Back to the registry
Agent passport

Miggo Rules for AWS WAF - AI/ML Application Protection

Miggo Security · Cybersecurity & IT

No attestation published

Certification per AWS Marketplace.

Provenance reach4 of 12 layers traced

Evidence tier Source Confirmed · 4 captures on record

User ratingNot rated0 reviews on the listing
Runs onUnknownSaaS
ProvenanceUnknown44% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

### What You Get

Miggo's AI/ML Application Protection is a managed rule group for AWS WAF that defends your generative-AI application stack against high-severity CVEs. Rules are continuously updated, exploit-validated, and ready to deploy within your existing AWS WAF WebACL.

Show the rest of the publisher’s description (35 more lines)

### Frameworks Covered

  • LangChain
  • LlamaIndex
  • LiteLLM
  • vLLM
  • Langflow
  • MCP Inspector
  • Ray
  • TorchServe
  • BentoML

### Exploitation Patterns Blocked

  • Unauthenticated RCE in agent endpoints
  • Pickle and HTTP-API deserialization attacks
  • SSRF in model-fetch paths
  • SQL injection in query engines
  • SSTI and code-injection vectors

### How Rules Are Built and Validated

Every Miggo rule is generated from real proof-of-concept exploit code - either internet-available or Miggo-generated. Before release, each rule is tested against multiple bypass and mutation variations in Miggo Lab, ensuring detection efficacy against evasion techniques that static rule sets miss. Rules ship on a versioned cadence so you always know what changed and when.

### How to Deploy

  • Subscribe to Miggo Rules for AWS WAF through AWS Marketplace.
  • In the AWS WAF console, add the Miggo managed rule group to your existing WebACL (associated with CloudFront, ALB, or API Gateway).
  • Set rule actions to Count mode initially to observe matches without blocking traffic.
  • Review matched requests in AWS WAF logs, then switch to Block mode once validated.
  • Complete the notification setup to receive versioning updates and alerts for high-priority threats.

### Prerequisites

  • An active AWS WAF subscription with a configured WebACL
  • A supported resource (CloudFront distribution, Application Load Balancer, or API Gateway) associated with the WebACL
  • Sufficient WAF rule group capacity in your WebACL

### Data Handling

Miggo rules execute entirely within AWS WAF. Request inspection and blocking happen inside your AWS account - no customer traffic data is sent to Miggo.

### Frequently Asked Questions (FAQs)

For more Frequently Asked Questions (FAQs) [here](https://www.miggo.io/pmr-for-aws-waf-faq-questions).

### Miggo WAF Copilot - Automate Your Full WAF Lifecycle

To harness the full power of AWS WAF as a preemptive mitigation layer for exploitable vulnerabilities specific to your applications, Miggo WAF Copilot automates WAF management end-to-end. It connects to your vulnerability scanner, assesses exploitability against your runtime environment, generates precise WAF mitigations, and pre-validates them against bypass variations before deployment. Leveraging proprietary agentic AI and runtime application context, WAF Copilot tailors rules and configurations to your continuously changing posture and threat landscape.

Learn more about Miggo WAF Copilot [here](https://www.miggo.io/book-a-miggo-aws-waf-demo).

Highlights

Highlighted by the publisher on AWS Marketplace.

Covers 9 AI/ML frameworks including LangChain, LlamaIndex, LiteLLM, vLLM, Langflow, MCP Inspector, Ray, TorchServe, and BentoML. Unlike generic WAF rule sets, Miggo rules are purpose-built for the unique attack surfaces of generative-AI stacks - agent endpoints, model-serving APIs, and LLM gateways - where standard managed rules provide no coverage.

Every rule is exploit-validated before release: generated from real proof-of-concept code, then tested against multiple bypass and mutation variations in Miggo Lab. This PoC-driven methodology ensures rules block actual exploitation techniques rather than relying on signature patterns that attackers easily evade. Rules ship on a versioned cadence with update notifications so your protection evolves as threats do.

Targets high-severity exploitation patterns specific to AI/ML infrastructure: unauthenticated RCE in agent endpoints, pickle and HTTP-API deserialization, SSRF in model-fetch paths, SQL injection in query engines, and SSTI/code-injection. Rules execute entirely within AWS WAF - no customer traffic leaves your AWS account - and deploy into any existing WebACL protecting CloudFront, ALB, or API Gateway resources.

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Plans and pricing as listed

2 listed
Charge per month in each available region (pro-rated by the hour)
  • Units
$0.00
Charge per million requests in each available region
  • Units
$1.00

Refund terms

As stated by the publisher on AWS Marketplace.

Non-Refundable

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource
CustomEulaCustomEulaSource

Publisher resources

2 links
Publisher linkaws.amazon.comSource
Publisher linkaws.amazon.comSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Paid
2 plans listed
Delivery
SaaS
### Contact Support For support with Miggo Rules for AWS WAF, questions about rule versioning, latest threat coverage, or deployment assistance, contact the Miggo team at pmr@miggo.io.
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.