Attacks blocked · 24h
Real-time WAF active
Protected sites
Backends behind Chazerai
Open findings
From recent scans
Live AI rules
Auto-learned + mined
Detector
Real-time WAF · inspecting every request
Total requests
Blocked
Blocked IPs
Latest alerts
Loading…
Open Detector
Scanner
Authenticated vulnerability scans
Scans run
Critical
High
Latest findings
Loading…
Open Scanner
Attack activity
Blocked requests · last 7 days
— total
Critical findings
Most recent CRITICAL + HIGH bugs
Loading…
Recently learned bugs
New CVEs · auto-imported from NVD daily
Loading…

Total Requests

Blocked

Alerts (all-time)

Critical (24h)

High (24h)

Medium (24h)

Blocked IPs

IP Allowlist — Restrict who can access protected sites

For each site below, you can lock access to specific IPs or CIDR ranges. Empty list = deny-by-default when enabled.

Protected Sites Backends behind Chazerai — each gets its own port

Add a website you want to protect. Chazerai will open a new port and shield it. Send your users to the new URL instead of the unprotected one.

NameBackendProtected URL (give users this)Added
No sites yet — add one above

Rule Exceptions Whitelist specific bugs on specific endpoints — useful when a "vulnerability" is intentional (e.g. public API)

How to use: Pick a site, enter just the path (e.g. /contact/me — no http://), click Pick bugs to allow and check the boxes, hit Add. Path supports * wildcards.

SitePath PatternAllowed Bug IDsReason
No exceptions yet

AI Code Review — Verdict & Secure Code

Paste code. AI returns SECURE/VULNERABLE verdict, lists each issue with CWE, and shows the corrected secure code.

Llama 3.2 3B runs locally. Reliable for common patterns (SQLi, raw HTML, shell injection); can be wrong on subtle issues. Always review.

Saved Analyses (0)

Recent Alerts Click any row marked FIX AVAILABLE to see the code fix inline

TimeSeverityRuleSource IPPathAction
Loading…

Blocked IPs

IPReasonExpires
Loading…

IP Allowlist Whitelisted IPs bypass ALL detection rules

Loading…

Top Attackers (24h)

Loading…

Top Rules (24h)

Loading…

Scanners Detected Last 7 days — attacks grouped by scanner signature

Loading…

AI Auto-Approve loading…

When ON, AI suggestions above the threshold get approved automatically — no clicks needed.

AI Suggestions from your Real Findings 0

Rules derived from bugs YOUR scanner found in the last 30 days — not generic OWASP.

SevNamePatternConf

Custom Rules Write your own detection rules — the WAF matches them against live traffic alongside the built-in rules

A rule is a regular expression matched against part of each request. If it matches, an alert is raised (and MEDIUM/HIGH/CRITICAL rules block the request). Use the tester below before saving.

Your custom rules

No custom rules yet. Create one above.

My Plan

Your current Chazerai plan and what's included.

Loading...

Plan Tiers

Pick a plan that fits your needs. Click "Upgrade" to request — we'll contact you to complete payment.

Alert Notifications Push critical alerts to Slack, Discord, or any webhook

Paste an incoming-webhook URL from Slack or Discord (or any endpoint that accepts a JSON {"text": "..."} POST). When an alert at or above your chosen severity fires, Chazerai posts a message there.

Settings

Auto-approve CVEs
When enabled, high-severity CVEs (CVSS ≥ 7) automatically become live blocking rules without admin approval. Default: ON.
Edit guard_config.json · key: auto_approve_cves

Include Learned Bugs in Scan 0

Real bug detection templates. Pick which ones to run, then click "Run Selected" — they test against the active site and report findings just like regular scans.

Vulnerability Scanner

Probes your protected sites for common vulnerabilities (SQLi, XSS, traversal, SSRF, sensitive files, etc). Per-site consent required — you must explicitly enable scanning on each site you own.

1. Pick a site
Loading sites…
2. Pick tests to run
Loading tests…

Check Learned Bugs with Auth 0

Run real bug templates with the captured auth context (cookie/token) so they hit logged-in pages.

Advanced: Endpoint Recording + Authenticated Scanning

Record the request shapes (paths, methods, parameters) your users actually use, then run authenticated scans against those endpoints.

Pick a site to configure — applies to all sections below

1. Endpoint Recording

Records every unique request shape (method + path + params) when real users browse the site. The scanner then uses this catalog to test endpoints with valid auth.

Pick a site above, then click Refresh.

2. Scanner Credentials

The scanner needs an account to test authenticated endpoints. Provide creds, or let scanner auto-register.

3. Run Authenticated Scan

Scanner logs in (or registers), then replays each recorded endpoint with its own session. Catches IDOR, auth bypass, mass assignment.

(uses site selected above)

4. Scheduled Scans

Auto-run a scan periodically. Runs in background; check Recent Findings for results.

5. Auto-Learn From CVE

Pick a CVE id and the AI will write a scanner test for it. New tests appear in the scanner library automatically. Requires LLM configured.

CVE must already be in your imported list. Run "Import recent CVEs" in the Detector view first.

Detection Templates (built-in, executable) 0

19 real bug detection templates: SQLi, XSS, SSRF, IDOR, etc. Enable/disable each. Selected templates run during scans.

Learned Bugs New attacks the scanner learned about — automatic CVE feed + pattern mining

Total Learned
With Test Pattern
Live Blocking
Mining Suggestions
Scanner uses these patterns automatically during auth scans
Loading...

Payload Library Self-learning attack payloads — from live traffic, AI generation, and WAF-bypass mutations

The scanner grows its own payload library over time. Real attacker payloads (captured by the WAF), AI-generated variations, and mutated WAF-bypass variants all feed into the scanner's tests.

Total payloads

Active

Experimental

WAF Bypasses

Bulk actions: "Use only built-in" enables the trusted built-in payloads and disables traffic/AI/mutation ones — useful if you want to test with the curated set only.
Loading…

New: Each finding row below now has a PoC button (full request & response) and a Delete button (remove just that finding). Click any scan in the list to see its findings.

Recent Findings Past scans and their results — click "View" to expand, to delete

No scans yet.