Skip to content

Traffic Generator

Deploy a traffic generation VM with 50+ security tools, 19 organized attack suites, and headless Chrome automation for comprehensive F5 XC demo validation.

The Traffic Generator is a purpose-built Azure VM that produces realistic attack traffic, reconnaissance scans, bot simulation, and API abuse patterns against an F5 Distributed Cloud HTTP load balancer. It validates that WAF policies, Bot Defense, API Security, and Client-Side Defense are correctly configured by generating the exact traffic those features are designed to detect and block.

All tools are pre-installed via cloud-init during Terraform provisioning. Traffic is organized into suites that can be run individually or in sequence using the included runner.sh orchestrator.

SuiteDescriptionF5 XC Feature Validated
api-attacksOWASP API Top 10, SQLMap API mode, parameter discovery, endpoint fuzzingAPI Security
bot-simulationHeadless Chrome, Puppeteer stealth, Playwright automation, rapid crawlingBot Defense
cdn-load-testingCache behavior, thundering herd, connection pool, HTTP/2 multiplexingCDN Integration
crapi-exploitsBOLA, OTP bruteforce, JWT manipulation, SSRF, NoSQL injection, IDORAPI Security
csd-demo-attacksCard skimmer, formjacker, keylogger, cryptominer, DOM hijackClient-Side Defense
dvga-exploitsBatch query DoS, deep recursion, SQL injection, introspection abuseAPI Security (GraphQL)
dvwa-exploitsBrute force, command injection, CSRF, file inclusion, SQLi, XSSWAF
javascript-exploitsDOM manipulation, inline script injection, Magecart-style skimming payloadsClient-Side Defense
juice-shop-exploitsSQLi login bypass, XSS, IDOR, admin access, null byte file accessWAF, Bot Defense
mitre-attackATT&CK tactics: recon, initial access, credential access, exfiltrationWAF, Bot Defense, API Security
owasp-scanningZAP, Nikto, Nuclei, Nmap vulnerability scanning, combined OWASP reportWAF, Web App Scanning
performance-testingConcurrency ramp, sustained load, spike testing, breakpoint discoveryDDoS, Rate Limiting
reconnaissanceNmap, Masscan, Gobuster, Subfinder, directory brute-forcingWAF / Bot Defense
restaurant-exploitsBOLA, BOPLA, BFLA, rate limiting bypass, JWT weak secretAPI Security
ssl-scanningSSLScan, sslyze, testssl.sh TLS configuration analysisWAF
traffic-generationHigh-volume legitimate HTTP traffic for baseline and load testingAll
waf-encoding-evasionMulti-layer URL/HTML/Unicode encoding, mixed nested encoding, chunked TE, header injectionWAF
web-app-attacksSQL injection, XSS, command injection, path traversal, Nikto, NucleiWAF
demoapp-attacksSQLi, XSS, path traversal against F5 DemoApp WAF testing endpointsWAF