Hi Joshi,
I'm not aware of Azure WAF having any of those features.
Azure waf provides a subset of the rules based on Mod Security.
If you'd like a waf with an extensive list of features like you've listed you're likely interested in another product.
reference
web-application-firewall
application-gateway-crs-rulegroups-rules
Does Azure WAF provide protection against Fraud Control account takeover prevention (ATP)?
Joshi, Deepak
1
Reputation point
Hello Experts,
We are currently reviewing the capabilities offered on Azure WAF, one of the ask is to have Account takeover prevention (ATP) to prevent attacker from gaining unauthorized access to a person's account. Something similar to what AWS currently has https://docs.aws.amazon.com/waf/latest/developerguide/waf-atp.html.
Some other key features that we are looking forward to our:
- Reputation based risk assessment
- Sequence based detection
- Livestream protection
- Model Tuning / Review Cycle
- Data sharing with us (as a company) to understand FP / FN rate
- Most important thing for us is parity with other cloud monitor logs. We HEAVILY rely on those logs for incidents and Bot fingerprinting. Basic Apache
logs will not cut it - We need to log EVERYTHING including http/ssl versions, cookies, jwts, HTTP status codes, WAF triggers, referrers, and most importantly - the ability to
create custom log extractions (regex) from the POST payload (to log things like username and/or various POST parameters. We HEAVILY rely on this
feature for incidents. - Essentially logging anything in the HTTP request headers should be mandatory, as well as the response headers, plus more.
If you can direct to my any useful documentations, that would be of a great help!
Azure Web Application Firewall
Azure Web Application Firewall
An Azure service that provides protection for web apps.
363 questions
1 answer
Sort by: Most helpful
-
David Broggy 6,376 Reputation points MVP Volunteer Moderator
2022-07-25T13:25:30.38+00:00