HomeIntelligenceBrief
BREACH BRIEF⚪ Informational Advisory

AWS Network Firewall Adds Rule‑Hit‑Count to Spot Dormant Rules and Validate Controls

AWS Network Firewall now reports how often each stateful rule matches traffic, giving teams a way to identify unused rules and prove that network controls are active—key for PCI DSS, DORA, and SOC 2 audit evidence.

LiveThreat™ Intelligence · 📅 August 24, 2026· 📰 helpnetsecurity.com
Severity
Informational
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
helpnetsecurity.com

AWS Network Firewall Adds Rule‑Hit‑Count to Spot Dormant Rules and Validate Controls

What Happened — AWS Network Firewall now surfaces a rule‑hit‑count metric for every stateful rule. The count increments each time a rule generates an alert, drop, or reject log entry, letting teams see which rules are actually matching traffic and which sit idle. The feature is enabled by default at no extra firewall charge (storage and query fees still apply).

Why It Matters for Compliance & Audit Readiness

  • Unused or redundant firewall rules can constitute a control gap, violating policies that require “least‑privilege” network segmentation (e.g., PCI DSS 4.0, DORA).
  • Continuous visibility of rule activity provides auditable evidence that security controls are in effect, simplifying SOC 2 CC6 (System and Communications Protection) testing.
  • The built‑in dashboard and export to CloudWatch Logs Insights or Athena enable automated evidence collection for continuous‑compliance programs.

Who Is Affected — Cloud‑infrastructure operators, SaaS providers, and any organization that relies on AWS VPCs for network isolation (finance, healthcare, e‑commerce, etc.).

Recommended Actions

  • Map the new rule‑hit‑count metric to your SOC 2 CC6 control‑monitoring procedures.
  • Incorporate the “Top Rule Hits” view into your periodic control‑effectiveness reviews and de‑provision any rule with zero hits for a defined period.
  • Automate log export to CloudWatch or Athena and retain evidence for the audit window required by your compliance framework.

Technical Notes – The capability applies only to stateful rules (custom and managed groups); stateless rules remain unsupported. Hit counts are generated when a rule logs an alert, drop, or reject action; pass‑only rules must include the alert keyword to be counted. Data is available in all AWS regions except the Middle East (UAE, Bahrain). Source: Help Net Security

📰 Original Source
https://www.helpnetsecurity.com/2026/08/24/aws-network-firewall-rule-hit-count-capability/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →