diff --git a/README.md b/README.md
--- a/README.md
+++ b/README.md
@@ -8,7 +8,7 @@
 
 ## Version
 
-`1.4.0`
+`1.4.1`
 
 
 ## Description
diff --git a/amazonka-waf.cabal b/amazonka-waf.cabal
--- a/amazonka-waf.cabal
+++ b/amazonka-waf.cabal
@@ -1,5 +1,5 @@
 name:                  amazonka-waf
-version:               1.4.0
+version:               1.4.1
 synopsis:              Amazon WAF SDK.
 homepage:              https://github.com/brendanhay/amazonka
 bug-reports:           https://github.com/brendanhay/amazonka/issues
@@ -51,12 +51,14 @@
         , Network.AWS.WAF.CreateSizeConstraintSet
         , Network.AWS.WAF.CreateSqlInjectionMatchSet
         , Network.AWS.WAF.CreateWebACL
+        , Network.AWS.WAF.CreateXSSMatchSet
         , Network.AWS.WAF.DeleteByteMatchSet
         , Network.AWS.WAF.DeleteIPSet
         , Network.AWS.WAF.DeleteRule
         , Network.AWS.WAF.DeleteSizeConstraintSet
         , Network.AWS.WAF.DeleteSqlInjectionMatchSet
         , Network.AWS.WAF.DeleteWebACL
+        , Network.AWS.WAF.DeleteXSSMatchSet
         , Network.AWS.WAF.GetByteMatchSet
         , Network.AWS.WAF.GetChangeToken
         , Network.AWS.WAF.GetChangeTokenStatus
@@ -66,12 +68,14 @@
         , Network.AWS.WAF.GetSizeConstraintSet
         , Network.AWS.WAF.GetSqlInjectionMatchSet
         , Network.AWS.WAF.GetWebACL
+        , Network.AWS.WAF.GetXSSMatchSet
         , Network.AWS.WAF.ListByteMatchSets
         , Network.AWS.WAF.ListIPSets
         , Network.AWS.WAF.ListRules
         , Network.AWS.WAF.ListSizeConstraintSets
         , Network.AWS.WAF.ListSqlInjectionMatchSets
         , Network.AWS.WAF.ListWebACLs
+        , Network.AWS.WAF.ListXSSMatchSets
         , Network.AWS.WAF.Types
         , Network.AWS.WAF.UpdateByteMatchSet
         , Network.AWS.WAF.UpdateIPSet
@@ -79,6 +83,7 @@
         , Network.AWS.WAF.UpdateSizeConstraintSet
         , Network.AWS.WAF.UpdateSqlInjectionMatchSet
         , Network.AWS.WAF.UpdateWebACL
+        , Network.AWS.WAF.UpdateXSSMatchSet
         , Network.AWS.WAF.Waiters
 
     other-modules:
@@ -86,7 +91,7 @@
         , Network.AWS.WAF.Types.Sum
 
     build-depends:
-          amazonka-core == 1.4.0.*
+          amazonka-core == 1.4.1.*
         , base          >= 4.7     && < 5
 
 test-suite amazonka-waf-test
@@ -106,9 +111,9 @@
         , Test.AWS.WAF.Internal
 
     build-depends:
-          amazonka-core == 1.4.0.*
-        , amazonka-test == 1.4.0.*
-        , amazonka-waf == 1.4.0.*
+          amazonka-core == 1.4.1.*
+        , amazonka-test == 1.4.1.*
+        , amazonka-waf == 1.4.1.*
         , base
         , bytestring
         , tasty
diff --git a/fixture/CreateXSSMatchSet.yaml b/fixture/CreateXSSMatchSet.yaml
new file mode 100644
--- /dev/null
+++ b/fixture/CreateXSSMatchSet.yaml
diff --git a/fixture/CreateXSSMatchSetResponse.proto b/fixture/CreateXSSMatchSetResponse.proto
new file mode 100644
--- /dev/null
+++ b/fixture/CreateXSSMatchSetResponse.proto
diff --git a/fixture/CreateXssMatchSet.yaml b/fixture/CreateXssMatchSet.yaml
new file mode 100644
--- /dev/null
+++ b/fixture/CreateXssMatchSet.yaml
diff --git a/fixture/CreateXssMatchSetResponse.proto b/fixture/CreateXssMatchSetResponse.proto
new file mode 100644
--- /dev/null
+++ b/fixture/CreateXssMatchSetResponse.proto
diff --git a/fixture/DeleteXSSMatchSet.yaml b/fixture/DeleteXSSMatchSet.yaml
new file mode 100644
--- /dev/null
+++ b/fixture/DeleteXSSMatchSet.yaml
diff --git a/fixture/DeleteXSSMatchSetResponse.proto b/fixture/DeleteXSSMatchSetResponse.proto
new file mode 100644
--- /dev/null
+++ b/fixture/DeleteXSSMatchSetResponse.proto
diff --git a/fixture/DeleteXssMatchSet.yaml b/fixture/DeleteXssMatchSet.yaml
new file mode 100644
--- /dev/null
+++ b/fixture/DeleteXssMatchSet.yaml
diff --git a/fixture/DeleteXssMatchSetResponse.proto b/fixture/DeleteXssMatchSetResponse.proto
new file mode 100644
--- /dev/null
+++ b/fixture/DeleteXssMatchSetResponse.proto
diff --git a/fixture/GetXSSMatchSet.yaml b/fixture/GetXSSMatchSet.yaml
new file mode 100644
--- /dev/null
+++ b/fixture/GetXSSMatchSet.yaml
diff --git a/fixture/GetXSSMatchSetResponse.proto b/fixture/GetXSSMatchSetResponse.proto
new file mode 100644
--- /dev/null
+++ b/fixture/GetXSSMatchSetResponse.proto
diff --git a/fixture/GetXssMatchSet.yaml b/fixture/GetXssMatchSet.yaml
new file mode 100644
--- /dev/null
+++ b/fixture/GetXssMatchSet.yaml
diff --git a/fixture/GetXssMatchSetResponse.proto b/fixture/GetXssMatchSetResponse.proto
new file mode 100644
--- /dev/null
+++ b/fixture/GetXssMatchSetResponse.proto
diff --git a/fixture/ListXSSMatchSets.yaml b/fixture/ListXSSMatchSets.yaml
new file mode 100644
--- /dev/null
+++ b/fixture/ListXSSMatchSets.yaml
diff --git a/fixture/ListXSSMatchSetsResponse.proto b/fixture/ListXSSMatchSetsResponse.proto
new file mode 100644
--- /dev/null
+++ b/fixture/ListXSSMatchSetsResponse.proto
diff --git a/fixture/ListXssMatchSets.yaml b/fixture/ListXssMatchSets.yaml
new file mode 100644
--- /dev/null
+++ b/fixture/ListXssMatchSets.yaml
diff --git a/fixture/ListXssMatchSetsResponse.proto b/fixture/ListXssMatchSetsResponse.proto
new file mode 100644
--- /dev/null
+++ b/fixture/ListXssMatchSetsResponse.proto
diff --git a/fixture/UpdateXSSMatchSet.yaml b/fixture/UpdateXSSMatchSet.yaml
new file mode 100644
--- /dev/null
+++ b/fixture/UpdateXSSMatchSet.yaml
diff --git a/fixture/UpdateXSSMatchSetResponse.proto b/fixture/UpdateXSSMatchSetResponse.proto
new file mode 100644
--- /dev/null
+++ b/fixture/UpdateXSSMatchSetResponse.proto
diff --git a/fixture/UpdateXssMatchSet.yaml b/fixture/UpdateXssMatchSet.yaml
new file mode 100644
--- /dev/null
+++ b/fixture/UpdateXssMatchSet.yaml
diff --git a/fixture/UpdateXssMatchSetResponse.proto b/fixture/UpdateXssMatchSetResponse.proto
new file mode 100644
--- /dev/null
+++ b/fixture/UpdateXssMatchSetResponse.proto
diff --git a/gen/Network/AWS/WAF.hs b/gen/Network/AWS/WAF.hs
--- a/gen/Network/AWS/WAF.hs
+++ b/gen/Network/AWS/WAF.hs
@@ -108,6 +108,15 @@
     -- ** GetRule
     , module Network.AWS.WAF.GetRule
 
+    -- ** DeleteXSSMatchSet
+    , module Network.AWS.WAF.DeleteXSSMatchSet
+
+    -- ** UpdateXSSMatchSet
+    , module Network.AWS.WAF.UpdateXSSMatchSet
+
+    -- ** ListXSSMatchSets
+    , module Network.AWS.WAF.ListXSSMatchSets
+
     -- ** GetChangeToken
     , module Network.AWS.WAF.GetChangeToken
 
@@ -123,6 +132,9 @@
     -- ** CreateSqlInjectionMatchSet
     , module Network.AWS.WAF.CreateSqlInjectionMatchSet
 
+    -- ** GetXSSMatchSet
+    , module Network.AWS.WAF.GetXSSMatchSet
+
     -- ** CreateByteMatchSet
     , module Network.AWS.WAF.CreateByteMatchSet
 
@@ -141,6 +153,9 @@
     -- ** ListIPSets
     , module Network.AWS.WAF.ListIPSets
 
+    -- ** CreateXSSMatchSet
+    , module Network.AWS.WAF.CreateXSSMatchSet
+
     -- ** GetByteMatchSet
     , module Network.AWS.WAF.GetByteMatchSet
 
@@ -390,6 +405,31 @@
     , webACLUpdate
     , wauAction
     , wauActivatedRule
+
+    -- ** XSSMatchSet
+    , XSSMatchSet
+    , xssMatchSet
+    , xmsName
+    , xmsXSSMatchSetId
+    , xmsXSSMatchTuples
+
+    -- ** XSSMatchSetSummary
+    , XSSMatchSetSummary
+    , xssMatchSetSummary
+    , xmssXSSMatchSetId
+    , xmssName
+
+    -- ** XSSMatchSetUpdate
+    , XSSMatchSetUpdate
+    , xssMatchSetUpdate
+    , xmsuAction
+    , xmsuXSSMatchTuple
+
+    -- ** XSSMatchTuple
+    , XSSMatchTuple
+    , xssMatchTuple
+    , xmtFieldToMatch
+    , xmtTextTransformation
     ) where
 
 import           Network.AWS.WAF.CreateByteMatchSet
@@ -398,12 +438,14 @@
 import           Network.AWS.WAF.CreateSizeConstraintSet
 import           Network.AWS.WAF.CreateSqlInjectionMatchSet
 import           Network.AWS.WAF.CreateWebACL
+import           Network.AWS.WAF.CreateXSSMatchSet
 import           Network.AWS.WAF.DeleteByteMatchSet
 import           Network.AWS.WAF.DeleteIPSet
 import           Network.AWS.WAF.DeleteRule
 import           Network.AWS.WAF.DeleteSizeConstraintSet
 import           Network.AWS.WAF.DeleteSqlInjectionMatchSet
 import           Network.AWS.WAF.DeleteWebACL
+import           Network.AWS.WAF.DeleteXSSMatchSet
 import           Network.AWS.WAF.GetByteMatchSet
 import           Network.AWS.WAF.GetChangeToken
 import           Network.AWS.WAF.GetChangeTokenStatus
@@ -413,12 +455,14 @@
 import           Network.AWS.WAF.GetSizeConstraintSet
 import           Network.AWS.WAF.GetSqlInjectionMatchSet
 import           Network.AWS.WAF.GetWebACL
+import           Network.AWS.WAF.GetXSSMatchSet
 import           Network.AWS.WAF.ListByteMatchSets
 import           Network.AWS.WAF.ListIPSets
 import           Network.AWS.WAF.ListRules
 import           Network.AWS.WAF.ListSizeConstraintSets
 import           Network.AWS.WAF.ListSqlInjectionMatchSets
 import           Network.AWS.WAF.ListWebACLs
+import           Network.AWS.WAF.ListXSSMatchSets
 import           Network.AWS.WAF.Types
 import           Network.AWS.WAF.UpdateByteMatchSet
 import           Network.AWS.WAF.UpdateIPSet
@@ -426,6 +470,7 @@
 import           Network.AWS.WAF.UpdateSizeConstraintSet
 import           Network.AWS.WAF.UpdateSqlInjectionMatchSet
 import           Network.AWS.WAF.UpdateWebACL
+import           Network.AWS.WAF.UpdateXSSMatchSet
 import           Network.AWS.WAF.Waiters
 
