Blog

Release notes, security deep dives, and engineering notes from the team building coreX Platform.

The Gaps coreX Fills

HAProxy can enforce anything. Cloud WAAPs will decide for you. The product gap is the control plane in between — policy you own, scores you can explain, traffic that never leaves your network.

#corex#waf#waap#haproxy#self-hosted#cloudflare#edge
Read post →

Why I Built coreX

I spent years shipping WAF and edge products. NGINX had real limits my teams and I kept hitting. coreX is extra magic on a stack operators already trust — HAProxy, Coraza, Varnish — plus the vision and hidden gems previous employers did not want to ship. I built it after I outgrew Nginx Proxy Manager at home.

#corex#waf#edge#homelab#haproxy
Read post →

coreX vs Cloudflare, Akamai, F5, and HAProxy: Which WAAP Belongs on Your Infrastructure?

Compare coreX Platform with Cloudflare, Akamai, Imperva, AWS WAF, Azure WAF, F5 Advanced WAF, and HAProxy Enterprise. A self-hosted WAAP with Cloudflare-style rules, API Armor, Page Protect, and an MCP gateway you run yourself.

#comparison#waap#self-hosted#cloudflare#haproxy#mcp
Read post →

Targeted Attacks that Slip by in the Noise

An AI agent with MCP access to coreX and the SIEM read 2,191,000 requests, pulled exploit body shapes out of request fingerprints, named four targeted actors that were not scanners, and wrote the block lists — in one 7 minute session.

#mcp#siem#threat-hunting#fingerprinting#security
Read post →

What an AI Agent Finds When You Connect It to Your Security Stack and SIEM

After 20+ years of threat hunting and writing WAF/DLP/IDS signatures, I put an MCP gateway in front of an AI agent. It found rules that don't behave the way people intended, concrete fixes for false positives, and bad traffic still getting through — in minutes, not hours.

#mcp#ai-agents#security#siem
Read post →

Fingerprinting the HTTP Request — Beyond User-Agent, JA4, and QUIC

User-Agent is a marketing string. JA4 names the TLS library. H2/QUIC fingerprints describe the transport. None of them capture how a client actually builds an HTTP request. The request fingerprint does.

#security#fingerprinting#deep-dive
Read post →