Website Security & Threat Management
Always-on detections: eliminating the WAF “log versus block” trade-off

Always-on detections: eliminating the WAF “log versus block” trade-off

3/4/2026 · Daniele Molteni

What this post added

Introduced 'Attack Signature Detection' and 'Full-Transaction Detection' as an evolution of the WAF's managed rules. Attack Signature Detection runs all detection signatures on every request, attaching metadata without impacting performance if no blocking rule is configured. Full-Transaction Detection analyzes both request and response to reduce false positives and detect more complex threats. The 'always-on' framework separates detection from mitigation, enriching analytics and enabling custom policies based on detection metadata.

Read the original post ↗