Listing Thumbnail

    Imperva - Managed Rules for IP Reputation on AWS WAF

     Info
    Sold by: Imperva 
    Deployed on AWS
    Imperva's Managed Rules for IP Reputation allow you to take a proactive approach to threat prevention and security management by providing an extensive IP whitelist/blacklist that is regularly monitored and updated.
    4.5

    Overview

    Imperva's Managed Rules for IP Reputation allows you to take a proactive approach to security by providing an extensive IP whitelist/blacklist which is regularly monitored and updated. Imperva's reputation feed leverages crowd-sourcing from aggregated attack data to update its list with newly detected malicious sources, taking the burden off of IT teams to account for undiscovered threats.

    Highlights

    • Proactive approach to threat prevention and security management; Automated protection regularly monitored and updated; Integrates seamlessly with AWS WAF

    Details

    Sold by

    Categories

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Imperva - Managed Rules for IP Reputation on AWS WAF

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (2)

     Info
    Dimension
    Cost/unit
    Charge per month in each available region (pro-rated by the hour)
    $40.00
    Charge per million requests in each available region
    $0.40

    Vendor refund policy

    non-refundable

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    For issues related specifically to an Imperva ruleset, you can contact Imperva support by email.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    4 reviews
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    IP Reputation Management
    Extensive IP whitelist/blacklist that is regularly monitored and updated to identify and block malicious sources
    Threat Intelligence Integration
    Crowd-sourced aggregated attack data leveraged to detect and update newly identified malicious IP sources
    AWS WAF Integration
    Seamless integration with AWS WAF for automated threat prevention and security management
    Automated Threat Detection
    Automated protection mechanism that continuously monitors and updates threat intelligence without manual intervention
    Managed Rule Set
    Pre-configured managed rules for IP reputation that reduce operational burden on security teams for threat identification
    Malicious IP Reputation Database
    Utilizes ThreatDB collected and analyzed from 700,000 websites across 171 countries to create and maintain a Malicious IP Reputation list for threat identification.
    Third-Party Validated Detection
    Achieves top-tier detection rate for malicious traffic, validated by independent third-party testing firm.
    Threat Intelligence Integration
    Integrates Cyber Threat Intelligence (CTI) from Cloudbric Labs to identify and block traffic from various threat IP sources.
    Real-Time Threat Information
    Provides real-time information about threats and vulnerabilities affecting web applications.
    AWS WAF Integration
    Operates as managed rules for AWS WAF to protect websites and web applications against malicious IP traffic.
    Threat Intelligence Integration
    Rulesets regularly updated with latest threat alerts using Cyber Threat Intelligence
    OWASP Top 10 Coverage
    Comprehensive protection against all OWASP Top 10 Web Application Threats
    Code Injection Prevention
    Managed rules targeting code injection techniques including SQLi, NoSQLi, and OS command injection
    Technology-Specific Vulnerability Protection
    Dedicated rules for known exploits in Apache Struts2, Apache Tomcat, Oracle WebLogic, WordPress, Drupal, and Joomla
    Malicious Bot Detection
    Malicious Bots rulesets included for bot-based threat mitigation

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    No security profile
    -
    -
    -
    -
    No security profile

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.5
    48 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    79%
    17%
    0%
    2%
    2%
    7 AWS reviews
    |
    41 external reviews
    External reviews are from G2 .
    Ayodeji Bayo-Makinde

    We have strengthened web threat protection and now focus our small team on higher‑value security work

    Reviewed on Jun 13, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I use Imperva Managed Rules on AWS WAF  in front of AWS WAF  to extend the native capabilities, leveraging Imperva's threat intelligence and web application security expertise to provide pre-configured protections against common web attacks while also helping to reduce operational burden on the team.

    Recently, we worked on creating a payment gateway, and we used Imperva Managed Rules on AWS WAF  to help stop threats such as SQL injection, cross-site scripting, command injection, local file inclusion, and path traversal, essentially all OWASP threats.

    You can also use the WAF  policy with Application Load Balancers , CloudFront distributions, and API Gateway endpoints on AWS , with most deployments being able to be completed in a few hours.

    Imperva Managed Rules on AWS WAF  is a very good tool, but you need to consider your use case, as it is well-suited for healthcare systems, financial applications, organizations with small security teams, those trying to improve compliance, and public-facing web applications exposed to the internet. However, if you have internal-only applications or small websites with minimal risk, and if your organization requires full control over detection rules, Imperva Managed Rules on AWS WAF would not work, and you must be willing to tune the WAF behavior even after deploying Imperva, or it will not work for you.

    What is most valuable?

    I use Imperva Managed Rules on AWS WAF because they have a rapid response to newly discovered attack techniques, and it is quickly updated, reducing the need for our internal security teams to create custom rules.

