Virtual Patching

Virtual patches that evolve with attackers

Previdian creates temporary WAF rules automatically from live honeypot observations, then updates them as new payloads appear. Deploy them for ModSecurity, Cloudflare, and AWS WAF while the vendor fix is tested.

WAF Platforms Supported
3
ModSecurity, Cloudflare, and AWS WAF deployable rules
Active Virtual Patches
141
Created from live honeypot observations
Automation-Ready Delivery
API
Enterprise pull via API for CI/CD and SOAR

Definition

What Is a Virtual Patch?

A virtual patch is a compensating control — usually a WAF rule — that helps reduce exposure to a known vulnerability before you can apply the vendor's official fix.

When a CVE is being exploited in the wild, patching windows, change freezes, and regression testing all take time. A virtual patch helps reduce exposure during the patch window.

Previdian delivers virtual patches as deployable rules for the WAFs your team already runs. The result is a fast, reversible compensating control you can ship while the permanent patch goes through its normal lifecycle.

Virtual Patches Help You:

  • Reduce exposure while remediation is underway.
  • Bridge the gap until vendor patches are tested and deployed.
  • Protect legacy or unpatchable systems that can't take the fix.
  • Deploy reversible WAF controls without code changes.
  • Standardize rules across ModSecurity, Cloudflare, and AWS WAF.

Pipeline

How Previdian Virtual Patches Work

From exploited CVE to a deployable WAF rule, on a repeatable pipeline.

Step 1

Observe

Read live exploitation attempts from Previdian honeypots.

Step 2

Generate

Create a WAF rule from those payloads, then update the rule when new payloads appear.

Step 3

Test

Validate the rule against must-block and must-allow cases for ModSecurity, Cloudflare, and AWS WAF.

Step 4

Deliver

Enterprise users pull deployable WAF rules via the Enterprise API and deploy into their existing WAF.

Platforms

Supported WAF Platforms

Deployable rules for the WAFs your team already operates.

ModSecurity

SecRule-format rules for the widely deployed open-source WAF engine and its CRS-based stacks.

Cloudflare

Cloudflare WAF custom rule expressions with a recommended action for edge deployment.

AWS WAF

AWS WAF rule JSON plus Terraform HCL so you can manage virtual patches as code.

Teams

Built for Operational Teams

Virtual patches plug into the workflows that already own exposure reduction.

Vulnerability Management

Reduce exposure on exploited vulnerabilities while remediation is underway and SLAs are at risk.

SOC & Detection

Turn exploitation intelligence into enforceable WAF controls and detection signals.

MSSPs

Roll out consistent, evidence-backed virtual patches across many client WAF estates.

Access

Free, Pro, and Enterprise Access

Availability indicators are public; deployable rule content is Enterprise-only.

Free

Free Previdian channels signal whether a virtual patch is available for a CVE and which WAF platforms are supported.

  • Per-CVE virtual patch availability indicator
  • Supported platform names on the CVE Virtual Patch section
  • Availability surfaced in the Free KEV RSS Feed and Free KEV JSON Feed

Pro

Pro accounts see the same virtual patch availability indicators as Free — not deployable rule content.

  • Per-CVE availability indicator on the CVE Virtual Patch section
  • Supported platform names (ModSecurity, Cloudflare, AWS WAF)
  • Full Pro API enrichment and limited sensor telemetry

Enterprise

Enterprise

Get the full deployable WAF rules from GET /api/v2/enterprise/virtual_patches.

  • Deployable ModSecurity, Cloudflare, and AWS WAF rules
  • Severity, confidence, and false-positive risk context
  • Embedded in Pro KEV show records for Enterprise accounts

FAQ

Frequently Asked Questions

What is a virtual patch?
A virtual patch is a compensating control — typically a WAF rule — that helps reduce exposure to a known vulnerability while the official vendor patch is tested and deployed. It buys security teams time to test and roll out permanent fixes during the patch window.
Which WAF platforms does Previdian support?
Previdian virtual patches ship as pre-generated, deployable WAF rules for ModSecurity, Cloudflare, and AWS WAF.
Which vulnerabilities get a virtual patch?
Previdian creates virtual patches automatically from live honeypot observations of actively exploited vulnerabilities, where a WAF rule can match the payloads. Not every exploited vulnerability has a rule.
Do the rules stay current?
Yes. Rules are created from live honeypot observations and updated as new payloads appear. Review and redeploy when a rule changes. They remain temporary controls until the vendor patch is applied.
Is virtual patch rule content free?
Free Previdian channels signal whether a virtual patch is available for a CVE (an availability indicator only). The full rule content and deployable ModSecurity, Cloudflare, and AWS WAF exports are available to Previdian Enterprise users via the Enterprise API.
How do I deploy a Previdian virtual patch?
Enterprise users fetch the deployable rules from GET /api/v2/enterprise/virtual_patches, then deploy the matching ModSecurity, Cloudflare, or AWS WAF rule into their existing WAF.

Reduce exposure

Patch the Vulnerabilities Attackers Are Exploiting

Previdian creates these rules from live honeypot observations and updates them as payloads change. Deploy them on ModSecurity, Cloudflare, and AWS WAF while the vendor fix is tested.