← Projects

Rolling out AWS WAF without breaking production

Took public ingestion endpoints from an allow-all web ACL to layered WAF protection, validating every rule in count mode before blocking.

Context

The platform exposes public endpoints that devices and customers use to send data. Those endpoints were getting a steady stream of attacks, mostly file enumeration. A web ACL existed, but it allowed everything by default and had no rules, so in practice there was no protection.

What I did

Results

Lessons learned