Block Web Attacks Live: Open-Source WAF with Automatic HTTPS

Published: 24 June 2026
on channel: Taylor Walton
11,646
235

Putting a Web Application Firewall in front of your app usually means wrestling
certificates, cryptic rules, and a per-request cloud bill. In this video I deploy
a fully self-hosted, open-source WAF in about 10 minutes — automatic TLS, the
OWASP Core Rule Set built in, and a real management UI — then block live attacks
and tune a false positive without opening a hole.

Built on Caddy + Coraza (a ModSecurity-compatible engine) + OWASP CRS v4, with a
FastAPI + React control panel. Runs from prebuilt Docker images. No vendor lock-in,
no per-request fees.

🔗 Get it (README + docker-compose + demo):
https://github.com/socfortress/waf-pl...

👨🏻‍💻 Professional Services: https://www.socfortress.co/ps.html

👾 Discord Channel:   / discord  

⏱️ Chapters
00:00 The problem with running a WAF
01:30 The solution: Caddy + Coraza + OWASP CRS + UI
02:30 Deploy the stack (docker compose up)
04:00 Add a site + automatic Let's Encrypt TLS
05:30 Block real attacks live (SQLi, XSS, LFI, RCE)
07:30 Full visibility: live logs, rule IDs, GeoIP
09:00 Fix a false positive with a scoped exclusion
10:30 Detection vs blocking mode + dashboard
11:30 Get started

✅ What you'll learn
• Deploy a self-hosted WAF from prebuilt images in minutes
• Get automatic, auto-renewing HTTPS with zero certbot/PEM wrangling
• Block SQL injection, XSS, path traversal, RCE and more with OWASP CRS v4
• See exactly what's blocked and why — rule ID, category, client IP, country
• Tune false positives with a scoped exclusion (no disabling rules, no config files)
• Roll out safely with detection-only mode before switching to blocking

🛠️ Stack
Caddy · Coraza · OWASP Core Rule Set v4 · FastAPI · React · PostgreSQL · Redis · Docker


#WAF #WebApplicationFirewall #CyberSecurity #OWASP #SelfHosted #Docker #DevSecOps
#Caddy #Coraza #InfoSec #HomeLab #OpenSource


On this page of the site you can watch the video online Block Web Attacks Live: Open-Source WAF with Automatic HTTPS with a duration of hours minute second in good quality, which was uploaded by the user Taylor Walton 24 June 2026, share the link with friends and acquaintances, this video has already been watched 11,646 times on youtube and it was liked by 235 viewers. Enjoy your viewing!