 {- $errors
diff --git a/gen/Network/AWS/WAF/CreateByteMatchSet.hs b/gen/Network/AWS/WAF/CreateByteMatchSet.hs
--- a/gen/Network/AWS/WAF/CreateByteMatchSet.hs
+++ b/gen/Network/AWS/WAF/CreateByteMatchSet.hs
@@ -109,6 +109,8 @@
 
 instance Hashable CreateByteMatchSet
 
+instance NFData CreateByteMatchSet
+
 instance ToHeaders CreateByteMatchSet where
         toHeaders
           = const
@@ -170,3 +172,5 @@
 -- | The response status code.
 cbmsrsResponseStatus :: Lens' CreateByteMatchSetResponse Int
 cbmsrsResponseStatus = lens _cbmsrsResponseStatus (\ s a -> s{_cbmsrsResponseStatus = a});
+
+instance NFData CreateByteMatchSetResponse
diff --git a/gen/Network/AWS/WAF/CreateIPSet.hs b/gen/Network/AWS/WAF/CreateIPSet.hs
--- a/gen/Network/AWS/WAF/CreateIPSet.hs
+++ b/gen/Network/AWS/WAF/CreateIPSet.hs
@@ -108,6 +108,8 @@
 
 instance Hashable CreateIPSet
 
+instance NFData CreateIPSet
+
 instance ToHeaders CreateIPSet where
         toHeaders
           = const
@@ -169,3 +171,5 @@
 -- | The response status code.
 cisrsResponseStatus :: Lens' CreateIPSetResponse Int
 cisrsResponseStatus = lens _cisrsResponseStatus (\ s a -> s{_cisrsResponseStatus = a});
+
+instance NFData CreateIPSetResponse
diff --git a/gen/Network/AWS/WAF/CreateRule.hs b/gen/Network/AWS/WAF/CreateRule.hs
--- a/gen/Network/AWS/WAF/CreateRule.hs
+++ b/gen/Network/AWS/WAF/CreateRule.hs
@@ -132,6 +132,8 @@
 
 instance Hashable CreateRule
 
+instance NFData CreateRule
+
 instance ToHeaders CreateRule where
         toHeaders
           = const
@@ -194,3 +196,5 @@
 -- | The response status code.
 crrsResponseStatus :: Lens' CreateRuleResponse Int
 crrsResponseStatus = lens _crrsResponseStatus (\ s a -> s{_crrsResponseStatus = a});
+
+instance NFData CreateRuleResponse
diff --git a/gen/Network/AWS/WAF/CreateSizeConstraintSet.hs b/gen/Network/AWS/WAF/CreateSizeConstraintSet.hs
--- a/gen/Network/AWS/WAF/CreateSizeConstraintSet.hs
+++ b/gen/Network/AWS/WAF/CreateSizeConstraintSet.hs
@@ -110,6 +110,8 @@
 
 instance Hashable CreateSizeConstraintSet
 
+instance NFData CreateSizeConstraintSet
+
 instance ToHeaders CreateSizeConstraintSet where
         toHeaders
           = const
@@ -172,3 +174,5 @@
 -- | The response status code.
 cscsrsResponseStatus :: Lens' CreateSizeConstraintSetResponse Int
 cscsrsResponseStatus = lens _cscsrsResponseStatus (\ s a -> s{_cscsrsResponseStatus = a});
+
+instance NFData CreateSizeConstraintSetResponse
diff --git a/gen/Network/AWS/WAF/CreateSqlInjectionMatchSet.hs b/gen/Network/AWS/WAF/CreateSqlInjectionMatchSet.hs
--- a/gen/Network/AWS/WAF/CreateSqlInjectionMatchSet.hs
+++ b/gen/Network/AWS/WAF/CreateSqlInjectionMatchSet.hs
@@ -113,6 +113,8 @@
 
 instance Hashable CreateSqlInjectionMatchSet
 
+instance NFData CreateSqlInjectionMatchSet
+
 instance ToHeaders CreateSqlInjectionMatchSet where
         toHeaders
           = const
@@ -178,3 +180,5 @@
 -- | The response status code.
 csimsrsResponseStatus :: Lens' CreateSqlInjectionMatchSetResponse Int
 csimsrsResponseStatus = lens _csimsrsResponseStatus (\ s a -> s{_csimsrsResponseStatus = a});
+
+instance NFData CreateSqlInjectionMatchSetResponse
diff --git a/gen/Network/AWS/WAF/CreateWebACL.hs b/gen/Network/AWS/WAF/CreateWebACL.hs
--- a/gen/Network/AWS/WAF/CreateWebACL.hs
+++ b/gen/Network/AWS/WAF/CreateWebACL.hs
@@ -141,6 +141,8 @@
 
 instance Hashable CreateWebACL
 
+instance NFData CreateWebACL
+
 instance ToHeaders CreateWebACL where
         toHeaders
           = const
@@ -204,3 +206,5 @@
 -- | The response status code.
 cwarsResponseStatus :: Lens' CreateWebACLResponse Int
 cwarsResponseStatus = lens _cwarsResponseStatus (\ s a -> s{_cwarsResponseStatus = a});
+
+instance NFData CreateWebACLResponse
diff --git a/gen/Network/AWS/WAF/CreateXSSMatchSet.hs b/gen/Network/AWS/WAF/CreateXSSMatchSet.hs
new file mode 100644
--- /dev/null
+++ b/gen/Network/AWS/WAF/CreateXSSMatchSet.hs
@@ -0,0 +1,177 @@
+{-# LANGUAGE DeriveDataTypeable #-}
+{-# LANGUAGE DeriveGeneric      #-}
+{-# LANGUAGE OverloadedStrings  #-}
+{-# LANGUAGE RecordWildCards    #-}
+{-# LANGUAGE TypeFamilies       #-}
+
+{-# OPTIONS_GHC -fno-warn-unused-imports #-}
+{-# OPTIONS_GHC -fno-warn-unused-binds   #-}
+{-# OPTIONS_GHC -fno-warn-unused-matches #-}
+
+-- Derived from AWS service descriptions, licensed under Apache 2.0.
+
+-- |
+-- Module      : Network.AWS.WAF.CreateXSSMatchSet
+-- Copyright   : (c) 2013-2016 Brendan Hay
+-- License     : Mozilla Public License, v. 2.0.
+-- Maintainer  : Brendan Hay <brendan.g.hay@gmail.com>
+-- Stability   : auto-generated
+-- Portability : non-portable (GHC extensions)
+--
+-- Creates an < XssMatchSet>, which you use to allow, block, or count
+-- requests that contain cross-site scripting attacks in the specified part
+-- of web requests. AWS WAF searches for character sequences that are
+-- likely to be malicious strings.
+--
+-- To create and configure an 'XssMatchSet', perform the following steps:
+--
+-- 1.  Use < GetChangeToken> to get the change token that you provide in
+--     the 'ChangeToken' parameter of a 'CreateXssMatchSet' request.
+-- 2.  Submit a 'CreateXssMatchSet' request.
+-- 3.  Use 'GetChangeToken' to get the change token that you provide in the
+--     'ChangeToken' parameter of an < UpdateXssMatchSet> request.
+-- 4.  Submit an < UpdateXssMatchSet> request to specify the parts of web
+--     requests in which you want to allow, block, or count cross-site
+--     scripting attacks.
+--
+-- For more information about how to use the AWS WAF API to allow or block
+-- HTTP requests, see the
+-- <http://docs.aws.amazon.com/waf/latest/developerguide/ AWS WAF Developer Guide>.
+module Network.AWS.WAF.CreateXSSMatchSet
+    (
+    -- * Creating a Request
+      createXSSMatchSet
+    , CreateXSSMatchSet
+    -- * Request Lenses
+    , cxmsName
+    , cxmsChangeToken
+
+    -- * Destructuring the Response
+    , createXSSMatchSetResponse
+    , CreateXSSMatchSetResponse
+    -- * Response Lenses
+    , cxmsrsXSSMatchSet
+    , cxmsrsChangeToken
+    , cxmsrsResponseStatus
+    ) where
+
+import           Network.AWS.Lens
+import           Network.AWS.Prelude
+import           Network.AWS.Request
+import           Network.AWS.Response
+import           Network.AWS.WAF.Types
+import           Network.AWS.WAF.Types.Product
+
+-- | A request to create an < XssMatchSet>.
+--
+-- /See:/ 'createXSSMatchSet' smart constructor.
+data CreateXSSMatchSet = CreateXSSMatchSet'
+    { _cxmsName        :: !Text
+    , _cxmsChangeToken :: !Text
+    } deriving (Eq,Read,Show,Data,Typeable,Generic)
+
+-- | Creates a value of 'CreateXSSMatchSet' with the minimum fields required to make a request.
+--
+-- Use one of the following lenses to modify other fields as desired:
+--
+-- * 'cxmsName'
+--
+-- * 'cxmsChangeToken'
+createXSSMatchSet
+    :: Text -- ^ 'cxmsName'
+    -> Text -- ^ 'cxmsChangeToken'
+    -> CreateXSSMatchSet
+createXSSMatchSet pName_ pChangeToken_ =
+    CreateXSSMatchSet'
+    { _cxmsName = pName_
+    , _cxmsChangeToken = pChangeToken_
+    }
+
+-- | A friendly name or description for the < XssMatchSet> that you\'re
+-- creating. You can\'t change 'Name' after you create the 'XssMatchSet'.
+cxmsName :: Lens' CreateXSSMatchSet Text
+cxmsName = lens _cxmsName (\ s a -> s{_cxmsName = a});
+
+-- | The value returned by the most recent call to < GetChangeToken>.
+cxmsChangeToken :: Lens' CreateXSSMatchSet Text
+cxmsChangeToken = lens _cxmsChangeToken (\ s a -> s{_cxmsChangeToken = a});
+
+instance AWSRequest CreateXSSMatchSet where
+        type Rs CreateXSSMatchSet = CreateXSSMatchSetResponse
+        request = postJSON waf
+        response
+          = receiveJSON
+              (\ s h x ->
+                 CreateXSSMatchSetResponse' <$>
+                   (x .?> "XssMatchSet") <*> (x .?> "ChangeToken") <*>
+                     (pure (fromEnum s)))
+
+instance Hashable CreateXSSMatchSet
+
+instance NFData CreateXSSMatchSet
+
+instance ToHeaders CreateXSSMatchSet where
+        toHeaders
+          = const
+              (mconcat
+                 ["X-Amz-Target" =#
+                    ("AWSWAF_20150824.CreateXssMatchSet" :: ByteString),
+                  "Content-Type" =#
+                    ("application/x-amz-json-1.1" :: ByteString)])
+
+instance ToJSON CreateXSSMatchSet where
+        toJSON CreateXSSMatchSet'{..}
+          = object
+              (catMaybes
+                 [Just ("Name" .= _cxmsName),
+                  Just ("ChangeToken" .= _cxmsChangeToken)])
+
+instance ToPath CreateXSSMatchSet where
+        toPath = const "/"
+
+instance ToQuery CreateXSSMatchSet where
+        toQuery = const mempty
+
+-- | The response to a 'CreateXssMatchSet' request.
+--
+-- /See:/ 'createXSSMatchSetResponse' smart constructor.
+data CreateXSSMatchSetResponse = CreateXSSMatchSetResponse'
+    { _cxmsrsXSSMatchSet    :: !(Maybe XSSMatchSet)
+    , _cxmsrsChangeToken    :: !(Maybe Text)
+    , _cxmsrsResponseStatus :: !Int
+    } deriving (Eq,Read,Show,Data,Typeable,Generic)
+
+-- | Creates a value of 'CreateXSSMatchSetResponse' with the minimum fields required to make a request.
+--
+-- Use one of the following lenses to modify other fields as desired:
+--
+-- * 'cxmsrsXSSMatchSet'
+--
+-- * 'cxmsrsChangeToken'
+--
+-- * 'cxmsrsResponseStatus'
+createXSSMatchSetResponse
+    :: Int -- ^ 'cxmsrsResponseStatus'
+    -> CreateXSSMatchSetResponse
+createXSSMatchSetResponse pResponseStatus_ =
+    CreateXSSMatchSetResponse'
+    { _cxmsrsXSSMatchSet = Nothing
+    , _cxmsrsChangeToken = Nothing
+    , _cxmsrsResponseStatus = pResponseStatus_
+    }
+
+-- | An < XssMatchSet>.
+cxmsrsXSSMatchSet :: Lens' CreateXSSMatchSetResponse (Maybe XSSMatchSet)
+cxmsrsXSSMatchSet = lens _cxmsrsXSSMatchSet (\ s a -> s{_cxmsrsXSSMatchSet = a});
+
+-- | The 'ChangeToken' that you used to submit the 'CreateXssMatchSet'
+-- request. You can also use this value to query the status of the request.
+-- For more information, see < GetChangeTokenStatus>.
+cxmsrsChangeToken :: Lens' CreateXSSMatchSetResponse (Maybe Text)
+cxmsrsChangeToken = lens _cxmsrsChangeToken (\ s a -> s{_cxmsrsChangeToken = a});
+
+-- | The response status code.
+cxmsrsResponseStatus :: Lens' CreateXSSMatchSetResponse Int
+cxmsrsResponseStatus = lens _cxmsrsResponseStatus (\ s a -> s{_cxmsrsResponseStatus = a});
+
+instance NFData CreateXSSMatchSetResponse
diff --git a/gen/Network/AWS/WAF/DeleteByteMatchSet.hs b/gen/Network/AWS/WAF/DeleteByteMatchSet.hs
--- a/gen/Network/AWS/WAF/DeleteByteMatchSet.hs
+++ b/gen/Network/AWS/WAF/DeleteByteMatchSet.hs
@@ -101,6 +101,8 @@
 
 instance Hashable DeleteByteMatchSet
 
+instance NFData DeleteByteMatchSet
+
 instance ToHeaders DeleteByteMatchSet where
         toHeaders
           = const
@@ -154,3 +156,5 @@
 -- | The response status code.
 dbmsrsResponseStatus :: Lens' DeleteByteMatchSetResponse Int
 dbmsrsResponseStatus = lens _dbmsrsResponseStatus (\ s a -> s{_dbmsrsResponseStatus = a});
+
+instance NFData DeleteByteMatchSetResponse
diff --git a/gen/Network/AWS/WAF/DeleteIPSet.hs b/gen/Network/AWS/WAF/DeleteIPSet.hs
--- a/gen/Network/AWS/WAF/DeleteIPSet.hs
+++ b/gen/Network/AWS/WAF/DeleteIPSet.hs
@@ -98,6 +98,8 @@
 
