WAF custom rules are more flexible, of course, and from a business perspective, I can understand why they would recommend that option instead.
I currently filter on an nginx access log file among other filters (sshd, bot-search, bad-requests) and let fail2ban execute the ban/unban action itself.
From a quick search, it should be possible to handle bans/unbans externally, if that's what you're after.
Hijacking:
With the above solution, it's also super easy to install modpacks and I would recommend Modrinth as both the modded Minecraft launcher and mod-shareplace.
Blue-white lightning icons/symbols are quite common, I would think.
Slay the Spire comes to mind:
Then again, there are some yellow ones, too: