GoTestWAF by Wallarm is an open-source tool designed to evaluate the performance and effectiveness of web application firewalls (WAFs). It simulates various cyberattacks on APIs using predetermined payloads such as XMLRPC, SOAP, and REST, and assesses the responses to generate detailed reports. GoTestWAF helps identify threats caught by the AppSec solution and provides insights into how attackers might exploit vulnerabilities in applications. It supports various API protocols including REST, GraphQL, gRPC, WebSockets, SOAP, and XMLRPC. The tool is shipped as a Docker container and produces detailed PDF reports on security solutions' performance. It is used to test WAFs, RASPs, and WAAPs against software and API threats, ensuring precise feedback on WAF performance and identifying weak points that could be exploited by hackers.