Real-time ingestion
Front Door WAF and access logs stream through Azure Event Hub into your workspace, deduplicated and replay-safe.
Built for Azure Front Door Premium WAF
WAFGuardAI streams your Front Door WAF and access logs in real time, separates genuine attacks from legitimate traffic your rules misread, and hands you the exact Azure CLI exception to apply — scoped to the rule that actually fired.
No agent to install. One Event Hub diagnostic setting, and logs start flowing in minutes.
The problem
Teams end up loosening rules, or switching the policy to Detection — and lose the protection they paid for. WAFGuardAI removes the guesswork instead.
Features
Front Door WAF and access logs stream through Azure Event Hub into your workspace, deduplicated and replay-safe.
Every Block is grouped with the AnomalyScoring records sharing its tracking reference, so you see which rules truly fired.
Scanner probes, SSRF sweeps and traversal attempts on routes you do not expose never reach analysis — or your inbox.
Each candidate is classified false positive, true positive or uncertain, with a confidence score and a written rationale.
A scoped managed-rules exception add command, resource group and policy filled in, in Bash and CMD variants.
Recipients are set per WAF policy, with confidence thresholds and throttling — and alert emails carry no sensitive request data.
How it works
Point the Front Door diagnostic setting at an Event Hub. Nothing is installed next to your applications.
A lightweight connector reads the hub and forwards records over a signed channel. Shared hubs are supported.
Blocks are correlated, filtered against your declared application routes, then classified by the AI pipeline.
Copy the generated exception, run it, and track how fast false positives get resolved on the dashboard.
Get started
Tell us about your Azure setup and we will walk you through a live session on real WAF traffic. Accounts are created by our team, so you always know who has access.
or write to contact@wafguardai.com