Listing Thumbnail

    ThreatSTOP Managed Rules - CoreThreats for AWS WAF

     Info
    Sold by: ThreatSTOP 
    Deployed on AWS
    Our famous CoreThreats is built by aggregating and analyzing over 800 quality threat intelligence feeds, applying human and machine intelligence, then rapidly updating the managed rules to block threats and attacker infrastructure. CoreThreats stops a broad range of attacks with very high accuracy.
    3.5

    Overview

    We have made our famous ThreatSTOP CoreThreats policies available for use with the AWS WAF. ThreatSTOP dynamically builds the CoreThreats policies by aggregating and analyzing over 800 hand-selected threat intelligence feeds, then applying human and machine intelligence to identify the most severe attacking IP addresses active on the internet at this moment. CoreThreats focuses on attackers and attack infrastructure, stopping broad range of threats with high accuracy and low false positive rates.

    Highlights

    • A powerful, yet simple upgrade for your AWS WAF security that focuses on automatically blocking the IP addresses and ranges being used by cyber criminals in the most severe up-to-the-moment attacks.
    • Built from high quality threat intelligence data sources and meticulously curated by ThreatSTOP, these Managed Rules are updated continuously to help you stay ahead of new and emerging attacks while keeping false-positives near zero.
    • Gain the security edge of a modern and sophisticated threat intelligence program that predicts and prevents advanced threats.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    ThreatSTOP Managed Rules - CoreThreats for AWS WAF

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (2)

     Info
    Dimension
    Cost/unit
    Charge per month in each available region (pro-rated by the hour)
    $38.00
    Charge per million requests in each available region
    $0.10

    AI Insights

     Info

    Dimensions summary

    You pay for the CoreThreats managed ruleset in two parts that add together. First, a monthly charge applies in each region where you use the ruleset, billed by the hour so partial months are pro-rated. Second, a usage charge applies per million requests processed in each region. Costs accrue separately for each WAF instance you attach the ruleset to. Both charges are region-specific, so running in more regions raises your total. Marketplace pricing covers this ruleset only, without a separate vendor account.

    Top-of-mind questions for buyers

    CoreThreats blocks a broad range of current threats gathered from hundreds of curated threat intelligence feeds. It stops active attacks aimed at your services, apps, and workloads. The ruleset maintains IP sets that block malicious incoming connections to web applications served through a supported load balancer, API gateway, or content delivery instance.
    Both charges apply at the same time and add together per region. The monthly charge is a fixed per-region fee, pro-rated by the hour. The per-request charge grows with the number of requests processed, billed per million. High-traffic applications see the request charge grow, while the monthly charge stays steady.
    Yes, if the ruleset is still attached to a WAF. Cancelling the Marketplace subscription does not remove rulesets already applied to your Web ACLs. Costs keep accruing until you delete the ruleset from each WAF instance. You must remove it from every Web ACL that uses it.
    docs.threatstop.com+1
    Helpful?

    Vendor refund policy

    Non-Refundable

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    50
    In Device Security

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Threat Intelligence Aggregation
    Aggregates and analyzes over 800 hand-selected threat intelligence feeds to identify severe attacking IP addresses and infrastructure
    Machine Learning and Human Analysis
    Applies human and machine intelligence to analyze threat data and identify the most critical threats active on the internet
    Dynamic Rule Updates
    Continuously updates managed rules to block emerging threats and attacker infrastructure with near-zero false positive rates
    IP-Based Attack Blocking
    Automatically blocks IP addresses and ranges being used by cyber criminals in active attacks
    AWS WAF Integration
    Integrates with AWS WAF to provide managed rules for web application firewall protection
    Threat Intelligence Integration
    Rulesets regularly updated with latest threat alerts using Cyber Threat Intelligence
    OWASP Top 10 Coverage
    Managed rules designed to mitigate and minimize all vulnerabilities on OWASP Top 10 Web Application Threats list
    Code Injection Prevention
    Targeted rules for common vulnerabilities including SQLi, NoSQLi, OS command injection, XSS, and directory traversal attacks
    Technology-Specific Protection
    Managed rules targeting known exploits for Apache Struts2, Apache Tomcat, Oracle WebLogic, WordPress, Drupal, Joomla, and malicious bots
    False Positive Optimization
    Designed with low false-positive rate while maintaining higher defense capability for web application protection
    OWASP Top 10 Attack Protection
    Provides protection against web attacks including SQL injection, cross-site scripting (XSS), command injection, NoSQL injection, path traversal, and predictable resource exploitation.
    Managed Rule Updates
    Rules are written, managed and regularly updated by F5's security specialists to ensure protection against evolving threats without requiring manual intervention.
    AWS WAF Integration
    Rules can be attached to AWS WAF instances for immediate deployment and protection enhancement.
    Automated Threat Detection
    Utilizes security expertise to identify and mitigate vulnerabilities that are part of the OWASP Top 10 attack vectors.
    Pay-as-You-Go Licensing Model
    Rules are licensed on a consumption-based pricing structure where usage determines costs.

