Test OWASP rules


We are onboarding to Cloudflare and I’d like to test some of the OWASP rules, just to understand them.

How would i go about this? I tried the following but it just returns a 200, even though I thought it would violate a bad bot rule “Request Indicates a Security Scanner Scanned the Site”.


user-agent = “Mozilla/5.0 (compatible; Nmap Scripting Engine)”
url = “https://www.example.com
header = "Host: www.example.com

curl -K waf-nmap-test.config


