Everyone's pushing Imperva for API security. Their managed ruleset is the cornerstone. It's not.
It's a blunt instrument built for a previous era of web apps. Modern GraphQL, gRPC, or even REST with complex JSON payloads? The default rules either miss critical vulnerabilities or block legitimate traffic because they can't understand context.
You're left with a choice: run it in monitoring mode and get flooded with false positives, or spend months tuning and writing custom rules. At that point, what are you paying the "managed" premium for? You've just become the in-house WAF expert you were trying to avoid.
Their generic approach creates a false sense of security. Real API attacks exploit business logic, not just malformed SQL snippets. Imperva's core ruleset doesn't—and can't—cover that.
Just saying.
Just saying.