
Waf
by aws188af2f810ceNo license2.8K starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated today
Configures AWS WAF to filter web traffic: creating web access control lists (web ACLs) on CloudFront, Application Load Balancers, API Gateway, and AppSync; AWS Managed Rules tuned in Count mode; rate-based rules for HTTP floods; IP set and geographic match rules; Bot Control (Common and Targeted); turning bot labels into a confidence signal; stripping spoofed inbound x-amzn-waf-* headers; recovering the real client IP behind a CDN; Fraud Control (account takeover and account creation fraud prevention); and logging and request sampling. Use when the user wants to protect a web application or API from common exploits, bots, credential stuffing, fake-account creation, or HTTP floods at the application layer (layer 7). Routes to the right per-task procedure in references. Do NOT use for L3/L4 DDoS protection (shieldadvanced skill), multi-account WAF rollout (firewallmanager skill), CloudFront configuration (cloudfront skill), or Route 53 health checks or records (route53 skill).
Only the file list is public. File contents are available once the skill is installed in a workspace.
| Path | Size | Type |
|---|---|---|
| references/adaptive-mitigation-playbook-for-forwarded-signals.md | 8.9 KB | text/markdown |
| references/adding-managed-rules-and-tuning-with-count-mode.md | 10.1 KB | text/markdown |
| references/adding-rate-based-rules.md | 10.5 KB | text/markdown |
| references/creating-a-web-acl-and-associating-it-with-a-resource.md | 9.3 KB | text/markdown |
| references/forwarding-signals-with-dynamic-label-interpolation.md | 9.5 KB | text/markdown |
| references/protecting-against-bots-with-bot-control.md | 9.9 KB | text/markdown |
| references/protecting-logins-and-signups-with-fraud-control.md | 9.2 KB | text/markdown |
| references/recovering-the-real-client-ip-behind-a-cdn.md | 9.4 KB | text/markdown |
| references/seeing-and-managing-ai-crawler-traffic.md | 7.3 KB | text/markdown |
| references/setting-up-logging-and-request-sampling.md | 9.2 KB | text/markdown |
| references/stripping-inbound-waf-headers-before-trusting-them.md | 7.5 KB | text/markdown |
| references/turning-bot-control-labels-into-a-confidence-signal.md | 11 KB | text/markdown |
| references/using-ip-sets-and-geographic-match-rules.md | 8.5 KB | text/markdown |
| SKILL.md | 8.6 KB | text/markdown |
Source and attribution
Source:aws/agent-toolkit-for-awsinskills/specialized-skills/networking-and-content-delivery-skills/wafat commit188af2f
License: No license
Content belongs to its original authors. SourceWeft indexes it from a public repository.
More from aws/agent-toolkit-for-aws

Rds Oss
aws
Advises on Amazon RDS MySQL, MariaDB and PostgreSQL instance creation, upgrades, commitment pricing, RDS Proxy and Blue/Green deployments.

Exporting Rds To S3
aws
Guides exporting Amazon RDS or Aurora snapshots to Amazon S3 as Parquet, covering IAM, KMS, monitoring and verification.

Creating Amazon Aurora Db Cluster With Instances
aws
Guides creation of an Amazon Aurora cluster with instances, including Secrets Manager password handling.

Debugging Lambda Timeouts
aws
Diagnoses AWS Lambda timeout failures by analyzing configuration, CloudWatch logs and metrics, networking, cold starts, and dependencies.

Creating Api Gateway Stage
aws
Creates and configures AWS API Gateway stages with logging, tracing, throttling, WAF and IAM roles.

Connecting Lambda To Dynamodb
aws
Sets up AWS Lambda to DynamoDB integration with IAM roles, streams, and event source mapping.
More in Security

Compliance Tracking
anthropics
Tracks compliance requirements, audit readiness, and evidence for frameworks such as SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS.

Dpop Adoption
Guides implementation of OAuth 2.0 DPoP (RFC 9449) sender-constrained refresh tokens for Google's OAuth platform.

Secops Triage
Guides SOC analysts through triaging Google SecOps security alerts, from investigation to closure or escalation.

Secops Investigate
Guides SOC analysts through deep security incident and entity investigations in Google SecOps using UDM queries and timelines.

Secops Hunt
Guides proactive threat hunting in Google SecOps using UDM queries, IoC lookback, prevalence and outlier analysis.

Secops Cases
Manages Google Security Operations SOAR cases across their lifecycle via MCP tools.