Listing Thumbnail

    Miggo Rules for AWS WAF - AI/ML Application Protection

     Info
    Exploit-validated AWS WAF rules defending AI/ML stacks, covering LangChain, vLLM, Ray, and more, against high-severity CVEs before attackers can weaponize them.

    Overview

    What You Get

    Miggo's AI/ML Application Protection is a managed rule group for AWS WAF that defends your generative-AI application stack against high-severity CVEs. Rules are continuously updated, exploit-validated, and ready to deploy within your existing AWS WAF WebACL.

    Frameworks Covered

    • LangChain
    • LlamaIndex
    • LiteLLM
    • vLLM
    • Langflow
    • MCP Inspector
    • Ray
    • TorchServe
    • BentoML

    Exploitation Patterns Blocked

    • Unauthenticated RCE in agent endpoints
    • Pickle and HTTP-API deserialization attacks
    • SSRF in model-fetch paths
    • SQL injection in query engines
    • SSTI and code-injection vectors

    How Rules Are Built and Validated

    Every Miggo rule is generated from real proof-of-concept exploit code - either internet-available or Miggo-generated. Before release, each rule is tested against multiple bypass and mutation variations in Miggo Lab, ensuring detection efficacy against evasion techniques that static rule sets miss. Rules ship on a versioned cadence so you always know what changed and when.

    How to Deploy

    1. Subscribe to Miggo Rules for AWS WAF through AWS Marketplace.
    2. In the AWS WAF console, add the Miggo managed rule group to your existing WebACL (associated with CloudFront, ALB, or API Gateway).
    3. Set rule actions to Count mode initially to observe matches without blocking traffic.
    4. Review matched requests in AWS WAF logs, then switch to Block mode once validated.
    5. Complete the notification setup to receive versioning updates and alerts for high-priority threats.

    Prerequisites

    • An active AWS WAF subscription with a configured WebACL
    • A supported resource (CloudFront distribution, Application Load Balancer, or API Gateway) associated with the WebACL
    • Sufficient WAF rule group capacity in your WebACL

    Data Handling

    Miggo rules execute entirely within AWS WAF. Request inspection and blocking happen inside your AWS account - no customer traffic data is sent to Miggo.

    Frequently Asked Questions (FAQs)

    For more Frequently Asked Questions (FAQs) here .

    Miggo WAF Copilot - Automate Your Full WAF Lifecycle

    To harness the full power of AWS WAF as a preemptive mitigation layer for exploitable vulnerabilities specific to your applications, Miggo WAF Copilot automates WAF management end-to-end. It connects to your vulnerability scanner, assesses exploitability against your runtime environment, generates precise WAF mitigations, and pre-validates them against bypass variations before deployment. Leveraging proprietary agentic AI and runtime application context, WAF Copilot tailors rules and configurations to your continuously changing posture and threat landscape.

    Learn more about Miggo WAF Copilot here .

    Highlights

    • Covers 9 AI/ML frameworks including LangChain, LlamaIndex, LiteLLM, vLLM, Langflow, MCP Inspector, Ray, TorchServe, and BentoML. Unlike generic WAF rule sets, Miggo rules are purpose-built for the unique attack surfaces of generative-AI stacks - agent endpoints, model-serving APIs, and LLM gateways - where standard managed rules provide no coverage.
    • Every rule is exploit-validated before release: generated from real proof-of-concept code, then tested against multiple bypass and mutation variations in Miggo Lab. This PoC-driven methodology ensures rules block actual exploitation techniques rather than relying on signature patterns that attackers easily evade. Rules ship on a versioned cadence with update notifications so your protection evolves as threats do.
    • Targets high-severity exploitation patterns specific to AI/ML infrastructure: unauthenticated RCE in agent endpoints, pickle and HTTP-API deserialization, SSRF in model-fetch paths, SQL injection in query engines, and SSTI/code-injection. Rules execute entirely within AWS WAF - no customer traffic leaves your AWS account - and deploy into any existing WebACL protecting CloudFront, ALB, or API Gateway resources.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Miggo Rules for AWS WAF - AI/ML Application Protection

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (2)

     Info
    Dimension
    Description
    Cost/unit
    Charge per month in each available region (pro-rated by the hour)
    0
    $0.00
    Charge per million requests in each available region
    1.00
    $1.00

    Vendor refund policy

    Non-Refundable

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Contact Support

    For support with Miggo Rules for AWS WAF, questions about rule versioning, latest threat coverage, or deployment assistance, contact the Miggo team at pmr@miggo.io .

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.