Skip to content

AWS WAF with Cloudbric Managed Rules in Four Simple Steps (Old & New Console Version)

How to Deploy Cloudbric Managed Rules for AWS WAF in 4 Steps

Protect your AWS applications in minutes. Cloudbric’s managed rules for AWS WAF condense enterprise-grade threat intelligence into a simple, one-click deployment. This guide shows you how to add battle-tested security logic to your applications without writing code or scheduling downtime.

Why Add Cloudbric to AWS WAF?

While AWS WAF provides a powerful framework, its effectiveness depends on the quality of the rules you apply. Cloudbric delivers curated, pre-tuned rule groups that allow you to:

  • Deploy Faster: Launch comprehensive security policies in under five minutes.
  • Stay Ahead of Threats: Benefit from daily rule updates that track emerging CVEs and attack patterns.
  • Reduce False Positives: Utilize machine learning-aided signatures that minimize noise and disruptions.
  • Pay as You Go: Subscribe per rule group for each web ACL with no long-term lock-in.

Setup at a Glance

Before you begin, ensure you have:

  • An AWS Account: With AWS WAF enabled and the necessary IAM permissions (e.g., wafv2:*).
  • A Target Resource: A CloudFront distribution, Application Load Balancer (ALB), API Gateway, or other supported AWS service you wish to protect.
  • A Cloudbric Subscription: If you’re a new user, AWS will prompt you to subscribe via the AWS Marketplace directly within the setup process—no need to leave the console.

Deploying Cloudbric Rules: A Step-by-Step Guide

This walk-through uses the modern AWS WAF console workflow.

Step 1: Navigate to AWS WAF & Create a Web ACL

From the AWS Management Console, go to WAF & Shield. In the left navigation pane, click Web ACLs, then click Create web ACL. A Web Access Control List (Web ACL) is a set of rules that provides fine-grained control over the web traffic that reaches your application.

Step 2: Describe the Web ACL and Associate Resources

Name your Web ACL and provide an optional description.

Select the AWS resource(s) you want to protect (e.g., your CloudFront distribution or ALB). Click Next.

Step 3: Add Cloudbric’s Managed Rules

This is where you integrate Cloudbric’s security intelligence.

  1. On the “Add rules and rule groups” screen, click the Add rules dropdown and select Add managed rule groups.
  2. Scroll down to the AWS Marketplace managed rule groups section.
  3. Expand the Cloudbric Corp. provider listing to see all available rule groups.
  4. Locate the rule group you need (e.g., OWASP Top 10 Rule Set) and toggle the Add to web ACL switch.

First-Time Subscription: If you haven’t subscribed before, a prompt will appear. Click “Subscribe in AWS Marketplace,” accept the terms, and return to the WAF console. The toggle will now be active.

Once added, the rule group will appear in your list with its associated WCU (Web ACL Capacity Unit) cost. Repeat this for any other Cloudbric rule groups you wish to add. Click Next.

Step 4: Set Rule Priority, Review, and Create

Set rule priority if you have added multiple rules. By default, your new rule group will be evaluated last.

Review your configuration to ensure all settings are correct.

Click Create web ACL. The deployment typically takes about 60-90 seconds.

A success banner will confirm that your AWS resources are now protected by your new Web ACL featuring Cloudbric’s managed rules.


Your Security Toolkit: The Cloudbric Rule Arsenal

Choose the right protection for your specific needs. Here’s a breakdown of the available rule groups, their purpose, and their capacity cost.

