
Waf
作者 aws188af2f810ce無授權條款2.8K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新
Configures AWS WAF to filter web traffic: creating web access control lists (web ACLs) on CloudFront, Application Load Balancers, API Gateway, and AppSync; AWS Managed Rules tuned in Count mode; rate-based rules for HTTP floods; IP set and geographic match rules; Bot Control (Common and Targeted); turning bot labels into a confidence signal; stripping spoofed inbound x-amzn-waf-* headers; recovering the real client IP behind a CDN; Fraud Control (account takeover and account creation fraud prevention); and logging and request sampling. Use when the user wants to protect a web application or API from common exploits, bots, credential stuffing, fake-account creation, or HTTP floods at the application layer (layer 7). Routes to the right per-task procedure in references. Do NOT use for L3/L4 DDoS protection (shieldadvanced skill), multi-account WAF rollout (firewallmanager skill), CloudFront configuration (cloudfront skill), or Route 53 health checks or records (route53 skill).
僅公開檔案列表。將技能安裝到工作區後即可檢視檔案內容。
| 路徑 | 大小 | 類型 |
|---|---|---|
| references/adaptive-mitigation-playbook-for-forwarded-signals.md | 8.9 KB | text/markdown |
| references/adding-managed-rules-and-tuning-with-count-mode.md | 10.1 KB | text/markdown |
| references/adding-rate-based-rules.md | 10.5 KB | text/markdown |
| references/creating-a-web-acl-and-associating-it-with-a-resource.md | 9.3 KB | text/markdown |
| references/forwarding-signals-with-dynamic-label-interpolation.md | 9.5 KB | text/markdown |
| references/protecting-against-bots-with-bot-control.md | 9.9 KB | text/markdown |
| references/protecting-logins-and-signups-with-fraud-control.md | 9.2 KB | text/markdown |
| references/recovering-the-real-client-ip-behind-a-cdn.md | 9.4 KB | text/markdown |
| references/seeing-and-managing-ai-crawler-traffic.md | 7.3 KB | text/markdown |
| references/setting-up-logging-and-request-sampling.md | 9.2 KB | text/markdown |
| references/stripping-inbound-waf-headers-before-trusting-them.md | 7.5 KB | text/markdown |
| references/turning-bot-control-labels-into-a-confidence-signal.md | 11 KB | text/markdown |
| references/using-ip-sets-and-geographic-match-rules.md | 8.5 KB | text/markdown |
| SKILL.md | 8.6 KB | text/markdown |
來源與署名
來源:aws/agent-toolkit-for-aws位於skills/specialized-skills/networking-and-content-delivery-skills/waf提交188af2f
授權條款: 無授權條款
內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。
更多來自 aws/agent-toolkit-for-aws 的技能

Rds Oss
aws
針對 Amazon RDS MySQL、MariaDB 與 PostgreSQL 的執行個體建立、升級、承諾定價、RDS Proxy 與藍綠部署提供建議。

Exporting Rds To S3
aws
指導將 Amazon RDS 或 Aurora 快照以 Parquet 格式匯出至 Amazon S3,涵蓋 IAM、KMS、監控與驗證。

Creating Amazon Aurora Db Cluster With Instances
aws
指導建立含執行個體的 Amazon Aurora 叢集,包含 Secrets Manager 密碼管理。

Debugging Lambda Timeouts
aws
透過分析組態、CloudWatch 日誌與指標、網路、冷啟動和相依項目,診斷 AWS Lambda 逾時故障。

Creating Api Gateway Stage
aws
建立並設定 AWS API Gateway 階段,包含日誌、追蹤、節流、WAF 與 IAM 角色。

Connecting Lambda To Dynamodb
aws
設定 AWS Lambda 與 DynamoDB 的整合,包含 IAM 角色、串流與事件來源映射。
更多Security技能

Compliance Tracking
anthropics
追蹤合規要求、稽核準備情況,以及 SOC 2、ISO 27001、GDPR、HIPAA 和 PCI DSS 等框架的證據。

Dpop Adoption
指導為 Google OAuth 平台實作 OAuth 2.0 DPoP(RFC 9449)傳送方約束的更新權杖。

Secops Triage
引導 SOC 分析師對 Google SecOps 安全警示進行分診,從調查到結案或升級。

Secops Investigate
指導 SOC 分析師在 Google SecOps 中使用 UDM 查詢與時間軸進行深入的安全事件與實體調查。

Secops Hunt
指導在 Google SecOps 中使用 UDM 查詢、IoC 回溯、普遍性與異常分析進行主動威脅狩獵。

Secops Cases
透過 MCP 工具管理 Google Security Operations SOAR 案件的完整生命週期。