Miggo Rules for AWS WAF - AI/ML Application Protection
Miggo Security · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
### What You Get
Miggo's AI/ML Application Protection is a managed rule group for AWS WAF that defends your generative-AI application stack against high-severity CVEs. Rules are continuously updated, exploit-validated, and ready to deploy within your existing AWS WAF WebACL.
Show the rest of the publisher’s description (35 more lines)
### Frameworks Covered
- LangChain
- LlamaIndex
- LiteLLM
- vLLM
- Langflow
- MCP Inspector
- Ray
- TorchServe
- BentoML
### Exploitation Patterns Blocked
- Unauthenticated RCE in agent endpoints
- Pickle and HTTP-API deserialization attacks
- SSRF in model-fetch paths
- SQL injection in query engines
- SSTI and code-injection vectors
### How Rules Are Built and Validated
Every Miggo rule is generated from real proof-of-concept exploit code - either internet-available or Miggo-generated. Before release, each rule is tested against multiple bypass and mutation variations in Miggo Lab, ensuring detection efficacy against evasion techniques that static rule sets miss. Rules ship on a versioned cadence so you always know what changed and when.
### How to Deploy
- Subscribe to Miggo Rules for AWS WAF through AWS Marketplace.
- In the AWS WAF console, add the Miggo managed rule group to your existing WebACL (associated with CloudFront, ALB, or API Gateway).
- Set rule actions to Count mode initially to observe matches without blocking traffic.
- Review matched requests in AWS WAF logs, then switch to Block mode once validated.
- Complete the notification setup to receive versioning updates and alerts for high-priority threats.
### Prerequisites
- An active AWS WAF subscription with a configured WebACL
- A supported resource (CloudFront distribution, Application Load Balancer, or API Gateway) associated with the WebACL
- Sufficient WAF rule group capacity in your WebACL
### Data Handling
Miggo rules execute entirely within AWS WAF. Request inspection and blocking happen inside your AWS account - no customer traffic data is sent to Miggo.
### Frequently Asked Questions (FAQs)
For more Frequently Asked Questions (FAQs) [here](https://www.miggo.io/pmr-for-aws-waf-faq-questions).
### Miggo WAF Copilot - Automate Your Full WAF Lifecycle
To harness the full power of AWS WAF as a preemptive mitigation layer for exploitable vulnerabilities specific to your applications, Miggo WAF Copilot automates WAF management end-to-end. It connects to your vulnerability scanner, assesses exploitability against your runtime environment, generates precise WAF mitigations, and pre-validates them against bypass variations before deployment. Leveraging proprietary agentic AI and runtime application context, WAF Copilot tailors rules and configurations to your continuously changing posture and threat landscape.
Learn more about Miggo WAF Copilot [here](https://www.miggo.io/book-a-miggo-aws-waf-demo).
Highlights
Highlighted by the publisher on AWS Marketplace.
Covers 9 AI/ML frameworks including LangChain, LlamaIndex, LiteLLM, vLLM, Langflow, MCP Inspector, Ray, TorchServe, and BentoML. Unlike generic WAF rule sets, Miggo rules are purpose-built for the unique attack surfaces of generative-AI stacks - agent endpoints, model-serving APIs, and LLM gateways - where standard managed rules provide no coverage.
Every rule is exploit-validated before release: generated from real proof-of-concept code, then tested against multiple bypass and mutation variations in Miggo Lab. This PoC-driven methodology ensures rules block actual exploitation techniques rather than relying on signature patterns that attackers easily evade. Rules ship on a versioned cadence with update notifications so your protection evolves as threats do.
Targets high-severity exploitation patterns specific to AI/ML infrastructure: unauthenticated RCE in agent endpoints, pickle and HTTP-API deserialization, SSRF in model-fetch paths, SQL injection in query engines, and SSTI/code-injection. Rules execute entirely within AWS WAF - no customer traffic leaves your AWS account - and deploy into any existing WebACL protecting CloudFront, ALB, or API Gateway resources.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Plans and pricing as listed
2 listed- Units
- Units
Refund terms
As stated by the publisher on AWS Marketplace.
Non-Refundable
Sources
Publisher resources
2 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