Rule GroupWhat It Does for YouWhen to Use It
API ProtectionGuards against the OWASP API Security Top 10 (injection, broken authentication, data exposure) with schema and rate-based checks.Any public or partner-facing REST/GraphQL API, especially for fintech, SaaS, or mobile back-ends.
Anonymous IP ProtectionDetects and blocks traffic from VPNs, proxies, Tor exits, and other anonymizing services to prevent fraud.Stop fraud rings, price scrapers, and location-based abuse without blocking legitimate users.
Bot ProtectionUses behavioral and signature-based filters to block credential stuffing, carding, inventory hoarding, and SEO spam.E-commerce checkouts, ticketing sites, and login portals where bot traffic harms business.
Malicious IP ReputationBlocks traffic from a real-time feed of 700k+ IPs linked to malware, spam, DDoS, and C2 servers.A quick, low-cost win for any business to instantly reduce its attack surface.
OWASP Top 10Provides broad protection against the most critical web application security risks like SQLi, XSS, and path traversal.The essential security blanket for every new website and application before it goes live.
Tor IP DetectionSpecifically flags and blocks traffic from Tor exit nodes to cut off high-risk, anonymous vectors.Banking, gaming, or any service where user identity and accountability are critical.

Pricing and WCU (Web ACL Capacity Units)

AWS WAF usage is calculated with WCUs. You can combine multiple rule groups in a single Web ACL, but note that the default WCU limit is 1,500 before additional charges apply.

Cloudbric Rule GroupTypical WCUMonthly List Price*
API Protection1,200Pay-as-you-go via AWS Marketplace
Anonymous IP Protection90“
Bot Protection150“
Malicious IP Reputation6“
OWASP Top 101,400“
Tor IP Detection6“

*Pricing is managed directly through your AWS bill.


Ready to Lock Down Your Edge?

Cloudbric brings enterprise-grade protection to your AWS WAF environment without the enterprise-level complexity. With a setup time of less than five minutes and threat intelligence that’s updated daily, you can secure your applications and get back to building.

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Advanced Persistent Threats (APTs): The Silent Threat in Your Network

We’ve all had “that cold”—the one that mostly clears up but leaves behind a nagging, persistent cough for weeks. In the world of cybersecurity, an Advanced Persistent Threat (APT) is the digital equivalent of that lingering cough, only far more dangerous. It’s an attack that stealthily breaches your network and then hides in the shadows, patiently waiting to achieve its objectives.

Understanding these silent, long-term threats is the first step toward building a truly resilient defense for your organization.

What Defines an Advanced Persistent Threat?

An Advanced Persistent Threat (APT) is a highly sophisticated, targeted cyberattack where a malicious actor gains unauthorized access to a network and remains undetected for an extended period. Unlike common cybercriminals focused on quick financial gain, APT actors play the long game. The name itself tells the story:

  • Advanced: The attackers use sophisticated, and often custom, tools and techniques to breach defenses. They are methodical, well-funded, and patient.
  • Persistent: This is not a one-time event. The primary goal is to establish a long-term foothold within the target’s network, maintaining access for months or even years to continuously gather intelligence.
  • Threat: Behind the attack is a coordinated human adversary—not just an automated script. These threat actors are typically well-organized groups targeting high-value entities like government agencies, defense contractors, and major corporations to conduct corporate or international espionage.

Their primary objective is data theft and intelligence gathering, not disruptive system damage.

The Anatomy of a Silent Breach: An APT’s Lifecycle

APT attacks unfold in distinct, methodical phases. While the specific tools may vary, the strategic process is consistent.

Phase 1: Infiltration – The Quiet Entry

The first step is to gain initial access. The attackers act like burglars casing a house, carefully looking for a way in.

  • Reconnaissance: They scan networks for vulnerabilities, identify misconfigured systems, and gather intelligence on employees and infrastructure.
  • Initial Access: They use their findings to breach the perimeter. Common methods include targeted phishing campaigns to steal credentials, exploiting unpatched software vulnerabilities, or even buying access from “Initial Access Brokers” on the dark web.
  • Establish a Foothold: Once inside, they immediately deploy tools like backdoors or rootkits. This ensures they can maintain access to the compromised system even if their initial entry point is discovered and closed.