 instance Hashable DeleteIPSet
 
+instance NFData DeleteIPSet
+
 instance ToHeaders DeleteIPSet where
         toHeaders
           = const
@@ -151,3 +153,5 @@
 -- | The response status code.
 disrsResponseStatus :: Lens' DeleteIPSetResponse Int
 disrsResponseStatus = lens _disrsResponseStatus (\ s a -> s{_disrsResponseStatus = a});
+
+instance NFData DeleteIPSetResponse
diff --git a/gen/Network/AWS/WAF/DeleteRule.hs b/gen/Network/AWS/WAF/DeleteRule.hs
--- a/gen/Network/AWS/WAF/DeleteRule.hs
+++ b/gen/Network/AWS/WAF/DeleteRule.hs
@@ -100,6 +100,8 @@
 
 instance Hashable DeleteRule
 
+instance NFData DeleteRule
+
 instance ToHeaders DeleteRule where
         toHeaders
           = const
@@ -153,3 +155,5 @@
 -- | The response status code.
 drrsResponseStatus :: Lens' DeleteRuleResponse Int
 drrsResponseStatus = lens _drrsResponseStatus (\ s a -> s{_drrsResponseStatus = a});
+
+instance NFData DeleteRuleResponse
diff --git a/gen/Network/AWS/WAF/DeleteSizeConstraintSet.hs b/gen/Network/AWS/WAF/DeleteSizeConstraintSet.hs
--- a/gen/Network/AWS/WAF/DeleteSizeConstraintSet.hs
+++ b/gen/Network/AWS/WAF/DeleteSizeConstraintSet.hs
@@ -102,6 +102,8 @@
 
 instance Hashable DeleteSizeConstraintSet
 
+instance NFData DeleteSizeConstraintSet
+
 instance ToHeaders DeleteSizeConstraintSet where
         toHeaders
           = const
@@ -157,3 +159,5 @@
 -- | The response status code.
 dscsrsResponseStatus :: Lens' DeleteSizeConstraintSetResponse Int
 dscsrsResponseStatus = lens _dscsrsResponseStatus (\ s a -> s{_dscsrsResponseStatus = a});
+
+instance NFData DeleteSizeConstraintSetResponse
diff --git a/gen/Network/AWS/WAF/DeleteSqlInjectionMatchSet.hs b/gen/Network/AWS/WAF/DeleteSqlInjectionMatchSet.hs
--- a/gen/Network/AWS/WAF/DeleteSqlInjectionMatchSet.hs
+++ b/gen/Network/AWS/WAF/DeleteSqlInjectionMatchSet.hs
@@ -105,6 +105,8 @@
 
 instance Hashable DeleteSqlInjectionMatchSet
 
+instance NFData DeleteSqlInjectionMatchSet
+
 instance ToHeaders DeleteSqlInjectionMatchSet where
         toHeaders
           = const
@@ -165,3 +167,5 @@
 -- | The response status code.
 dsimsrsResponseStatus :: Lens' DeleteSqlInjectionMatchSetResponse Int
 dsimsrsResponseStatus = lens _dsimsrsResponseStatus (\ s a -> s{_dsimsrsResponseStatus = a});
+
+instance NFData DeleteSqlInjectionMatchSetResponse
diff --git a/gen/Network/AWS/WAF/DeleteWebACL.hs b/gen/Network/AWS/WAF/DeleteWebACL.hs
--- a/gen/Network/AWS/WAF/DeleteWebACL.hs
+++ b/gen/Network/AWS/WAF/DeleteWebACL.hs
@@ -95,6 +95,8 @@
 
 instance Hashable DeleteWebACL
 
+instance NFData DeleteWebACL
+
 instance ToHeaders DeleteWebACL where
         toHeaders
           = const
@@ -148,3 +150,5 @@
 -- | The response status code.
 dwarsResponseStatus :: Lens' DeleteWebACLResponse Int
 dwarsResponseStatus = lens _dwarsResponseStatus (\ s a -> s{_dwarsResponseStatus = a});
+
+instance NFData DeleteWebACLResponse
diff --git a/gen/Network/AWS/WAF/DeleteXSSMatchSet.hs b/gen/Network/AWS/WAF/DeleteXSSMatchSet.hs
new file mode 100644
--- /dev/null
+++ b/gen/Network/AWS/WAF/DeleteXSSMatchSet.hs
@@ -0,0 +1,164 @@
+{-# LANGUAGE DeriveDataTypeable #-}
+{-# LANGUAGE DeriveGeneric      #-}
+{-# LANGUAGE OverloadedStrings  #-}
+{-# LANGUAGE RecordWildCards    #-}
+{-# LANGUAGE TypeFamilies       #-}
+
+{-# OPTIONS_GHC -fno-warn-unused-imports #-}
+{-# OPTIONS_GHC -fno-warn-unused-binds   #-}
+{-# OPTIONS_GHC -fno-warn-unused-matches #-}
+
+-- Derived from AWS service descriptions, licensed under Apache 2.0.
+
+-- |
+-- Module      : Network.AWS.WAF.DeleteXSSMatchSet
+-- Copyright   : (c) 2013-2016 Brendan Hay
+-- License     : Mozilla Public License, v. 2.0.
+-- Maintainer  : Brendan Hay <brendan.g.hay@gmail.com>
+-- Stability   : auto-generated
+-- Portability : non-portable (GHC extensions)
+--
+-- Permanently deletes an < XssMatchSet>. You can\'t delete an
+-- 'XssMatchSet' if it\'s still used in any 'Rules' or if it still contains
+-- any < XssMatchTuple> objects.
+--
+-- If you just want to remove an 'XssMatchSet' from a 'Rule', use
+-- < UpdateRule>.
+--
+-- To permanently delete an 'XssMatchSet' from AWS WAF, perform the
+-- following steps:
+--
+-- 1.  Update the 'XssMatchSet' to remove filters, if any. For more
+--     information, see < UpdateXssMatchSet>.
+-- 2.  Use < GetChangeToken> to get the change token that you provide in
+--     the 'ChangeToken' parameter of a 'DeleteXssMatchSet' request.
+-- 3.  Submit a 'DeleteXssMatchSet' request.
+module Network.AWS.WAF.DeleteXSSMatchSet
+    (
+    -- * Creating a Request
+      deleteXSSMatchSet
+    , DeleteXSSMatchSet
+    -- * Request Lenses
+    , dxmsXSSMatchSetId
+    , dxmsChangeToken
+
+    -- * Destructuring the Response
+    , deleteXSSMatchSetResponse
+    , DeleteXSSMatchSetResponse
+    -- * Response Lenses
+    , dxmsrsChangeToken
+    , dxmsrsResponseStatus
+    ) where
+
+import           Network.AWS.Lens
+import           Network.AWS.Prelude
+import           Network.AWS.Request
+import           Network.AWS.Response
+import           Network.AWS.WAF.Types
+import           Network.AWS.WAF.Types.Product
+
+-- | A request to delete an < XssMatchSet> from AWS WAF.
+--
+-- /See:/ 'deleteXSSMatchSet' smart constructor.
+data DeleteXSSMatchSet = DeleteXSSMatchSet'
+    { _dxmsXSSMatchSetId :: !Text
+    , _dxmsChangeToken   :: !Text
+    } deriving (Eq,Read,Show,Data,Typeable,Generic)
+
+-- | Creates a value of 'DeleteXSSMatchSet' with the minimum fields required to make a request.
+--
+-- Use one of the following lenses to modify other fields as desired:
+--
+-- * 'dxmsXSSMatchSetId'
+--
+-- * 'dxmsChangeToken'
+deleteXSSMatchSet
+    :: Text -- ^ 'dxmsXSSMatchSetId'
+    -> Text -- ^ 'dxmsChangeToken'
+    -> DeleteXSSMatchSet
+deleteXSSMatchSet pXSSMatchSetId_ pChangeToken_ =
+    DeleteXSSMatchSet'
+    { _dxmsXSSMatchSetId = pXSSMatchSetId_
+    , _dxmsChangeToken = pChangeToken_
+    }
+
+-- | The 'XssMatchSetId' of the < XssMatchSet> that you want to delete.
+-- 'XssMatchSetId' is returned by < CreateXssMatchSet> and by
+-- < ListXssMatchSets>.
+dxmsXSSMatchSetId :: Lens' DeleteXSSMatchSet Text
+dxmsXSSMatchSetId = lens _dxmsXSSMatchSetId (\ s a -> s{_dxmsXSSMatchSetId = a});
+
+-- | The value returned by the most recent call to < GetChangeToken>.
+dxmsChangeToken :: Lens' DeleteXSSMatchSet Text
+dxmsChangeToken = lens _dxmsChangeToken (\ s a -> s{_dxmsChangeToken = a});
+
+instance AWSRequest DeleteXSSMatchSet where
+        type Rs DeleteXSSMatchSet = DeleteXSSMatchSetResponse
+        request = postJSON waf
+        response
+          = receiveJSON
+              (\ s h x ->
+                 DeleteXSSMatchSetResponse' <$>
+                   (x .?> "ChangeToken") <*> (pure (fromEnum s)))
+
+instance Hashable DeleteXSSMatchSet
+
+instance NFData DeleteXSSMatchSet
+
+instance ToHeaders DeleteXSSMatchSet where
+        toHeaders
+          = const
+              (mconcat
+                 ["X-Amz-Target" =#
+                    ("AWSWAF_20150824.DeleteXssMatchSet" :: ByteString),
+                  "Content-Type" =#
+                    ("application/x-amz-json-1.1" :: ByteString)])
+
+instance ToJSON DeleteXSSMatchSet where
+        toJSON DeleteXSSMatchSet'{..}
+          = object
+              (catMaybes
+                 [Just ("XssMatchSetId" .= _dxmsXSSMatchSetId),
+                  Just ("ChangeToken" .= _dxmsChangeToken)])
+
+instance ToPath DeleteXSSMatchSet where
+        toPath = const "/"
+
+instance ToQuery DeleteXSSMatchSet where
+        toQuery = const mempty
+
+-- | The response to a request to delete an < XssMatchSet> from AWS WAF.
+--
+-- /See:/ 'deleteXSSMatchSetResponse' smart constructor.
+data DeleteXSSMatchSetResponse = DeleteXSSMatchSetResponse'
+    { _dxmsrsChangeToken    :: !(Maybe Text)
+    , _dxmsrsResponseStatus :: !Int
+    } deriving (Eq,Read,Show,Data,Typeable,Generic)
+
+-- | Creates a value of 'DeleteXSSMatchSetResponse' with the minimum fields required to make a request.
+--
+-- Use one of the following lenses to modify other fields as desired:
+--
+-- * 'dxmsrsChangeToken'
+--
+-- * 'dxmsrsResponseStatus'
+deleteXSSMatchSetResponse
+    :: Int -- ^ 'dxmsrsResponseStatus'
+    -> DeleteXSSMatchSetResponse
+deleteXSSMatchSetResponse pResponseStatus_ =
+    DeleteXSSMatchSetResponse'
+    { _dxmsrsChangeToken = Nothing
+    , _dxmsrsResponseStatus = pResponseStatus_
+    }
+
+-- | The 'ChangeToken' that you used to submit the 'DeleteXssMatchSet'
+-- request. You can also use this value to query the status of the request.
+-- For more information, see < GetChangeTokenStatus>.
+dxmsrsChangeToken :: Lens' DeleteXSSMatchSetResponse (Maybe Text)
+dxmsrsChangeToken = lens _dxmsrsChangeToken (\ s a -> s{_dxmsrsChangeToken = a});
+
+-- | The response status code.
+dxmsrsResponseStatus :: Lens' DeleteXSSMatchSetResponse Int
+dxmsrsResponseStatus = lens _dxmsrsResponseStatus (\ s a -> s{_dxmsrsResponseStatus = a});
+
+instance NFData DeleteXSSMatchSetResponse
diff --git a/gen/Network/AWS/WAF/GetByteMatchSet.hs b/gen/Network/AWS/WAF/GetByteMatchSet.hs
--- a/gen/Network/AWS/WAF/GetByteMatchSet.hs
+++ b/gen/Network/AWS/WAF/GetByteMatchSet.hs
@@ -77,6 +77,8 @@
 
 instance Hashable GetByteMatchSet
 
+instance NFData GetByteMatchSet
+
 instance ToHeaders GetByteMatchSet where
         toHeaders
           = const
@@ -136,3 +138,5 @@
 -- | The response status code.
 gbmsrsResponseStatus :: Lens' GetByteMatchSetResponse Int
 gbmsrsResponseStatus = lens _gbmsrsResponseStatus (\ s a -> s{_gbmsrsResponseStatus = a});
+
+instance NFData GetByteMatchSetResponse
diff --git a/gen/Network/AWS/WAF/GetChangeToken.hs b/gen/Network/AWS/WAF/GetChangeToken.hs
--- a/gen/Network/AWS/WAF/GetChangeToken.hs
+++ b/gen/Network/AWS/WAF/GetChangeToken.hs
@@ -76,6 +76,8 @@
 
