Listing Thumbnail

    ThreatSTOP Managed Rules - New and Active HTTP Threats for AWS WAF

     Info
    Sold by: ThreatSTOP 
    Deployed on AWS
    The New and Active HTTP Threats Managed Rules for AWS WAF protects exposed services from a range of threats including SSH attacks, Brute Forcers, Crackers, Shellshock, Apache Server Attacks, and more. Multiple HTTP threat intel feeds are aggregated and analyzed for continuously updated protection.
    3.5

    Overview

    ThreatSTOP WAFXtender New and Active HTTP Threats Managed Rules for AWS WAF protects against a variety of inbound HTTP threat types, including IPs known to initiate different types of SSH attacks, Brute forcers, Crackers, Shellshock, attacks on Apache servers, and more. Environments with exposed services should especially consider using these managed rules. Multiple HTTP threat intelligence feeds are aggregated and analyzed to provide continuously updated protection.

    Register with ThreatSTOP on the fulfillment page (no cost) and receive a 1 year subscription for ThreatSTOP's CheckIOC product for free!

    Highlights

    • Extend the security power of your AWS WAF. ThreatSTOP Managed Rules help with blocking new and emerging inbound HTTP threats that are currently active.
    • Built from high quality threat intelligence data sources and meticulously curated by ThreatSTOP, these Managed Rules are updated continuously to help you stay ahead of new and emerging attacks while keeping false-positives near zero.
    • Gain the security edge of a modern and sophisticated threat intelligence program that predicts and prevents advanced threats.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    ThreatSTOP Managed Rules - New and Active HTTP Threats for AWS WAF

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (2)

     Info
    Dimension
    Cost/unit
    Charge per month in each available region (pro-rated by the hour)
    $38.00
    Charge per million requests in each available region
    $0.10

    AI Insights

     Info

    Dimensions summary

    You pay on a usage basis with two combined charges. The first is a monthly charge applied in each AWS region where you run the ruleset, pro-rated by the hour. This means you pay only for the hours the ruleset is active. The second is a charge per million requests processed in each region, so this part scales with your traffic volume. You add or remove the ruleset from a Web ACL at any time, and charges accrue per WAF instance where it is applied.

    Top-of-mind questions for buyers

    This ruleset automatically blocks new and emerging inbound HTTP threats to your exposed services, web apps, and websites. It stops SSH attacks, brute forcers, crackers, and similar threats. The rule groups update several times daily using curated threat intelligence feeds, keeping protection current as attacks evolve.
    Both charges apply at the same time and appear together. The monthly charge accrues per region while the ruleset is active on a WAF, pro-rated hourly. The per-million-request charge scales with the HTTP traffic your WAF processes in each region. Higher traffic volumes push the request charge higher.
    No. Charges keep accruing until you actually delete the ruleset from each WAF instance. Cancelling the Marketplace subscription does not remove rulesets already applied to your Web ACLs. Remove the rules from every Web ACL that uses them to stop the charges.
    docs.threatstop.com+1
    Helpful?

    Vendor refund policy

    Non-Refundable

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    25
    In Device Security

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Threat Intelligence Aggregation
    Multiple HTTP threat intelligence feeds are aggregated and analyzed to provide continuously updated protection against emerging threats.
    Real-time Threat Detection
    Detects and blocks active inbound HTTP threats including SSH attacks, brute force attempts, shellshock exploits, and Apache server attacks.
    AWS WAF Integration
    Integrates with AWS WAF as managed rules to extend security capabilities for protecting exposed services.
    Continuous Rule Updates
    Managed rules are continuously updated to address new and emerging attack patterns while maintaining minimal false-positive rates.
    Threat Intelligence Curation
    Threat intelligence data is curated and validated from high-quality sources to ensure accuracy and effectiveness of detection rules.
    Threat Intelligence Integration
    Rulesets regularly updated with latest threat alerts using Cyber Threat Intelligence
    OWASP Top 10 Coverage
    Managed rules designed to mitigate and minimize all vulnerabilities on OWASP Top 10 Web Application Threats list
    Code Injection Prevention
    Targeted rules for common vulnerabilities including SQLi, NoSQLi, OS command injection, XSS, and directory traversal attacks
    Technology-Specific Protection
    Managed rules targeting known exploits for Apache Struts2, Apache Tomcat, Oracle WebLogic, WordPress, Drupal, Joomla, and malicious bots
    False Positive Optimization
    Designed with low false-positive rate while maintaining higher defense capability for web application protection
    OWASP Top 10 Attack Protection
    Provides protection against web attacks including SQL injection, cross-site scripting (XSS), command injection, NoSQL injection, path traversal, and predictable resource exploitation.
    Managed Rule Updates
    Rules are written, managed and regularly updated by F5's security specialists to ensure protection against evolving threats without requiring manual intervention.
    AWS WAF Integration
    Rules can be attached to AWS WAF instances for immediate deployment and protection enhancement.
    Automated Threat Detection
    Utilizes security expertise to identify and mitigate vulnerabilities that are part of the OWASP Top 10 attack vectors.
    Pay-as-You-Go Licensing Model
    Rules are licensed on a consumption-based pricing structure where usage determines costs.

