AWS Managed Rules cover the internet baseline (OWASP, bots, common abuse, SQLi, known bad inputs). Miggo Rulesets layer above them with CVE-specific protection for the patch gap that baseline rules don't address.
New CVEs are continuously evaluated by Miggo's agentic engine and in-house research team. To ensure optimal defense without delaying protection, rule deployment is prioritized by threat urgency:
Both patterns are supported. Pin a tested version for stability or follow the latest for coverage. The full AWS WAF managed rule group versioning lifecycle, expiry behavior, and how to set a static version is documented at: .
The PMR consistently ships versioned releases to defend against the top recent threats. However, you may want to seek enhanced protection in scenarios such as: When CVEs land in your custom application code, when exploits specifically attack non-HTTP paths, or when your application faces memory-corruption bugs. To upgrade your protection capabilities with the full Miggo Platform, reach out to [email protected] .
A monthly subscription fee per AWS region where the rule group is attached to a Protection Pack (Web ACL), hourly pro-rated, plus a usage fee per 1,000,000 HTTP requests AWS WAF evaluates against the rule group. Requests blocked earlier in the Protection Pack (Web ACL) by other rules are not billed for this managed ruleset.
Yes. AWS charges separately for AWS WAF itself (Web ACL, per-rule, and per-request fees). Miggo bills only the subscription and per-million-request fees shown on the Marketplace listing. See aws.amazon.com/waf/pricing for the AWS-side numbers.
You can cancel anytime from AWS Marketplace; charges are pro-rated through the cancellation date. The product is non-refundable, but pro-rating means you only pay for the time you actually used.
No. The PMR runs within AWS WAF infrastructure and only in your account; AWS WAF inspects requests on your behalf against the rule patterns.
Every Miggo rule is built to protect against real exploits and their variations, validated against bypass and mutation variations. Confirmed false negatives reported post-release are fixed in the release.
We recommend starting in Count action so AWS WAF records matches without blocking requests. Let production traffic flow for 4 to 48 hours, depending on urgency, traffic volume, and risk tolerance, then review WAF metrics per rule and sampled requests in the AWS WAF console. Then, promote specific rules or the whole group to Block mode.
Per-rule metric is published to CloudWatch under the AWS/WAFV2 namespace. Sampled requests in the AWS WAF console show the exact requests that matched. For full capture, enable AWS WAF logs to Kinesis Firehose, S3, or CloudWatch Logs.
Email [email protected] with the rule group ID, rule name, and a sample blocked request from CloudWatch. Also, please provide the AccountID for reference by support. Miggo triages and patches confirmed false positives in the version, typically within 24 to 72 hours. While the fix ships, pin to the version or set the offending rule to Count.
Email [email protected] . Response SLA: 1 business day, Mon to Fri, US business hours. Languages: English. For CVE coverage requests, include CVE ID, affected component, and a link to the advisory; for false-positive reports, include the rule group ID, rule name, and a sample blocked request from CloudWatch.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
