Use when securing API Gateway endpoints with AWS WAF by configuring managed
Scanned 9/8/2026
Install to Claude Code
npx -y skills add oyi77/1ai-skills --skill securing-api-gateway-with-aws-waf --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Securing Api Gateway With Aws Waf?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/oyi77-securing-api-gateway-with-aws-waf)More formats (shields.io, HTML) on the badges page.
---
name: securing-api-gateway-with-aws-waf
description: Use when securing API Gateway endpoints with AWS WAF by configuring managed
rule groups for OWASP Top 10 protection, creating custom rate limiting rules, implementing
bot control, setting up IP reputation filtering, and monitoring WAF metrics for
security effectiveness. . Use when working with securing api gateway with aws waf.
domain: cybersecurity
tags:
- cloud-security
- aws
- waf
- api-gateway
- rate-limiting
- bot-protection
- owasp
subdomain: cloud-security
version: '1.0'
author: oyi77
license: Apache-2.0
nist_csf:
- PR.IR-01
- ID.AM-08
- GV.SC-06
- DE.CM-01
category: cybersecurity
---
# Securing Api Gateway With Aws Waf
## Overview
Cybersecurity skill for securing api gateway with aws waf. Follows industry best practices and security standards.
## When to Use
**Trigger phrases:**
- "securing api gateway with aws waf"
- "Securing API Gateway endpoints with AWS WAF by configuring managed rule groups f"
- When deploying API Gateway endpoints that require protection against common web attacks
- When implementing rate limiting and throttling to prevent API abuse and DDoS attacks
- When building bot detection and mitigation for API endpoints exposed to the internet
- When compliance requires WAF protection for all public-facing API endpoints
- When customizing access controls based on IP reputation, geolocation, or request patterns
**Do not use** for network-level DDoS protection (use AWS Shield), for application logic vulnerabilities (use SAST/DAST tools), or for internal API security between microservices (use service mesh authentication and authorization).
## When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
## Prerequisites
- AWS API Gateway (REST or HTTP API) deployed with public endpoints
- IAM permissions for `wafv2:*` and `apigateway:*` operations
- CloudWatch and S3 or Kinesis Firehose configured for WAF logging
- Understanding of the API's expected traffic patterns for rate limiting configuration
- IP reputation lists or threat intelligence feeds for custom IP blocking
## Workflow
```python
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
```
1. **Define Objectives** — Clarify the goals and scope for api gateway.
2. **Gather Resources** — Collect tools, data, and access needed for api gateway.
3. **Execute Process** — Carry out api gateway operations methodically.
4. **Verify Quality** — Check results against acceptance criteria.
5. **Document Outcomes** — Record findings, decisions, and next steps.
## Tools
- **aws waf** — Primary tool for this skill
- **Analysis Platform** — Data processing and visualization
- **Collaboration Tools** — Team coordination and knowledge sharing
## Process
1. **Design** — Define interface, identify patterns, plan implementation
1. **Implement** — Write code following existing conventions, add tests
1. **Verify** — Run tests, check integration, validate behavior
## Verification
- [ ] All api gateway procedures executed completely and documented
- [ ] Findings validated against multiple data sources
- [ ] False positives identified and filtered
- [ ] Results documented with evidence and timestamps
- [ ] Recommendations provided with risk-based prioritization
## Anti-Rationalization Table
| Rationalization | Reality |
|---|---|
| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |
| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!