    Contract

     Info
    Standard contract
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    3.5
    1 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    100%
    0%
    0%
    0%
    0 AWS reviews
    |
    1 external reviews
    External reviews are from PeerSpot .
    reviewer2888679

    Improved ddos protection has reduced false positives but installation and interface still need work

    Reviewed on Aug 17, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for ThreatSTOP Platform is that we are using an A10 DDoS protection device in our internal network as an on-premise device, and we are using ThreatSTOP Platform's feature to prevent well-known attacks from well-known IP addresses in A10's database.

    For example, my use of ThreatSTOP Platform in our environment involves a category named well-known bank attacks, where there were subnets in ThreatSTOP Platform's database that we added into the system, and then ThreatSTOP Platform converged those IP addresses into our A10 devices, preventing attacks from well-known bank attackers and financial attackers.

    ThreatSTOP Platform functioned as an IP address database, so it was not a day-to-day use device. Instead, we were checking IP addresses from ThreatSTOP Platform and using it as a USOM list.

    What is most valuable?

    The best features ThreatSTOP Platform offers are that it gives us categories to create a policy and add IP addresses and categories into that policy, which we can use directly on the A10.

    The category and policy creation made my work easier and more effective because I did not add IP addresses one-by-one into that policy. Instead, I added categories into the policy, so I did not use any irrelevant IP addresses or irrelevant categories in my policies.

    ThreatSTOP Platform has impacted our organization positively by reducing our DDoS false positive protection, and since we were doing some fine-tuning in our DDoS devices, it reduced our work time in the device.

    I cannot say an exact number regarding how much time was saved, but we obviously observed that it helped to reduce our work time in the A10 device. However, I cannot say exactly how much the impact was, but it was really helpful.

    What needs improvement?

    ThreatSTOP Platform can be improved by enhancing the graphical user interface, making it work faster, and addressing the installation part, which was difficult because they sent us too many port numbers and IP addresses to add to our firewall policies, along with an OS to install on our Linux server, which I think should not have to be part of buying the product.

    Initial support and setup support being great would be an additional improvement needed.

    For how long have I used the solution?

    I have been working in my current field for about six years.

    What do I think about the stability of the solution?

    I describe the stability of ThreatSTOP Platform as adequate for an IP list database.

    What do I think about the scalability of the solution?

    ThreatSTOP Platform's scalability has a good side because it has so many options and categories, but the scalability side allows using categories in your system, and I think the categories are static.

    How are customer service and support?

    Customer support, as far as I remember, was good, and they were quick and fast.

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution because we just used well-known IP lists like USOM in our firewall, so ThreatSTOP Platform was the first in my previous company.

    Which other solutions did I evaluate?

    Before choosing ThreatSTOP Platform, I did not evaluate other options because the A10 team, the DDoS device we use, had a support team that offered us ThreatSTOP Platform.

    What other advice do I have?

    My advice to others looking into using ThreatSTOP Platform is to consider it as an IP list, so if anything occurs on the DDoS side, it might be related to ThreatSTOP Platform, and they should check it when troubleshooting.

    ThreatSTOP Platform's AI capabilities and its governance and security were not used by me because these features were not published yet when I was using ThreatSTOP Platform, so I do not have any comments on that.

    In terms of ThreatSTOP Platform's AI capabilities, I think its accuracy and reliability of output is the same situation because I used ThreatSTOP Platform from 2021 to 2023, and when I was using it, it was not involved with AI, meaning we did not use a chatbot or anything else to use ThreatSTOP Platform.

    My overall rating for this product is 7 out of 10.

    View all reviews