Refer a site. You both get 10% off for 3 months. Get your referral link

EXAMPLE DATAExample University (example.com). Not a customer. Not live traffic.

Example Tuning

The WAF that tells you what's safe to block.

This is the Tuning view for a fictional site. Pick Promote, Hold, or Needs allowlist. Each card is the real decision, with the why and the evidence. A human clicks Promote. Nothing blocks automatically.

The buttons below do not change a rule. Rules start in count. After 24 hours, your dashboard shows what's safe to block — one click.

example.com

EXAMPLE DATA

Example University · Tuning · invented counts. Not a customer. Not live traffic.

A human clicks Promote. Nothing blocks automatically.

  • PromoteQuiet in the window — safe to start blocking after you click.
  • HoldStill watching or noisy — keep counting.
  • Needs allowlistLooks like real visitors — allow that traffic first.

Promote

Linux server exploits (linux_exploits) counted 12 hit(s) in the 24-hour window, and every sample looks like a probe (GET /.env).

Promoting blocks those attack shapes, not a known-good login or payment path. You still click Promote — Copilot does not flip the rule.

A human clicks Promote. Nothing blocks automatically. The button on the card does not send that click.

Hold

Common attacks (OWASP) (common_attacks) flagged a large share of requests (620 counted) in the 24-hour window.

That pattern often includes real campus traffic — LMS, registration POSTs, monitoring, CMS, or SSO paths. Keep it in count until you confirm the hits are abuse, not students or editors. Copilot will not promote this for you.

What would change this. every sample has to be an attack the log can explain

Needs allowlist

Known exploits (known_exploits) counted POST /saml/acs.

It looks like SSO in the 24-hour window. Allow that path before you promote. You still click — Copilot does not block.

What would change this. add an exact-path allowlist if this is your own form

Allow POST /saml/acs. Copilot does not write the allowlist. You still decide.

Example dataInvented counts for Example University (example.com). Not a customer. Not live traffic.

Promote Copilot

Tuning is count → promote. Rules start in count. After 24 hours, Promote Copilot names what's safe — you click once. Nothing auto-blocks. It never flips a rule to block on its own.

The 24-hour window is over. Promote quiet rules, or hold / allowlist anything noisy.

Count window

Each managed rule in count is on this track. Counted hits and site requests are the shared 24-hour CloudWatch rollup, so they match Analytics and Promote Copilot. A missing series says not confirmed, not zero.

  1. StartRules enter count
  2. 12hseries
  3. 24hdecision
  4. 7dyour click
  • Site requests in 24h: 4,000
  • CloudWatch series: 24 hours
  • In count for 30 hours, since this site was protected
  • Linux server exploitsIn count for 30 hours, since this site was protected
    • Counted hits in 24h: 12
    Before Promote

    Nothing else. Copilot can say Promote.

    What happens next. Click Promote if you want this rule in block. The samples are attacks and the count is within 8× the sample rows. Copilot does not flip the rule.

  • Common attacks (OWASP)In count for 30 hours, since this site was protected
    • Counted hits in 24h: 620
    Before Promote
    • Samples that are attacks and explain the count, or a share under 15% of site requests. This rule is at least 15% and the samples are not an explained attack.

    What would change this. every sample has to be an attack the log can explain

    What happens next. Hold this rule. A large share of traffic often includes real visitors. Copilot will not Promote it for you.

  • Known exploitsIn count for 30 hours, since this site was protected
    • Counted hits in 24h: 64
    Before Promote
    • An allowlist for the known-good path, saved by you, before this rule can be promoted.

    What would change this. add an exact-path allowlist if this is your own form

    What happens next. Allow that path if you recognize it, then come back. Copilot does not write the allowlist. Promote stays your click.

Virtual patch available

Example dataInvented advisory. Not a customer. Not live traffic.

A managed rule group can watch this class in count. You click Add in count mode. A rule that is already on stays as it is. Nothing here blocks on its own.

Catalog 2026.10.1

  • Log4Shell-style JNDI strings

    Relevant

    JNDI lookup strings in a header, query, or path.

    Managed rule group: Known exploits

    Already on in count for this site.

    A sampled request matched a pattern this group watches.

  • Drupalgeddon-style form API probes

    General advisory

    Form API arrays such as a render callback on a user form.

    Managed rule group: PHP application attacks

    Not on for this site.

    General advisory. No signal on this site ties this class to the site.

  • WordPress plugin and xmlrpc probes

    Relevant

    Plugin paths and xmlrpc calls used to look for weak plugins.

