Sign in Agent Mode
Categories
Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Reviews from AWS customer

5 AWS reviews

4-star reviews ( Show all reviews )

    reviewer2817840

Managed rules have protected our ecommerce site and have reduced botnet and sql injection attacks

  • April 17, 2026
  • Review from a verified AWS customer

What is our primary use case?

My main use case for Cyber Security Cloud Managed Rules is to protect against malicious attacks like SQL injection attacks and cyber attacks.

Recently, I discovered malicious IPs which I believed were operating as a botnet and attacking my e-commerce website. Because WAF is for web application security, I used WAF managed rules related to IP and IP injection attacks. There are additional rules available for IP rate limiting based attacks, which allow me to implement a maximum number of attempts from a particular IP within a specific time period. This rate-limiting rule helps prevent unknown IPs from accessing my website.

The general security vulnerabilities provided by AWS WAF through managed rules or custom rules that I can implement will protect my application and enhance the security of my application through these security rules. This is the main use case of implementing WAF rules.

What is most valuable?

The best features of Cyber Security Cloud Managed Rules are that there are managed rules available for free that I can implement. I can stop SQL injection attacks, which is one significant vulnerable attack that can be stopped by WAF. Bitcoin mining attacks can also be stopped by implementing WAF. Additionally, there are specific rules related to bot control, which are especially helpful when a bot attacks my website. I implemented a framework known as OWASP Top 10, so these ten security critical vulnerabilities can be mitigated by implementing them.

I implemented free managed rules by AWS, which include Cyber Security Cloud Managed Rules. These managed rules control SQL injection attacks and other attacks that are managed by WAF to prevent them from affecting my systems.

Cyber Security Cloud Managed Rules have impacted my organization very positively because my company is security-focused. We are focusing mainly on security-based setups and implementing everything that can enhance security. This is one of the key applications or services I can implement in my company to stop mitigation attacks, which is why I implemented WAF and attached it to CloudFront, API Gateway, and sometimes to a load balancer to stop and mitigate these attacks.

I noticed specific outcomes or metrics from Cyber Security Cloud Managed Rules in the form of reduced attacks. I discovered that there was no system through which I could conclusively determine what happened, but I noticed some IPs in the logs that were attacking my website and trying to exploit Bitcoin through our platform. This activity was reduced by implementing WAF, and this is what I verified from the logs, which were very helpful.

What needs improvement?

I believe that Cyber Security Cloud Managed Rules can be improved by reducing false positives with traffic-aware tuning. Out-of-the-box managed rules are generic, and sometimes they block legitimate traffic. Improvements can be achieved by running rules in count monitor mode first, reviewing blocked requests using logs, adding custom rules on top of managed rules, and enabling request inspection depth layer seven hardening. These are techniques I can use to improve these rules.

For how long have I used the solution?

I have been using Cyber Security Cloud Managed Rules for the past one year.

What do I think about the stability of the solution?

Cyber Security Cloud Managed Rules are stable in the sense that I do not experience issues with availability or performance.

What do I think about the scalability of the solution?

Regarding scalability, I can easily implement them.

Which solution did I use previously and why did I switch?

I have not previously used a different solution because we are AWS native and implemented this solution only.

How was the initial setup?

Regarding pricing, setup cost, and licensing, I find it a bit more expensive.

What about the implementation team?

Regarding scalability, I can easily implement them.

What was our ROI?

I have seen a return on investment.

What's my experience with pricing, setup cost, and licensing?

Regarding pricing, setup cost, and licensing, I find it a bit more expensive.

Which other solutions did I evaluate?

Before deciding on Cyber Security Cloud Managed Rules, we went straight to using these rules. Everything is deployed on AWS, and we want to use AWS. This is the only sole provider for our company, so we are bound to use it.

What other advice do I have?

I would advise others looking into Cyber Security Cloud Managed Rules to use WAF if they want to eliminate security attacks, especially if they are using AWS. I would rate this product 8 out of 10.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)


showing 1 - 1