AWS Shield Anti-DDoS Managed Rule Group L7 Flood Detection

Detects high-volume activity (BLOCK or COUNT actions) from the AWS Shield Advanced managed DDoS protection rule set within a 1-minute time window. The rule alerts on potential Layer 7 DDoS attacks by monitoring for significant spikes in event volume or the number of unique source IP addresses targeting a specific AWS WAF Web ACL.