Noam Moshe from Team T82 @Claroty has an excellent writeup of bypassing Web Application Firewalls by abusing JSON-based SQL.

https://t.co/k6jXwZCVkb