Blog
Release notes, security deep dives, and engineering notes from the team building coreX Platform.
The Gaps coreX Fills
HAProxy can enforce anything. Cloud WAAPs will decide for you. The product gap is the control plane in between — policy you own, scores you can explain, traffic that never leaves your network.
Read post →Why I Built coreX
I spent years shipping WAF and edge products. NGINX had real limits my teams and I kept hitting. coreX is extra magic on a stack operators already trust — HAProxy, Coraza, Varnish — plus the vision and hidden gems previous employers did not want to ship. I built it after I outgrew Nginx Proxy Manager at home.
Read post →coreX vs Cloudflare, Akamai, F5, and HAProxy: Which WAAP Belongs on Your Infrastructure?
Compare coreX Platform with Cloudflare, Akamai, Imperva, AWS WAF, Azure WAF, F5 Advanced WAF, and HAProxy Enterprise. A self-hosted WAAP with Cloudflare-style rules, API Armor, Page Protect, and an MCP gateway you run yourself.
Read post →Targeted Attacks that Slip by in the Noise
An AI agent with MCP access to coreX and the SIEM read 2,191,000 requests, pulled exploit body shapes out of request fingerprints, named four targeted actors that were not scanners, and wrote the block lists — in one 7 minute session.
Read post →What an AI Agent Finds When You Connect It to Your Security Stack and SIEM
After 20+ years of threat hunting and writing WAF/DLP/IDS signatures, I put an MCP gateway in front of an AI agent. It found rules that don't behave the way people intended, concrete fixes for false positives, and bad traffic still getting through — in minutes, not hours.
Read post →Fingerprinting the HTTP Request — Beyond User-Agent, JA4, and QUIC
User-Agent is a marketing string. JA4 names the TLS library. H2/QUIC fingerprints describe the transport. None of them capture how a client actually builds an HTTP request. The request fingerprint does.
Read post →