Its work
Best set of rules for AWS WAF. Works fine.
The main problem is the speed of updating the reputation lists. Several hours pass from the moment a bot appears until it is blacklisted
Thanks for taking the time to write this comment. The Imperva Managed Rules for IP Reputation provide an extensive IP allow/deny list that is regularly monitored and updated. Imperva leverages crowdsourcing from aggregated attack data to regularly update the list with newly detected malicious sources. Suspected malicious IP will go through a vetting process in which an algorithm analyzes and decide in which list to include the given IP. In some cases, this process involves a manual analysis by one of our threat research team members. In the case of advance persistence bot we recommend using Imperva advance bot detection to gain immediate detection and mitigation.