 instance Hashable GetChangeToken
 
+instance NFData GetChangeToken
+
 instance ToHeaders GetChangeToken where
         toHeaders
           = const
@@ -124,3 +126,5 @@
 -- | The response status code.
 gctrsResponseStatus :: Lens' GetChangeTokenResponse Int
 gctrsResponseStatus = lens _gctrsResponseStatus (\ s a -> s{_gctrsResponseStatus = a});
+
+instance NFData GetChangeTokenResponse
diff --git a/gen/Network/AWS/WAF/GetChangeTokenStatus.hs b/gen/Network/AWS/WAF/GetChangeTokenStatus.hs
--- a/gen/Network/AWS/WAF/GetChangeTokenStatus.hs
+++ b/gen/Network/AWS/WAF/GetChangeTokenStatus.hs
@@ -85,6 +85,8 @@
 
 instance Hashable GetChangeTokenStatus
 
+instance NFData GetChangeTokenStatus
+
 instance ToHeaders GetChangeTokenStatus where
         toHeaders
           = const
@@ -136,3 +138,5 @@
 -- | The response status code.
 gctsrsResponseStatus :: Lens' GetChangeTokenStatusResponse Int
 gctsrsResponseStatus = lens _gctsrsResponseStatus (\ s a -> s{_gctsrsResponseStatus = a});
+
+instance NFData GetChangeTokenStatusResponse
diff --git a/gen/Network/AWS/WAF/GetIPSet.hs b/gen/Network/AWS/WAF/GetIPSet.hs
--- a/gen/Network/AWS/WAF/GetIPSet.hs
+++ b/gen/Network/AWS/WAF/GetIPSet.hs
@@ -76,6 +76,8 @@
 
 instance Hashable GetIPSet
 
+instance NFData GetIPSet
+
 instance ToHeaders GetIPSet where
         toHeaders
           = const
@@ -130,3 +132,5 @@
 -- | The response status code.
 gisrsResponseStatus :: Lens' GetIPSetResponse Int
 gisrsResponseStatus = lens _gisrsResponseStatus (\ s a -> s{_gisrsResponseStatus = a});
+
+instance NFData GetIPSetResponse
diff --git a/gen/Network/AWS/WAF/GetRule.hs b/gen/Network/AWS/WAF/GetRule.hs
--- a/gen/Network/AWS/WAF/GetRule.hs
+++ b/gen/Network/AWS/WAF/GetRule.hs
@@ -77,6 +77,8 @@
 
 instance Hashable GetRule
 
+instance NFData GetRule
+
 instance ToHeaders GetRule where
         toHeaders
           = const
@@ -131,3 +133,5 @@
 -- | The response status code.
 grrsResponseStatus :: Lens' GetRuleResponse Int
 grrsResponseStatus = lens _grrsResponseStatus (\ s a -> s{_grrsResponseStatus = a});
+
+instance NFData GetRuleResponse
diff --git a/gen/Network/AWS/WAF/GetSampledRequests.hs b/gen/Network/AWS/WAF/GetSampledRequests.hs
--- a/gen/Network/AWS/WAF/GetSampledRequests.hs
+++ b/gen/Network/AWS/WAF/GetSampledRequests.hs
@@ -135,6 +135,8 @@
 
 instance Hashable GetSampledRequests
 
+instance NFData GetSampledRequests
+
 instance ToHeaders GetSampledRequests where
         toHeaders
           = const
@@ -212,3 +214,5 @@
 -- | The response status code.
 gsrrsResponseStatus :: Lens' GetSampledRequestsResponse Int
 gsrrsResponseStatus = lens _gsrrsResponseStatus (\ s a -> s{_gsrrsResponseStatus = a});
+
+instance NFData GetSampledRequestsResponse
diff --git a/gen/Network/AWS/WAF/GetSizeConstraintSet.hs b/gen/Network/AWS/WAF/GetSizeConstraintSet.hs
--- a/gen/Network/AWS/WAF/GetSizeConstraintSet.hs
+++ b/gen/Network/AWS/WAF/GetSizeConstraintSet.hs
@@ -78,6 +78,8 @@
 
 instance Hashable GetSizeConstraintSet
 
+instance NFData GetSizeConstraintSet
+
 instance ToHeaders GetSizeConstraintSet where
         toHeaders
           = const
@@ -139,3 +141,5 @@
 -- | The response status code.
 gscsrsResponseStatus :: Lens' GetSizeConstraintSetResponse Int
 gscsrsResponseStatus = lens _gscsrsResponseStatus (\ s a -> s{_gscsrsResponseStatus = a});
+
+instance NFData GetSizeConstraintSetResponse
diff --git a/gen/Network/AWS/WAF/GetSqlInjectionMatchSet.hs b/gen/Network/AWS/WAF/GetSqlInjectionMatchSet.hs
--- a/gen/Network/AWS/WAF/GetSqlInjectionMatchSet.hs
+++ b/gen/Network/AWS/WAF/GetSqlInjectionMatchSet.hs
@@ -82,6 +82,8 @@
 
 instance Hashable GetSqlInjectionMatchSet
 
+instance NFData GetSqlInjectionMatchSet
+
 instance ToHeaders GetSqlInjectionMatchSet where
         toHeaders
           = const
@@ -145,3 +147,5 @@
 -- | The response status code.
 gsimsrsResponseStatus :: Lens' GetSqlInjectionMatchSetResponse Int
 gsimsrsResponseStatus = lens _gsimsrsResponseStatus (\ s a -> s{_gsimsrsResponseStatus = a});
+
+instance NFData GetSqlInjectionMatchSetResponse
diff --git a/gen/Network/AWS/WAF/GetWebACL.hs b/gen/Network/AWS/WAF/GetWebACL.hs
--- a/gen/Network/AWS/WAF/GetWebACL.hs
+++ b/gen/Network/AWS/WAF/GetWebACL.hs
@@ -76,6 +76,8 @@
 
 instance Hashable GetWebACL
 
+instance NFData GetWebACL
+
 instance ToHeaders GetWebACL where
         toHeaders
           = const
@@ -133,3 +135,5 @@
 -- | The response status code.
 gwarsResponseStatus :: Lens' GetWebACLResponse Int
 gwarsResponseStatus = lens _gwarsResponseStatus (\ s a -> s{_gwarsResponseStatus = a});
+
+instance NFData GetWebACLResponse
diff --git a/gen/Network/AWS/WAF/GetXSSMatchSet.hs b/gen/Network/AWS/WAF/GetXSSMatchSet.hs
new file mode 100644
--- /dev/null
+++ b/gen/Network/AWS/WAF/GetXSSMatchSet.hs
@@ -0,0 +1,145 @@
+{-# LANGUAGE DeriveDataTypeable #-}
+{-# LANGUAGE DeriveGeneric      #-}
+{-# LANGUAGE OverloadedStrings  #-}
+{-# LANGUAGE RecordWildCards    #-}
+{-# LANGUAGE TypeFamilies       #-}
+
+{-# OPTIONS_GHC -fno-warn-unused-imports #-}
+{-# OPTIONS_GHC -fno-warn-unused-binds   #-}
+{-# OPTIONS_GHC -fno-warn-unused-matches #-}
+
+-- Derived from AWS service descriptions, licensed under Apache 2.0.
+
+-- |
+-- Module      : Network.AWS.WAF.GetXSSMatchSet
+-- Copyright   : (c) 2013-2016 Brendan Hay
+-- License     : Mozilla Public License, v. 2.0.
+-- Maintainer  : Brendan Hay <brendan.g.hay@gmail.com>
+-- Stability   : auto-generated
+-- Portability : non-portable (GHC extensions)
+--
+-- Returns the < XssMatchSet> that is specified by 'XssMatchSetId'.
+module Network.AWS.WAF.GetXSSMatchSet
+    (
+    -- * Creating a Request
+      getXSSMatchSet
+    , GetXSSMatchSet
+    -- * Request Lenses
+    , gxmsXSSMatchSetId
+
+    -- * Destructuring the Response
+    , getXSSMatchSetResponse
+    , GetXSSMatchSetResponse
+    -- * Response Lenses
+    , gxmsrsXSSMatchSet
+    , gxmsrsResponseStatus
+    ) where
+
+import           Network.AWS.Lens
+import           Network.AWS.Prelude
+import           Network.AWS.Request
+import           Network.AWS.Response
+import           Network.AWS.WAF.Types
+import           Network.AWS.WAF.Types.Product
+
+-- | A request to get an < XssMatchSet>.
+--
+-- /See:/ 'getXSSMatchSet' smart constructor.
+newtype GetXSSMatchSet = GetXSSMatchSet'
+    { _gxmsXSSMatchSetId :: Text
+    } deriving (Eq,Read,Show,Data,Typeable,Generic)
+
+-- | Creates a value of 'GetXSSMatchSet' with the minimum fields required to make a request.
+--
+-- Use one of the following lenses to modify other fields as desired:
+--
+-- * 'gxmsXSSMatchSetId'
+getXSSMatchSet
+    :: Text -- ^ 'gxmsXSSMatchSetId'
+    -> GetXSSMatchSet
+getXSSMatchSet pXSSMatchSetId_ =
+    GetXSSMatchSet'
+    { _gxmsXSSMatchSetId = pXSSMatchSetId_
+    }
+
+-- | The 'XssMatchSetId' of the < XssMatchSet> that you want to get.
+-- 'XssMatchSetId' is returned by < CreateXssMatchSet> and by
+-- < ListXssMatchSets>.
+gxmsXSSMatchSetId :: Lens' GetXSSMatchSet Text
+gxmsXSSMatchSetId = lens _gxmsXSSMatchSetId (\ s a -> s{_gxmsXSSMatchSetId = a});
+
+instance AWSRequest GetXSSMatchSet where
+        type Rs GetXSSMatchSet = GetXSSMatchSetResponse
+        request = postJSON waf
+        response
+          = receiveJSON
+              (\ s h x ->
+                 GetXSSMatchSetResponse' <$>
+                   (x .?> "XssMatchSet") <*> (pure (fromEnum s)))
+
+instance Hashable GetXSSMatchSet
+
+instance NFData GetXSSMatchSet
+
+instance ToHeaders GetXSSMatchSet where
+        toHeaders
+          = const
+              (mconcat
+                 ["X-Amz-Target" =#
+                    ("AWSWAF_20150824.GetXssMatchSet" :: ByteString),
+                  "Content-Type" =#
+                    ("application/x-amz-json-1.1" :: ByteString)])
+
+instance ToJSON GetXSSMatchSet where
+        toJSON GetXSSMatchSet'{..}
+          = object
+              (catMaybes
+                 [Just ("XssMatchSetId" .= _gxmsXSSMatchSetId)])
+
+instance ToPath GetXSSMatchSet where
+        toPath = const "/"
+
+instance ToQuery GetXSSMatchSet where
+        toQuery = const mempty
+
+-- | The response to a < GetXssMatchSet> request.
+--
+-- /See:/ 'getXSSMatchSetResponse' smart constructor.
+data GetXSSMatchSetResponse = GetXSSMatchSetResponse'
+    { _gxmsrsXSSMatchSet    :: !(Maybe XSSMatchSet)
+    , _gxmsrsResponseStatus :: !Int
+    } deriving (Eq,Read,Show,Data,Typeable,Generic)
+
+-- | Creates a value of 'GetXSSMatchSetResponse' with the minimum fields required to make a request.
+--
+-- Use one of the following lenses to modify other fields as desired:
+--
+-- * 'gxmsrsXSSMatchSet'
+--
+-- * 'gxmsrsResponseStatus'
+getXSSMatchSetResponse
+    :: Int -- ^ 'gxmsrsResponseStatus'
+    -> GetXSSMatchSetResponse
+getXSSMatchSetResponse pResponseStatus_ =
+    GetXSSMatchSetResponse'
+    { _gxmsrsXSSMatchSet = Nothing
+    , _gxmsrsResponseStatus = pResponseStatus_
+    }
+
+-- | Information about the < XssMatchSet> that you specified in the
+-- 'GetXssMatchSet' request. For more information, see the following
+-- topics:
+--
+-- -   < XssMatchSet>: Contains 'Name', 'XssMatchSetId', and an array of
+--     'XssMatchTuple' objects
+-- -   < XssMatchTuple>: Each 'XssMatchTuple' object contains
+--     'FieldToMatch' and 'TextTransformation'
+-- -   < FieldToMatch>: Contains 'Data' and 'Type'
+gxmsrsXSSMatchSet :: Lens' GetXSSMatchSetResponse (Maybe XSSMatchSet)
+gxmsrsXSSMatchSet = lens _gxmsrsXSSMatchSet (\ s a -> s{_gxmsrsXSSMatchSet = a});
+
+-- | The response status code.
+gxmsrsResponseStatus :: Lens' GetXSSMatchSetResponse Int
+gxmsrsResponseStatus = lens _gxmsrsResponseStatus (\ s a -> s{_gxmsrsResponseStatus = a});
+
+instance NFData GetXSSMatchSetResponse
diff --git a/gen/Network/AWS/WAF/ListByteMatchSets.hs b/gen/Network/AWS/WAF/ListByteMatchSets.hs
--- a/gen/Network/AWS/WAF/ListByteMatchSets.hs
+++ b/gen/Network/AWS/WAF/ListByteMatchSets.hs
@@ -95,6 +95,8 @@
 
