WAF Rule Lookup
Cloudflare's WAF logs only show a Rule UUID when it blocks something. Search the OWASP CRS ruleset by ID, or upload a security event to find out why — and decrypt the matched payload right here, without sending your key anywhere.
Upload a security event
Export a blocked request's security event as JSON from the Cloudflare dashboard. We'll match its rules automatically. If it has an encrypted payload, add your payload log private key to decrypt it — both stay in your browser and are never sent anywhere.
All processing — search, upload parsing, and decryption — happens entirely in your browser. Nothing is uploaded to OriginError's servers.