
Waf
作者 aws188af2f810ce无许可证2.8K 个星标收录于 2026年10月8日更新于 2026年10月8日仓库今天更新
Configures AWS WAF to filter web traffic: creating web access control lists (web ACLs) on CloudFront, Application Load Balancers, API Gateway, and AppSync; AWS Managed Rules tuned in Count mode; rate-based rules for HTTP floods; IP set and geographic match rules; Bot Control (Common and Targeted); turning bot labels into a confidence signal; stripping spoofed inbound x-amzn-waf-* headers; recovering the real client IP behind a CDN; Fraud Control (account takeover and account creation fraud prevention); and logging and request sampling. Use when the user wants to protect a web application or API from common exploits, bots, credential stuffing, fake-account creation, or HTTP floods at the application layer (layer 7). Routes to the right per-task procedure in references. Do NOT use for L3/L4 DDoS protection (shieldadvanced skill), multi-account WAF rollout (firewallmanager skill), CloudFront configuration (cloudfront skill), or Route 53 health checks or records (route53 skill).
仅公开文件列表。将技能安装到工作区后即可查看文件内容。
| 路径 | 大小 | 类型 |
|---|---|---|
| references/adaptive-mitigation-playbook-for-forwarded-signals.md | 8.9 KB | text/markdown |
| references/adding-managed-rules-and-tuning-with-count-mode.md | 10.1 KB | text/markdown |
| references/adding-rate-based-rules.md | 10.5 KB | text/markdown |
| references/creating-a-web-acl-and-associating-it-with-a-resource.md | 9.3 KB | text/markdown |
| references/forwarding-signals-with-dynamic-label-interpolation.md | 9.5 KB | text/markdown |
| references/protecting-against-bots-with-bot-control.md | 9.9 KB | text/markdown |
| references/protecting-logins-and-signups-with-fraud-control.md | 9.2 KB | text/markdown |
| references/recovering-the-real-client-ip-behind-a-cdn.md | 9.4 KB | text/markdown |
| references/seeing-and-managing-ai-crawler-traffic.md | 7.3 KB | text/markdown |
| references/setting-up-logging-and-request-sampling.md | 9.2 KB | text/markdown |
| references/stripping-inbound-waf-headers-before-trusting-them.md | 7.5 KB | text/markdown |
| references/turning-bot-control-labels-into-a-confidence-signal.md | 11 KB | text/markdown |
| references/using-ip-sets-and-geographic-match-rules.md | 8.5 KB | text/markdown |
| SKILL.md | 8.6 KB | text/markdown |
来源与署名
来源:aws/agent-toolkit-for-aws位于skills/specialized-skills/networking-and-content-delivery-skills/waf提交188af2f
许可证: 无许可证
内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。
更多来自 aws/agent-toolkit-for-aws 的技能

Rds Oss
aws
针对 Amazon RDS MySQL、MariaDB 和 PostgreSQL 的实例创建、升级、承诺定价、RDS Proxy 与蓝绿部署提供建议。

Exporting Rds To S3
aws
指导将 Amazon RDS 或 Aurora 快照以 Parquet 格式导出到 Amazon S3,涵盖 IAM、KMS、监控与验证。

Creating Amazon Aurora Db Cluster With Instances
aws
指导创建带实例的 Amazon Aurora 集群,包括 Secrets Manager 密码管理。

Debugging Lambda Timeouts
aws
通过分析配置、CloudWatch 日志与指标、网络、冷启动和依赖项,诊断 AWS Lambda 超时故障。

Creating Api Gateway Stage
aws
创建并配置 AWS API Gateway 阶段,包含日志、追踪、限流、WAF 与 IAM 角色。

Connecting Lambda To Dynamodb
aws
设置 AWS Lambda 与 DynamoDB 的集成,包括 IAM 角色、流和事件源映射。
更多Security技能

Compliance Tracking
anthropics
跟踪合规要求、审计准备情况以及 SOC 2、ISO 27001、GDPR、HIPAA 和 PCI DSS 等框架的证据。

Dpop Adoption
指导为 Google OAuth 平台实现 OAuth 2.0 DPoP(RFC 9449)发送方约束刷新令牌。

Secops Triage
指导 SOC 分析师对 Google SecOps 安全告警进行分诊,从调查到关闭或升级。

Secops Investigate
指导 SOC 分析师在 Google SecOps 中使用 UDM 查询和时间线进行深入的安全事件与实体调查。

Secops Hunt
指导在 Google SecOps 中使用 UDM 查询、IoC 回溯、普遍性与异常分析进行主动威胁狩猎。

Secops Cases
通过 MCP 工具管理 Google Security Operations SOAR 案例的整个生命周期。