# Nginx WAF rules for EVALUATION # Automatically generated from OWASP rules. # Include this file in your server or location block. map $request_uri $waf_block_evaluation { default 0; "~*@ge 3" 1; "~*@ge 2" 1; "~*@ge %{tx.inbound_anomaly_score_threshold}" 1; "~*@ge 4" 1; "~*@eq 1" 1; "~*@ge %{tx.outbound_anomaly_score_threshold}" 1; "~*@ge 1" 1; } if ($waf_block_evaluation) { return 403; # Log the blocked request (optional) # access_log /var/log/nginx/waf_blocked.log; }