    Imperva Managed Rules on AWS WAF offers continuous threat intelligence updates as the best feature, as they have a rapid response to newly discovered attack techniques and base their detection logic on real-world threat data with easy integration with AWS .

    It has greatly reduced operational overhead, because without Imperva Managed Rules on AWS WAF, we would have to dedicate a team to analyze traffic attacks, write custom WAF rules, test the rules, and then maintain signatures. Imperva Managed Rules on AWS WAF helps to handle much of this maintenance work and allows our teams to focus on higher priorities.

    What needs improvement?

    Imperva Managed Rules on AWS WAF can usually have false positives sometimes, blocking legitimate traffic and struggling with complex search queries, particularly with large JSON requests and certain GraphQL requests, which makes us initially deploy the rules in monitoring mode before switching to blocking mode to ensure all our use cases are supported.

    Because the rules of Imperva Managed Rules on AWS WAF are vendor-managed, the detection methods are not fully transparent, and our security teams cannot inspect every signature, leading to troubleshooting that usually requires vendor documentation, which can make it a bit difficult.

    Imperva Managed Rules on AWS WAF is quite good for what it is, but it is still not suitable in some use cases such as internal-only applications, and if your organization requires full control over every detection rule, it does not work. Additionally, you need to tune the WAF behavior after deployment; it is not just a deploy and leave situation.

    For how long have I used the solution?

    I have been using Imperva Managed Rules on AWS WAF for about a year and six months.

    What do I think about the stability of the solution?

    Imperva Managed Rules on AWS WAF is fairly stable.

    What do I think about the scalability of the solution?

    On the AWS cloud, Imperva Managed Rules on AWS WAF is fairly scalable for what it is as a managed WAF rule, so I give it good marks in scalability.

    How are customer service and support?

    The customer support for Imperva Managed Rules on AWS WAF is quite good; I have used it once and received good responses. For my one experience, I would rate the customer support a nine, as it was good.

    Which solution did I use previously and why did I switch?

    I did not previously use any solution.

    How was the initial setup?

    I did purchase Imperva Managed Rules on AWS WAF through the AWS Marketplace .

    Which other solutions did I evaluate?

    I did evaluate F5 and Fortinet also before choosing Imperva Managed Rules on AWS WAF.

    What other advice do I have?

    I have not really made use of the AI capabilities of Imperva Managed Rules on AWS WAF, but from what I have heard from others, it seems it is quite standard for the market.

    For my end, the cost of Imperva Managed Rules on AWS WAF might sometimes be a bit high, making it not suitable for small websites with minimal risk because the cost outweighs the benefits in that case. However, for a big e-commerce platform or payment gateway, it is definitely a worthwhile investment.

    I can definitely speak to the fewer employees needed because the time and effort it would take to dedicate engineers or resources to create custom WAF rules is cut out by using Imperva Managed Rules on AWS WAF.

    I would rate this solution an eight overall.

    Miguel Ángel Carvajal Ramos

    Hybrid security layer has simplified compliance audits and now protects high-traffic web APIs

    Reviewed on Jun 05, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Imperva Managed Rules on AWS WAF  was used to protect high traffic enterprise web applications and APIs, handling millions of monthly requests. I was part of the domain management and CDN  network team. It served as the primary baseline security layer, integrated directly into AWS  web ACLs.

    Imperva Managed Rules on AWS WAF  is deployed in a hybrid cloud environment in my organization. We have direct traffic from Akamai  CDN , but everything was passing through Imperva.

    What is most valuable?

    Automatic updates are the best features Imperva Managed Rules on AWS WAF  offers. When I mention updates, I am referring to the automatic threat intelligence and frequency of rule updates. Imperva automatically updates threat intelligence and signatures, which saved a lot of engineering teams considerable time.

    The customer support for Imperva Managed Rules on AWS WAF  is the best. As soon as I had any issue when I was on-call rotation, the support was very friendly, very accurate, and always helpful.

    Imperva Managed Rules on AWS WAF's governance and security is very robust. The security and compliance is always the best. If you do not have proper roles or privileges, it's impossible to access information or details from other users or accounts.

    Imperva Managed Rules on AWS WAF's accuracy and reliability of output is very accurate. I would say it's one of the industry standards, with more accuracy. I have never seen greater accuracy with Imperva or Incapsula.

    What needs improvement?

    Sometimes the rules act as a black box with Imperva Managed Rules on AWS WAF because you cannot see the underlying rule logic or regular expressions, which can be challenging when troubleshooting false positives on complex API payloads.

    Better documentation would help with the needed improvements. I was trying to use the Terraform  provider, looking for the Imperva provider, but it was not easy to integrate.

    Low operational overhead is the only additional feature I would mention.

    For how long have I used the solution?

    I have been using Imperva Managed Rules on AWS WAF for two years.

    What do I think about the stability of the solution?

