Security · Applications

Managed AWS WAF — rules that get tuned, updated and actually watched

A WAF left on default settings blocks little and disrupts a lot. We operate AWS WAF with managed rules curated by threat intelligence, tuned against your application real behaviour and monitored 24×7.

Most of the WAFs we find in production are switched on, not operated. They were enabled with a generic rule set, someone started getting false positives that hit real users, and the fix was to relax rules until the noise stopped. The result is a control that shows as implemented on the compliance matrix and in practice lets through what it was meant to stop. We operate AWS WAF with managed rules updated through threat intelligence — including Cyber Security Cloud rules via WafCharm — and with a tuning method that starts in count mode so we never block legitimate traffic blindly.

What you get with Caleidos

Managed rules that update themselves

Rule sets maintained by dedicated teams and fed with threat intelligence: OWASP Top 10 web, OWASP API Security Top 10, serverless protection and HTTP protocol enforcement. When a known vulnerability appears in a widely used platform, the rule arrives without your team having to write it.

Count mode first, blocking later

No new rule goes straight to blocking. We start in count mode, observe your real application traffic, identify false positives and only then enable blocking. That is the difference between a WAF that protects and one the business asks to switch off on the first busy Monday.

Per-application tuning, not generic

Every application has its own routes, parameters and patterns. We adjust exceptions and custom rules against the observed behaviour of yours, so protection goes up without noise going up with it. The generic rule is the starting point, never the destination.

Someone is watching the dashboards

Blocks, attack trends, sources and anomalies are reviewed continuously from Caleidos Lens© 24×7, with alerts wired into the service desk. A WAF with nobody interpreting what it records is a log archive, not a control.

Protection across the exposed surface

We apply rules where your traffic actually enters: CloudFront, Application Load Balancer, API Gateway and AppSync, with reputation lists, rate limiting, geo filtering and bot control as needed. It integrates with the security architecture already deployed, including controlled egress with AWS Network Firewall.

Evidence for the auditor

AWS WAF logs to S3 or CloudWatch, rule versioning in Terraform, change history and periodic reports on blocks and adjustments. When the auditor asks how the exposed application is protected, there is a document that answers.

How we work

1

Exposed surface mapping

We inventory which applications, APIs and domains are exposed, where traffic enters and what protection exists today. Output: surface map, prioritized risks and the proposed rule set for each entry point.

2

Count-mode deployment

We enable AWS WAF with managed rules in count mode across CloudFront, ALB, API Gateway or AppSync as applicable, everything defined in Terraform. Nothing blocks yet: first we observe.

3

Tuning against real traffic

We analyse logs over a representative period, identify false positives, write exceptions and custom rules, and validate with your application team before moving each rule to blocking.

4

Continuous operation

24×7 monitoring, periodic review of new rules, adjustment as the application changes, and reporting on blocks and trends. When your application changes, the rules change with it.

How we apply it

Enterprises with applications exposed on AWS

A WAF that is operated, not just switched on

The pattern we correct again and again is the same: a WAF enabled with default rules that started blocking legitimate users and ended up relaxed into decoration. We reverse it with the opposite method — count mode, tuning against real traffic, progressive blocking — and with managed rules that update without depending on someone having time that week.

Let us talk →

Tech stack

AWS WAFCyber Security Cloud Managed RulesWafCharmAWS Managed RulesAmazon CloudFrontApplication Load BalancerAmazon API GatewayAWS AppSyncAWS ShieldAWS Firewall ManagerAmazon CloudWatchTerraform
Frequently asked questions

What we get asked the most

What is AWS WAF and what does it protect?

AWS WAF is a web application firewall that inspects HTTP and HTTPS traffic before it reaches your application and blocks requests based on rules. It protects against OWASP Top 10 categories — SQL injection, cross-site scripting, directory traversal, XML external entities, server-side request forgery — against exploitation of known vulnerabilities in widely used platforms, and against malicious bots. It applies to CloudFront, Application Load Balancer, API Gateway and AppSync.

What are managed rules and why use them?

They are rule sets maintained by AWS or specialist providers, updated with threat intelligence so your team does not have to write or review every signature. The alternative — writing and maintaining rules by hand — demands permanent attention most teams do not have, and ages fast. We work with Cyber Security Cloud managed rules through WafCharm, covering OWASP Top 10 web, OWASP API Security Top 10 and serverless environments, alongside AWS managed rules.

What is WafCharm?

WafCharm is a Cyber Security Cloud service that automates AWS WAF operation: it selects and updates rules using learning over attack patterns observed globally, and its security team publishes new rules as vulnerabilities emerge. It integrates directly with AWS without deploying a separate platform and is available on AWS Marketplace. Caleidos implements and operates it inside your architecture, with the per-application tuning no automation solves on its own.

Will the WAF block my legitimate users?

Not if it is implemented properly. That is why no rule goes straight into blocking mode: we start in count mode, measure what each rule would have blocked on your real traffic, correct false positives with specific exceptions and only then enable blocking, rule by rule. The cost of that method is time; the cost of skipping it is a WAF the business eventually asks to turn off.

Does it replace a pentest or other security controls?

No. The WAF reduces application exposure while you fix the code, and stops automated attacks at scale, but it does not fix the underlying vulnerability. It works as one layer within an architecture that includes pipeline controls, identity management, controlled Internet egress and monitoring. We address them together in Security & Compliance.

How long does it take to get to production?

Count-mode deployment takes days. The observation and tuning period depends on your traffic volume and seasonality: we need to see enough real behaviour to tell an attack from a user doing something unusual. In most cases we reach full blocking within a few weeks, advancing rule set by rule set.

Who operates the WAF afterwards?

It can stay with your team, using the documentation and Terraform code we leave, or sit inside Caleidos Lens© 24×7, with continuous rule review, alert handling and periodic reporting. In regulated clients it is normally operated with us, because the control has to hold up during the months when nobody has time to look at it.

Ready to get started?

Tell us about your challenge. No pitch, no commitment. Just understanding.

Let us review your WAF configuration
Let's talk