<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Peakhour.IO - OWASP CRS</title><link>https://www.peakhour.io/</link><description></description><lastBuildDate>Wed, 29 Jul 2026 10:00:00 +1000</lastBuildDate><item><title>How to Tune Google Cloud Armor WAF Rules</title><link>https://www.peakhour.io/blog/how-to-tune-google-cloud-armor-waf/</link><description>&lt;p&gt;Tune Cloud Armor preconfigured WAF rules with preview traffic, versioned signatures, sensitivity levels, field exclusions and policy priority.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Wed, 29 Jul 2026 10:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-07-29:/blog/how-to-tune-google-cloud-armor-waf/</guid><category>Application Security</category><category>WAF</category><category>Google Cloud Armor</category><category>Google Cloud</category><category>OWASP CRS</category><category>Application Security</category><category>False Positives</category><category>WAF Tuning</category></item><item><title>How to Tune Cloudflare WAF When Rule 949110 Blocks a Request</title><link>https://www.peakhour.io/blog/how-to-tune-cloudflare-waf/</link><description>&lt;p&gt;Trace a Cloudflare OWASP anomaly-score block to the rules that raised the score, then choose the right override or exception.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Wed, 29 Jul 2026 09:45:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-07-29:/blog/how-to-tune-cloudflare-waf/</guid><category>Application Security</category><category>Cloudflare WAF</category><category>WAF</category><category>OWASP CRS</category><category>Application Security</category><category>False Positives</category><category>WAF Tuning</category></item><item><title>How to Tune Coraza on Caddy</title><link>https://www.peakhour.io/blog/how-to-tune-coraza-waf/</link><description>&lt;p&gt;Run Coraza and OWASP CRS on Caddy in DetectionOnly, read the audit log and limit each exclusion to the field and route that need it.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Wed, 29 Jul 2026 09:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-07-29:/blog/how-to-tune-coraza-waf/</guid><category>Application Security</category><category>Coraza</category><category>Caddy</category><category>OWASP CRS</category><category>WAF</category><category>Application Security</category><category>False Positives</category><category>WAF Tuning</category></item><item><title>How to Tune Your WAF Without Turning It Off</title><link>https://www.peakhour.io/blog/how-to-tune-your-waf/</link><description>&lt;p&gt;A practical process for running a CRS-based or managed WAF in detection mode, finding repeatable false positives and writing narrow exceptions that survive real application traffic.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Tue, 28 Jul 2026 10:30:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-07-28:/blog/how-to-tune-your-waf/</guid><category>Application Security</category><category>WAF</category><category>OWASP CRS</category><category>ModSecurity</category><category>Coraza</category><category>Application Security</category><category>False Positives</category><category>WAF Tuning</category></item></channel></rss>