The business case · Web application firewall
OWASP Coraza, by the risk it changes
An OWASP web application firewall that can sit in front of the HTTP traffic an agent sends or receives. Its documentation describes an audit engine that logs complete transactions. Written as an answer, that is a partial record of what the agent did, for the traffic that passes through it, once somebody switches the audit engine on: its default is off.
Open source: Apache-2.0 · OWASP · get involved
The deployment: The model's typical deployment, with the answers this project addresses stated as they are without it: what it did cannot be reconstructed.
The model: the RiskGraph Explorer's 49 facts, 49 risks and 10 roles, copied into this site with its provenance; the register below is computed, not written. How.