AWS Managed Rules changelog
This section lists changes to the AWS Managed Rules for AWS WAF since their release in November, 2019.
Note
This changelog reports changes to the rules and rule groups in AWS Managed Rules for AWS WAF.
For the IP reputation rule
groups, this changelog reports changes to the rules and rule group, and it reports significant changes to the sources of the IP address lists that the rules use. It does not report changes to the IP address lists themselves, due to the dynamic nature of those lists. If you have questions about the IP address lists, contact your account manager or open a case at AWS Support Center
Rule group and rules | Description | Date |
---|---|---|
AWS WAF Bot Control rule group
New rules:
Deleted rules:
New labels:
Additional labeling in existing rules. |
Released static versions 2.0 and 3.0 of this rule group. Version 2.0 is the same as version 3.0, but with rule actions for all new rules set to Count. This guide documents the latest version of each rule group. Added the listed new rules. Updated labeling so that all rules apply a label with the pattern
Added cloud service provider labels to the Bot Control signal labels. Added new bot name labels that are inspected for by bot category rules. |
2024-09-13 |
AWS WAF Fraud Control account takeover prevention (ATP) rule group
All rules |
Released static version 1.1 of this rule group. Updated labeling so that all rules apply a label with the pattern
|
2024-09-13 |
AWS WAF Fraud Control account creation fraud prevention (ACFP) rule group
All rules |
Released static version 1.1 of this rule group. Updated labeling so that all rules apply a label with the pattern
|
2024-09-13 |
Linux operating system managed rule group
All rules |
Released static version 2.5 of this rule group. Added signatures to improve detection. |
2024-09-02 |
Core rule set (CRS) managed rule group
|
Released static version 1.15 of this rule group. Improved detection signatures for the generic LFI rules. |
2024-08-30 |
Windows operating system managed rule group
|
Released static version 2.3 of this rule group. Adjusted detection signatures in the listed rules to reduce false positives. |
2024-08-28 |
WordPress application managed rule group
|
Released static version 1.3 of this rule group. Added the JS_DECODE text transformation to the listed rule. |
2024-07-15 |
Linux operating system managed rule group
|
Released static version 2.4 of this rule group. Added the JS_DECODE text transformation to the listed rule. |
2024-07-12 |
Core rule set (CRS) managed rule group
|
Released static version 1.14 of this rule group. Added the JS_DECODE text transformation to the listed rules. |
2024-07-09 |
PHP application managed rule group
|
Released static version 2.1 of this rule group. Added the JS_DECODE text transformation to the listed rules. |
2024-07-03 |
Windows operating system managed rule group
|
Released static version 2.2 of this rule group. Added the JS_DECODE text transformation to the listed rules. |
2024-07-03 |
Linux operating system managed rule group
All rules |
Released static version 2.3 of this rule group. Added signatures to improve detection. |
2024-06-06 |
AWS WAF Bot Control rule group AWS WAF Fraud Control account takeover prevention (ATP) rule group AWS WAF Fraud Control account creation fraud prevention (ACFP) rule group |
The bot and fraud rule groups are now versioned. If you're using any of these rule groups, this update doesn't change how they handle your web traffic. This update sets the current rule group version to static version 1.0 and sets the default version to point to it. For more information about versioned managed rules, see the following: |
2024-05-29 |
POSIX operating system managed rule group
|
Released static version 3.0 of this rule group. Removed Added the rule Updated all the rules in the managed rule group with improved detection logic. Corrected the documented capitalization of the label for |
2024-05-28 |
Core rule set (CRS) managed rule group
|
Released static version 1.12 of this rule group. Added signatures to all of the cross site scripting rules to improve detection and reduce false positives. |
2024-05-21 |
SQL database managed rule group
|
Released static version 1.2 of this rule group. Added the |
2024-05-14 |
Known bad inputs managed rule group
|
Released static version 1.22 of this rule group. Added the |
2024-05-08 |
POSIX operating system managed rule group | Released static version 2.2 of this rule group. Added the |
2024-05-08 |
Windows operating system managed rule group
|
Released static version 2.1 of this rule group. Added signatures to |
2024-05-03 |
Amazon IP reputation list managed rule group
|
Updated the sources of the IP reputation list, to improve identification of addresses that are actively engaging in malicious activities and to reduce false positives. This update doesn't involve a new version because this rule group isn't versioned. |
2024-03-13 |
Known bad inputs managed rule group | Released static version 1.21 of this rule group. Added signatures to improve detection and reduce false positives. |
2023-12-16 |
Known bad inputs managed rule group
|
Released static version 1.20 of this rule group. Updated the |
2023-12-14 |
Core rule set (CRS) managed rule group
|
Released static version 1.11 of this rule group. Added signatures to all of the cross site scripting rules to improve detection and reduce false positives. |
2023-12-06 |
AWS WAF Bot Control rule group
|
Added the coordinated activity low label to the rule group's targeted protection level labels. This label isn't associated with any rule. This labeling is in addition to the medium and high level rules and labels. |
2023-12-05 |
Bot Control labels
|
Added a signal label to the rule group that indicates the detection of a browser extension that assists in automation. This label isn't specific to an individual rule. |
2023-11-14 |
Core rule set (CRS) managed rule group
|
Released static version 1.10 of this rule group. Updated one rule to improve detection and reduce false positives. |
2023-11-02 |
Core rule set (CRS) managed rule group
|
Released static version 1.9 of this rule group. Updated rules to improve detection and reduce false positives. |
2023-10-30 |
POSIX operating system managed rule group
|
Released static version 2.1 of this rule group. Updated the query arguments rule to improve detection. |
