Built for Azure Front Door Premium WAF

Stop chasing Azure WAF false positives

WAFGuardAI streams your Front Door WAF and access logs in real time, separates genuine attacks from legitimate traffic your rules misread, and hands you the exact Azure CLI exception to apply — scoped to the rule that actually fired.

No agent to install. One Event Hub diagnostic setting, and logs start flowing in minutes.

The problem

A WAF that blocks your own users is a WAF nobody trusts

Teams end up loosening rules, or switching the policy to Detection — and lose the protection they paid for. WAFGuardAI removes the guesswork instead.

Today

  • 01Noise buries the signal. Thousands of scanner hits a day drown the handful of blocks that hurt real customers.
  • 02Exceptions are written by hand. Wrong rule id, wrong operator, path instead of full URL — the exception silently never matches.
  • 03Fixes take days. The block is reported by a customer, reproduced, escalated, then finally patched.

With WAFGuardAI

  • 01Only what matters. Scanner noise is filtered out and blocks are matched against the routes your application really exposes.
  • 02A fix you can paste. The exception targets the CRS rule that raised the anomaly score, on the full request URL, in Bash or CMD.
  • 03Minutes, not days. The right people get one targeted email per policy, with a direct link to the analysis.

Features

Everything between an Event Hub and a working exception

Real-time ingestion

Front Door WAF and access logs stream through Azure Event Hub into your workspace, deduplicated and replay-safe.

Request correlation

Every Block is grouped with the AnomalyScoring records sharing its tracking reference, so you see which rules truly fired.

Noise filtering

Scanner probes, SSRF sweeps and traversal attempts on routes you do not expose never reach analysis — or your inbox.

AI verdicts

Each candidate is classified false positive, true positive or uncertain, with a confidence score and a written rationale.

Ready-to-run fixes

A scoped managed-rules exception add command, resource group and policy filled in, in Bash and CMD variants.

Targeted alerts

Recipients are set per WAF policy, with confidence thresholds and throttling — and alert emails carry no sensitive request data.

How it works

Four steps, no agent on your workloads

01

Export your logs

Point the Front Door diagnostic setting at an Event Hub. Nothing is installed next to your applications.

02

Connect the hub

A lightweight connector reads the hub and forwards records over a signed channel. Shared hubs are supported.

03

Analyse the blocks

Blocks are correlated, filtered against your declared application routes, then classified by the AI pipeline.

04

Apply the fix

Copy the generated exception, run it, and track how fast false positives get resolved on the dashboard.

Get started

See it on your own Front Door logs

Tell us about your Azure setup and we will walk you through a live session on real WAF traffic. Accounts are created by our team, so you always know who has access.

or write to contact@wafguardai.com