WAF: Web Application Firewall
WAF filtra tráfego HTTP/HTTPS malicioso protegendo contra OWASP Top 10 (SQL injection, XSS, etc). Pode ser cloud-based (Cloudflare, AWS WAF), on-prem (ModSecurity) ou hybrid, com regras OWASP Core Rule Set e customizações específicas.
