The research focuses on evading the XSS filters of all popular Web-Application Firewalls. F5 Big IP, Imperva Incapsula, AQTRONIX WebKnight, PHP-IDS, Mod-Security, Sucuri, QuickDefense, Barracuda WAF. The research should have been published in July 2015, but as a supporter of the responsible disclosure concept, I waited for companies to patch the bypasses. I am not responsible for any malicious actions that is done using the information in the research.”]
Source: https://mazinahmed.net/blog/evading-all-web-application-firewalls/