AWS WAF adds Salt Security managed rule group for API and AI agent threats
AWS WAF now supports a new managed rule group from Salt Security, available via AWS Marketplace, designed to detect and mitigate threats targeting APIs and AI agents. This integration offers customers protection against common and complex API attack vectors and provides visibility into Model Context Protocol (MCP) interactions without requiring custom rule creation. The rule group is available directly through the AWS WAF console and AWS Marketplace, with pricing determined by Salt Security.
- →Salt Security managed rule group for API and AI agent threats
- →Enhanced API attack detection and mitigation
- →Improved visibility and control for AI agent and MCP traffic
- →Availability and Subscription
Features (1) ›
- Salt Security managed rule group for API and AI agent threats
AWS WAF now supports the Salt Security managed rule group, providing detection and mitigation for API-focused attacks and traffic from AI agents and MCP endpoints. This rule group identifies various API attack vectors, labels MCP traffic, and applies rate limiting to sensitive request parameters. It is available through AWS Marketplace, requiring no additional configuration beyond subscription and addition to a web ACL.
Enhancements (2) ›
- Enhanced API attack detection and mitigation
The new rule group detects common and complex API attack vectors such as credential brute force, excessive GraphQL queries, SSRF, prototype pollution, and JWT anomalies. It also helps mitigate enumeration and abuse by applying rate limiting to sensitive parameters like user identifiers and email addresses.
- Improved visibility and control for AI agent and MCP traffic
The rule group identifies and labels traffic from Model Context Protocol (MCP) endpoints, blocks unauthenticated MCP access, and adds observability into MCP interactions within AWS WAF. It also labels request attributes, including authorization headers, user identifiers, and GraphQL queries, for better downstream analysis.
Notes (1) ›
- Availability and Subscription
The Salt Security managed rule group can be subscribed to and added to a web ACL directly within the AWS WAF console via AWS Marketplace. The rule group supports versioning, and its pricing is set by Salt Security. Availability by region can be verified on the AWS Regional Services page.
https://aws.amazon.com/about-aws/whats-new/2026/08/aws-waf-salt-security-managed-rules/
Related releases
- Terraform AWS Provider v6.60.0 Adds New Resources and Fixes Bugs Terraform AWS Provider Releases ·
- Amazon S3 enhances access denied errors with specific policy ARNs AWS What's New ·
- OpenAI Daybreak Red and Blue Cyber Defense Models Now on Amazon Bedrock AWS What's New ·
- AppFolio Transforms Data Streaming with Amazon MSK Express Brokers AWS Big Data Blog ·
- AWS IAM Role Manager Automates Service Role Setup AWS What's New ·
- Amazon Quick Integrates Microsoft Purview for Data Loss Prevention AWS What's New ·