Skip to content

Traffic Generator

Choose an independent Azure or AWS deployment to generate controlled security traffic and collect demo evidence against F5 Distributed Cloud.

The Traffic Generator produces controlled attack traffic, reconnaissance scans, bot simulations, API abuse patterns, and browser-driven Client-Side Defense scenarios against an F5 Distributed Cloud HTTP load balancer. Choose either the existing Azure deployment or the independent AWS deployment. They share suite intent, but they do not imply cloud, runtime, or detection parity.

The Azure path provisions its established toolset with cloud-init. The AWS path uses a public-subnet worker with an explicit Elastic IP, SSH restricted to the operator jumpbox’s current public /32, Systems Manager recovery, immutable source and runtime inputs, and sanitized browser evidence. A completed browser scenario proves execution and evidence capture; it does not guarantee a corresponding F5 Distributed Cloud detection.

For AWS Client-Side Defense, csd-violations is the only maintained suite. Other suite entries below describe the existing Azure deployment.

SuiteDescriptionF5 XC Feature Validated
api-attacksOWASP API Top 10, SQLMap API mode, parameter discovery, endpoint fuzzingAPI Security
bot-simulationHeadless Chrome, Puppeteer stealth, Playwright automation, rapid crawlingBot Defense
cdn-load-testingCache behavior, thundering herd, connection pool, HTTP/2 multiplexingCDN Integration
crapi-exploitsBOLA, OTP bruteforce, JWT manipulation, SSRF, NoSQL injection, IDORAPI Security
csd-violationsEleven controlled, sanitized browser scenarios with per-step evidenceClient-Side Defense
dvga-exploitsBatch query DoS, deep recursion, SQL injection, introspection abuseAPI Security (GraphQL)
dvwa-exploitsBrute force, command injection, CSRF, file inclusion, SQLi, XSSWAF
juice-shop-exploitsSQLi login bypass, XSS, IDOR, admin access, null byte file accessWAF, Bot Defense
mitre-attackATT&CK tactics: recon, initial access, credential access, exfiltrationWAF, Bot Defense, API Security
owasp-scanningZAP, Nikto, Nuclei, Nmap vulnerability scanning, combined OWASP reportWAF, Web App Scanning
performance-testingConcurrency ramp, sustained load, spike testing, breakpoint discoveryDDoS, Rate Limiting
reconnaissanceNmap, Masscan, Gobuster, Subfinder, directory brute-forcingWAF / Bot Defense
restaurant-exploitsBOLA, BOPLA, BFLA, rate limiting bypass, JWT weak secretAPI Security
ssl-scanningSSLScan, sslyze, testssl.sh TLS configuration analysisWAF
traffic-generationHigh-volume legitimate HTTP traffic for baseline and load testingAll
waf-encoding-evasionMulti-layer URL/HTML/Unicode encoding, mixed nested encoding, chunked Transfer-Encoding, header injectionWAF
web-app-attacksSQL injection, XSS, command injection, path traversal, Nikto, NucleiWAF
demoapp-attacksSQLi, XSS, path traversal against F5 DemoApp WAF testing endpointsWAF