# AWAF Detection Inconsistency Between Similar Test Payloads

**URL:** <https://community.f5.com/t/awaf-detection-inconsistency-between-similar-test-payloads/77158>\
**Category:** Technical Forums\
**Tags:** security\
**Created:** [May 29, 2026, 6:54am UTC](https://community.f5.com/t/awaf-detection-inconsistency-between-similar-test-payloads/77158 "2026-05-29T06:54:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kuyidong](https://avatars.discourse-cdn.com/v4/letter/k/e9bcb4/32.png) [@Kuyidong](https://community.f5.com/u/Kuyidong)\
**Post date:** [May 29, 2026, 6:54am UTC](https://community.f5.com/t/awaf-detection-inconsistency-between-similar-test-payloads/77158/1 "2026-05-29T06:54:01Z")

</div>

![image_346625.png](https://d20hrnpixdzcsd.cloudfront.net/original/2X/7/71e70eb2cc7662f8e9088277ef8447a5f0ea581c.png)

 ![image_346625.png](https://d20hrnpixdzcsd.cloudfront.net/original/2X/2/2f15bf2ebc06607bde8a041aff866a84d85f3247.png)

 ![image_346625.png](https://d20hrnpixdzcsd.cloudfront.net/original/2X/7/77395a752f673fd04fe066e508e520a13ada360c.png)

 ![image_346625.png](https://d20hrnpixdzcsd.cloudfront.net/original/3X/b/8/b8607af0c17420c15c1a0c14310d5707806599a2.png)

 ![image_346625.png](https://d20hrnpixdzcsd.cloudfront.net/original/2X/7/7228fef55d98f428ddc1c2bc01f3cef9b662c8db.png)

 ![image_346625.png](https://d20hrnpixdzcsd.cloudfront.net/original/2X/b/b2b48ded5c7611454c6bee67eecc45f6ae9215f2.png)

Hi everyone,

I’m testing F5 AWAF against several attack payloads in a lab environment (crAPI).

I noticed some inconsistent detection behavior and would like to know whether this is expected, a signature coverage issue, or a content profile configuration issue.

**Environment**

F5 AWAF / ASM

Wildcard URL policy

Attack signatures enabled

Form Data, JSON, and XML request body handling configured

Default content profile set to “Apply value and content signatures and detect threat campaigns”

**Case 1 - Command Injection**

The following payload is detected:

POST /clam.php Content-Type: application/x-www-form-urlencoded cmd=cat /etc/passwd

AWAF triggers:

Unix “cmd” parameter execution attempt

However, the following payload is not detected:

POST /clam.php Content-Type: application/x-www-form-urlencoded cmd=127.0.0.1 && ls /etc

The request body is visible in the event logs, so parsing appears to be working correctly.

Has anyone observed similar behavior with command execution signatures?

**Case 2 - Multipart Form Data**

AWAF successfully detects directory traversal inside multipart/form-data:

Content-Disposition: form-data; name=“/static/img/../../etc/passwd” test

However, some multipart XSS payloads are not detected, for example:

Content-Disposition: form-data; name=“random” \<x/Onpointerrawupdate=confirm&lpar;)\>xxxxx

while other XSS payloads such as onerror-based payloads are detected and blocked.

Questions

Is this expected signature coverage behavior?

Are command execution signatures expected to detect payloads like:127.0.0.1 && ls /etc

Are there known limitations for newer event handlers such as:onpointerrawupdate=

Would enabling Base64 Decoding in Header-Based Content Profiles have any effect on these cases, or is this unrelated because the payloads are not Base64 encoded?

Are there recommended Signature Sets or Evasion settings that improve detection for these payloads?

Any guidance would be appreciated.

---

<div class="post-metadata">

**Author:** ![Anoop\_Jayadharan](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/anoop_jayadharan/32/17359_2.png) [@Anoop\_Jayadharan](https://community.f5.com/u/Anoop_Jayadharan)\
**Post date:** [June 1, 2026, 5:04pm UTC](https://community.f5.com/t/awaf-detection-inconsistency-between-similar-test-payloads/77158/2 "2026-06-01T17:04:14Z")

</div>

Hey @Kuyidong

Have you enabled specific attack-type signatures and enforced them within the security policy? For example, signatures related to command execution or Cross-Site Scripting (XSS).

 ![image_346655.png](https://d20hrnpixdzcsd.cloudfront.net/original/3X/4/8/48e2a448dc20d5f4beb8aba810c8842fb0e15b9c.png)

Have a good read about Multipart/form-data below.

[HTTP Multipart and Security Implications](https://community.f5.com/topic/316894)

---

<div class="post-metadata">

**Author:** ![Nikoolayy1](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/nikoolayy1/32/3589_2.png) [@Nikoolayy1](https://community.f5.com/u/Nikoolayy1)\
**Post date:** [June 3, 2026, 7:34am UTC](https://community.f5.com/t/awaf-detection-inconsistency-between-similar-test-payloads/77158/3 "2026-06-03T07:34:01Z")

</div>

About POST /clam.php Content-Type: application/x-www-form-urlencoded cmd=127.0.0.1 && ls /etc maybe see if there is no low level signature about this as if you are using medium/high level only this could be it. Also if you selected specific server technologies maybe then if this is a signature for Linux but you selected Windows in server technologies this could explain the Linux signatures are not applied.

I think I saw similar stuff 2 years and if needed raise F5 case but maybe this is considered not affecting currently systems (who knows ) and you may need to write a custom signature for it if F5 says that for them this is not security risk and this is not covered by low level signatures.

---

<div class="post-metadata">

**Author:** ![zamroni777](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/zamroni777/32/1473_2.png) [@zamroni777](https://community.f5.com/u/zamroni777)\
**Post date:** [June 11, 2026, 2:21pm UTC](https://community.f5.com/t/awaf-detection-inconsistency-between-similar-test-payloads/77158/4 "2026-06-11T14:21:02Z")

</div>

incositently usually happens when the tested webserver (the pool member) has been compromized by your earlier attacks, e.g. script injection has been stored in the app’s db.

if haven’t, also set the Server Technologies config properly according to the tech used by pool member.  
this config usually too strong for live use cases and needs to be loosen using learning from legitimate testers.
