Skip to content

What it blocks

Blackwall checks each request against the OWASP Core Rule Set, version 4.25.0, at its standard strictness: 159 rules in 7 kinds. A request is stopped when what it matches adds up to an attack, not for one weak sign.

What this list is, and is not

  • These are the rule set's rules, not ours. We did not invent a way of detecting attacks; we run a well-known one for you and explain what it reports.
  • The rule set has stricter levels that catch more and stop more real visitors. Blackwall uses the standard level for everyone.
  • What your site sends back to a visitor is not inspected in this version, only what visitors send to your site.
  • No rule set catches everything. What Blackwall does not protect against.