İçeriğe geç
Tres Teknoloji
Products / NetWaf
N
NetWaf Web application firewall

The firewall that stands in front of your application

Stop OWASP Top 10 attacks, bot traffic and application-layer DDoS before they reach your application. Live within minutes with a DNS change.

OWASP Top 10 Bot management L7 DDoS protection Virtual patching
Minutes Deployment via DNS
0.01% False positive rate
< 3 ms Added latency
4+ Tbps Scrubbing capacity
Problem

Until you fix the code, the vulnerability stays exposed

When a vulnerability is reported, the patching process can take weeks, and during that time the application is defenseless. With virtual patching, NetWaf closes the gap without touching the code side, so your team can plan the fix at ease.

OWASP rule set

Block attacks such as SQL injection, XSS, RCE and path traversal with a ready-made rule set.

Virtual patching

Close a known vulnerability at the WAF layer without changing the application code.

Bot management

Let good bots (search engines) through and stop scraper and credential-stuffing bots.

Rate limiting

Define request limits per IP, session or endpoint.

Learning mode

It watches traffic for the first week and suggests rules; you decide what to block.

Logchase integration

Blocked requests flow into the SIEM; incident analysis is done on one screen.

Integrations

It runs as a reverse proxy; it does not matter where your application is hosted. It can be on the Tres cloud, in your own data center or with another provider.

Nginx Apache IIS Cloudflare front Kubernetes Ingress Load Balancer WordPress Magento Laravel Node.js ASP.NET Logchase

Compliance

PCI DSS 6.6 Meets the web application firewall requirement.
KVKK Records and blocks attack attempts that would leak personal data.
ISO 27001 Application-layer access control and monitoring requirements.
BDDK / TCMB Aligned with the application-security expectations of financial institutions.

Pricing

Pricing is based on the number of domains you protect, your traffic and the management level (you manage it or we manage it). We prepare a quote to fit your needs.

Get a quote

Pricing tailored to your needs

We prepare a custom quote based on your usage volume and requirements, and get back to you within a few minutes.

Get a quote
FAQ

NetWaf — frequently asked questions

No. NetWaf runs as a reverse proxy; you only need to point your domain's DNS record to NetWaf. No code, server or architecture change is required, and deployment takes minutes.

OWASP Top 10 attacks such as SQL injection, XSS, remote code execution and path traversal are blocked before reaching the application with a continuously updated ready-made rule set. You can also write rules specific to your own application.

Yes. Virtual patching lets you close a known vulnerability by blocking it with a rule at the WAF layer, without touching the application code. While your development team plans the permanent fix, the vulnerability is not left exposed.

For the first week NetWaf only watches your traffic in learning mode and suggests rules; you turn on blocking. This keeps the false positive rate at the 0.01% level and does not interrupt the real user flow.

No. NetWaf verifies and lets through good bots (search engines such as Google and Bing); it stops malicious bots that scrape, do credential stuffing and scan inventory.

Yes. NetWaf is independent of where your application is hosted; it can be on the Tres cloud, in your own data center or with another provider. It receives traffic at the front, scrubs it and forwards it to your backend server.

It meets PCI DSS's web application firewall requirement (Requirement 6.6). Blocked requests are logged and can be reported for audit; with the Logchase integration you perform incident analysis on one screen.

NetWaf counters seemingly legitimate HTTP requests sent to exhaust the application (L7 DDoS) with rate limiting and behavioral analysis. Volumetric network-layer attacks, meanwhile, are absorbed by the scrubbing infrastructure in front of it.

Customer reviews

What teams using NetWaf say

“When a vulnerability was reported, we turned on virtual patching within minutes and closed the gap; the team made the permanent fix without pressure. We never touched the code side.”
DY Deniz Yılmaz Security Engineer · Trendhane
“Within 10 minutes of pointing our DNS, protection was live. Thanks to learning mode, we did not block even a single real user by mistake.”
BD Buse Demir Infrastructure Team Lead · Paykolay
“On campaign days, bot traffic was melting our stock pages. With NetWaf bot management the fake traffic was filtered out, and speed returned for real customers.”
OK Onur Kaya Software Director · Modanova
“Being able to plan backups and snapshots separately greatly strengthened our hand in disaster scenarios.”
EK Emre Kılıç Information Security Manager · Kuzey Ödeme Sistemleri
“Region options and low latency gave our users in Turkey a noticeable speed boost.”
KD Kerem Doğan Digital Channels Manager · Nova Dijital
“When traffic spikes suddenly we can scale resources up within seconds; campaign days are no longer stressful.”
TE Tolga Erdoğan Chief Architect · Oyunistan
“Being able to quickly spin up and try a test environment made our purchasing decision much easier.”
NG Nazlı Güneş Software Director · Ticaretix
“Thanks to hourly billing we only pay for what we use; no surprise invoice at the end of the month.”
EK Emre Kılıç Information Security Manager · Kuzey Ödeme Sistemleri
“The flexibility on the network side (private network, firewall, IP management) exceeded our expectations.”
KD Kerem Doğan Digital Channels Manager · Nova Dijital

Let us monitor your application free for a week

In learning mode we analyze your traffic and report which attacks are coming. Without turning on blocking — just see them.