Enforce Before the Alert: VisionHeight Managed Rules for AWS Network Firewall

VisionHeight Managed Rules bring proactive threat intelligence to AWS Network Firewall, blocking malicious infrastructure early and reducing mass-scanning and Tor noise.

Author:
Nitsan Daniel
04 min
June 29, 2026

There is a lag built into most threat intelligence. An address has to be caught, reported, and published before it reaches a public blocklist, and by then the operators using it have often rotated to new hosts that no list has flagged. Teams end up defending against where attackers were, not where they are. And the signals that matter are buried under a constant flood of mass scanning and probing, which makes telling a real threat apart from background noise that much harder.

VisionHeight was built to close that lag. Starting today, our intelligence is available as Partner Managed Rules inside AWS Network Firewall through AWS Marketplace.

Adding protection without adding overhead

AWS Network Firewall already gives teams managed traffic inspection that scales with their environment. What it cannot do on its own is know which hosts on the internet are dangerous at any given moment. That judgment comes from whoever writes the rules, and keeping rules abreast of infrastructure that turns over daily is work that never quite ends.

That is the gap managed rules from AWS Marketplace are meant to fill. A customer can turn on a partner's rule group from inside the AWS Network Firewall console, next to the AWS-authored rules and in-house policies already in place, and skip the overhead of standing up new infrastructure or another tool to manage. VisionHeight Managed Rules are now in that catalog, including Zero-Day Threat Protection and Noisy Scanners and Tor Protection.

Built on Pulse

Every VisionHeight rule group draws on Pulse, the telemetry we operate. Pulse gives us a read on the infrastructure adversaries run on (the data centers, hosting providers, and proxy networks behind the global attack surface) and on how those operators behave. When an actor we already track shifts to a new host, we see the move and can flag the new infrastructure as it comes online.

That signal is our own. It is not stitched together from public feeds, which is why our picture of attacker infrastructure runs proactive rather than reactive: customers can act on a threat while it is still taking shape.

Zero-Day Threat Protection

Zero-Day Threat Protection blocks traffic to and from the infrastructure that verified malicious actors are using, frequently before that infrastructure shows up in public threat intelligence. As operators leave behind the hosts already known to blocklists and stand up new ones, Pulse tracks the shift and surfaces what they move to. The feed updates every day, and the infrastructure it flags often appears on public blocklists only days or weeks later.

For an AWS Network Firewall customer, that means shutting the door on a host while the campaign behind it is still being built, rather than waiting for the activity to surface and work its way onto a list weeks later.

Noisy Scanners and Tor Protection

Noisy Scanners and Tor Protection clears out the largest single source of noise in your firewall logs. Mass scanning and probing pour into perimeter logs all day, drowning the events that matter and eating analyst time. This rule group filters that traffic out at the firewall, removing tens of millions of mass scanning and probing connections so your team reads from cleaner logs.

It also takes Tor off the table as a path into or out of your environment, blocking communication with active Tor exit nodes. For teams with no reason to allow Tor anywhere near their AWS workloads, that shuts a well-worn route for both inbound probing and outbound activity.

Why teams turn it on

Act before the public catches up. Your firewall starts blocking attacker infrastructure as soon as VisionHeight identifies it, rather than waiting for a public blocklist, which typically flags that infrastructure only after it has already been used in attacks.

Quieter logs. Mass scanning and Tor traffic are dropped at the firewall, freeing analysts to spend their time on the events worth chasing.

No project to launch. Enabling a rule group is a Marketplace subscription and a policy reference, not a deployment, and there is no software of ours to run.

Fits your policy model. Both strict order and action order rule groups are available, so they drop into existing AWS Network Firewall policies without changing how those policies evaluate traffic.

Coverage that follows you. New regions, accounts, and traffic pick up the same protection on their own, and the underlying lists refresh every day without your involvement.

Pay for what flows. Billing is per gigabyte of inspected traffic, handled through AWS Marketplace.

Bringing it into your firewall

Adoption is light. You subscribe to the VisionHeight products in AWS Marketplace, choose the rule groups, and reference them from the firewall policies that already guard your traffic. From there, AWS Network Firewall logging shows what the rules are matching, and you can feed those events into whatever monitoring or response pipeline your team already uses.

VisionHeight maintains the feeds and the rule content. Deploying and running the rules inside the firewall stays with AWS Network Firewall, the same way it works for any managed rule group.

Where it helps

• Cut off connections to infrastructure that VisionHeight has tied to active malicious operators, often before it is publicly known.

• Keep mass scanning and probing from filling your perimeter logs.

• Remove Tor as a route in or out, by blocking communication with active Tor exit nodes.

Try it

The simplest way in is to find the VisionHeight listings in AWS Marketplace, check the regions and pricing, and subscribe. A low-risk first move is to attach a rule group to a test policy in alert mode, confirm it behaves the way you expect against your own traffic, then switch it to blocking and extend it across the rest of your environment when you are ready.

Marketplace listings: Zero-Day Threat Protection and Noisy Scanners and Tor Protection. Each listing shows current per-region pricing.

Attackers keep getting quicker, and intelligence that only confirms what is already public cannot match that pace. VisionHeight Managed Rules give AWS Network Firewall a proactive edge: you block the infrastructure behind tomorrow's activity today, and keep your perimeter clean while you do it.

Stop reacting.
Start preventing.

Predict malicious infrastructure
Explain decisions with full lineage
Enforce across your stack autonomously
SEE IT IN ACTION