 instance Hashable ListByteMatchSets
 
+instance NFData ListByteMatchSets
+
 instance ToHeaders ListByteMatchSets where
         toHeaders
           = const
@@ -158,3 +160,5 @@
 -- | The response status code.
 lbmsrsResponseStatus :: Lens' ListByteMatchSetsResponse Int
 lbmsrsResponseStatus = lens _lbmsrsResponseStatus (\ s a -> s{_lbmsrsResponseStatus = a});
+
+instance NFData ListByteMatchSetsResponse
diff --git a/gen/Network/AWS/WAF/ListIPSets.hs b/gen/Network/AWS/WAF/ListIPSets.hs
--- a/gen/Network/AWS/WAF/ListIPSets.hs
+++ b/gen/Network/AWS/WAF/ListIPSets.hs
@@ -94,6 +94,8 @@
 
 instance Hashable ListIPSets
 
+instance NFData ListIPSets
+
 instance ToHeaders ListIPSets where
         toHeaders
           = const
@@ -157,3 +159,5 @@
 -- | The response status code.
 lisrsResponseStatus :: Lens' ListIPSetsResponse Int
 lisrsResponseStatus = lens _lisrsResponseStatus (\ s a -> s{_lisrsResponseStatus = a});
+
+instance NFData ListIPSetsResponse
diff --git a/gen/Network/AWS/WAF/ListRules.hs b/gen/Network/AWS/WAF/ListRules.hs
--- a/gen/Network/AWS/WAF/ListRules.hs
+++ b/gen/Network/AWS/WAF/ListRules.hs
@@ -93,6 +93,8 @@
 
 instance Hashable ListRules
 
+instance NFData ListRules
+
 instance ToHeaders ListRules where
         toHeaders
           = const
@@ -156,3 +158,5 @@
 -- | The response status code.
 lrrsResponseStatus :: Lens' ListRulesResponse Int
 lrrsResponseStatus = lens _lrrsResponseStatus (\ s a -> s{_lrrsResponseStatus = a});
+
+instance NFData ListRulesResponse
diff --git a/gen/Network/AWS/WAF/ListSizeConstraintSets.hs b/gen/Network/AWS/WAF/ListSizeConstraintSets.hs
--- a/gen/Network/AWS/WAF/ListSizeConstraintSets.hs
+++ b/gen/Network/AWS/WAF/ListSizeConstraintSets.hs
@@ -98,6 +98,8 @@
 
 instance Hashable ListSizeConstraintSets
 
+instance NFData ListSizeConstraintSets
+
 instance ToHeaders ListSizeConstraintSets where
         toHeaders
           = const
@@ -162,3 +164,5 @@
 -- | The response status code.
 lscsrsResponseStatus :: Lens' ListSizeConstraintSetsResponse Int
 lscsrsResponseStatus = lens _lscsrsResponseStatus (\ s a -> s{_lscsrsResponseStatus = a});
+
+instance NFData ListSizeConstraintSetsResponse
diff --git a/gen/Network/AWS/WAF/ListSqlInjectionMatchSets.hs b/gen/Network/AWS/WAF/ListSqlInjectionMatchSets.hs
--- a/gen/Network/AWS/WAF/ListSqlInjectionMatchSets.hs
+++ b/gen/Network/AWS/WAF/ListSqlInjectionMatchSets.hs
@@ -101,6 +101,8 @@
 
 instance Hashable ListSqlInjectionMatchSets
 
+instance NFData ListSqlInjectionMatchSets
+
 instance ToHeaders ListSqlInjectionMatchSets where
         toHeaders
           = const
@@ -168,3 +170,5 @@
 -- | The response status code.
 lsimsrsResponseStatus :: Lens' ListSqlInjectionMatchSetsResponse Int
 lsimsrsResponseStatus = lens _lsimsrsResponseStatus (\ s a -> s{_lsimsrsResponseStatus = a});
+
+instance NFData ListSqlInjectionMatchSetsResponse
diff --git a/gen/Network/AWS/WAF/ListWebACLs.hs b/gen/Network/AWS/WAF/ListWebACLs.hs
--- a/gen/Network/AWS/WAF/ListWebACLs.hs
+++ b/gen/Network/AWS/WAF/ListWebACLs.hs
@@ -94,6 +94,8 @@
 
 instance Hashable ListWebACLs
 
+instance NFData ListWebACLs
+
 instance ToHeaders ListWebACLs where
         toHeaders
           = const
@@ -157,3 +159,5 @@
 -- | The response status code.
 lwarsResponseStatus :: Lens' ListWebACLsResponse Int
 lwarsResponseStatus = lens _lwarsResponseStatus (\ s a -> s{_lwarsResponseStatus = a});
+
+instance NFData ListWebACLsResponse
diff --git a/gen/Network/AWS/WAF/ListXSSMatchSets.hs b/gen/Network/AWS/WAF/ListXSSMatchSets.hs
new file mode 100644
--- /dev/null
+++ b/gen/Network/AWS/WAF/ListXSSMatchSets.hs
@@ -0,0 +1,169 @@
+{-# LANGUAGE DeriveDataTypeable #-}
+{-# LANGUAGE DeriveGeneric      #-}
+{-# LANGUAGE OverloadedStrings  #-}
+{-# LANGUAGE RecordWildCards    #-}
+{-# LANGUAGE TypeFamilies       #-}
+
+{-# OPTIONS_GHC -fno-warn-unused-imports #-}
+{-# OPTIONS_GHC -fno-warn-unused-binds   #-}
+{-# OPTIONS_GHC -fno-warn-unused-matches #-}
+
+-- Derived from AWS service descriptions, licensed under Apache 2.0.
+
+-- |
+-- Module      : Network.AWS.WAF.ListXSSMatchSets
+-- Copyright   : (c) 2013-2016 Brendan Hay
+-- License     : Mozilla Public License, v. 2.0.
+-- Maintainer  : Brendan Hay <brendan.g.hay@gmail.com>
+-- Stability   : auto-generated
+-- Portability : non-portable (GHC extensions)
+--
+-- Returns an array of < XssMatchSet> objects.
+module Network.AWS.WAF.ListXSSMatchSets
+    (
+    -- * Creating a Request
+      listXSSMatchSets
+    , ListXSSMatchSets
+    -- * Request Lenses
+    , lxmsNextMarker
+    , lxmsLimit
+
+    -- * Destructuring the Response
+    , listXSSMatchSetsResponse
+    , ListXSSMatchSetsResponse
+    -- * Response Lenses
+    , lxmsrsXSSMatchSets
+    , lxmsrsNextMarker
+    , lxmsrsResponseStatus
+    ) where
+
+import           Network.AWS.Lens
+import           Network.AWS.Prelude
+import           Network.AWS.Request
+import           Network.AWS.Response
+import           Network.AWS.WAF.Types
+import           Network.AWS.WAF.Types.Product
+
+-- | A request to list the < XssMatchSet> objects created by the current AWS
+-- account.
+--
+-- /See:/ 'listXSSMatchSets' smart constructor.
+data ListXSSMatchSets = ListXSSMatchSets'
+    { _lxmsNextMarker :: !(Maybe Text)
+    , _lxmsLimit      :: !Nat
+    } deriving (Eq,Read,Show,Data,Typeable,Generic)
+
+-- | Creates a value of 'ListXSSMatchSets' with the minimum fields required to make a request.
+--
+-- Use one of the following lenses to modify other fields as desired:
+--
+-- * 'lxmsNextMarker'
+--
+-- * 'lxmsLimit'
+listXSSMatchSets
+    :: Natural -- ^ 'lxmsLimit'
+    -> ListXSSMatchSets
+listXSSMatchSets pLimit_ =
+    ListXSSMatchSets'
+    { _lxmsNextMarker = Nothing
+    , _lxmsLimit = _Nat # pLimit_
+    }
+
+-- | If you specify a value for 'Limit' and you have more < XssMatchSet>
+-- objects than the value of 'Limit', AWS WAF returns a 'NextMarker' value
+-- in the response that allows you to list another group of 'XssMatchSets'.
+-- For the second and subsequent 'ListXssMatchSets' requests, specify the
+-- value of 'NextMarker' from the previous response to get information
+-- about another batch of 'XssMatchSets'.
+lxmsNextMarker :: Lens' ListXSSMatchSets (Maybe Text)
+lxmsNextMarker = lens _lxmsNextMarker (\ s a -> s{_lxmsNextMarker = a});
+
+-- | Specifies the number of < XssMatchSet> objects that you want AWS WAF to
+-- return for this request. If you have more 'XssMatchSet' objects than the
+-- number you specify for 'Limit', the response includes a 'NextMarker'
+-- value that you can use to get another batch of 'Rules'.
+lxmsLimit :: Lens' ListXSSMatchSets Natural
+lxmsLimit = lens _lxmsLimit (\ s a -> s{_lxmsLimit = a}) . _Nat;
+
+instance AWSRequest ListXSSMatchSets where
+        type Rs ListXSSMatchSets = ListXSSMatchSetsResponse
+        request = postJSON waf
+        response
+          = receiveJSON
+              (\ s h x ->
+                 ListXSSMatchSetsResponse' <$>
+                   (x .?> "XssMatchSets" .!@ mempty) <*>
+                     (x .?> "NextMarker")
+                     <*> (pure (fromEnum s)))
+
+instance Hashable ListXSSMatchSets
+
+instance NFData ListXSSMatchSets
+
+instance ToHeaders ListXSSMatchSets where
+        toHeaders
+          = const
+              (mconcat
+                 ["X-Amz-Target" =#
+                    ("AWSWAF_20150824.ListXssMatchSets" :: ByteString),
+                  "Content-Type" =#
+                    ("application/x-amz-json-1.1" :: ByteString)])
+
+instance ToJSON ListXSSMatchSets where
+        toJSON ListXSSMatchSets'{..}
+          = object
+              (catMaybes
+                 [("NextMarker" .=) <$> _lxmsNextMarker,
+                  Just ("Limit" .= _lxmsLimit)])
+
+instance ToPath ListXSSMatchSets where
+        toPath = const "/"
+
+instance ToQuery ListXSSMatchSets where
+        toQuery = const mempty
+
+-- | The response to a < ListXssMatchSets> request.
+--
+-- /See:/ 'listXSSMatchSetsResponse' smart constructor.
+data ListXSSMatchSetsResponse = ListXSSMatchSetsResponse'
+    { _lxmsrsXSSMatchSets   :: !(Maybe [XSSMatchSetSummary])
+    , _lxmsrsNextMarker     :: !(Maybe Text)
+    , _lxmsrsResponseStatus :: !Int
+    } deriving (Eq,Read,Show,Data,Typeable,Generic)
+
+-- | Creates a value of 'ListXSSMatchSetsResponse' with the minimum fields required to make a request.
+--
+-- Use one of the following lenses to modify other fields as desired:
+--
+-- * 'lxmsrsXSSMatchSets'
+--
+-- * 'lxmsrsNextMarker'
+--
+-- * 'lxmsrsResponseStatus'
+listXSSMatchSetsResponse
+    :: Int -- ^ 'lxmsrsResponseStatus'
+    -> ListXSSMatchSetsResponse
+listXSSMatchSetsResponse pResponseStatus_ =
+    ListXSSMatchSetsResponse'
+    { _lxmsrsXSSMatchSets = Nothing
+    , _lxmsrsNextMarker = Nothing
+    , _lxmsrsResponseStatus = pResponseStatus_
+    }
+
+-- | An array of < XssMatchSetSummary> objects.
+lxmsrsXSSMatchSets :: Lens' ListXSSMatchSetsResponse [XSSMatchSetSummary]
+lxmsrsXSSMatchSets = lens _lxmsrsXSSMatchSets (\ s a -> s{_lxmsrsXSSMatchSets = a}) . _Default . _Coerce;
+
+-- | If you have more < XssMatchSet> objects than the number that you
+-- specified for 'Limit' in the request, the response includes a
+-- 'NextMarker' value. To list more 'XssMatchSet' objects, submit another
+-- 'ListXssMatchSets' request, and specify the 'NextMarker' value from the
+-- response in the 'NextMarker' value in the next request.
+lxmsrsNextMarker :: Lens' ListXSSMatchSetsResponse (Maybe Text)
+lxmsrsNextMarker = lens _lxmsrsNextMarker (\ s a -> s{_lxmsrsNextMarker = a});
+
+-- | The response status code.
+lxmsrsResponseStatus :: Lens' ListXSSMatchSetsResponse Int
+lxmsrsResponseStatus = lens _lxmsrsResponseStatus (\ s a -> s{_lxmsrsResponseStatus = a});
+
+instance NFData ListXSSMatchSetsResponse
diff --git a/gen/Network/AWS/WAF/Types.hs b/gen/Network/AWS/WAF/Types.hs
--- a/gen/Network/AWS/WAF/Types.hs
+++ b/gen/Network/AWS/WAF/Types.hs
@@ -254,6 +254,31 @@
     , webACLUpdate
     , wauAction
     , wauActivatedRule
+
+    -- * XSSMatchSet
+    , XSSMatchSet
+    , xssMatchSet
+    , xmsName
+    , xmsXSSMatchSetId
+    , xmsXSSMatchTuples
+
+    -- * XSSMatchSetSummary
+    , XSSMatchSetSummary
+    , xssMatchSetSummary
+    , xmssXSSMatchSetId
+    , xmssName
+
+    -- * XSSMatchSetUpdate
+    , XSSMatchSetUpdate
+    , xssMatchSetUpdate
+    , xmsuAction
+    , xmsuXSSMatchTuple
+
+    -- * XSSMatchTuple
+    , XSSMatchTuple
+    , xssMatchTuple
+    , xmtFieldToMatch
+    , xmtTextTransformation
     ) where
 
 import           Network.AWS.Lens
@@ -289,6 +314,8 @@
       | has (hasCode "ThrottlingException" . hasStatus 400) e =
           Just "throttling_exception"
       | has (hasCode "Throttling" . hasStatus 400) e = Just "throttling"
+      | has (hasStatus 504) e = Just "gateway_timeout"
+      | has (hasStatus 502) e = Just "bad_gateway"
       | has (hasStatus 503) e = Just "service_unavailable"
       | has (hasStatus 500) e = Just "general_server_error"
       | has (hasStatus 509) e = Just "limit_exceeded"
diff --git a/gen/Network/AWS/WAF/Types/Product.hs b/gen/Network/AWS/WAF/Types/Product.hs
--- a/gen/Network/AWS/WAF/Types/Product.hs
+++ b/gen/Network/AWS/WAF/Types/Product.hs
@@ -97,6 +97,8 @@
 
 instance Hashable ActivatedRule
 
+instance NFData ActivatedRule
+
 instance ToJSON ActivatedRule where
         toJSON ActivatedRule'{..}
           = object
@@ -148,7 +150,7 @@
 
