AWS WAF looks simple until it becomes important.
At first it is a few managed rule groups, an IP allowlist, maybe a rate limit on /login. Then a real application grows around it. You add exceptions. You tune false positives. You need different behavior for APIs, static assets, GraphQL, login pages, admin paths, mobile clients, partners, scanners,...
🛡️ VERIFIED CYBER INTELLIGENCE ID: #3646213