Protected while you fix it.
Defend takes the exploits Assess finds and neutralizes them at your middleware layer, inside your app, as a Generative Counter Exploit (GCE), not a generic WAF signature. No need to touch the vulnerable code. No tuning. No 30–90 day exposure window while developers work.
A GCE is not a WAF signature. It's a targeted mitigation.
When Assess confirms an exploit against your app, Defend generates a Counter Exploit: a piece of code that intercepts the specific request pattern that broke your app and blocks it on the endpoint where it was proved, or adds the response header the app was missing.
Block
Stop the proven exploit on the endpoint where Assess proved it. Example: a withdraw request with a negative amount is rejected before your handler sees it.
Header inject
Add the protective header the app forgot. Example: missing CSRF, Content-Security-Policy, or X-Frame-Options.
Negative numbers, a withdraw form, and one line of GCE
A real finding from a banking application. The kind of flaw scanners systematically miss and WAF signatures can't describe.
// Attacker submits:
POST /api/withdraw
Authorization: Bearer <victim-token>
Content-Type: application/json
{ "account": "...",
"amount": -50000 }
// Server trusts the sign.
// balance += amount → balance increases.
// Attacker just "withdrew" -$50K.
Status: 200 OKScanner response: HTTP 200, valid JSON, nothing to flag. No CVE matches. The signature layer has no concept of "negative withdrawal is a fraud vector."
// GCE-2847 · middleware
defend.intercept('POST /api/withdraw', (req) => {
if (req.body.amount < 0) {
return block(403);
}
return req;
});
// Attacker sees:
Status: 403 Forbidden // blocked before
// the handler runs.
// Attack dead.Three lines of targeted code. Generated from the exact exploit payload. Log-only until your team turns on blocking. Zero impact on any other route, user, or legitimate request.
Where Defend actually runs
No network proxy. No CDN dependency. No tuning phase.
SDK at the middleware layer
Node.js SDK today
No call to Manticore per request
Runs in your app, not at the edge
One-click enable / one-click disable
What Defend is not
Scope discipline. Here's what we don't claim.
Not a WAF signature set
GCEs are generated from the specific exploits Assess ran, not a generic rule library.
Not a replacement for code fixes
GCEs buy time. Architecturally, your team still owns the underlying fix — that's where Fix comes in.
Not an always-on blocker
Every GCE is scoped to a specific route and payload shape. It doesn't re-inspect every request against a thousand rules.
Not a CDN or reverse proxy
It runs in your application process, not in front of it. No traffic redirection, no TLS terminator in the middle.
What GCE neutralizes — and what routes to Fix
Honesty about the seam. Defend covers the majority of findings; Fix covers the rest.
- Business-logic flaws (price tampering, negative amounts, coupon stacking)
- Injection (SQLi, XSS, SSRF, command injection, path traversal)
- Broken auth (weak sessions, missing CSRF, MFA gaps, cookie flags)
- API authz (IDOR, BOLA, mass assignment, excessive data exposure)
- Missing security headers (CSP, X-Frame-Options, HSTS)
- Rate-limit evasion on sensitive endpoints
- Architectural rewrites (redesigning a whole auth flow)
- Cryptographic algorithm changes (moving off a weak hash)
- Vulnerable dependency upgrades
- Schema / data-model changes
- Anything the GCE can only mask, not cure
When you reach for Defend
The zero-day window
A critical finding lands. Devs need weeks to ship the architectural fix. A GCE covers the exposed endpoint while the fix ships.
Vulnerable third-party dependency
Library has a known CVE, upgrade breaks compatibility. GCE neutralizes the specific call path until upgrade lands.
Legacy systems you can't easily touch
Platform you inherited, team that's moved on. Defend protects at the middleware layer without requiring a release.
Auditor-window mitigation
Audit finding, 30-day remediation SLA. Defend is active within hours and evidenced in the Assess replay stream.