// LAB · RED TEAM · WEB

🧱 WAF Bypass Lab

A WAF (Web Application Firewall) blocks "obvious" payloads, but a blocklist filter can almost always be evaded. Each level gives you the WAF rules and a goal: write a payload that passes the filter and achieves the attack. It is a simulator, everything runs in your browser.