CLOUD WAF — ALSO AVAILABLE SELF-HOSTED

Stop threats
before they reach
your websites.

CerberusWaf is a managed Web Application Firewall that protects hundreds of websites from one panel. Point your DNS, we handle the rest — real-time threat detection, anti-bot challenges, IP intelligence, and a SOC-grade dashboard.

14phases
WAF Pipeline
<1ms
Inspection Latency
300K+
GeoIP Ranges
now BLOCK SQLi 185.220.×.× → /wp-login
now CHAL Bot 45.134.×.× → /api/v2
now BLOCK RCE 192.241.×.× → /cgi-bin
70+
Nodes Protected
3
Datacenters
38
Database Tables
20K+
Lines of Code
SOC 2
DC Certifications

Every layer of protection,
one panel to rule them all

40+ security modules. Domain-first interface. Multi-tenant. Managed or self-hosted.

WAF Engine

12-phase request pipeline with pattern matching for SQLi, XSS, RCE, path traversal, SSRF, and scanner detection. Audit or block per domain.

Free

Anti-Bot Protection

JavaScript Proof-of-Work challenge with Web Worker computation and HMAC cookie verification. Under Attack mode forces challenge for all visitors.

Starter+

IP Intelligence

Multi-source threat feeds (AbuseIPDB, VirusTotal). Reputation scoring, Tor/VPN/proxy detection, and auto-block by threat level.

Professional

Application Rulesets

Pre-built catalogs for WordPress, WooCommerce, Magento, Laravel, APIs. Pentesting-derived rules for RCE, SSRF, file uploads.

Free

Rate Limiting

Per-domain limits with progressive penalties. Presets for API, login, and general traffic. Burst and connection control.

Free

GeoBlocking

Country-based access control with local GeoIP database — 312K+ ranges, sub-millisecond lookup. Allow, deny, challenge, or log.

Professional

ACL Rules

Match IP, country, User-Agent, referer, URI path. Time windows, day-of-week schedules, and HTTP method filtering.

Professional

SOC Dashboard

World map attack visualization, real-time threat timeline, top attacking IPs with WHOIS, and one-click block/whitelist.

Professional

SSH Discovery

Auto-import domains from remote servers via SSH. Supports Nginx, cPanel, Apache, Plesk with bulk import and deduplication.

Business

SSL / Let's Encrypt

Automated certificate management with Let's Encrypt. Custom upload, auto-renew, and bulk renewal across all domains.

Free

CDN & Load Balancer

Proxy cache with TTL, purge, gzip. Load balancer with round-robin, least-conn, ip-hash. Health checks with auto-failover.

Business

Multi-Tenant

Client management with domain limits, user roles (superadmin, admin, client), 2FA/TOTP, and full audit trail.

Professional

32 pre-built rulesets. 409 rules.
Assign per domain in one click.

Pentesting-derived rule catalogs covering OWASP Top 10, CMS platforms, API abuse, protocol attacks, and more.

