Skip to main content
Senior Digital Product Manager

Ahmed Maghawry

5
Posts authored

Posts

Article

Detection or Proof: Rethinking the Central Question Behind WAFs

This paper challenges the idea that WAFs should rely primarily on attack detection. It proposes a risk-based architecture where lower-risk endpoints use detection and anomaly analysis, while high-risk functions require validation of structure, authorization, context, and business logic. The paper concludes that effective WAF security is fundamentally a risk-routing problem.

Ahmed Maghawry · Oct 5, 2026 · 6 min
Article

The Invisible Attack Surface: What Vulnerability Scanners Are Not Telling You!

Traditional vulnerability scanners only see known assets, leaving unknown systems and exposures invisible. As cloud, APIs, and third-party services expand the attack surface, continuous discovery becomes critical. This post shows how Attack Surface Management fills that gap by uncovering hidden risks before attackers do.

Ahmed Maghawry · Aug 9, 2026 · 7 min
Article

WAF Evasion 101: How Attackers Bypass “Security Gates”

Attackers reshape the same malicious payload just enough that the WAF no longer recognizes it, while the backend still executes it exactly as intended. This post walks through the real evasion playbook (encoding tricks, token splitting, noise injection, and reinforcement-learning-driven automated probing) and shows why the problem is structural, not a matter of sloppy engineering.

Ahmed Maghawry · Jul 27, 2026 · 14 min
Article

Why High Accuracy Can Still Mean Bad Security!

High accuracy in security does not guarantee real-world protection. Through the WAMM research study, this post examines what accuracy metrics hide, how false positives and false negatives manifest in production environments, and what a security-grade evaluation framework should actually measure.

Ahmed Maghawry · Jul 12, 2026 · 5 min
Article

Can AI Detect Web Attacks Better Than Rules?

The real challenge is not choosing rules or AI, but designing detection systems that can operate under uncertainty and adversarial pressure. This article examines web attack detection and WAF evasion through scientific research and real-world observations.

Ahmed Maghawry · Jun 16, 2026 · 15 min