 -- | The 'ByteMatchSetId' for a 'ByteMatchSet'. You use 'ByteMatchSetId' to
 -- get information about a 'ByteMatchSet' (see < GetByteMatchSet>), update
--- a 'ByteMatchSet' (see < UpdateByteMatchSet>, insert a 'ByteMatchSet'
+-- a 'ByteMatchSet' (see < UpdateByteMatchSet>), insert a 'ByteMatchSet'
 -- into a 'Rule' or delete one from a 'Rule' (see < UpdateRule>), and
 -- delete a 'ByteMatchSet' from AWS WAF (see < DeleteByteMatchSet>).
 --
@@ -174,6 +176,8 @@
 
 instance Hashable ByteMatchSet
 
+instance NFData ByteMatchSet
+
 -- | Returned by < ListByteMatchSets>. Each 'ByteMatchSetSummary' object
 -- includes the 'Name' and 'ByteMatchSetId' for one < ByteMatchSet>.
 --
@@ -224,6 +228,8 @@
 
 instance Hashable ByteMatchSetSummary
 
+instance NFData ByteMatchSetSummary
+
 -- | In an < UpdateByteMatchSet> request, 'ByteMatchSetUpdate' specifies
 -- whether to insert or delete a < ByteMatchTuple> and includes the
 -- settings for the 'ByteMatchTuple'.
@@ -265,6 +271,8 @@
 
 instance Hashable ByteMatchSetUpdate
 
+instance NFData ByteMatchSetUpdate
+
 instance ToJSON ByteMatchSetUpdate where
         toJSON ByteMatchSetUpdate'{..}
           = object
@@ -485,6 +493,8 @@
 
 instance Hashable ByteMatchTuple
 
+instance NFData ByteMatchTuple
+
 instance ToJSON ByteMatchTuple where
         toJSON ByteMatchTuple'{..}
           = object
@@ -563,6 +573,8 @@
 
 instance Hashable FieldToMatch
 
+instance NFData FieldToMatch
+
 instance ToJSON FieldToMatch where
         toJSON FieldToMatch'{..}
           = object
@@ -613,6 +625,8 @@
 
 instance Hashable HTTPHeader
 
+instance NFData HTTPHeader
+
 -- | The response from a < GetSampledRequests> request includes an
 -- 'HTTPRequest' complex type that appears as 'Request' in the response
 -- syntax. 'HTTPRequest' contains information about one of the web requests
@@ -706,6 +720,8 @@
 
 instance Hashable HTTPRequest
 
+instance NFData HTTPRequest
+
 -- | Contains one or more IP addresses or blocks of IP addresses specified in
 -- Classless Inter-Domain Routing (CIDR) notation. To specify an individual
 -- IP address, you specify the four-part IP address followed by a '\/32',
@@ -775,6 +791,8 @@
 
 instance Hashable IPSet
 
+instance NFData IPSet
+
 -- | Specifies the IP address type ('IPV4') and the IP address range (in CIDR
 -- format) that web requests originate from.
 --
@@ -829,6 +847,8 @@
 
 instance Hashable IPSetDescriptor
 
+instance NFData IPSetDescriptor
+
 instance ToJSON IPSetDescriptor where
         toJSON IPSetDescriptor'{..}
           = object
@@ -879,6 +899,8 @@
 
 instance Hashable IPSetSummary
 
+instance NFData IPSetSummary
+
 -- | Specifies the type of update to perform to an < IPSet> with
 -- < UpdateIPSet>.
 --
@@ -916,6 +938,8 @@
 
 instance Hashable IPSetUpdate
 
+instance NFData IPSetUpdate
+
 instance ToJSON IPSetUpdate where
         toJSON IPSetUpdate'{..}
           = object
@@ -923,10 +947,11 @@
                  [Just ("Action" .= _isuAction),
                   Just ("IPSetDescriptor" .= _isuIPSetDescriptor)])
 
--- | Specifies the < ByteMatchSet>, < IPSet>, and < SqlInjectionMatchSet>
--- objects that you want to add to a 'Rule' and, for each object, indicates
--- whether you want to negate the settings, for example, requests that do
--- NOT originate from the IP address 192.0.2.44.
+-- | Specifies the < ByteMatchSet>, < IPSet>, < SqlInjectionMatchSet>,
+-- < XssMatchSet>, and < SizeConstraintSet> objects that you want to add to
+-- a 'Rule' and, for each object, indicates whether you want to negate the
+-- settings, for example, requests that do NOT originate from the IP
+-- address 192.0.2.44.
 --
 -- /See:/ 'predicate' smart constructor.
 data Predicate = Predicate'
@@ -958,15 +983,17 @@
 
 -- | Set 'Negated' to 'False' if you want AWS WAF to allow, block, or count
 -- requests based on the settings in the specified < ByteMatchSet>,
--- < IPSet>, or < SqlInjectionMatchSet>. For example, if an 'IPSet'
--- includes the IP address '192.0.2.44', AWS WAF will allow or block
--- requests based on that IP address.
+-- < IPSet>, < SqlInjectionMatchSet>, < XssMatchSet>, or
+-- < SizeConstraintSet>. For example, if an 'IPSet' includes the IP address
+-- '192.0.2.44', AWS WAF will allow or block requests based on that IP
+-- address.
 --
 -- Set 'Negated' to 'True' if you want AWS WAF to allow or block a request
 -- based on the negation of the settings in the < ByteMatchSet>, < IPSet>,
--- or < SqlInjectionMatchSet>. For example, if an 'IPSet' includes the IP
--- address '192.0.2.44', AWS WAF will allow, block, or count requests based
--- on all IP addresses /except/ '192.0.2.44'.
+-- < SqlInjectionMatchSet>, < XssMatchSet>, or < SizeConstraintSet>. For
+-- example, if an 'IPSet' includes the IP address '192.0.2.44', AWS WAF
+-- will allow, block, or count requests based on all IP addresses /except/
+-- '192.0.2.44'.
 pNegated :: Lens' Predicate Bool
 pNegated = lens _pNegated (\ s a -> s{_pNegated = a});
 
@@ -990,6 +1017,8 @@
 
 instance Hashable Predicate
 
+instance NFData Predicate
+
 instance ToJSON Predicate where
         toJSON Predicate'{..}
           = object
@@ -1078,6 +1107,8 @@
 
 instance Hashable Rule
 
+instance NFData Rule
+
 -- | Contains the identifier and the friendly name or description of the
 -- 'Rule'.
 --
@@ -1127,6 +1158,8 @@
 
 instance Hashable RuleSummary
 
+instance NFData RuleSummary
+
 -- | Specifies a 'Predicate' (such as an 'IPSet') and indicates whether you
 -- want to add it to a 'Rule' or delete it from a 'Rule'.
 --
@@ -1165,6 +1198,8 @@
 
 instance Hashable RuleUpdate
 
+instance NFData RuleUpdate
+
 instance ToJSON RuleUpdate where
         toJSON RuleUpdate'{..}
           = object
@@ -1241,6 +1276,8 @@
 
 instance Hashable SampledHTTPRequest
 
+instance NFData SampledHTTPRequest
+
 -- | Specifies a constraint on the size of a part of the web request. AWS WAF
 -- uses the 'Size', 'ComparisonOperator', and 'FieldToMatch' to build an
 -- expression in the form of \"'Size' 'ComparisonOperator' size in bytes of
@@ -1399,6 +1436,8 @@
 
 instance Hashable SizeConstraint
 
+instance NFData SizeConstraint
+
 instance ToJSON SizeConstraint where
         toJSON SizeConstraint'{..}
           = object
@@ -1446,7 +1485,7 @@
 -- | A unique identifier for a 'SizeConstraintSet'. You use
 -- 'SizeConstraintSetId' to get information about a 'SizeConstraintSet'
 -- (see < GetSizeConstraintSet>), update a 'SizeConstraintSet' (see
--- < UpdateSizeConstraintSet>, insert a 'SizeConstraintSet' into a 'Rule'
+-- < UpdateSizeConstraintSet>), insert a 'SizeConstraintSet' into a 'Rule'
 -- or delete one from a 'Rule' (see < UpdateRule>), and delete a
 -- 'SizeConstraintSet' from AWS WAF (see < DeleteSizeConstraintSet>).
 --
@@ -1470,6 +1509,8 @@
 
 instance Hashable SizeConstraintSet
 
+instance NFData SizeConstraintSet
+
 -- | The 'Id' and 'Name' of a 'SizeConstraintSet'.
 --
 -- /See:/ 'sizeConstraintSetSummary' smart constructor.
@@ -1498,7 +1539,7 @@
 -- | A unique identifier for a 'SizeConstraintSet'. You use
 -- 'SizeConstraintSetId' to get information about a 'SizeConstraintSet'
 -- (see < GetSizeConstraintSet>), update a 'SizeConstraintSet' (see
--- < UpdateSizeConstraintSet>, insert a 'SizeConstraintSet' into a 'Rule'
+-- < UpdateSizeConstraintSet>), insert a 'SizeConstraintSet' into a 'Rule'
 -- or delete one from a 'Rule' (see < UpdateRule>), and delete a
 -- 'SizeConstraintSet' from AWS WAF (see < DeleteSizeConstraintSet>).
 --
@@ -1520,6 +1561,8 @@
 
 instance Hashable SizeConstraintSetSummary
 
+instance NFData SizeConstraintSetSummary
+
 -- | Specifies the part of a web request that you want to inspect the size of
 -- and indicates whether you want to add the specification to a
 -- < SizeConstraintSet> or delete it from a 'SizeConstraintSet'.
@@ -1563,6 +1606,8 @@
 
 instance Hashable SizeConstraintSetUpdate
 
+instance NFData SizeConstraintSetUpdate
+
 instance ToJSON SizeConstraintSetUpdate where
         toJSON SizeConstraintSetUpdate'{..}
           = object
@@ -1611,7 +1656,7 @@
 -- | A unique identifier for a 'SqlInjectionMatchSet'. You use
 -- 'SqlInjectionMatchSetId' to get information about a
 -- 'SqlInjectionMatchSet' (see < GetSqlInjectionMatchSet>), update a
--- 'SqlInjectionMatchSet' (see < UpdateSqlInjectionMatchSet>, insert a
+-- 'SqlInjectionMatchSet' (see < UpdateSqlInjectionMatchSet>), insert a
 -- 'SqlInjectionMatchSet' into a 'Rule' or delete one from a 'Rule' (see
 -- < UpdateRule>), and delete a 'SqlInjectionMatchSet' from AWS WAF (see
 -- < DeleteSqlInjectionMatchSet>).
@@ -1636,6 +1681,8 @@
 
 instance Hashable SqlInjectionMatchSet
 
+instance NFData SqlInjectionMatchSet
+
 -- | The 'Id' and 'Name' of a 'SqlInjectionMatchSet'.
 --
 -- /See:/ 'sqlInjectionMatchSetSummary' smart constructor.
@@ -1664,7 +1711,7 @@
 -- | A unique identifier for a 'SqlInjectionMatchSet'. You use
 -- 'SqlInjectionMatchSetId' to get information about a
 -- 'SqlInjectionMatchSet' (see < GetSqlInjectionMatchSet>), update a
--- 'SqlInjectionMatchSet' (see < UpdateSqlInjectionMatchSet>, insert a
+-- 'SqlInjectionMatchSet' (see < UpdateSqlInjectionMatchSet>), insert a
 -- 'SqlInjectionMatchSet' into a 'Rule' or delete one from a 'Rule' (see
 -- < UpdateRule>), and delete a 'SqlInjectionMatchSet' from AWS WAF (see
 -- < DeleteSqlInjectionMatchSet>).
@@ -1687,6 +1734,8 @@
 
 instance Hashable SqlInjectionMatchSetSummary
 
+instance NFData SqlInjectionMatchSetSummary
+
 -- | Specifies the part of a web request that you want to inspect for
 -- snippets of malicious SQL code and indicates whether you want to add the
 -- specification to a < SqlInjectionMatchSet> or delete it from a
@@ -1729,6 +1778,8 @@
 
 instance Hashable SqlInjectionMatchSetUpdate
 
+instance NFData SqlInjectionMatchSetUpdate
+
 instance ToJSON SqlInjectionMatchSetUpdate where
         toJSON SqlInjectionMatchSetUpdate'{..}
           = object
@@ -1839,6 +1890,8 @@
 
 instance Hashable SqlInjectionMatchTuple
 
+instance NFData SqlInjectionMatchTuple
+
 instance ToJSON SqlInjectionMatchTuple where
         toJSON SqlInjectionMatchTuple'{..}
           = object
@@ -1904,6 +1957,8 @@
 
 instance Hashable TimeWindow
 
+instance NFData TimeWindow
+
 instance ToJSON TimeWindow where
         toJSON TimeWindow'{..}
           = object
@@ -1954,6 +2009,8 @@
 
 instance Hashable WafAction
 
+instance NFData WafAction
+
 instance ToJSON WafAction where
         toJSON WafAction'{..}
           = object (catMaybes [Just ("Type" .= _waType)])
@@ -2014,7 +2071,7 @@
 