🛡
32
Rulesets
📜
409
Total Rules
🌐
2
Global Rulesets
9
Auto-Assign
All (32)
OWASP Top 10
CMS & Frameworks
API Security
Authentication
Protocol
Detection
Data Protection
E-Commerce
owasp a03
🗃
SQL Injection (SQLi)
v1.0
UNION, blind, time-based, error-based injection. Protects against the #1 web attack vector.
12 rules
AUTO
owasp a03
🗃
SQL Injection Advanced
v1.0
Stacked queries, NoSQL injection (MongoDB), WAF bypass techniques, advanced blind SQLi.
24 rules
owasp a03
💻
Command Injection
v1.0
OS command injection: pipes, backticks, exec, system calls. Protects against RCE (CVSS 9.8).
13 rules
AUTO
owasp a10
🔗
SSRF Protection
v1.0
Blocks Server-Side Request Forgery: internal URLs, cloud metadata (169.254.x), private IP ranges.
14 rules
AUTO
owasp a05
📄
XML/XXE Attacks
v1.0
XML External Entity, SOAP injection, XML bombs (billion laughs), DTD injection.
8 rules
owasp a05
📄
XML/XXE Protection
v1.0
Advanced XXE protection: SOAP injection, billion laughs bomb, DTD injection, OOB extraction.
16 rules
cve-2021-44228
Log4Shell & Java Exploits
v1.0
Log4j (${jndi:), Spring4Shell, Struts OGNL, Java deserialization payloads.
26 rules
AUTO
cve-2014-6271
💣
Shellshock & CGI
v1.0
Bash Shellshock, CGI abuse, Server-Side Includes injection.
7 rules
cms
W
WordPress
v1.0
xmlrpc, wp-admin, wp-login, themes, plugins, REST API, uploads protection.
19 rules
cms
W
WordPress Extended
v1.0
Plugin vulns: RevSlider, TimThumb, WPBakery, Elementor. Hidden endpoints.
10 rules
cms
W
WordPress Extended v2
v1.0
REST API abuse, registration spam, author enumeration, specific plugin vulnerabilities.
20 rules
cms
🛒
WooCommerce
v1.0
Checkout, cart, payment endpoints, customer data, coupon abuse protection.
8 rules
cms
🛒
Magento
v1.0
Admin panel, API, customer accounts, catalog injection for Magento/Adobe Commerce.
10 rules
cms
🛒
PrestaShop
v1.0
Back-office, modules, webservice, admin-dev path protection.
6 rules
cms
🛡
Drupal
v1.0
Admin paths, AJAX endpoints, update.php, install.php protection.
8 rules
cms
🛡
Joomla
v1.0
Administrator, com_* components, installation paths protection.
6 rules
framework
🔨
Laravel / PHP Framework
v1.0
Debug mode, artisan, .env exposure, CSRF bypass for Laravel, Symfony, CodeIgniter.
9 rules
api
🔌
API Abuse Protection
v1.0
Mass assignment, IDOR, GraphQL introspection, excessive data exposure, parameter tampering.
26 rules
api
🔌
API REST / JSON
v1.0
Rate abuse, JSON injection, auth bypass, mass assignment for REST APIs.
6 rules
auth
🔑
Authentication Brute Force
v1.0
Detects brute force on auth endpoints, user enumeration, credential stuffing attempts.
10 rules
auth
🕵
Credential Stuffing & ATO
v1.0
Detects mass credential stuffing, login from TOR/proxies, suspicious User-Agent rotation.
6 rules
auth
🔒
Admin Panel Protection
v1.0
Protects /admin, /manager, /phpmyadmin, /login, /dashboard admin paths.
14 rules
protocol
🔃
Protocol & HTTP Abuse
v1.0
HTTP request smuggling, CRLF injection, response splitting, header injection, HTTP/2 downgrade.
9 rules
AUTO
protocol
🔃
Protocol Smuggling
v1.0
HTTP request smuggling (CL+TE), CRLF injection, response splitting, header injection.
16 rules
protocol
H
Host Header Validation
v1.0
Prevents Host Header Injection: malicious redirects, cache poisoning, phishing.
6 rules
detection
🔍
Scanner & Recon Detection
v1.0
Identifies Nmap, Nikto, SQLMap, WPScan, Acunetix, Burp Suite and other recon tools.
12 rules
GLOBALAUTO
detection
🤖
Bot & Crawler Control
v1.0
Detects malicious bots: scrapers, spam bots, fake Googlebot, automated scanners (sqlmap, nikto).
24 rules
dlp
🛡
Data Leak Prevention (DLP)
v1.0
Detects exfiltration of sensitive data: Chilean RUT, credit cards, API keys, mass emails in responses.
12 rules
GLOBALAUTO
files
📂
Directory Traversal & Sensitive Files
v1.0
Blocks path traversal, directory listing, access to .env, .git, config files.
17 rules
AUTO
files
📤
File Upload Validation
v1.0
Validates uploads: dangerous extensions, double extensions, PHP in uploads, webshells.
12 rules
AUTO
sanitization
Error Page Sanitization
v1.0
Hides sensitive info in error responses: stack traces, paths, versions, SQL errors.
9 rules
ecommerce
💰
E-Commerce Protection
v1.0
Carding, price manipulation, coupon abuse, payment tampering, checkout scraping.
14 rules

How CerberusWaf protects your traffic

Your traffic flows through our Nginx reverse proxy with an auth_request-based WAF engine. Every request passes through 14 security checkpoints before reaching your origin.

