
Overview
This product is for new AWS WAF. Cyber Security Cloud Managed Rules provide rulesets that are regularly updated to include the latest threat alerts by using Cyber Threat Intelligence. These rulesets are designed to mitigate and minimize vulnerabilities, including all those on OWASP Top 10 Web Application Threats list. By using our rulesets, you can satisfy the security requirements for web applications in order to comply with security standards such as PCI-DSS. Included are a lot of managed rules targeting common vulnerabilities such as code injection techniques (SQLi, NoSQLi, OScommandi, etc), XSS, directory traversal and known exploits involving web-applications using technologies such as Apache Struts2/ Apache Tomcat/ Oracle WebLogic/ WordPress/ Drupal/ Joomla! and Malicious Bots rulesets.
Cyber Security Cloud Managed Rules are designed to mitigate and minimize vulnerabilities, including all those on OWASP Top 10 Web Application Threats list. With the HighSecurity OWASP Set, you can start protecting your web applications right away with a low false-positive rate and a higher defense capability.
Want to add enhanced automation to these rules? Learn about our add-on products belows:
- WafCharm : https://www.wafcharm.com/
Highlights
- Can build a more secure environment immediately
- Designed to have the defense capability needed to protect your web applications, with a low false-positive rate
- Minimizes OWASP Top 10 Web Application threats
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Cost/unit |
|---|---|
Charge per month in each available region (pro-rated by the hour) | $25.00 |
Charge per million requests in each available region | $1.20 |
Vendor refund policy
Non-Refundable
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
For issues related specifically to Cyber Security Cloud Managed Rules, you can contact support offered by Cyber Security Cloud by email (We can respond in English or Japanese) https://www.wafcharm.com/en/managed-rules/support/
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.


Standard contract
Customer reviews
Managed rules have protected our ecommerce site and have reduced botnet and sql injection attacks
What is our primary use case?
My main use case for Cyber Security Cloud Managed Rules is to protect against malicious attacks like SQL injection attacks and cyber attacks.
Recently, I discovered malicious IPs which I believed were operating as a botnet and attacking my e-commerce website. Because WAF is for web application security, I used WAF managed rules related to IP and IP injection attacks. There are additional rules available for IP rate limiting based attacks, which allow me to implement a maximum number of attempts from a particular IP within a specific time period. This rate-limiting rule helps prevent unknown IPs from accessing my website.
The general security vulnerabilities provided by AWS WAF through managed rules or custom rules that I can implement will protect my application and enhance the security of my application through these security rules. This is the main use case of implementing WAF rules.
What is most valuable?
The best features of Cyber Security Cloud Managed Rules are that there are managed rules available for free that I can implement. I can stop SQL injection attacks, which is one significant vulnerable attack that can be stopped by WAF. Bitcoin mining attacks can also be stopped by implementing WAF. Additionally, there are specific rules related to bot control, which are especially helpful when a bot attacks my website. I implemented a framework known as OWASP Top 10, so these ten security critical vulnerabilities can be mitigated by implementing them.
I implemented free managed rules by AWS , which include Cyber Security Cloud Managed Rules. These managed rules control SQL injection attacks and other attacks that are managed by WAF to prevent them from affecting my systems.
Cyber Security Cloud Managed Rules have impacted my organization very positively because my company is security-focused. We are focusing mainly on security-based setups and implementing everything that can enhance security. This is one of the key applications or services I can implement in my company to stop mitigation attacks, which is why I implemented WAF and attached it to CloudFront, API Gateway, and sometimes to a load balancer to stop and mitigate these attacks.
I noticed specific outcomes or metrics from Cyber Security Cloud Managed Rules in the form of reduced attacks. I discovered that there was no system through which I could conclusively determine what happened, but I noticed some IPs in the logs that were attacking my website and trying to exploit Bitcoin through our platform. This activity was reduced by implementing WAF, and this is what I verified from the logs, which were very helpful.
What needs improvement?
I believe that Cyber Security Cloud Managed Rules can be improved by reducing false positives with traffic-aware tuning. Out-of-the-box managed rules are generic, and sometimes they block legitimate traffic. Improvements can be achieved by running rules in count monitor mode first, reviewing blocked requests using logs, adding custom rules on top of managed rules, and enabling request inspection depth layer seven hardening. These are techniques I can use to improve these rules.
For how long have I used the solution?
I have been using Cyber Security Cloud Managed Rules for the past one year.
What do I think about the stability of the solution?
Cyber Security Cloud Managed Rules are stable in the sense that I do not experience issues with availability or performance.
What do I think about the scalability of the solution?
Regarding scalability, I can easily implement them.
Which solution did I use previously and why did I switch?
I have not previously used a different solution because we are AWS native and implemented this solution only.
How was the initial setup?
