Overview

Product video
Overview: Salt Security has released a specialized ruleset in the AWS Marketplace that extends the native capabilities of AWS WAF, delivering advanced protection against modern API threats and AI-agent-driven interactions. Designed as an add-on for existing AWS WAF customers, this ruleset brings deep, context-aware detection and response to environments where APIs and intelligent agents are core to digital workflows.
Why It Matters: Traditional WAF rules were never built to understand the behavioral nuances of APIs or the complex, dynamic nature of AI-powered agents. With APIs now underpinning nearly every digital experience - and AI agents increasingly driving autonomous actions - security teams face blind spots that existing tools do not cover. This ruleset closes those gaps.
Key Capabilities: Advanced API Threat Detection - Blocks common and complex API attack vectors such as brute force on credentials, excessive GraphQL queries, SSR threats and JWT-based anomalies.
Context-Aware Rate Limiting - Implements smart rate limits on sensitive parameters like user_id, email, and numeric-only values to stop enumeration and abuse patterns.
AI Agent and MCP Awareness - Uniquely identifies traffic related to AI-driven agents and MCP endpoints, blocking unauthorized access (unauthenticated_mcp_access) and labeling agent-like behaviors for deeper observability.
Security Signal Enrichment - Labels critical request attributes (e.g., auth headers, user IDs, GraphQL queries) to enhance detection fidelity and downstream analytics.
Proactive Threat Prevention - Detects and blocks sophisticated threats such as SSRF, prototype pollution, and brute force attempts on documentation endpoints.
Who Its For: AWS WAF users who want to:
- Strengthen their defenses against API-specific and logic-layer attacks
- Extend visibility and control over AI agent activity
- Accelerate detection and response without adding heavy infrastructure
- Ensure MCP, GraphQL, and JWT traffic is governed properly
Highlights
- Strengthen protection for modern API and agent interactions. No specialized security expertise required.
- Salt Lab security experts continuously monitor, maintain, and update rulesets to help defind against emerging API, AI, and agentic threats.
- Configure rules to log, alert, and/or block activity based on your organization security posture and operational requirements.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/unit |
|---|---|---|
entity_usage | Charge per month in each available region (pro-rated by the hour) | $25.00 |
volume_usage | Charge per million requests in each available region | $1.75 |
Vendor refund policy
All fees are non-cancellable and non-refundable except as required by law.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
Support offered by Salt Security.
Contact Salt directly by email at support@salt.security
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products