 -- | A unique identifier for a 'WebACL'. You use 'WebACLId' to get
 -- information about a 'WebACL' (see < GetWebACL>), update a 'WebACL' (see
--- < UpdateWebACL>, and delete a 'WebACL' from AWS WAF (see
+-- < UpdateWebACL>), and delete a 'WebACL' from AWS WAF (see
 -- < DeleteWebACL>).
 --
 -- 'WebACLId' is returned by < CreateWebACL> and by < ListWebACLs>.
@@ -2043,6 +2100,8 @@
 
 instance Hashable WebACL
 
+instance NFData WebACL
+
 -- | Contains the identifier and the name or description of the < WebACL>.
 --
 -- /See:/ 'webACLSummary' smart constructor.
@@ -2070,7 +2129,7 @@
 
 -- | A unique identifier for a 'WebACL'. You use 'WebACLId' to get
 -- information about a 'WebACL' (see < GetWebACL>), update a 'WebACL' (see
--- < UpdateWebACL>, and delete a 'WebACL' from AWS WAF (see
+-- < UpdateWebACL>), and delete a 'WebACL' from AWS WAF (see
 -- < DeleteWebACL>).
 --
 -- 'WebACLId' is returned by < CreateWebACL> and by < ListWebACLs>.
@@ -2091,6 +2150,8 @@
 
 instance Hashable WebACLSummary
 
+instance NFData WebACLSummary
+
 -- | Specifies whether to insert a 'Rule' into or delete a 'Rule' from a
 -- 'WebACL'.
 --
@@ -2128,9 +2189,287 @@
 
 instance Hashable WebACLUpdate
 
+instance NFData WebACLUpdate
+
 instance ToJSON WebACLUpdate where
         toJSON WebACLUpdate'{..}
           = object
               (catMaybes
                  [Just ("Action" .= _wauAction),
                   Just ("ActivatedRule" .= _wauActivatedRule)])
+
+-- | A complex type that contains 'XssMatchTuple' objects, which specify the
+-- parts of web requests that you want AWS WAF to inspect for cross-site
+-- scripting attacks and, if you want AWS WAF to inspect a header, the name
+-- of the header. If a 'XssMatchSet' contains more than one 'XssMatchTuple'
+-- object, a request needs to include cross-site scripting attacks in only
+-- one of the specified parts of the request to be considered a match.
+--
+-- /See:/ 'xssMatchSet' smart constructor.
+data XSSMatchSet = XSSMatchSet'
+    { _xmsName           :: !(Maybe Text)
+    , _xmsXSSMatchSetId  :: !Text
+    , _xmsXSSMatchTuples :: ![XSSMatchTuple]
+    } deriving (Eq,Read,Show,Data,Typeable,Generic)
+
+-- | Creates a value of 'XSSMatchSet' with the minimum fields required to make a request.
+--
+-- Use one of the following lenses to modify other fields as desired:
+--
+-- * 'xmsName'
+--
+-- * 'xmsXSSMatchSetId'
+--
+-- * 'xmsXSSMatchTuples'
+xssMatchSet
+    :: Text -- ^ 'xmsXSSMatchSetId'
+    -> XSSMatchSet
+xssMatchSet pXSSMatchSetId_ =
+    XSSMatchSet'
+    { _xmsName = Nothing
+    , _xmsXSSMatchSetId = pXSSMatchSetId_
+    , _xmsXSSMatchTuples = mempty
+    }
+
+-- | The name, if any, of the 'XssMatchSet'.
+xmsName :: Lens' XSSMatchSet (Maybe Text)
+xmsName = lens _xmsName (\ s a -> s{_xmsName = a});
+
+-- | A unique identifier for an 'XssMatchSet'. You use 'XssMatchSetId' to get
+-- information about an 'XssMatchSet' (see < GetXssMatchSet>), update an
+-- 'XssMatchSet' (see < UpdateXssMatchSet>), insert an 'XssMatchSet' into a
+-- 'Rule' or delete one from a 'Rule' (see < UpdateRule>), and delete an
+-- 'XssMatchSet' from AWS WAF (see < DeleteXssMatchSet>).
+--
+-- 'XssMatchSetId' is returned by < CreateXssMatchSet> and by
+-- < ListXssMatchSets>.
+xmsXSSMatchSetId :: Lens' XSSMatchSet Text
+xmsXSSMatchSetId = lens _xmsXSSMatchSetId (\ s a -> s{_xmsXSSMatchSetId = a});
+
+-- | Specifies the parts of web requests that you want to inspect for
+-- cross-site scripting attacks.
+xmsXSSMatchTuples :: Lens' XSSMatchSet [XSSMatchTuple]
+xmsXSSMatchTuples = lens _xmsXSSMatchTuples (\ s a -> s{_xmsXSSMatchTuples = a}) . _Coerce;
+
+instance FromJSON XSSMatchSet where
+        parseJSON
+          = withObject "XSSMatchSet"
+              (\ x ->
+                 XSSMatchSet' <$>
+                   (x .:? "Name") <*> (x .: "XssMatchSetId") <*>
+                     (x .:? "XssMatchTuples" .!= mempty))
+
+instance Hashable XSSMatchSet
+
+instance NFData XSSMatchSet
+
+-- | The 'Id' and 'Name' of an 'XssMatchSet'.
+--
+-- /See:/ 'xssMatchSetSummary' smart constructor.
+data XSSMatchSetSummary = XSSMatchSetSummary'
+    { _xmssXSSMatchSetId :: !Text
+    , _xmssName          :: !Text
+    } deriving (Eq,Read,Show,Data,Typeable,Generic)
+
+-- | Creates a value of 'XSSMatchSetSummary' with the minimum fields required to make a request.
+--
+-- Use one of the following lenses to modify other fields as desired:
+--
+-- * 'xmssXSSMatchSetId'
+--
+-- * 'xmssName'
+xssMatchSetSummary
+    :: Text -- ^ 'xmssXSSMatchSetId'
+    -> Text -- ^ 'xmssName'
+    -> XSSMatchSetSummary
+xssMatchSetSummary pXSSMatchSetId_ pName_ =
+    XSSMatchSetSummary'
+    { _xmssXSSMatchSetId = pXSSMatchSetId_
+    , _xmssName = pName_
+    }
+
+-- | A unique identifier for an 'XssMatchSet'. You use 'XssMatchSetId' to get
+-- information about a 'XssMatchSet' (see < GetXssMatchSet>), update an
+-- 'XssMatchSet' (see < UpdateXssMatchSet>), insert an 'XssMatchSet' into a
+-- 'Rule' or delete one from a 'Rule' (see < UpdateRule>), and delete an
+-- 'XssMatchSet' from AWS WAF (see < DeleteXssMatchSet>).
+--
+-- 'XssMatchSetId' is returned by < CreateXssMatchSet> and by
+-- < ListXssMatchSets>.
+xmssXSSMatchSetId :: Lens' XSSMatchSetSummary Text
+xmssXSSMatchSetId = lens _xmssXSSMatchSetId (\ s a -> s{_xmssXSSMatchSetId = a});
+
+-- | The name of the 'XssMatchSet', if any, specified by 'Id'.
+xmssName :: Lens' XSSMatchSetSummary Text
+xmssName = lens _xmssName (\ s a -> s{_xmssName = a});
+
+instance FromJSON XSSMatchSetSummary where
+        parseJSON
+          = withObject "XSSMatchSetSummary"
+              (\ x ->
+                 XSSMatchSetSummary' <$>
+                   (x .: "XssMatchSetId") <*> (x .: "Name"))
+
+instance Hashable XSSMatchSetSummary
+
+instance NFData XSSMatchSetSummary
+
+-- | Specifies the part of a web request that you want to inspect for
+-- cross-site scripting attacks and indicates whether you want to add the
+-- specification to an < XssMatchSet> or delete it from an 'XssMatchSet'.
+--
+-- /See:/ 'xssMatchSetUpdate' smart constructor.
+data XSSMatchSetUpdate = XSSMatchSetUpdate'
+    { _xmsuAction        :: !ChangeAction
+    , _xmsuXSSMatchTuple :: !XSSMatchTuple
+    } deriving (Eq,Read,Show,Data,Typeable,Generic)
+
+-- | Creates a value of 'XSSMatchSetUpdate' with the minimum fields required to make a request.
+--
+-- Use one of the following lenses to modify other fields as desired:
+--
+-- * 'xmsuAction'
+--
+-- * 'xmsuXSSMatchTuple'
+xssMatchSetUpdate
+    :: ChangeAction -- ^ 'xmsuAction'
+    -> XSSMatchTuple -- ^ 'xmsuXSSMatchTuple'
+    -> XSSMatchSetUpdate
+xssMatchSetUpdate pAction_ pXSSMatchTuple_ =
+    XSSMatchSetUpdate'
+    { _xmsuAction = pAction_
+    , _xmsuXSSMatchTuple = pXSSMatchTuple_
+    }
+
+-- | Specify 'INSERT' to add a < XssMatchSetUpdate> to an < XssMatchSet>. Use
+-- 'DELETE' to remove a 'XssMatchSetUpdate' from an 'XssMatchSet'.
+xmsuAction :: Lens' XSSMatchSetUpdate ChangeAction
+xmsuAction = lens _xmsuAction (\ s a -> s{_xmsuAction = a});
+
+-- | Specifies the part of a web request that you want AWS WAF to inspect for
+-- cross-site scripting attacks and, if you want AWS WAF to inspect a
+-- header, the name of the header.
+xmsuXSSMatchTuple :: Lens' XSSMatchSetUpdate XSSMatchTuple
+xmsuXSSMatchTuple = lens _xmsuXSSMatchTuple (\ s a -> s{_xmsuXSSMatchTuple = a});
+
+instance Hashable XSSMatchSetUpdate
+
+instance NFData XSSMatchSetUpdate
+
+instance ToJSON XSSMatchSetUpdate where
+        toJSON XSSMatchSetUpdate'{..}
+          = object
+              (catMaybes
+                 [Just ("Action" .= _xmsuAction),
+                  Just ("XssMatchTuple" .= _xmsuXSSMatchTuple)])
+
+-- | Specifies the part of a web request that you want AWS WAF to inspect for
+-- cross-site scripting attacks and, if you want AWS WAF to inspect a
+-- header, the name of the header.
+--
+-- /See:/ 'xssMatchTuple' smart constructor.
+data XSSMatchTuple = XSSMatchTuple'
+    { _xmtFieldToMatch       :: !FieldToMatch
+    , _xmtTextTransformation :: !TextTransformation
+    } deriving (Eq,Read,Show,Data,Typeable,Generic)
+
+-- | Creates a value of 'XSSMatchTuple' with the minimum fields required to make a request.
+--
+-- Use one of the following lenses to modify other fields as desired:
+--
+-- * 'xmtFieldToMatch'
+--
+-- * 'xmtTextTransformation'
+xssMatchTuple
+    :: FieldToMatch -- ^ 'xmtFieldToMatch'
+    -> TextTransformation -- ^ 'xmtTextTransformation'
+    -> XSSMatchTuple
+xssMatchTuple pFieldToMatch_ pTextTransformation_ =
+    XSSMatchTuple'
+    { _xmtFieldToMatch = pFieldToMatch_
+    , _xmtTextTransformation = pTextTransformation_
+    }
+
+-- | Undocumented member.
+xmtFieldToMatch :: Lens' XSSMatchTuple FieldToMatch
+xmtFieldToMatch = lens _xmtFieldToMatch (\ s a -> s{_xmtFieldToMatch = a});
+
+-- | Text transformations eliminate some of the unusual formatting that
+-- attackers use in web requests in an effort to bypass AWS WAF. If you
+-- specify a transformation, AWS WAF performs the transformation on
+-- 'FieldToMatch' before inspecting a request for a match.
+--
+-- __CMD_LINE__
+--
+-- When you\'re concerned that attackers are injecting an operating system
+-- commandline command and using unusual formatting to disguise some or all
+-- of the command, use this option to perform the following
+-- transformations:
+--
+-- -   Delete the following characters: \\ \" \' ^
+-- -   Delete spaces before the following characters: \/ (
+-- -   Replace the following characters with a space: , ;
+-- -   Replace multiple spaces with one space
+-- -   Convert uppercase letters (A-Z) to lowercase (a-z)
+--
+-- __COMPRESS_WHITE_SPACE__
+--
+-- Use this option to replace the following characters with a space
+-- character (decimal 32):
+--
+-- -   \\f, formfeed, decimal 12
+-- -   \\t, tab, decimal 9
+-- -   \\n, newline, decimal 10
+-- -   \\r, carriage return, decimal 13
+-- -   \\v, vertical tab, decimal 11
+-- -   non-breaking space, decimal 160
+--
+-- 'COMPRESS_WHITE_SPACE' also replaces multiple spaces with one space.
+--
+-- __HTML_ENTITY_DECODE__
+--
+-- Use this option to replace HTML-encoded characters with unencoded
+-- characters. 'HTML_ENTITY_DECODE' performs the following operations:
+--
+-- -   Replaces '(ampersand)quot;' with '\"'
+-- -   Replaces '(ampersand)nbsp;' with a non-breaking space, decimal 160
+-- -   Replaces '(ampersand)lt;' with a \"less than\" symbol
+-- -   Replaces '(ampersand)gt;' with '>'
+-- -   Replaces characters that are represented in hexadecimal format,
+--     '(ampersand)#xhhhh;', with the corresponding characters
+-- -   Replaces characters that are represented in decimal format,
+--     '(ampersand)#nnnn;', with the corresponding characters
+--
+-- __LOWERCASE__
+--
+-- Use this option to convert uppercase letters (A-Z) to lowercase (a-z).
+--
+-- __URL_DECODE__
+--
+-- Use this option to decode a URL-encoded value.
+--
+-- __NONE__
+--
+-- Specify 'NONE' if you don\'t want to perform any text transformations.
+xmtTextTransformation :: Lens' XSSMatchTuple TextTransformation
+xmtTextTransformation = lens _xmtTextTransformation (\ s a -> s{_xmtTextTransformation = a});
+
+instance FromJSON XSSMatchTuple where
+        parseJSON
+          = withObject "XSSMatchTuple"
+              (\ x ->
+                 XSSMatchTuple' <$>
+                   (x .: "FieldToMatch") <*>
+                     (x .: "TextTransformation"))
+
+instance Hashable XSSMatchTuple
+
+instance NFData XSSMatchTuple
+
+instance ToJSON XSSMatchTuple where
+        toJSON XSSMatchTuple'{..}
+          = object
+              (catMaybes
+                 [Just ("FieldToMatch" .= _xmtFieldToMatch),
+                  Just
+                    ("TextTransformation" .= _xmtTextTransformation)])
diff --git a/gen/Network/AWS/WAF/Types/Sum.hs b/gen/Network/AWS/WAF/Types/Sum.hs
--- a/gen/Network/AWS/WAF/Types/Sum.hs
+++ b/gen/Network/AWS/WAF/Types/Sum.hs
@@ -37,6 +37,7 @@
         Insert -> "INSERT"
 