    Contract

     Info
    Standard contract
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    3.5
    1 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    100%
    0%
    0%
    0%
    0 AWS reviews
    |
    1 external reviews
    External reviews are from PeerSpot .
    reviewer2888679

    Improved ddos protection has reduced false positives but installation and interface still need work

    Reviewed on Aug 17, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for ThreatSTOP Platform is that we are using an A10 DDoS protection device in our internal network as an on-premise device, and we are using ThreatSTOP Platform's feature to prevent well-known attacks from well-known IP addresses in A10's database.

    For example, my use of ThreatSTOP Platform in our environment involves a category named well-known bank attacks, where there were subnets in ThreatSTOP Platform's database that we added into the system, and then ThreatSTOP Platform converged those IP addresses into our A10 devices, preventing attacks from well-known bank attackers and financial attackers.

    ThreatSTOP Platform functioned as an IP address database, so it was not a day-to-day use device. Instead, we were checking IP addresses from ThreatSTOP Platform and using it as a USOM list.

    What is most valuable?

    The best features ThreatSTOP Platform offers are that it gives us categories to create a policy and add IP addresses and categories into that policy, which we can use directly on the A10.

    The category and policy creation made my work easier and more effective because I did not add IP addresses one-by-one into that policy. Instead, I added categories into the policy, so I did not use any irrelevant IP addresses or irrelevant categories in my policies.

    ThreatSTOP Platform has impacted our organization positively by reducing our DDoS false positive protection, and since we were doing some fine-tuning in our DDoS devices, it reduced our work time in the device.

    I cannot say an exact number regarding how much time was saved, but we obviously observed that it helped to reduce our work time in the A10 device. However, I cannot say exactly how much the impact was, but it was really helpful.

    What needs improvement?

    ThreatSTOP Platform can be improved by enhancing the graphical user interface, making it work faster, and addressing the installation part, which was difficult because they sent us too many port numbers and IP addresses to add to our firewall policies, along with an OS to install on our Linux server, which I think should not have to be part of buying the product.

    Initial support and setup support being great would be an additional improvement needed.

    For how long have I used the solution?

    I have been working in my current field for about six years.

    What do I think about the stability of the solution?

    I describe the stability of ThreatSTOP Platform as adequate for an IP list database.

    What do I think about the scalability of the solution?

    ThreatSTOP Platform's scalability has a good side because it has so many options and categories, but the scalability side allows using categories in your system, and I think the categories are static.

    How are customer service and support?

    Customer support, as far as I remember, was good, and they were quick and fast.

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution because we just used well-known IP lists like USOM in our firewall, so ThreatSTOP Platform was the first in my previous company.

    Which other solutions did I evaluate?

    Before choosing ThreatSTOP Platform, I did not evaluate other options because the A10 team, the DDoS device we use, had a support team that offered us ThreatSTOP Platform.

    What other advice do I have?

    My advice to others looking into using ThreatSTOP Platform is to consider it as an IP list, so if anything occurs on the DDoS side, it might be related to ThreatSTOP Platform, and they should check it when troubleshooting.

    ThreatSTOP Platform's AI capabilities and its governance and security were not used by me because these features were not published yet when I was using ThreatSTOP Platform, so I do not have any comments on that.

    In terms of ThreatSTOP Platform's AI capabilities, I think its accuracy and reliability of output is the same situation because I used ThreatSTOP Platform from 2021 to 2023, and when I was using it, it was not involved with AI, meaning we did not use a chatbot or anything else to use ThreatSTOP Platform.

    My overall rating for this product is 7 out of 10.

    View all reviews