app-under-test

A dynamic site with the shape of an attackable application — login form, reflected search, file upload, JSON API — and none of the actual holes. Point WAF, bot and rate-limit rules at it, then ask the detector what reached the origin.

Test surface

EndpointWhat it is for
POST /logincredential stuffing, bot detection, JS challenges
GET /search?q=reflected parameter — SQLi/XSS-shaped WAF probes
POST /uploadmultipart body inspection, body-size limits
GET|POST /api/ordersAPI schema enforcement, per-endpoint rate limits
GET /_detector/requestswhat actually arrived — the blocking oracle
POST /_detector/resetclear the buffer before a test run

Catalogue

IDNameCategoryPrice
1Edge Widgethardware42.0
2Origin Shieldservice99.0
3Cache Key Ringhardware12.5
4Bot Deterrentservice250.0
5TLS Certificate Holdermisc7.25

app-under-test · version 0.1.0-rc.4