Block the request.
Remember
the attacker.

WAFGuard runs inside your AWS account, reads AWS WAF logs from S3, and enriches attack signals with FraudGuard intelligence to automate temporary IP blocks through your FraudGuard blacklist and AWS WAF IP-set synchronization.

From evidence to enforcement Example
One source. Multiple attempts.203.0.113.42
01SQL injection/searchWAF blocked
02Cross-site scripting/catalogWAF blocked
03SQL injection/productsWAF blocked
Selected matches meet your policy
Temporary FraudGuard block10 min

Customer lists checked Tagged WAFGuard

Sync to AWS WAF IP setsBlock subsequent requests across the attached web ACL.
Optional

Beyond a single request

An attack on one endpoint
should inform the next.

Your WAF catches an injection attempt. The same IP moves on to your login page. The first block tells you something worth remembering.

WAFGuard enriches those attack signals with FraudGuard intelligence, then turns qualifying sources into temporary blacklist entries your security integrations can enforce.

The workflow

From WAF logs
to informed IP blocks.

  1. 01

    Read the signals

    Process existing S3 WAF logs. Look for repeated matches from the security rules or labels you select.

    AWS WAF → S3 → Lambda
  2. 02

    Enrich the signals

    The default policy adds ACE v2 intelligence to your WAF evidence. Customer list checks protect whitelisted IPs and skip existing blocks.

    ACE enrichment or WAF-only detection
  3. 03

    Apply a temporary block

    When enforcement is enabled, publish eligible IPs to your FraudGuard blacklist with an expiry and a WAFGuard tag.

    Traceable, time-limited entries
  4. 04

    Extend the protection

    Optionally mirror your effective blacklist into dedicated AWS WAF IP sets, alongside your existing rules.

    IPv4 + IPv6 enforcement

Automation on your terms

Build confidence.
Then turn on blocking.

See what WAFGuard would do before letting it act. Tune your policy against real traffic, then enable the enforcement you want.

What you need to get started
01

Observe Default

Review proposed decisions in CloudWatch. No blacklist publishing or IP-set sync.

02

Enforce When you're ready

Enable blacklist publishing and optional AWS WAF sync. Keep a record of every decision.

DetectionWAF + ACE, or WAF only
Block durationYour setting, or ACE guidance
NotificationsOptional Amazon SNS

AWS-native deployment

Your account.
Your logs. Your control.

Deploy with CloudFormation. WAFGuard runs in your AWS account using Lambda, S3, and DynamoDB, with credentials held in Secrets Manager.

Raw log files stay in your account. Selected attacker IPs and customer-list operations go to the FraudGuard API.

Bring what you already run

  • A regional AWS WAF web ACL
  • WAF request logs delivered to S3
  • FraudGuard Professional or higher
CloudFormation handles the WAFGuard resources.
Your existing WAF rules stay in place.

A few useful details

Before you deploy.

Explore the FraudGuard API
Does every blocked request trigger a ban?

No. You choose the WAF security rules or labels and how many matching requests are required within a time window. WAFGuard checks your FraudGuard customer lists before proposing or publishing a block. Whitelisted IPs are excluded.

Do I have to use FraudGuard IP intelligence?

No. The default policy requires selected WAF evidence plus an ACE v2 block recommendation. WAF-only detection skips ACE lookups while still checking your FraudGuard whitelist and blacklist. Choose an explicit block duration for WAF-only mode.

How quickly does protection take effect?

WAFGuard processes logs after AWS WAF delivers them to S3, then applies eligible decisions on its scheduled run. Allow several minutes for log delivery and processing. Your WAF handles the original request; WAFGuard helps protect against subsequent activity.

How does AWS WAF enforcement work?

In Enforce mode, enable sync to mirror your effective FraudGuard blacklist into dedicated IPv4 and IPv6 IP sets. Attach WAFGuard's rule group to your web ACL at the appropriate priority. The sync excludes whitelisted and expired entries; changes take effect after synchronization and AWS propagation.

Which AWS WAF deployments are supported?

The initial release supports regional AWS WAF web ACLs with request logging to S3. Deploy WAFGuard in the same AWS account and region. CloudFront-scoped web ACLs are not supported in this release.

What is included, and what costs extra?

WAFGuard is included with Professional ($99/month), Business, and Enterprise. API calls count toward your plan allowance; Professional includes 5 million requests per month shared across your account. AWS infrastructure and log-processing charges are separate.

Ready to deploy

Put enriched WAF signals
to work.

Connect your S3 WAF logs to FraudGuard intelligence.
Review enriched decisions, then automate temporary blocks.