01

Point your DNS

Change your DNS to CerberusWaf. We handle SSL, caching, and security automatically.

02

WAF Inspection

14-phase pipeline: bot check, IP intel, ACL, rate limit, pattern matching — all in <1ms.

03

Decision

Block (403), challenge (JS PoW), log (audit), or pass. Per-domain config.

04

Proxy → Your Server

Clean traffic proxied to your origin with load balancing, caching, and health checks.

14-Phase Request Inspection Pipeline
1
UA Flags
~0.01ms
2
Offline
~0.01ms
3
Bot / Under Attack
~0.05ms
4
IP Whitelist
~0.01ms
5
IP Blacklist
~0.01ms
6
GeoBlock
~0.02ms
7
IP Intel
~0.1ms
8
Rate Limit
~0.1ms
9
ACL
~0.05ms
10
CMS Auth
~0.05ms
11
WAF Rules
~0.3ms
12
Rulesets
~0.3ms
Pass
→ origin
Near-zero cost Light processing Heavier analysis Block / deny

Why the order matters — saving CPU, RAM, and bandwidth

Most WAFs run every check on every request. CerberusWaf's pipeline is ordered cheapest-first: if a request is blocked at phase 2, phases 3–12 never execute.

Phases 1–5: Near-zero cost

UA flags, Offline mode, Bot cookie, IP white/blacklist — simple lookups in memory. This alone stops 40–60% of malicious traffic.

Phases 6–10: Light processing

GeoBlock, IP Intel, Rate Limit, ACL, CMS Auth — fast indexed lookups and counters. These catch 20–30% more threats before regex.

Phases 11–12: Deep inspection

WAF Rules + Rulesets — regex pattern matching. By now 60–80% of bad traffic has been blocked. Only clean requests pay full cost.

60–80%
attacks blocked before regex
<1ms
average pipeline latency
3–5×
less CPU vs flat WAF
0bytes
bandwidth for blocked requests
🔒

Your data. Your configs. Always exportable.

CerberusWaf generates standard Nginx configuration files. No proprietary format, no vendor lock-in.

What you can export

  • Nginx vhost configs — complete server blocks for each domain
  • SSL certificates — Let's Encrypt or custom certs with private keys
  • WAF rules — all rulesets as Nginx location/if blocks
  • Rate limit zones — limit_req_zone directives
  • GeoIP & ACL maps — Nginx maps
  • Upstream definitions — load balancing config

Emergency & migration

  • Instant rollback — download configs, point DNS back
  • Multi-provider — run on your own Nginx
  • Audit & compliance — full visibility, no black boxes
  • Self-hosted migration — same configs
  • Backup automation — via API or panel
  • Zero downtime — test locally before switching
# Export all domain configs as plain Nginx
cerberuswaf export --format nginx --output ./nginx-configs/
# Output:
./nginx-configs/acmeshop.io.conf    # vhost + WAF rules
./nginx-configs/ssl/acmeshop.io.pem # SSL certificate
./nginx-configs/waf/rulesets.conf   # all WAF rules
sudo cp ./nginx-configs/*.conf /etc/nginx/sites-enabled/
sudo nginx -t && sudo systemctl reload nginx
🛡 No vendor lock-in, ever.  Your security configuration belongs to you.

Domain-first. SOC-grade. Dark by default.

Select a domain, everything contextualizes. Auto-cycling preview — hover to pause.