Regarding pricing, setup cost, and licensing, I find it a bit more expensive.
What about the implementation team?
Regarding scalability, I can easily implement them.
What was our ROI?
I have seen a return on investment.
What's my experience with pricing, setup cost, and licensing?
Regarding pricing, setup cost, and licensing, I find it a bit more expensive.
Which other solutions did I evaluate?
Before deciding on Cyber Security Cloud Managed Rules, we went straight to using these rules. Everything is deployed on AWS, and we want to use AWS. This is the only sole provider for our company, so we are bound to use it.
What other advice do I have?
I would advise others looking into Cyber Security Cloud Managed Rules to use WAF if they want to eliminate security attacks, especially if they are using AWS. I would rate this product 8 out of 10.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Automated rules have reduced manual security work and now protect our APIs from modern attacks
What is our primary use case?
My main use case for Cyber Security Cloud Managed Rules is the protection of any cyber attack on my API servers and cloud managed rules on my WAF .
A specific example of how I use Cyber Security Cloud Managed Rules to protect my API servers is that we have an AWS WAF at the parameter level where we have implemented the OWASP top 10 attack rule as a cybersecurity managed rule in the parameter. Any traffic coming to our API server passes through the WAF , and the WAF OWASP top 10 rule filters that traffic for any attack.
What is most valuable?
The best features Cyber Security Cloud Managed Rules offers are mainly that there is less human intervention, which reduces the chances of error, and it is also less time-consuming and more intelligent compared to manual rules.
When I mention more intelligent, Cyber Security Cloud Managed Rules stands out in that these rules are generally updated according to the latest cyber attacks and the latest signatures in the system, so we don't need to manually change the rule, as they get updated mostly in real time, making detection easier.
Cyber Security Cloud Managed Rules has positively impacted my organization because earlier, a complete SOC team was required 24/7 for manually checking the alerts, acting upon those alerts, and doing forensics. With cloud managed rules being automated and intelligent and updating in real time, the manual intervention by the SOC team has been significantly reduced, resulting in a comparatively higher detection rate than before.
What needs improvement?
I sometimes need to tweak Cyber Security Cloud Managed Rules because it is a predefined rule where I adjust it based on our request sizes. Sometimes a rule states that only a 5 MB request is allowed, but we have requests greater than 5 MB, which causes it to block that traffic. I have to adjust the rule and increase the size of the request or payload above 5 MB to resolve this issue.
Cyber Security Cloud Managed Rules can be improved in that they are mostly general rules and not specific to organizational needs. Being predefined rules, if we have to make any changes, we need to create a rule above or before that cybersecurity rule or a bypass rule. There should be an option to tweak those cloud managed rules to adjust them based on organizational needs, as this has been one challenge we faced.
Cyber Security Cloud Managed Rules is limited to specific scenarios. For example, AWS WAF can only be used in an AWS scenario, which makes it complex to integrate with on-prem systems.
For how long have I used the solution?
I have been using Cyber Security Cloud Managed Rules for more than five years.
What do I think about the stability of the solution?
Cyber Security Cloud Managed Rules is stable, and the support is excellent with the cloud service. The after-sales support and technical support team are very reliable, so I have no issues with that.
What do I think about the scalability of the solution?
Scalability with Cyber Security Cloud Managed Rules is not a problem, as we have opted for a BYOL (bring your own license) model where systems automatically adjust during high demand, which is advantageous for scalability.
How are customer service and support?
Customer support for Cyber Security Cloud Managed Rules is great, as it is easy to reach out compared to on-prem vendors, and overall, I am satisfied with the customer support provided.
Which solution did I use previously and why did I switch?
I previously used an on-prem solution where everything was done manually, which was expensive regarding employee count and time, with higher chances of error. This prompted us to switch to a hybrid environment that includes both on-prem and cloud solutions.
What was our ROI?
The return on investment is great. Earlier, we had to manage the whole infrastructure on-prem with a different team at every step, which incurs high costs. With cloud infrastructure, we avoid a significant upfront investment, so it operates on a pay-as-we-grow model, which is beneficial.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is that it is very transparent and easy to manage the infrastructure in the cloud. The pricing is very clear, allowing us to track costs using the price calculator and the pricing dashboard, making it very straightforward.
Which other solutions did I evaluate?
Before choosing Cyber Security Cloud Managed Rules, I evaluated other options including on-prem systems and building our servers for automation with tools such as Ansible . I found that the cloud managed rules were easier to set up and better suited for our environment.
What other advice do I have?
My advice to others looking into using Cyber Security Cloud Managed Rules is to maintain a blend of on-prem and cloud solutions, while also performing regular checks and balances on the cloud managed rules to observe their behavior with applications.
