Head Of Cloud & Customer Success at a university with 501-1,000 employees
Real User
Top 20
Jun 16, 2026
For improvement, it would be better to have access to deeper configuration levels in Imperva Managed Rules on AWS WAF. For example, if my application is using Nginx or a certain middle-level application tool with different runtimes and middleware products, I would want to go to a more granular level to help fix vulnerabilities at the best level. In terms of needed improvements, I think integrating AI with knowledge bases and adding SRE configurations for an agentic approach would benefit my resolution part, especially since I work on applications that need immediate protection. Improvements in agentic-based resolution to minimize MTTR on SRE and AI-enabled documentation finding would be a great approach to develop. Regarding the governance and security of Imperva Managed Rules on AWS WAF's AI capabilities, I see the security in application security as present, but there does need to be improvement in governance. I have to manage uploads and downloads when using applications like the Inland Revenue Department for document scanning.
Imperva Managed Rules on AWS WAF can usually have false positives sometimes, blocking legitimate traffic and struggling with complex search queries, particularly with large JSON requests and certain GraphQL requests, which makes us initially deploy the rules in monitoring mode before switching to blocking mode to ensure all our use cases are supported. Because the rules of Imperva Managed Rules on AWS WAF are vendor-managed, the detection methods are not fully transparent, and our security teams cannot inspect every signature, leading to troubleshooting that usually requires vendor documentation, which can make it a bit difficult. Imperva Managed Rules on AWS WAF is quite good for what it is, but it is still not suitable in some use cases such as internal-only applications, and if your organization requires full control over every detection rule, it does not work. Additionally, you need to tune the WAF behavior after deployment; it is not just a deploy and leave situation.
There are many improvements I would identify. The native AWS integration plugs directly into my existing Web ACLs along with the native AWS managed rule sets without conflict. There are no software regressions because it relies entirely on standard WAF matching conditions and it has zero impact on the application middleware or container environment. This aspect could be improved. Other issues include that the marketplace sellers do not allow me to modify individual parameters inside the vendor's compiled rule set, meaning any false positive must be handled by a custom override rule. This also needs improvement.
Learn what your peers think about Imperva Managed Rules on AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
Imperva Managed Rules on AWS WAF offers advanced protection against web application attacks with rule sets designed for efficient threat management.This solution provides a comprehensive layer of security by integrating seamlessly with AWS infrastructure. Targeting vulnerabilities, it ensures robust protection while minimizing false positives. With easy rule management, users can dynamically address threats, maintaining optimal security postures across AWS environments. This allows for...
For improvement, it would be better to have access to deeper configuration levels in Imperva Managed Rules on AWS WAF. For example, if my application is using Nginx or a certain middle-level application tool with different runtimes and middleware products, I would want to go to a more granular level to help fix vulnerabilities at the best level. In terms of needed improvements, I think integrating AI with knowledge bases and adding SRE configurations for an agentic approach would benefit my resolution part, especially since I work on applications that need immediate protection. Improvements in agentic-based resolution to minimize MTTR on SRE and AI-enabled documentation finding would be a great approach to develop. Regarding the governance and security of Imperva Managed Rules on AWS WAF's AI capabilities, I see the security in application security as present, but there does need to be improvement in governance. I have to manage uploads and downloads when using applications like the Inland Revenue Department for document scanning.
Imperva Managed Rules on AWS WAF can usually have false positives sometimes, blocking legitimate traffic and struggling with complex search queries, particularly with large JSON requests and certain GraphQL requests, which makes us initially deploy the rules in monitoring mode before switching to blocking mode to ensure all our use cases are supported. Because the rules of Imperva Managed Rules on AWS WAF are vendor-managed, the detection methods are not fully transparent, and our security teams cannot inspect every signature, leading to troubleshooting that usually requires vendor documentation, which can make it a bit difficult. Imperva Managed Rules on AWS WAF is quite good for what it is, but it is still not suitable in some use cases such as internal-only applications, and if your organization requires full control over every detection rule, it does not work. Additionally, you need to tune the WAF behavior after deployment; it is not just a deploy and leave situation.
There are many improvements I would identify. The native AWS integration plugs directly into my existing Web ACLs along with the native AWS managed rule sets without conflict. There are no software regressions because it relies entirely on standard WAF matching conditions and it has zero impact on the application middleware or container environment. This aspect could be improved. Other issues include that the marketplace sellers do not allow me to modify individual parameters inside the vendor's compiled rule set, meaning any false positive must be handled by a custom override rule. This also needs improvement.