| name | implementing-cloud-waf-rules |
| description | Use when this skill covers deploying and tuning Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare to protect cloud-hosted applications against OWASP Top 10 attacks. It details configuring managed rule sets, creating custom rules for business logic protection, implementing rate limiting, deploying bot management, and reducing false positives through rule tuning and logging analysis. |
| domain | cybersecurity |
| tags | ["cloud-waf","aws-waf","azure-waf","cloudflare-waf","owasp-protection","rate-limiting"] |
| subdomain | cloud-security |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["PR.IR-01","ID.AM-08","GV.SC-06","DE.CM-01"] |
Implementing Cloud Waf Rules
Overview
Cybersecurity skill for implementing cloud waf rules. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"implementing cloud waf rules"
-
"This skill covers deploying and tuning Web Application Firewall rules on AWS WAF"
-
When deploying new web applications or APIs behind cloud load balancers requiring OWASP protection
-
When application penetration testing reveals SQL injection, XSS, or other injection vulnerabilities
-
When experiencing brute force, credential stuffing, or bot attacks against authentication endpoints
-
When compliance requirements mandate a WAF for PCI-DSS or similar standards
-
When tuning WAF rules to reduce false positives blocking legitimate application traffic
Do not use for network-level DDoS protection (use AWS Shield or Azure DDoS Protection), for API authentication design (see managing-cloud-identity-with-okta), or for application code-level security fixes (WAF is a compensating control, not a replacement for secure code).
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- AWS ALB/CloudFront, Azure Application Gateway, or Cloudflare configured as the application entry point
- Application traffic logs for baseline analysis before WAF deployment
- Test environment for validating WAF rules before production enforcement
- Understanding of application request patterns to minimize false positives
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: ) -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}