My additional thoughts on Cyber Security Cloud Managed Rules are that the effectiveness largely depends on the specific business use case, as it will not fit every business logic. Sometimes, there is over-blocking within the cloud managed rules where valid requests or IPs could be blocked, which should be fine-tuned to reduce over-blocking. I would rate this product an 8 overall.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Security guardrails have protected web and AI workflows but rules need more flexibility and accuracy
What is our primary use case?
A specific example of how we have used Cyber Security Cloud Managed Rules to protect our web applications or CDN is that we have a proper dashboard of all attacks that were attempted on those exposed URLs at the application level and we have clear visibility. Whenever there is some type of IP which is trying to DDoS our domain, then it gets automatically blocked and we have configured alerts as well. We do get a consolidated report weekly and monthly that shows a lot of hits, what the IP was, and that it was automatically blocked.
We also have AI workload, so it is important to consider that in our main use case for Cyber Security Cloud Managed Rules. We are catering to that in our workflow and trying to manage it so that even our AI workflows do not have prompt injections or, if we are having agents, we do not get man-in-the-middle attacks with the prompts.
What is most valuable?
Cyber Security Cloud Managed Rules has positively impacted our organization because we are a tech company, so we always prefer to get security first. This is a big thing when it comes to exposing any domain. We would want to ensure that we have secure guardrails around it, and whenever we roll it out, we properly ensure that there was a design doc, there was a review, and make sure that it was behind those security gates to avoid any issues after go-live. It is a proper process that we follow to ensure that no new application sneaks through and before go-live, all these checks are done.
What needs improvement?
Cyber Security Cloud Managed Rules does the job, and if you have it configured in the correct way as per your requirements, such as IP sets or SQL injection, you are able to get a basic cover, but the workloads are evolving, and I would like to see more flexibility around those rules so that I can make better use of them. Because use cases are increasing, I would to play around with the rules a bit more so that I can say with certainty that my workloads are secure and ingress traffic is secure. That would help me, so I would give a better rating if that can happen.
Cyber Security Cloud Managed Rules are generally stable in my experience, but if a new attack vector rises or if something new comes up, they are not very adaptable, which is my feeling and experience. I would say they are stable, but not very versatile.
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
Which solution did I use previously and why did I switch?
Before choosing Cyber Security Cloud Managed Rules, I have always used WAF as a web application firewall and at the network level, we have a network firewall. That is how it has been. At the API Gateway level also we have WAF and even if we expose it via a load balancer, we use WAF. No matter how we expose to the internet, it has always been WAF in the forefront. WAF rules are the thing we have always used.
What was our ROI?
What other advice do I have?
I think the AI space is something really big right now, so I would to see some improvements around those lines.
I am not one hundred percent sure if we purchased Cyber Security Cloud Managed Rules through the AWS Marketplace . We may have, but I have not looked into that.
I have not been involved in the pricing, setup cost, and licensing phase for Cyber Security Cloud Managed Rules. It usually comes via procurement, so I am not involved in the licensing side of things because I am mostly technical and I am someone who implements things. I have not come across looking at the pricing, licensing, or setup cost.
I would give Cyber Security Cloud Managed Rules an overall rating of seven.
Managed rules have protected our APIs and AI chatbot and now need better automation and insights
What is our primary use case?
I am integrating these WAF rules with the API Gateway and CloudFront to ensure security from cybersecurity issues, minimizing vulnerabilities and mitigating threats from hackers, including the OWASP top 10 web application threat lists. I have configured it for our front end and for the API Gateway.
I am using Cyber Security Cloud Managed Rules for our GenAI applications, specifically for the chatbot I have recently created, which helps tremendously and prevents hackers' exploits in our application.
What is most valuable?
In my day-to-day work, I find the malicious bot detection feature of Cyber Security Cloud Managed Rules to be the most valuable.
Cyber Security Cloud Managed Rules has positively impacted my organization by reducing the manual WAF management by fifty percent and accelerating the automated updates and improvement in threat intelligence.
What needs improvement?
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
Which solution did I use previously and why did I switch?
How was the initial setup?
What was our ROI?
What's my experience with pricing, setup cost, and licensing?
What other advice do I have?
I do not have any additional thoughts about Cyber Security Cloud Managed Rules at the moment, but if I encounter something while developing more agentic AI applications in the future, I hope to find something helpful for improving the cybersecurity managed rules. I have provided this review with a rating of seven.
The most detect vulnerability scans
We tested how many detected attacks when select waf rules.
We used vulnerability scanner to many rules, this rule detected the most attacks and few false positive.
This rule covers basic attacks on web applications such as SQL Injection and XSS and can block a wide range of attacks.
You can check which request was blocked by outputting the WAF log through Amazon Kinesis Data Firehose to see if there is a false positive and how much is blocked by which rule.
We could reductioned noise request for our application.