    Managed rule group: WordPress protection

    Not on for this site.

    A sampled request matched a pattern this group watches.

  • Shellshock

    General advisory

    A shell function prefix in a header or query, the Shellshock shape.

    Managed rule group: Unix / POSIX exploits

    Not on for this site.

    General advisory. No signal on this site ties this class to the site.

Rule-based notes from this count window. You still click once.

1 ready to promote · 1 needs an allowlist · 1 on hold.

  • Linux server exploitsPromote

    Linux server exploits (linux_exploits) counted 12 hit(s) in the 24-hour window, and every sample looks like a probe (GET /.env).

    Promoting blocks those attack shapes, not a known-good login or payment path. You still click Promote — Copilot does not flip the rule.

    Evidence
    • 24h window
    • Counted 12
    • GET /.env
    Top paths in the sample
    • 3GET /.env
    • 2GET /wp-config.php
    • 1GET /.git/config

    Sample rows only. Counted 12 is the full 24h window.

    Sample requests
    • GET /.env · 203.0.113.xx
    • GET /wp-config.php · 203.0.113.xx
    • GET /.git/config · 198.51.100.xx
    If you promote
    • 12 counted request(s) on Linux server exploits in this 24h window would start being blocked.
    • Includes GET /.env.
    • Only this rule switches to block. Undo puts it back in count — we do not auto-rollback.
  • Common attacks (OWASP)Hold

    Low confidence to promote — review the evidence first. You still click once.

    Common attacks (OWASP) (common_attacks) flagged a large share of requests (620 counted) in the 24-hour window.

    That pattern often includes real campus traffic — LMS, registration POSTs, monitoring, CMS, or SSO paths. Keep it in count until you confirm the hits are abuse, not students or editors. Copilot will not promote this for you.

    What would change this. every sample has to be an attack the log can explain

    Evidence
    • 24h window
    • Counted 620
    • GET /search
    Top paths in the sample
    • 2GET /search
    • 1GET /calendar
    • 1GET /news/story

    Sample rows only. Counted 620 is the full 24h window.

    Sample requests
    • GET /search · 203.0.113.xx
    • GET /calendar · 203.0.113.xx
    • GET /news/story · 198.51.100.xx
  • Known exploitsNeeds allowlist

    Low confidence to promote — review the evidence first. You still click once.

    Known exploits (known_exploits) counted POST /saml/acs.

    It looks like SSO in the 24-hour window. Allow that path before you promote. You still click — Copilot does not block.

    What would change this. add an exact-path allowlist if this is your own form

    Evidence
    • 24h window
    • Counted 64
    • POST /saml/acs
    Top paths in the sample
    • 4POST /saml/acs

    Sample rows only. Counted 64 is the full 24h window.

    Sample requests
    • POST /saml/acs · 192.0.2.xx · SSO

    False-positive risk: SSO.

    Allow this path

    Allow this path before you promote. The rule stays in count until you click.

    Allow POST /saml/acs

    Flagged: POST /saml/acs · SSO · 192.0.2.xx · this path only

    • Allows POST /saml/acs exactly.
    • Other paths still hit your managed rules.
    • This does not turn a managed rule off. Count and block stay as they are until you promote.

    Known exploits counted this traffic. The draft allows only what the preview says.

    1. Review the draft. It matches the preview.
    2. Save to add it. Nothing is written before that.
    3. Come back here. The decision updates after the save.
Since you promoted

Blocked counts are the current 24h window. Sampled blocks are log rows at or after the promote time. Undo is one click back to count. We never auto-rollback.

SQL injectionPromoted
  • Blocked 27 in 24h
  • Sampled blocks since promote: 2

No known-good paths in the sampled blocks since promote.

Questions

Is Example University a real customer?

No. Example University and example.com on this page are example data: an invented site and invented counts. Not a customer. Not live traffic.

Does a Promote click on this page block anything?

No. The Promote button is inert. A human clicks Promote on a real site. Nothing blocks automatically, and this page does not change a rule.

What does Hold’s “what would change this” line mean?

It names the gap that would have to close before that rule could say Promote. The line is display only. It does not block, and it does not change the decision.

See it on your site

Rules start in count. After 24 hours, your dashboard shows what's safe to block — one click.

Start a 14-day trial

Card at Stripe checkout. Cancel before the 14-day trial ends and you won't be charged.

$150/site/mo after the trial

Full example panel · Promote Copilot docs · What is Promote Copilot? · Pricing