AWS Shield Advanced Is Embracing the AWS WAF Anti-DDoS Managed Rule Group: What Changes and How to Prepare
AWS, Monday, July 27th, 2026
AWS explains how Shield Advanced customers should migrate to the WAF Anti-DDoS managed rule group.
Application-layer DDoS attacks are difficult to detect because they closely resemble legitimate traffic, and HTTP request floods using valid-looking requests are now among the most common vectors against web applications.
AWS is consolidating its application-layer defenses around the AWS WAF Anti-DDoS managed rule group, and Shield Advanced is adopting it. The post explains what changes for existing Shield Advanced customers, what protections carry over, and how the AWS Firewall Manager migration path works.
It includes preparation steps to take before the transition. AWS updated the guidance on July 29 to clarify the Firewall Manager path.