to zcr for zcrWAF sizing, deployment model, and final quote.
zcrADC
Application Delivery Controller
Live demo
demo.waf.zcr.ai
Continue with zcrLog
Unified Log Monitoring & SIEM
zcrWAF · Cyber Defense Made Visible