Overview
Cloudbric Managed Rules for AWS WAF - OWASP Top 10 Protection was created to protect the websites and web applications against the threats from OWASP Top 10 Web Application Security Risks.
OWASP Top 10 Protection utilizes the logic-based detection engine of Penta Security, which has been acknowledged by the top research organizations such as Gartner, Forrester, and Frost & Sullivan, to protect the web applications from security threats such as SQL injection and Cross Site Scripting (XSS) by detecting abnormal traffic patterns or behavior and implementing appropriate rule action on incoming traffic.
Cloudbric Managed Rules for AWS WAF is created based on the security technologies and expertise of WAPPLES which has protected the web services for enterprises since 2005 and has recently been validated by a third-party testing firm to have a top-tier detection rate. Cloudbric Managed Rules for AWS WAF utilizes Penta Security's own Cyber Threat intelligence (CTI), Cloudbric Labs, to provide a safer online environment.
Interested in trying out the product before committing? Click the 'Request Private Offer' button to contact us. We offer a 14-day free trial so you can explore the product firsthand. Please note that after the free trial period, the private offer will automatically convert to a regular subscription at the standard rate.
Having difficulties managing the rules for your AWS WAF? Cloudbric WAF Managed Service (WMS) provides you with accurate information about the threats and vulnerabilities on your web application in real time, easy-to-use management system and dedicated console, and rule optimization from our security experts so that you can implement a security level best fit for your AWS WAF even if you do not have an expert security knowledge.
AWS Marketplace: https://aws.amazon.com/marketplace/pp/prodview-r4opjncghemnc Cloudbric Website: https://www.cloudbric.com/cloudbric-wms/
Highlights
- Provides web security against the threats from OWASP Top 10 Web Application Security Risks.
- Top-tier detection rate validated by a third-party testing firm.
- Regularly managed and updated by Cloudbric Labs.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Security credentials achieved
(2)


Financing for AWS Marketplace purchases
Pricing
Dimension | Cost/unit |
|---|---|
Charge per month in each available region (pro-rated by the hour) | $25.00 |
Charge per million requests in each available region | $1.00 |
Vendor refund policy
Non-Refundable
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
For product-related all inquiries, please contact : awsmkp@pentasecurity.com .
If you are a buyer based in Japan, and need to request a TQI, please contact: jp-sales@pentasecurity.com .
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

FedRAMP
GDPR
HIPAA
ISO/IEC 27001
PCI DSS
SOC 2 Type 2
Standard contract
Customer reviews
Granular api security has freed team resources and reduced effort but detection accuracy needs work
What is our primary use case?
Currently, I use Cloudbric Managed Rules for AWS WAF for one of my AWS Load Balancer integrations, placing the managed rules in front of my load balancer as a form of security measure for traffic coming into the application. My application is a public internet-facing application, which is unique about my environment and setup.
What is most valuable?
The feature that stands out to me the most about Cloudbric Managed Rules for AWS WAF is the API protection, as many managed WAF rule sets are originally designed around traditional websites, but Cloudbric integrates a dedicated API protection module aimed at REST APIs, GraphQL endpoints, XML validation, and API-specific attacks.
My experience with the API protection module is positive, as I had one implementation for a mobile backend and some FinTech APIs where Cloudbric Managed Rules for AWS WAF really worked wonders for that setup, requiring minimal modifications or tweaking.
Another thing I appreciate about Cloudbric Managed Rules for AWS WAF is that it does not force me into a monolithic package, allowing for selective deployments where I can choose specific protections such as only malicious IP, thus providing flexibility to control costs and capacity consumption.
Cloudbric Managed Rules for AWS WAF has positively impacted my organization by freeing up human resources that would otherwise be dedicated to creating and managing WAF rules, helping me reduce costs as I can streamline WAF rules for some applications and deploy protection in less than an hour instead of days or weeks.
What needs improvement?
I find that the only drawbacks with Cloudbric Managed Rules for AWS WAF are its less market penetration, especially in North America and Europe, resulting in fewer community reviews, published case studies, and a small ecosystem of users, along with less third-party validation and occasional false positives triggered by API payload or JSON bodies.
For how long have I used the solution?
I have been using Cloudbric Managed Rules for AWS WAF for just over a year.
What do I think about the stability of the solution?
Cloudbric Managed Rules for AWS WAF has been fairly stable in my experience.
What do I think about the scalability of the solution?
In terms of scalability, Cloudbric Managed Rules for AWS WAF has been fairly scalable for my use case, working really well.
How are customer service and support?
Customer support for Cloudbric Managed Rules for AWS WAF has been quite good, and although I have not had to use it often, the few times I have reached out, they have been satisfactory.
Which solution did I use previously and why did I switch?
Previously, I was using Imperva and F5 for that particular use case, but I switched to Cloudbric Managed Rules for AWS WAF because I did not need the full protection those tools provided; I needed something more flexible.
How was the initial setup?
My experience with Cloudbric Managed Rules for AWS WAF's pricing and setup was positive; the setup was fairly straightforward and took less than an hour, and the pricing is very good and flexible, allowing me to choose the parts of WAF protection I want.
What's my experience with pricing, setup cost, and licensing?
I can definitely say that since using Cloudbric Managed Rules for AWS WAF, I need fewer employees because those who would have been dedicated to creating and managing WAF rules are now free to pursue higher priorities, leading to reduced cost in human resources.
Which other solutions did I evaluate?
The only other option I evaluated before choosing Cloudbric Managed Rules for AWS WAF was Fortinet, but it was still too much for what I needed.
What other advice do I have?
I have not had to use the AI capabilities of Cloudbric Managed Rules for AWS WAF yet, but from others' feedback, it has been fairly standard performance for the markets.
I have not noticed anything specific regarding the accuracy and reliability of output from Cloudbric Managed Rules for AWS WAF since I have not really made use of the AI capabilities, so that is still to be seen on my end.
I did purchase Cloudbric Managed Rules for AWS WAF through the AWS Marketplace .
My advice for others looking into using Cloudbric Managed Rules for AWS WAF is that if you have a use case for granular WAF rules where you do not need full traditional rule protection, especially for securing APIs, Cloudbric Managed Rules for AWS WAF is really effective at API-specific protection. I would rate this product a seven out of ten.
I’ve been using Cloudbric’s Managed Rules for AWS WAF – OWASP Top 10 Rule Set
After testing several AWS WAF rule providers, we selected Cloudbric’s OWASP Top 10 bundle for its balance of coverage and efficiency. Setup through AWS Marketplace was intuitive, and the default rule priorities required only minor adjustment to suit our application. During simulated attack scenarios, the managed rules consistently blocked attempts without breaking legitimate API calls. In comparison, open-source rule sets needed more manual tuning. The Cloudbric solution reduced our security team’s maintenance time by roughly 50%, allowing us to focus on new feature development rather than constant rule tweaking.
Simple, strong, well performing
Just like the others, it was simple to set up, smoothly integrated, and packed with all the essentials—especially key protections aligned with OWASP standards.
What really stood out, though, was the support team—quick to respond, incredibly helpful, and genuinely considerate. I really value that kind of human touch and attention to detail. It’s rare, and it makes a difference.
At this point, I’m seriously leaning toward accepting their offer and migrating permanently. Very satisfying overall. Kudos to them!
Just had to adjust a few initial settings during setup. But with support that solid, it wasn’t a big deal at all.
Easy to implement, high detection rate.
perform well
I used this product this time. perform well It seems to prevent hacking well.
It looks better and better than other products.
