Waf

by aws188af2f810ceNo license2.8K starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated today

Configures AWS WAF to filter web traffic: creating web access control lists (web ACLs) on CloudFront, Application Load Balancers, API Gateway, and AppSync; AWS Managed Rules tuned in Count mode; rate-based rules for HTTP floods; IP set and geographic match rules; Bot Control (Common and Targeted); turning bot labels into a confidence signal; stripping spoofed inbound x-amzn-waf-* headers; recovering the real client IP behind a CDN; Fraud Control (account takeover and account creation fraud prevention); and logging and request sampling. Use when the user wants to protect a web application or API from common exploits, bots, credential stuffing, fake-account creation, or HTTP floods at the application layer (layer 7). Routes to the right per-task procedure in references. Do NOT use for L3/L4 DDoS protection (shieldadvanced skill), multi-account WAF rollout (firewallmanager skill), CloudFront configuration (cloudfront skill), or Route 53 health checks or records (route53 skill).

Instructions onlySecurityDevOps & Cloud

Only the file list is public. File contents are available once the skill is installed in a workspace.

PathSizeType
references/adaptive-mitigation-playbook-for-forwarded-signals.md8.9 KBtext/markdown
references/adding-managed-rules-and-tuning-with-count-mode.md10.1 KBtext/markdown
references/adding-rate-based-rules.md10.5 KBtext/markdown
references/creating-a-web-acl-and-associating-it-with-a-resource.md9.3 KBtext/markdown
references/forwarding-signals-with-dynamic-label-interpolation.md9.5 KBtext/markdown
references/protecting-against-bots-with-bot-control.md9.9 KBtext/markdown
references/protecting-logins-and-signups-with-fraud-control.md9.2 KBtext/markdown
references/recovering-the-real-client-ip-behind-a-cdn.md9.4 KBtext/markdown
references/seeing-and-managing-ai-crawler-traffic.md7.3 KBtext/markdown
references/setting-up-logging-and-request-sampling.md9.2 KBtext/markdown
references/stripping-inbound-waf-headers-before-trusting-them.md7.5 KBtext/markdown
references/turning-bot-control-labels-into-a-confidence-signal.md11 KBtext/markdown
references/using-ip-sets-and-geographic-match-rules.md8.5 KBtext/markdown
SKILL.md8.6 KBtext/markdown

Source and attribution

Source:aws/agent-toolkit-for-awsinskills/specialized-skills/networking-and-content-delivery-skills/wafat commit188af2f

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal