Virtual Patching
Virtual patches that evolve with attackers
Previdian creates temporary WAF rules automatically from live honeypot observations, then updates them as new payloads appear. Deploy them for ModSecurity, Cloudflare, and AWS WAF while the vendor fix is tested.
- WAF Platforms Supported
- 3
- ModSecurity, Cloudflare, and AWS WAF deployable rules
- Active Virtual Patches
- 141
- Created from live honeypot observations
- Automation-Ready Delivery
- API
- Enterprise pull via API for CI/CD and SOAR
Definition
What Is a Virtual Patch?
A virtual patch is a compensating control — usually a WAF rule — that helps reduce exposure to a known vulnerability before you can apply the vendor's official fix.
When a CVE is being exploited in the wild, patching windows, change freezes, and regression testing all take time. A virtual patch helps reduce exposure during the patch window.
Previdian delivers virtual patches as deployable rules for the WAFs your team already runs. The result is a fast, reversible compensating control you can ship while the permanent patch goes through its normal lifecycle.
Virtual Patches Help You:
- Reduce exposure while remediation is underway.
- Bridge the gap until vendor patches are tested and deployed.
- Protect legacy or unpatchable systems that can't take the fix.
- Deploy reversible WAF controls without code changes.
- Standardize rules across ModSecurity, Cloudflare, and AWS WAF.
Pipeline
How Previdian Virtual Patches Work
From exploited CVE to a deployable WAF rule, on a repeatable pipeline.
Step 1
Observe
Read live exploitation attempts from Previdian honeypots.
Step 2
Generate
Create a WAF rule from those payloads, then update the rule when new payloads appear.
Step 3
Test
Validate the rule against must-block and must-allow cases for ModSecurity, Cloudflare, and AWS WAF.
Step 4
Deliver
Enterprise users pull deployable WAF rules via the Enterprise API and deploy into their existing WAF.
Platforms
Supported WAF Platforms
Deployable rules for the WAFs your team already operates.
ModSecurity
SecRule-format rules for the widely deployed open-source WAF engine and its CRS-based stacks.
Cloudflare
Cloudflare WAF custom rule expressions with a recommended action for edge deployment.
AWS WAF
AWS WAF rule JSON plus Terraform HCL so you can manage virtual patches as code.
Teams
Built for Operational Teams
Virtual patches plug into the workflows that already own exposure reduction.
Vulnerability Management
Reduce exposure on exploited vulnerabilities while remediation is underway and SLAs are at risk.
SOC & Detection
Turn exploitation intelligence into enforceable WAF controls and detection signals.
MSSPs
Roll out consistent, evidence-backed virtual patches across many client WAF estates.
Access
Free, Pro, and Enterprise Access
Availability indicators are public; deployable rule content is Enterprise-only.
Free
Free Previdian channels signal whether a virtual patch is available for a CVE and which WAF platforms are supported.
- Per-CVE virtual patch availability indicator
- Supported platform names on the CVE Virtual Patch section
- Availability surfaced in the Free KEV RSS Feed and Free KEV JSON Feed
Pro
Pro accounts see the same virtual patch availability indicators as Free — not deployable rule content.
- Per-CVE availability indicator on the CVE Virtual Patch section
- Supported platform names (ModSecurity, Cloudflare, AWS WAF)
- Full Pro API enrichment and limited sensor telemetry
Enterprise
EnterpriseGet the full deployable WAF rules from GET /api/v2/enterprise/virtual_patches.
- Deployable ModSecurity, Cloudflare, and AWS WAF rules
- Severity, confidence, and false-positive risk context
- Embedded in Pro KEV show records for Enterprise accounts
FAQ
Frequently Asked Questions
- What is a virtual patch?
- A virtual patch is a compensating control — typically a WAF rule — that helps reduce exposure to a known vulnerability while the official vendor patch is tested and deployed. It buys security teams time to test and roll out permanent fixes during the patch window.
- Which WAF platforms does Previdian support?
- Previdian virtual patches ship as pre-generated, deployable WAF rules for ModSecurity, Cloudflare, and AWS WAF.
- Which vulnerabilities get a virtual patch?
- Previdian creates virtual patches automatically from live honeypot observations of actively exploited vulnerabilities, where a WAF rule can match the payloads. Not every exploited vulnerability has a rule.
- Do the rules stay current?
- Yes. Rules are created from live honeypot observations and updated as new payloads appear. Review and redeploy when a rule changes. They remain temporary controls until the vendor patch is applied.
- Is virtual patch rule content free?
- Free Previdian channels signal whether a virtual patch is available for a CVE (an availability indicator only). The full rule content and deployable ModSecurity, Cloudflare, and AWS WAF exports are available to Previdian Enterprise users via the Enterprise API.
- How do I deploy a Previdian virtual patch?
- Enterprise users fetch the deployable rules from GET /api/v2/enterprise/virtual_patches, then deploy the matching ModSecurity, Cloudflare, or AWS WAF rule into their existing WAF.
Reduce exposure
Patch the Vulnerabilities Attackers Are Exploiting
Previdian creates these rules from live honeypot observations and updates them as payloads change. Deploy them on ModSecurity, Cloudflare, and AWS WAF while the vendor fix is tested.