    Imperva Managed Rules on AWS WAF is very stable.

    What do I think about the scalability of the solution?

    I have never had any issue regarding scalability with Imperva Managed Rules on AWS WAF because it is always cloud-based or hybrid but has never been a concern.

    How are customer service and support?

    The customer support for Imperva Managed Rules on AWS WAF is the best. As soon as I had any issue when I was on-call rotation, the support was very friendly, very accurate, and always helpful.

    I would rate the customer support a ten out of ten.

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution before Imperva Managed Rules on AWS WAF. We are still using the same solution.

    How was the initial setup?

    Imperva Managed Rules on AWS WAF was integrated very quickly without having to build custom rule sets from scratch, positively impacting my organization.

    The quick integration of Imperva Managed Rules on AWS WAF benefited my team with compliance like PCI DSS and SOC 2. It was integrated very quickly without creating something from scratch. The security compliance audits were easier.

    What about the implementation team?

    We did not purchase Imperva Managed Rules on AWS WAF through the AWS Marketplace . We have a direct partner.

    What was our ROI?

    I have seen a return on investment when something involves any deployment for blue or green deployment. I was in charge of redirection rules, so traffic from one cluster to another was very useful.

    What's my experience with pricing, setup cost, and licensing?

    I was not part of the billing team, so I do not have much experience with pricing, setup cost, and licensing. Imperva Managed Rules on AWS WAF was already in place when I joined the team, and it is still one of the most used tools.

    Which other solutions did I evaluate?

    I was evaluating Akamai  before choosing Imperva Managed Rules on AWS WAF.

    What other advice do I have?

    Imperva Managed Rules on AWS WAF is great for meeting security compliance audits, using the out-of-the-box compliance and low operational overheads.

    I highly recommend Imperva Managed Rules on AWS WAF when you need something fast and low-maintenance threat protection. For applications with highly customized API payloads, there may be some false positives.

    I would highly recommend Imperva Managed Rules on AWS WAF when you need fast, low-maintenance threat protection.

    I would like to continue using Imperva and integrate it with Terraform , so my pipelines will be much more secure.

    I give this review an overall rating of eight out of ten.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    reviewer2678862

    Advanced rules have strengthened our layer seven defenses and reduced critical cyber attacks

    Reviewed on Jun 03, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Imperva Managed Rules on AWS WAF  is to protect my layer seven applications and application load balancers (ALBs) so that I can protect my applications from layer seven cybersecurity attacks.

    I can give a specific example of how I've used Imperva Managed Rules on AWS WAF  to protect an application, as the rules help me protect from cyber attacks which are part of the OWASP Top 10, including cross-site scripting, SQL injection attacks, and sometimes modifications of MFA for specific applications.

    I'm mainly focusing on protecting my applications that are hosted on CloudFront and sometimes on the application load balancer in AWS , for which I'm using Imperva Managed Rules on AWS WAF .

    What is most valuable?

    The best features of Imperva Managed Rules on AWS WAF  are that all the rules are in line with the updated OWASP Top 10 security vulnerabilities, which allows me to counter attack with the respective attack patterns that are present in the market.

    Staying up to date with the latest OWASP Top 10 has helped my team significantly, as with the updated 2026 rules, we can counter the cyber attacks that are more aligned with artificial intelligence tools. Earlier, there were certain OWASP Top 10 rules that were not present in the environment.

    Imperva Managed Rules on AWS WAF has impacted my organization positively to a very good extent, as along with the default AWS WAF  rules, Imperva Managed Rules on AWS WAF is giving more edge on layer seven security for protecting the applications at the organization, making them good-to-go rules.

    Since using Imperva Managed Rules on AWS WAF, I've noticed specific outcomes such as a reduction in security incidents, and it provides me with more robust solutions along with protections and analysis, allowing it to protect against cyber attacks at any level or capacity.

    What needs improvement?

    Imperva Managed Rules on AWS WAF keeps updating its rule sets, but the company could increase the number of rules on a yearly basis and incorporate more rules aligned with artificial intelligence security. There should be more alignment with AI and ML security.

    For how long have I used the solution?

    I have been using Imperva Managed Rules on AWS WAF for about one or two years.

    What other advice do I have?

    Everything looks good with Imperva Managed Rules on AWS WAF as of now.

    Regarding Imperva Managed Rules on AWS WAF's AI capabilities, I believe it has a good alignment from the governance and security perspective, and it is capable of protecting from cyber attacks effectively.

    In terms of accuracy and reliability of output regarding Imperva Managed Rules on AWS WAF's AI capabilities, it all depends on which AI generative model is being used. Currently, Imperva is in good shape with a decent capacity for accuracy and reliability, though not perfect.

    My advice to others looking into using Imperva Managed Rules on AWS WAF is that if customers do not want to use the default AWS WAF  rules or if they are looking for add-on features or protection, they should proceed with Imperva Managed Rules on AWS WAF to gain more security.

