Reaching authorized targets behind a WAF or CDN
A scanner that trips a WAF or CDN returns nothing useful, even against a target you are authorized to test. Crossfyre presents a genuine browser handshake instead of a self-identifying scanner fingerprint, and can discover a target’s real origin behind the CDN, so an authorized scan reaches the in-scope app instead of bouncing off the edge.
Why do normal scanners get blocked?
A default scanner is flagged before it sends a single request: its TLS and HTTP fingerprints are recognizable, and its User-Agent names the tool. Changing the source IP alone does not help, because the fingerprint gives it away. The result is a scan that looks busy but is quietly being served blocks, so it reports nothing.
How does Crossfyre stay reachable?
Two things. It can find a target’s real origin behind the CDN/WAF (through certificate, DNS-history, and related pivots), so the scan reaches the app directly and that origin exposure is itself a reportable finding, available on every plan. And on Reaper it presents a real browser handshake, so an authorized scan is not flagged on TLS/HTTP fingerprint alone. Pacing is adaptive throughout, so throughput stays high without hammering any single source.
Isn’t this just for evading detection?
No, and the framing matters. These capabilities exist so an authorized scanner can reach the in-scope app that happens to sit behind a WAF, not to hide malicious activity. Confirm the protected asset and its origin are in scope before bypassing; origin exposure is usually reportable, but directly attacking an out-of-scope origin is not. Many programs will allowlist you, and Crossfyre can also present an attribution identity when that is the sanctioned first move.
What about residential or mobile egress?
Origin discovery and adaptive pacing are available on every plan; browser-impersonation (fingerprint parity) is a Reaper capability. Paid egress levers, like routing through an operator-supplied residential or mobile proxy, are always opt-in and kept node-side so they never share Clickswave infrastructure.
Frequently asked
Is WAF bypass legal?
Reaching an in-scope asset behind a WAF during authorized testing is a normal part of an engagement; attacking something you are not authorized to test is not. Crossfyre is for authorized work only: assets you own or have written permission to test. Confirm the WAF-protected asset and its origin are in scope first.
Do I have to configure any of this?
A single node-level Evasiveness switch controls it, default on. Browser-impersonation applies on Reaper; other tiers still get adaptive pacing and can use origin discovery. Turn the switch off for targets you know are unprotected (internal, CTF, dev, allowlisted). Paid egress levers are separately opt-in.