March 21st, 2026

New

Integration

AWS WAF Integration

Connect your AWS account to the Praetorian Guard platform for automated WAF resource discovery, scanner bypass configuration, and continuous security auditing across both Regional and CloudFront WAFv2 deployments.

Highlights

  • Scanner IP Whitelisting β€” Automatically creates a chariot-scanner-bypass IP set and wires bypass rules into every WebACL so Guard scanners are not blocked by AWS WAF

  • Full Resource Discovery β€” Enumerates Web ACLs, IP Sets, Rule Groups, and Regex Pattern Sets across both REGIONAL and CLOUDFRONT scopes, with optional Firewall Manager policy discovery

  • 5-Point Security Audit β€” Flags missing WebACLs, default-allow actions, empty rule sets, absent rate limiting, and overly permissive COUNT-only configurations

  • Cross-Account Role Support β€” Connects via IAM role assumption with External ID for secure, confused-deputy-protected access

Get Started

Documentation can be found at

https://docs.praetorian.com/en/articles/4068564-aws-waf

To integrate go to Integrations > Firewall > AWS WAF, then connect with your IAM Role ARN and External ID.