Phase 2: Expansion – Mapping the Territory

With a foothold secured, the attackers begin to explore. This phase is about moving deeper into the network and gaining more control.

  • Lateral Movement: The attackers move silently from one system to another, mapping the network architecture and identifying where valuable data is stored.
  • Privilege Escalation: The initial breach often occurs through a standard user account with limited permissions. The attackers then work to escalate their privileges, often by targeting and taking over administrator accounts. Gaining this level of access allows them to disable security controls, manipulate systems, and move freely.

Phase 3: Exfiltration – The Heist

This is the culmination of their efforts. Having mapped the network and gained privileged access, the attackers begin to steal the targeted data.

  • Data Collection & Exfiltration: They gather, encrypt, and compress sensitive data before transferring it to their own servers. To avoid detection, they often exfiltrate data in small, slow increments that mimic normal network traffic.
  • Covering Their Tracks: To distract security teams during the exfiltration, APT groups may launch a diversionary attack, such as a Distributed Denial of Service (DDoS) or ransomware attack.
  • Remaining Embedded: Even after the initial data theft, the attackers may choose to remain hidden in the network, allowing them to launch future attacks or continue stealing information over the long term.

Hunting for Digital Ghosts: How to Detect an APT

Because APTs are designed for stealth, detection is challenging. Security teams must shift from looking for loud alarms to hunting for subtle anomalies that, when connected, tell the story of a hidden intruder. Key signs include:

  • Anomalous Log-in Activity: Look for unusual patterns, especially with privileged accounts, such as log-ins at odd hours or from unexpected geographic locations.
  • Unexpected Data Flows: Monitor for abnormal network traffic, like large data transfers to external servers or unusual internal data bundling, which could indicate data being staged for exfiltration.
  • Widespread Backdoor Trojans: The discovery of sophisticated malware designed to maintain persistent access on multiple machines is a strong indicator of an APT.
  • Subtle, Persistent Issues: Small, recurring anomalies or unexplained account lockouts that seem minor on their own could be part of a larger, coordinated attack.

Building a Resilient Defense Against APTs

Defending against a patient and well-resourced adversary requires a multi-layered, proactive security strategy. Key best practices include:

  • Shrink the Attack Surface: Regularly apply security patches, implement robust firewall rules, and continuously scan for and remediate vulnerabilities to give attackers fewer entry points.
  • Enforce Strict Access Controls: Implement the principle of least privilege, ensuring users only have access to the data and systems essential for their jobs. Deploy a Privileged Access Management (PAM) solution to closely monitor and control high-value accounts.
  • Adopt a Proactive Mindset: Don’t wait for alerts. Implement and automate threat hunting to actively search for indicators of compromise. Mapping your defenses to frameworks like MITRE ATT&CK can help you focus on the tactics and techniques used by known APT groups.
  • Secure Remote Connections: Use a Virtual Private Network (VPN) to encrypt all remote connections, making it harder for attackers to intercept data in transit.

Conclusion: The Importance of Vigilance

Advanced Persistent Threats are not loud, smash-and-grab robberies; they are patient, methodical espionage campaigns. Detecting and mitigating them requires a fundamental shift from a reactive security posture to one of continuous vigilance. By understanding their methods, hunting for subtle signs of their presence, and building a deep, proactive defense, organizations can turn their network from a hunting ground into a formidable fortress.

About Graylog
At Graylog, our vision is a secure digital world where organizations of all sizes can effectively guard against cyber threats. We’re committed to turning this vision into reality by providing Threat Detection & Response that sets the standard for excellence. Our cloud-native architecture delivers SIEM, API Security, and Enterprise Log Management solutions that are not just efficient and effective—whether hosted by us, on-premises, or in your cloud—but also deliver a fantastic Analyst Experience at the lowest total cost of ownership. We aim to equip security analysts with the best tools for the job, empowering every organization to stand resilient in the ever-evolving cybersecurity landscape.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.