All glossary terms
Glossary
WAF bypass
A WAF bypass is any way for traffic to reach an application without being inspected by the WAF, such as an exposed origin server, an unprotected subdomain, or a payload the rules can't parse.
The most common bypass isn't clever: the application's origin server accepts direct connections, so attackers skip the CDN and WAF entirely. Others include new subdomains launched without a policy, and teams routing traffic around the WAF to avoid false positives.
On the payload side, attackers use encodings, oversized requests or unusual formats that the WAF doesn't inspect fully.
Where Huskeys fits
Huskeys maps which applications and paths are actually covered, and flags exposed origins and unprotected hosts.
