We built a WAF tester that adapted each request based on what the WAF blocked or passed. This helped us explore variations that a fixed test might miss. We ran it across six attack categories on an authorized staging environment and discovered detection gaps worth fixing.
Source: [Cloudflare Blog](https://blog.cloudflare.com/adaptive-ai-waf-testing/)