The WAF engineer’s Swiss Army knife — discover, compare, explain, and validate browser, proxy, origin, cache, rate-limit, bot, TLS, headers, and GenAI security. Local-first, evidence-backed, with a teachable “why it matters.”
No HAR loaded. Processing stays in this browser.
Client HAR evidence
→
WAF / CDN edge controls
→
Origin / AI probe + logs
Evidence boundary: HAR captures browser-facing DNS, connection, request, response, redirect, timing, and headers. It normally cannot prove the WAF-to-origin route, source allowlist, private TLS trust, or backend logs.
▣ Session Vault 0 saved
Current investigation · unsaved
Primary / Protected HAR
Not loaded
Load the current/protected trace here.
Comparison / Before HAR
Not loaded
No comparison HAR loaded — before/after deltas are unavailable.
Load a HAR to build the visual assessment.
Load a HAR.
Request waterfall
Relative to the first HAR entry. Bars show request duration; slow and failed requests are highlighted.