2023-10-12 |
Core rule set (CRS) managed rule group
|
Released static version 1.8 of this rule group. Updated rules to improve detection. |
2023-10-11 |
Known bad inputs managed rule group
|
Exception deployment: released static version 1.19 of this rule group. Updated the default version to use version 1.19. Updated the For information about this deployment type, see Exception deployments for AWS Managed Rules. |
2023-10-04 |
Known bad inputs managed rule group
|
Exception deployment: released static version 1.18 of this rule group. This is a quick rollout of this static version to accommodate the creation and rollout of version 1.19. Updated the For information about this deployment type, see Exception deployments for AWS Managed Rules. |
2023-10-04 |
AWS WAF Bot Control rule group
|
Added rules to the rule group with Count action. The token reuse IP rule detects and counts token sharing across IP addresses. The coordinated activity rules use automated, machine-learning (ML) analysis of website traffic to detect bot-related activity. In your rule group configuration, you can opt out of the use of ML. With this release, customers who are currently using the targeted protection level are opted in to the use of ML. Opting out disables the coordinated activity rules. |
2023-09-06 |
AWS WAF Bot Control rule group
|
Added the rule |
2023-08-30 |
Core rule set (CRS) managed rule group
|
Released static version 1.7 of this rule group. Updated restricted extensions and EC2 metadata SSRF rules to improve detection and reduce false positives. |
2023-07-26 |
AWS WAF Fraud Control account creation fraud prevention (ACFP) rule group
All rules in new rule group |
Added the rule group AWSManagedRulesACFPRuleSet . |
2023-06-13 |
Linux operating system managed rule group
|
Released static version 2.2 of this rule group. Added signatures to improve detection. |
2023-05-22 |
Core rule set (CRS) managed rule group
|
Released static version 1.6 of this rule group. Updated cross-site scripting (XSS) and restricted extension rules to improve detection and reduce false positives. |
2023-04-28 |
PHP application managed rule group
|
Released static version 2.0 of this rule group. Added signatures to improve detection in all rules. Replaced the rule Added the rule Updated the following labels to align with standard AWS Managed Rules labeling:
|
2023-02-27 |
AWS WAF Fraud Control account takeover prevention (ATP) rule group
|
Added login response inspection rules for use with protected Amazon CloudFront distributions. These rules can block new login attempts from IP addresses and client sessions that have recently been the source of too many failed login attempts. |
2023-02-15 |
Core rule set (CRS) managed rule group
|
Released static version 1.5 of this rule group. Updated Cross Site Scripting (XSS) filters to improve detection. |
2023-01-25 |
Linux operating system managed rule group
|
Released static version 2.1 of this rule group. Removed the rule Added text transformations and signatures to all rules to improve detection. |
2022-12-15 |
Core rule set (CRS) managed rule group
|
Released static version 1.4 of this rule group. Added a text transformation to |
2022-12-05 |
Known bad inputs managed rule group
|
Released static version 1.17 of this rule group. Updated the Java deserialization rules to add detection for requests matching Apache CVE-2022-42889,
a remote code execution (RCE) vulnerability in Apache Commons Text versions prior to 1.10.0.
For more information, see NIST: National Vulnerability Database: CVE-2022-42889 Detail Improved detection in |
2022-10-20 |
Known bad inputs managed rule group
|
Released static version 1.16 of this rule group. Removed false positives that AWS identified in version 1.15. |
2022-10-05 |
POSIX operating system managed rule group |
Corrected the documented label names. |
2022-09-19 |
IP reputation rule
groups
|
This change doesn't alter how the rule group handles web traffic. Added a new rule with Count action to inspect for IP addresses that are actively engaging in DDoS activities, according to Amazon threat intelligence. |
2022-08-30 |
Known bad inputs managed rule group
|
Released static version 1.15 of this rule group. Removed Added signatures for improved detection and blocking to Updated labels to correct capitalization in Corrected the description of |
2022-08-22 |
AWS WAF Fraud Control account takeover prevention (ATP) rule group
|
Added a rule to prevent the use of the account takeover prevention managed rule group for Amazon Cognito user pool web traffic. |
2022-08-11 |
Core rule set (CRS) managed rule group | AWS has scheduled expiration for versions |
2022-06-09 |
Core rule set (CRS) managed rule group
|
Released version 1.3 of this rule group. This release updates the match signatures in the rules |
2022-05-24 |
AWS WAF Bot Control rule group
|
Added the rule |
2022-04-06 |
Known bad inputs managed rule group
|
Released version 1.14 of this rule group. The four |
2022-03-31 |
Known bad inputs managed rule group
|
Released version 1.13 of this rule group. Updated the text transformation for Spring Core and Cloud Function RCE vulnerabilities. These rules are in count mode to gather metrics and evaluate matched patterns. The label can be used to block requests in a custom rule. A subsequent version will be deployed with these rules in block mode. |
2022-03-31 |
Known bad inputs managed rule group
|
Released version 1.12 of this rule group. Added signatures for Spring Core and Cloud Function RCE vulnerabilities. These rules are in count mode to gather metrics and evaluate matched patterns. The label can be used to block requests in a custom rule. A subsequent version will be deployed with these rules in block mode. Removed the rules |
2022-03-30 |
IP reputation rule
groups
|
Updated the AWSManagedReconnaissanceList rule to change the action from count to block. |
2022-02-15 |
AWS WAF Fraud Control account takeover prevention (ATP) rule group
All rules in new rule group |
Added the rule group AWSManagedRulesATPRuleSet . |
2022-02-11 |
Known bad inputs managed rule group
|
Released version 1.9 of this rule group. Removed the rule |
2022-01-28 |
Core rule set (CRS)
|
Released version 2.0 of this rule group. For these rules,
tuned detection signatures to reduce false positives.
