SYLink WAF · Web applications

Your sites and your APIs,
filtered before they reach you.

A sovereign application firewall in front of your domains: Coraza engine and OWASP CRS rules, observation-then-blocking mode, geo-blocking — without touching your hosting.

Coraza + OWASP CRSObserve then blockCountry filteringDNS cutover
1 CNAME
to be protected
OWASP
Core Rule Set maintained
0
line of code to change

A brochure site, an extranet, an API: it is the door to your IS that stays open 24/7, and the only one everyone can push on. SYLink WAF sits in front of your domains via a single DNS record. It inspects every request with the Coraza engine and OWASP CRS rules, starts in observation mode so nothing breaks, then blocks the day you decide.

How it works

From threat to evidence, in real time.

The module captures the signal, SYLink AI correlates it and decides — you keep control.

Web request
Visitor or attacker
SYLink WAF
Coraza + OWASP CRS
SYLink AI
Qualifies and correlates
Site served
Attack repelled
In the portal

The WAF, from the portal.

Three domains behind the application firewall, and everything it has seen pass — in observation first, in blocking when you decide.

01

Your domains and what the WAF saw

client.unisoc.fr/waf
Your domains and what the WAF saw
One business template per domain (SaaS B2B, API…), DNS status, the score — and the 24 h window: queries analysed, detections in observation, unique sources, most-triggered OWASP rules.
02

Where attacks come from

client.unisoc.fr/waf
Where attacks come from
Hour-by-hour activity (legitimate, detected, blocked), top source countries with the 'Block this country' button — blocking a country also adds IPs already seen attacking from it — and the recent events log, URI by URI.
03

Four-step onboarding

client.unisoc.fr/waf
Four-step onboarding
You specify the domain to protect, the portal gives you the DNS record to create and verifies its propagation. No changes to your hosting.

Real screenshots of the UniSOC portal. The data shown comes from a demonstration environment.

Capabilities

The technology, in detail.

What the module actually does — functions, not promises.

Coraza engine + OWASP CRS

  • SQL injection, XSS, path traversal
  • OWASP Core Rule Set, kept up to date
  • Ready-made profiles: e-commerce, SaaS, brochure, API
  • Exceptions and custom rules per domain
  • Observe first, block when you want

Geographic & source filtering

  • Country blocking using the full ISO list
  • Preventive blocking, even for a never-before-seen country
  • On-demand IP and range blocking
  • Top countries and top sources live

DNS-based commissioning

  • A CNAME — ALIAS/ANAME on a root domain
  • DNS propagation check in the portal
  • TLS certificate issued and renewed automatically
  • No change to your hosting
  • Rollback = a DNS record

Evidence and transparency

  • Blocked requests log, rule by rule
  • Public status page per domain
  • Alerts forwarded to the UniSOC SOC
  • Processing and hosting in France
Use cases

What is it actually for?

Hold out until the patch

A vulnerability drops for your CMS on a Friday night: the CRS rule blocks exploitation while the vendor prepares its patch.

Shut out background noise

Bruteforce on admin pages, automated scans, inventory bots: filtered before reaching the server.

Reduce exposure to the strict minimum

Your extranet only serves France and Italy: all other countries are blocked with one click, with the associated evidence.

The method, in four steps
From raw signal to defensible evidence.
Detect
Understand
Decide
Prove
01The module captures the raw signal — traffic, behaviour or indicator.signal captured
Specifications
EngineCoraza + OWASP Core Rule Set
ModesObservation (detection) then blocking
CommissioningCNAME — ALIAS/ANAME on an apex
TLSCertificate issued and renewed automatically
FilteringApplication rules + countries + IPs
ControlClient portal, WAF page
Natively integrated with
SYLink AI — attack qualification
Attack surface — domains discovered
AI Firewall — shared malicious sources
DPI sensor — network correlation
Compliance module — NIS2 evidence
Sovereign

Driven by SYLink AI, hosted 100% in France (HDS v2), with no Cloud Act exposure. Every decision is logged and defensible under NIS2 and DORA.

Live in under 48 hours

Ready to see what is really
happening on your network?

First trial free, no credit card, no commitment. On your existing infrastructure.

Cookie settings

We use cookies to improve your experience on our site. By continuing to browse, you accept our privacy policy and our use of cookies under the GDPR.