Overview
What It Protects Against
Miggo's High Emerging Threats managed rule group defends against the highest-impact, recent web-exploitable CVEs or new exploits. Rules are weighted toward CISA Known Exploited Vulnerabilities (KEV) additions and CVEs with public proof-of-concept code or confirmed active exploitation. Coverage spans enterprise web stacks including Apache ActiveMQ, Flowise, Marimo, LiteLLM, Craft CMS, Laravel Livewire, Zimbra, Ivanti EPMM, cPanel, and ScreenConnect.
How Rules Are Built and Validated
Unlike static managed rule sets, every Miggo rule is exploit-aware:
- PoC-driven generation - Rules are written from internet-available or Miggo-generated and validated proof-of-concept exploit code, not generic signatures.
- Bypass and mutation testing - Each rule is tested against multiple bypass and mutation variations inside Miggo Lab before release, reducing false negatives without inflating false positives.
- Continuous updates - Miggo's agentic engine, real-time threat intelligence feed, and in-house security researchers deliver versioned rule updates on a regular cadence so your protection evolves with the threat landscape.
The result for security teams: an immediate mitigation layer for emerging threats so patching can occur safely, without interruption of engineering cycles or emergency change windows.
Requirements and Scope
- Prerequisite: An existing AWS WAF Web ACL associated with an ALB, CloudFront distribution, or API Gateway stage.
- Scope: Web-exploitable CVEs targeting server-side application components. Client-side-only vulnerabilities and non-HTTP protocols are out of scope.
- Deployment: Subscribe via AWS Marketplace, then associate the managed rule group with your Web ACL. Start in Count mode to evaluate matches before switching to Block.
- Notifications: Complete the full setup steps to receive versioning update alerts and high-priority threat notifications.
Licensing
Rules are licensed on a subscription and usage basis through AWS Marketplace.
Frequently Asked Questions (FAQs)
For Frequently Asked Questions (FAQs) visit here .
Upgrade to Miggo WAF Copilot
To harness the full power of AWS WAF as a preemptive mitigation layer for exploitable vulnerabilities specific to your applications, explore Miggo WAF Copilot. Leveraging proprietary agentic AI, runtime application context, and exploit-aware rule generation, WAF Copilot automates the end-to-end WAF lifecycle:
- Connects to your scanner of choice and assesses vulnerability exploitability against your runtime environment.
- Generates precise WAF or sensor mitigations pre-validated against bypass variations before deployment.
- Tailors rules and configurations to your continuously changing posture and threat landscape.
Learn more and book a demo at miggo.io .
Highlights
- Continuously updated threat intelligence aware rule generation, including catching fresh exploitation patterns, testing and validation. Please complete set up to receive versioning updates and alerts for high priority upgrades.
- Provides security teams with an immediate mitigation for emerging threats so patching can occur safely, effectively and without interruption of engineering cycles.
- Covers enterprise web stacks including Apache ActiveMQ, Flowise, Marimo, LiteLLM, Craft CMS, Laravel Livewire, Zimbra, Ivanti EPMM, cPanel, and ScreenConnect.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/unit |
|---|---|---|
Charge per month in each available region (pro-rated by the hour) | 0 | $0.00 |
Charge per million requests in each available region | 1.00 | $1.00 |
Vendor refund policy
Non-Refundable. You may cancel at any time.
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
Support Contact
For support with Miggo Rules for AWS WAF, questions about rule versioning, latest threat coverage, false-positive tuning, or configuration assistance, please contact the Miggo team at pmr@miggo.io .
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.