Replaced the |
2022-01-10 |
Core rule set (CRS)
|
As part of the release of version 2.0 of this rule group,
added the |
2022-01-10 |
SQL database
|
Released version 2.0 of this rule group.
Replaced the Added more detection signatures to
Added JSON inspection to Added the rule
Removed the rule |
2022-01-10 |
Known bad inputs
|
Released version 1.8 of the rule |
2021-12-17 |
Known bad inputs
|
Released version 1.4 of the rule |
2021-12-11 |
Known bad inputs
|
Added the rule Removed the rule |
2021-12-10 |
The following table lists changes prior to December, 2021.
Rule group and rules | Description | Date | |
---|---|---|---|
Amazon IP reputation list |
|
Added the AWSManagedReconnaissanceList rule in
monitoring/count mode. This rule contains IP addresses that are
performing reconnaissance against AWS resources. |
2021-11-23 |
Windows operating system |
|
Added three new rules for WindowsShell commands: Added a new PowerShell rule: Restructured the Added more comprehensive detection signatures to Added |
2021-11-23 |
Linux operating system |
|
Replaced double Added Replaced the Added more comprehensive detection signatures for all |
2021-11-23 |
Core rule set (CRS) |
|
Reduced the size limit to block web requests with body payloads larger than 8 KB. Previously, the limit was 10 KB. | 2021-10-27 |
Core rule set (CRS) |
|
Added more detection signatures. Added double unicode URL decode to improve blocking. | 2021-10-27 |
Core rule set (CRS) |
|
Added double unicode URL decode to improve blocking. | 2021-10-27 |
Core rule set (CRS) |
|
Updated the rule signatures to reduce false positives, based on customer feedback. Added double unicode URL decode to improve blocking. | 2021-10-27 |
All | All rules |
Added support for AWS WAF labels to all rules that didn't already support labeling. | 2021-10-25 |
Amazon IP reputation list |
|
Restructured the IP reputation list, removed suffixes from rule name, and added support for AWS WAF labels. | 2021-05-04 |
Anonymous IP list |
|
Added support for AWS WAF labels. | 2021-05-04 |
Bot Control | All | Added the Bot Control rule set. | 2021-04-01 |
Core rule set (CRS) |
|
Added double URL decode. | 2021-03-03 |
Core rule set (CRS) |
|
Improved the configuration of the rules and added an extra URL decode. | 2021-03-03 |
Admin protection |
|
Added double URL decode. | 2021-03-03 |
Known bad inputs |
|
Improved the configuration of the rules and added an extra URL decode. | 2021-03-03 |
Linux operating system |
|
Improved the configuration of the rules and added an extra URL decode. | 2021-03-03 |
Windows operating system | All | Improved the configuration of the rules. | 2020-09-23 |
PHP application |
|
Changed the text transformation from HTML decode to URL decode, to improve blocking. | 2020-09-16 |
POSIX operating system |
|
Changed the text transformation from HTML decode to URL decode, to improve blocking. | 2020-09-16 |
Core rule set |
GenericLFI_BODY |
Changed the text transformation from HTML decode to URL decode, to improve blocking. | 2020-08-07 |
Linux operating system |
|
Changed the text transformation from HTML entity decode to URL decode, to improve detection and blocking. | 2020-05-19 |
Anonymous IP List | All | New rule group in IP reputation rule groups to block requests from services that permit the obfuscation of viewer identity, to help mitigate bots and evasion of geographic restrictions. | 2020-03-06 |
WordPress application |
|
New rule that checks for exploitable commands in the query string. | 2020-03-03 |
Core rule set (CRS) |
|
Adjusted the size value constraints for improved accuracy. | 2020-03-03 |
SQL database |
|
The rules now check the message URI. | 2020-01-23 |
SQL database |
|
Updated text transformations. | 2019-12-20 |
Core rule set (CRS) |
|
Updated text transformations. | 2019-12-20 |