This is a list of what you can do for application security with Nginx (mostly with open source tools):
https://github.com/wallarm/awesome-nginx-security
My talk from Nginx conference: https://www.nginx.com/blog/build-application-security-shield...
Important note. Care about vulnerabilities. Not about attacks. Buy Burp license. Run appsec training for all of your developers; it's easy while you're small.
Disclaimer: I am a co-founder of Wallarm mentioned in preso.