    I give this product a rating of 9 out of 10.

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    BasilJiji

    Edge protection has reduced junk traffic and now safeguards APIs with automated threat intelligence

    Reviewed on May 22, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case is proactive edge security and IP reputation management. I use Imperva Managed Rules on AWS WAF 's IP reputation rule group attached to my main application load balancer. Because Imperva leverages crowd-sourced global threat intelligence from their entire network, the rule layer automatically blocks requests originating from known botnets, exit nodes, and active attackers. For example, during a distributed credential stuffing attempt, Imperva dropped the malicious connections at the AWS  edge layer instantly. This saves my back-end applications' API from resource exhaustion.

    What is most valuable?

    The best feature I would say is the compliance. It satisfies enterprise audit criteria for web application profiling that is required by PCI DSS and HIPAA. Also, it aligns fully with my security compliance matrices, the OWASP Top 10 alignment, and standard core rules to defend against injection attacks, cross-site scripting, and path traversal. These are the major features.

    The managed rule set proves that modern security does not have to be slow or complicated. It turns threat intelligence into a utility function that I can enable with a few clicks.

    It has eliminated the heavy operational burden of threat research. Instead of my internal security engineers spending hours tracking new malicious IPs or writing custom regex signatures to deal with emerging exploits, Imperva automatically updates the rule set in the background.

    What needs improvement?

    There are many improvements I would identify. The native AWS  integration plugs directly into my existing Web ACLs along with the native AWS managed rule sets without conflict. There are no software regressions because it relies entirely on standard WAF  matching conditions and it has zero impact on the application middleware or container environment. This aspect could be improved.

    Other issues include that the marketplace sellers do not allow me to modify individual parameters inside the vendor's compiled rule set, meaning any false positive must be handled by a custom override rule. This also needs improvement.

    For how long have I used the solution?

    I have been using Imperva Managed Rules on AWS WAF  for about three years.

    What do I think about the stability of the solution?

    Imperva Managed Rules on AWS WAF  is highly stable because the rules run directly inside the native AWS WAF  engine. Availability is backed by AWS global infrastructure. There is no middleman latency or point of failures. It inherits the high stability and scaling of AWS itself.

    What do I think about the scalability of the solution?

    It scales flawlessly via elastic hyper-scale. Since it handles inspection inside the cloud provider's network edge, it can handle millions of web requests per second without requiring my team to provision large compute instances or worry about bandwidth bottlenecks.

    How are customer service and support?

    The customer support is providing excellent service. The support and reference models are very structured. AWS documentation explicitly outlines how to subscribe to and deploy vendor rule sets, while Imperva provides clear definitions for what each rule group evaluates. Support for rule matching is managed through AWS Premium Support channels with escalation lines to Imperva's threat research team for enterprise subscribers.

    Which solution did I use previously and why did I switch?

    I previously managed custom IP blocklists manually via standard network firewall rules. I switched because manual lists are reactive, rigid, and impossible to maintain efficiently against rapidly changing cloud threat vectors.

    How was the initial setup?

    I fixed this by putting Imperva Managed Rules on AWS WAF's rule group into count mode for the first two weeks. This allowed me to analyze the traffic pattern safely in my logs and write specific bypass exceptions before switching the rules to strict block mode.

    What about the implementation team?

    I always leverage count mode when introducing a new vendor rule package. Let it observe your real production traffic patterns for a week, verify it against your monitoring dashboard, and only toggle it to fully blocking once you are confident your legitimate APIs will not be disrupted.

    What was our ROI?

    The return on investment is highly visible in my infrastructure savings. By stopping illegitimate traffic at my utmost edge, I noticed a 15% drop in junk traffic reaching my application layers. This reduced my downstream compute cost and lowered my database resource consumption.

    What's my experience with pricing, setup cost, and licensing?

    The experience was very efficient. The product uses a transparent, pay-as-you-go consumption-based pricing model that is billed through the AWS Marketplace . It eliminates heavy upfront contract costs, handles automatic licensing, and bundles all fees directly into my unified AWS monthly billing.

    Which other solutions did I evaluate?

    Splunk was another option that I considered, but ultimately I chose Imperva Managed Rules on AWS WAF, which offered many more benefits.

    What other advice do I have?

    I noticed a 12% drop in junk traffic reaching my application layer. I would rate this solution 9 out of 10.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Financial Services

    Good solution but poor support in my region

    Reviewed on Jul 29, 2025
    Review provided by G2
    What do you like best about the product?
    It is a reliable cybersecurity solution that has many tools to help protect web applications.
    What do you dislike about the product?
    It is very expensive for our South American region and the support from the partners is bad.
    What problems is the product solving and how is that benefiting you?
    The technical support from the local partners is bad.
    View all reviews