aws AWS What's New ·

AWS WAF adds Salt Security managed rule group for API and AI agent threats

aisecurityawsengineer
feature announcement

AWS WAF now supports a new managed rule group from Salt Security, available via AWS Marketplace, designed to detect and mitigate threats targeting APIs and AI agents. This integration offers customers protection against common and complex API attack vectors and provides visibility into Model Context Protocol (MCP) interactions without requiring custom rule creation. The rule group is available directly through the AWS WAF console and AWS Marketplace, with pricing determined by Salt Security.

  • Salt Security managed rule group for API and AI agent threats
  • Enhanced API attack detection and mitigation
  • Improved visibility and control for AI agent and MCP traffic
  • Availability and Subscription
Features (1)
  • Salt Security managed rule group for API and AI agent threats

    AWS WAF now supports the Salt Security managed rule group, providing detection and mitigation for API-focused attacks and traffic from AI agents and MCP endpoints. This rule group identifies various API attack vectors, labels MCP traffic, and applies rate limiting to sensitive request parameters. It is available through AWS Marketplace, requiring no additional configuration beyond subscription and addition to a web ACL.

Enhancements (2)
  • Enhanced API attack detection and mitigation

    The new rule group detects common and complex API attack vectors such as credential brute force, excessive GraphQL queries, SSRF, prototype pollution, and JWT anomalies. It also helps mitigate enumeration and abuse by applying rate limiting to sensitive parameters like user identifiers and email addresses.

  • Improved visibility and control for AI agent and MCP traffic

    The rule group identifies and labels traffic from Model Context Protocol (MCP) endpoints, blocks unauthenticated MCP access, and adds observability into MCP interactions within AWS WAF. It also labels request attributes, including authorization headers, user identifiers, and GraphQL queries, for better downstream analysis.

Notes (1)
  • Availability and Subscription

    The Salt Security managed rule group can be subscribed to and added to a web ACL directly within the AWS WAF console via AWS Marketplace. The rule group supports versioning, and its pricing is set by Salt Security. Availability by region can be verified on the AWS Regional Services page.

Read the original announcement →

https://aws.amazon.com/about-aws/whats-new/2026/08/aws-waf-salt-security-managed-rules/

Related releases