https://app.cerberuswaf.com
LIVE
acmeshop.io ▾
Domain
Dashboard
WAF Logs
WAF Rules
Anti-Bot PRO
Rulesets
Rate Limits
ACL Rules PRO
GeoBlock PRO
Global
All Domains
Settings
Dashboard
adminProfessional
acmeshop.ioWAF: DEFENSESSLBot
87A
Security Score
3,847
Events 24h
1,291
Blocked
847
Challenged
2,103
Unique IPs
42.8
Req/sec
12
Rulesets
Threats (24h)
Top Countries
China
847
Russia
612
USA
384
Brazil
271
Germany
189
Action: All
Severity: All
Search
TimeActionCategorySeverityIP AddressURIDomain
14:32:01BLOCKEDSQLiCRITICAL185.220.101.34/wp-login.phpacmeshop.io
14:32:01BLOCKEDXSSHIGH45.134.26.91/search?q=<script>novex.dev
14:32:02CHALLENGEDBotMEDIUM192.241.213.5/api/v2/productsacmeshop.io
14:32:03BLOCKEDRCECRITICAL103.75.201.88/cgi-bin/test-cgibrighthr.co
14:32:04BLOCKEDScannerLOW167.94.138.12/.envacmeshop.io
14:32:05BLOCKEDPath TravHIGH89.248.165.5/../../etc/passwdgreenleaf.com
6 Applications
+ ADD
acmeshop.io
DEFENSESSL
→ 45.33.×.×:4431,847
dashboard.novex.dev
DEFENSESSL
→ 192.168.×.×923
portal.brighthr.co
AUDIT
→ 10.0.×.×:443341
blog.novex.dev
OFF
→ novex.dev (301)0
2,847
Challenges
1,923
Verified
891
Failed
33
Expired
Config
EnabledON
ModeJS PoW
Difficulty18 bits
Cookie TTL3600s
Top Failed IPs
185.220.101.3447×BAN
103.75.201.8831×BAN
167.94.138.1222×BAN

Simple pricing. Per domain. No surprises.

Start with a 7-day free trial. No per-request fees, no bandwidth limits.

Free
Try it out — 7 day trial
$0
7 days · up to 3 domains
  • WAF audit mode
  • Basic rate limiting
  • SSL / Let's Encrypt
  • Security headers
  • Application rulesets (3)
  • 24h log retention
  • Anti-bot protection
  • IP Intelligence
  • GeoBlocking / ACL
Start Free Trial
Starter
Freelancers & small sites
$9
/domain/month · from $7.50 in bundles
  • WAF defense mode
  • Anti-bot JS challenges
  • Full rate limiting
  • Application rulesets (5)
  • SSL / Let's Encrypt
  • 7-day log retention
  • IP Intelligence
  • GeoBlocking / ACL
  • SOC Dashboard
Start Starter
Business
Hosting providers & MSPs
$29
/domain/month · from $19.90 in bundles
  • Everything in Professional
  • REST API access
  • Client portal (white-label)
  • PDF / Excel reports
  • Webhook & Telegram alerts
  • CDN & load balancer
  • 90-day log retention
  • Priority support (4h SLA)
  • Prometheus metrics
Start Business

Volume discounts — the more domains, the less you pay

6–10 domains: 10% off · 11–25: 20% off · 26–50: 30% off · 51+: custom pricing

Contact Sales →

Enterprise — Unlimited domains, white-label, SSO

Custom pricing for large-scale deployments. Dedicated support with 1h SLA.

Contact Sales →

Self-Hosted licenses

Install CerberusWaf on your own server. Same features, full data sovereignty.

Contact Sales →

All plans include SSL, security headers, and basic auth. Annual billing saves 20%.

Protecting your first domain takes 3 minutes

No installation. No server configuration. Just sign up, add your domain, and update your DNS.

1
Create your account
Sign up for free at app.cerberuswaf.com. No credit card required. 7-day free trial with 3 domains.
2
Add your domain & upstream
Enter your domain and origin server IP. CerberusWaf auto-configures SSL, security headers, and WAF rules.
3
Update your DNS
Point your domain's A record to the CerberusWaf edge IP. Traffic flows through our WAF immediately.

Zero infrastructure to manage

Your traffic is proxied through CerberusWaf's infrastructure across datacenters in Miami, Tampa, and Santiago.

  • SOC 2, ISO 27001, PCI-DSS certified DCs
  • Auto SSL via Let's Encrypt
  • 312K+ GeoIP ranges updated weekly
  • Multi-feed threat intel (AbuseIPDB, VirusTotal)
  • 99.9% uptime SLA on paid plans
Start Free Trial

Your traffic. Your rules.
Our infrastructure.

Start your 7-day free trial with 3 domains. Upgrade as you grow. No server to manage.