Head Of Cloud & Customer Success at a university with 501-1,000 employees
Real User
Top 20
Jun 16, 2026
My main use case for Imperva Managed Rules on AWS WAF is using Layer 7 particular OWASP 10 and SP10 based security rules. I had to enable the Layer 7-based attacks by setting up bots and related configurations, so that was the primary case. On WAF, I set up those rules for the particular finance application security part. Imperva Managed Rules on AWS WAF has helped my finance application specifically by allowing us to identify bots and adapt to attacks that were changing over time. Once I identified Imperva's product capability and set up those rules, I was able to rectify the attacks that I was not able to prevent with previous products.
I use Imperva Managed Rules on AWS WAF in front of AWS WAF to extend the native capabilities, leveraging Imperva's threat intelligence and web application security expertise to provide pre-configured protections against common web attacks while also helping to reduce operational burden on the team. Recently, we worked on creating a payment gateway, and we used Imperva Managed Rules on AWS WAF to help stop threats such as SQL injection, cross-site scripting, command injection, local file inclusion, and path traversal, essentially all OWASP threats. You can also use the WAF policy with Application Load Balancers, CloudFront distributions, and API Gateway endpoints on AWS, with most deployments being able to be completed in a few hours. Imperva Managed Rules on AWS WAF is a very good tool, but you need to consider your use case, as it is well-suited for healthcare systems, financial applications, organizations with small security teams, those trying to improve compliance, and public-facing web applications exposed to the internet. However, if you have internal-only applications or small websites with minimal risk, and if your organization requires full control over detection rules, Imperva Managed Rules on AWS WAF would not work, and you must be willing to tune the WAF behavior even after deploying Imperva, or it will not work for you.
My main use case is proactive edge security and IP reputation management. I use Imperva Managed Rules on AWS WAF's IP reputation rule group attached to my main application load balancer. Because Imperva leverages crowd-sourced global threat intelligence from their entire network, the rule layer automatically blocks requests originating from known botnets, exit nodes, and active attackers. For example, during a distributed credential stuffing attempt, Imperva dropped the malicious connections at the AWS edge layer instantly. This saves my back-end applications' API from resource exhaustion.
Learn what your peers think about Imperva Managed Rules on AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
Imperva Managed Rules on AWS WAF offers advanced protection against web application attacks with rule sets designed for efficient threat management.This solution provides a comprehensive layer of security by integrating seamlessly with AWS infrastructure. Targeting vulnerabilities, it ensures robust protection while minimizing false positives. With easy rule management, users can dynamically address threats, maintaining optimal security postures across AWS environments. This allows for...
My main use case for Imperva Managed Rules on AWS WAF is using Layer 7 particular OWASP 10 and SP10 based security rules. I had to enable the Layer 7-based attacks by setting up bots and related configurations, so that was the primary case. On WAF, I set up those rules for the particular finance application security part. Imperva Managed Rules on AWS WAF has helped my finance application specifically by allowing us to identify bots and adapt to attacks that were changing over time. Once I identified Imperva's product capability and set up those rules, I was able to rectify the attacks that I was not able to prevent with previous products.
I use Imperva Managed Rules on AWS WAF in front of AWS WAF to extend the native capabilities, leveraging Imperva's threat intelligence and web application security expertise to provide pre-configured protections against common web attacks while also helping to reduce operational burden on the team. Recently, we worked on creating a payment gateway, and we used Imperva Managed Rules on AWS WAF to help stop threats such as SQL injection, cross-site scripting, command injection, local file inclusion, and path traversal, essentially all OWASP threats. You can also use the WAF policy with Application Load Balancers, CloudFront distributions, and API Gateway endpoints on AWS, with most deployments being able to be completed in a few hours. Imperva Managed Rules on AWS WAF is a very good tool, but you need to consider your use case, as it is well-suited for healthcare systems, financial applications, organizations with small security teams, those trying to improve compliance, and public-facing web applications exposed to the internet. However, if you have internal-only applications or small websites with minimal risk, and if your organization requires full control over detection rules, Imperva Managed Rules on AWS WAF would not work, and you must be willing to tune the WAF behavior even after deploying Imperva, or it will not work for you.
My main use case is proactive edge security and IP reputation management. I use Imperva Managed Rules on AWS WAF's IP reputation rule group attached to my main application load balancer. Because Imperva leverages crowd-sourced global threat intelligence from their entire network, the rule layer automatically blocks requests originating from known botnets, exit nodes, and active attackers. For example, during a distributed credential stuffing attempt, Imperva dropped the malicious connections at the AWS edge layer instantly. This saves my back-end applications' API from resource exhaustion.