Once your rate-based rules are configured, you have the option of adding support from the AWS DRT. This is a specialized team at AWS who can help you to review, analyze, and monitor suspected malicious activity within your account and offer help and solutions on how to resolve a potential attack.Â
To help the DRT team with your investigations, they will need access to your AWS WAF rules web ACLs within your affected account. This obviously requires your authorization for them to access this information should you need their assistance. Should you require access to the DRT team, then you need to pre-authorize their access at this stage. If you do not want the DRT team to have access to your resources, then you must select the Do not grant the DRT access to my account option.
If access to DRT is required, it will be governed by an IAM role that will have the AWSShieldDRTAccessPolicy managed policy attached, which trusts the...