wafep
    
            
                
                    Web Application Firewall Evaluation Project
                
            
             
            
             
            
        
            ... ideally be used in twin instances - one BEHIND the WAF (the defender/target website), and another before the WAF (the attacker website).
The payloads can be executed manually through the WAFEP attacker website instance by activating one test case at a time, or automatically, by using a crawling mechanism such as the one implemented in ZAP, Burpsuite, etc.
*Note*
The target website should be configured in the attacker website FIRST, by accessing: /wafep/config/change-target.jsp