azure_analyze_application_gateway
Analyzes Azure Application Gateway and WAF configurations to detect security gaps, including disabled WAF, weak SSL/TLS, and HTTP-only listeners.
Instructions
Analyze Azure Application Gateway and WAF (Web Application Firewall) security configuration. Checks: WAF enabled/disabled, WAF mode (Detection vs Prevention), OWASP rule set version, disabled rule groups, SSL/TLS policy version (TLSv1.0/1.1 = CRITICAL), HTTP-only listeners (no HTTPS redirect), backend authentication certificates, request routing rules. Identifies misconfigurations leading to WAF bypass and MitM attacks.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| subscriptionId | Yes | Azure subscription ID | |
| resourceGroup | No | Optional: Filter by specific resource group | |
| format | No | Output format: 'markdown' (default) or 'json' |