 instance Hashable     ChangeAction
+instance NFData       ChangeAction
 instance ToByteString ChangeAction
 instance ToQuery      ChangeAction
 instance ToHeader     ChangeAction
@@ -65,6 +66,7 @@
         Provisioned -> "PROVISIONED"
 
 instance Hashable     ChangeTokenStatus
+instance NFData       ChangeTokenStatus
 instance ToByteString ChangeTokenStatus
 instance ToQuery      ChangeTokenStatus
 instance ToHeader     ChangeTokenStatus
@@ -102,6 +104,7 @@
         NE -> "NE"
 
 instance Hashable     ComparisonOperator
+instance NFData       ComparisonOperator
 instance ToByteString ComparisonOperator
 instance ToQuery      ComparisonOperator
 instance ToHeader     ComparisonOperator
@@ -127,6 +130,7 @@
         IPV4 -> "IPV4"
 
 instance Hashable     IPSetDescriptorType
+instance NFData       IPSetDescriptorType
 instance ToByteString IPSetDescriptorType
 instance ToQuery      IPSetDescriptorType
 instance ToHeader     IPSetDescriptorType
@@ -164,6 +168,7 @@
         URI -> "URI"
 
 instance Hashable     MatchFieldType
+instance NFData       MatchFieldType
 instance ToByteString MatchFieldType
 instance ToQuery      MatchFieldType
 instance ToHeader     MatchFieldType
@@ -201,6 +206,7 @@
         StartsWith -> "STARTS_WITH"
 
 instance Hashable     PositionalConstraint
+instance NFData       PositionalConstraint
 instance ToByteString PositionalConstraint
 instance ToQuery      PositionalConstraint
 instance ToHeader     PositionalConstraint
@@ -216,6 +222,7 @@
     | IPMatch
     | SizeConstraint
     | SqlInjectionMatch
+    | XSSMatch
     deriving (Eq,Ord,Read,Show,Enum,Bounded,Data,Typeable,Generic)
 
 instance FromText PredicateType where
@@ -224,8 +231,9 @@
         "ipmatch" -> pure IPMatch
         "sizeconstraint" -> pure SizeConstraint
         "sqlinjectionmatch" -> pure SqlInjectionMatch
+        "xssmatch" -> pure XSSMatch
         e -> fromTextError $ "Failure parsing PredicateType from value: '" <> e
-           <> "'. Accepted values: ByteMatch, IPMatch, SizeConstraint, SqlInjectionMatch"
+           <> "'. Accepted values: ByteMatch, IPMatch, SizeConstraint, SqlInjectionMatch, XssMatch"
 
 instance ToText PredicateType where
     toText = \case
@@ -233,8 +241,10 @@
         IPMatch -> "IPMatch"
         SizeConstraint -> "SizeConstraint"
         SqlInjectionMatch -> "SqlInjectionMatch"
+        XSSMatch -> "XssMatch"
 
 instance Hashable     PredicateType
+instance NFData       PredicateType
 instance ToByteString PredicateType
 instance ToQuery      PredicateType
 instance ToHeader     PredicateType
@@ -275,6 +285,7 @@
         URLDecode -> "URL_DECODE"
 
 instance Hashable     TextTransformation
+instance NFData       TextTransformation
 instance ToByteString TextTransformation
 instance ToQuery      TextTransformation
 instance ToHeader     TextTransformation
@@ -306,6 +317,7 @@
         Count -> "COUNT"
 
 instance Hashable     WafActionType
+instance NFData       WafActionType
 instance ToByteString WafActionType
 instance ToQuery      WafActionType
 instance ToHeader     WafActionType
diff --git a/gen/Network/AWS/WAF/UpdateByteMatchSet.hs b/gen/Network/AWS/WAF/UpdateByteMatchSet.hs
--- a/gen/Network/AWS/WAF/UpdateByteMatchSet.hs
+++ b/gen/Network/AWS/WAF/UpdateByteMatchSet.hs
@@ -139,6 +139,8 @@
 
 instance Hashable UpdateByteMatchSet
 
+instance NFData UpdateByteMatchSet
+
 instance ToHeaders UpdateByteMatchSet where
         toHeaders
           = const
@@ -193,3 +195,5 @@
 -- | The response status code.
 ubmsrsResponseStatus :: Lens' UpdateByteMatchSetResponse Int
 ubmsrsResponseStatus = lens _ubmsrsResponseStatus (\ s a -> s{_ubmsrsResponseStatus = a});
+
+instance NFData UpdateByteMatchSetResponse
diff --git a/gen/Network/AWS/WAF/UpdateIPSet.hs b/gen/Network/AWS/WAF/UpdateIPSet.hs
--- a/gen/Network/AWS/WAF/UpdateIPSet.hs
+++ b/gen/Network/AWS/WAF/UpdateIPSet.hs
@@ -136,6 +136,8 @@
 
 instance Hashable UpdateIPSet
 
+instance NFData UpdateIPSet
+
 instance ToHeaders UpdateIPSet where
         toHeaders
           = const
@@ -190,3 +192,5 @@
 -- | The response status code.
 uisrsResponseStatus :: Lens' UpdateIPSetResponse Int
 uisrsResponseStatus = lens _uisrsResponseStatus (\ s a -> s{_uisrsResponseStatus = a});
+
+instance NFData UpdateIPSetResponse
diff --git a/gen/Network/AWS/WAF/UpdateRule.hs b/gen/Network/AWS/WAF/UpdateRule.hs
--- a/gen/Network/AWS/WAF/UpdateRule.hs
+++ b/gen/Network/AWS/WAF/UpdateRule.hs
@@ -132,6 +132,8 @@
 
 instance Hashable UpdateRule
 
+instance NFData UpdateRule
+
 instance ToHeaders UpdateRule where
         toHeaders
           = const
@@ -186,3 +188,5 @@
 -- | The response status code.
 urrsResponseStatus :: Lens' UpdateRuleResponse Int
 urrsResponseStatus = lens _urrsResponseStatus (\ s a -> s{_urrsResponseStatus = a});
+
+instance NFData UpdateRuleResponse
diff --git a/gen/Network/AWS/WAF/UpdateSizeConstraintSet.hs b/gen/Network/AWS/WAF/UpdateSizeConstraintSet.hs
--- a/gen/Network/AWS/WAF/UpdateSizeConstraintSet.hs
+++ b/gen/Network/AWS/WAF/UpdateSizeConstraintSet.hs
@@ -143,6 +143,8 @@
 
 instance Hashable UpdateSizeConstraintSet
 
+instance NFData UpdateSizeConstraintSet
+
 instance ToHeaders UpdateSizeConstraintSet where
         toHeaders
           = const
@@ -199,3 +201,5 @@
 -- | The response status code.
 uscsrsResponseStatus :: Lens' UpdateSizeConstraintSetResponse Int
 uscsrsResponseStatus = lens _uscsrsResponseStatus (\ s a -> s{_uscsrsResponseStatus = a});
+
+instance NFData UpdateSizeConstraintSetResponse
diff --git a/gen/Network/AWS/WAF/UpdateSqlInjectionMatchSet.hs b/gen/Network/AWS/WAF/UpdateSqlInjectionMatchSet.hs
--- a/gen/Network/AWS/WAF/UpdateSqlInjectionMatchSet.hs
+++ b/gen/Network/AWS/WAF/UpdateSqlInjectionMatchSet.hs
@@ -140,6 +140,8 @@
 
 instance Hashable UpdateSqlInjectionMatchSet
 
+instance NFData UpdateSqlInjectionMatchSet
+
 instance ToHeaders UpdateSqlInjectionMatchSet where
         toHeaders
           = const
@@ -200,3 +202,5 @@
 -- | The response status code.
 usimsrsResponseStatus :: Lens' UpdateSqlInjectionMatchSetResponse Int
 usimsrsResponseStatus = lens _usimsrsResponseStatus (\ s a -> s{_usimsrsResponseStatus = a});
+
+instance NFData UpdateSqlInjectionMatchSetResponse
diff --git a/gen/Network/AWS/WAF/UpdateWebACL.hs b/gen/Network/AWS/WAF/UpdateWebACL.hs
--- a/gen/Network/AWS/WAF/UpdateWebACL.hs
+++ b/gen/Network/AWS/WAF/UpdateWebACL.hs
@@ -153,6 +153,8 @@
 
 instance Hashable UpdateWebACL
 
+instance NFData UpdateWebACL
+
 instance ToHeaders UpdateWebACL where
         toHeaders
           = const
@@ -208,3 +210,5 @@
 -- | The response status code.
 uwarsResponseStatus :: Lens' UpdateWebACLResponse Int
 uwarsResponseStatus = lens _uwarsResponseStatus (\ s a -> s{_uwarsResponseStatus = a});
+
+instance NFData UpdateWebACLResponse
diff --git a/gen/Network/AWS/WAF/UpdateXSSMatchSet.hs b/gen/Network/AWS/WAF/UpdateXSSMatchSet.hs
new file mode 100644
--- /dev/null
+++ b/gen/Network/AWS/WAF/UpdateXSSMatchSet.hs
@@ -0,0 +1,198 @@
+{-# LANGUAGE DeriveDataTypeable #-}
+{-# LANGUAGE DeriveGeneric      #-}
+{-# LANGUAGE OverloadedStrings  #-}
+{-# LANGUAGE RecordWildCards    #-}
+{-# LANGUAGE TypeFamilies       #-}
+
+{-# OPTIONS_GHC -fno-warn-unused-imports #-}
+{-# OPTIONS_GHC -fno-warn-unused-binds   #-}
+{-# OPTIONS_GHC -fno-warn-unused-matches #-}
+
+-- Derived from AWS service descriptions, licensed under Apache 2.0.
+
+-- |
+-- Module      : Network.AWS.WAF.UpdateXSSMatchSet
+-- Copyright   : (c) 2013-2016 Brendan Hay
+-- License     : Mozilla Public License, v. 2.0.
+-- Maintainer  : Brendan Hay <brendan.g.hay@gmail.com>
+-- Stability   : auto-generated
+-- Portability : non-portable (GHC extensions)
+--
+-- Inserts or deletes < XssMatchTuple> objects (filters) in an
+-- < XssMatchSet>. For each 'XssMatchTuple' object, you specify the
+-- following values:
+--
+-- -   'Action': Whether to insert the object into or delete the object
+--     from the array. To change a 'XssMatchTuple', you delete the existing
+--     object and add a new one.
+-- -   'FieldToMatch': The part of web requests that you want AWS WAF to
+--     inspect and, if you want AWS WAF to inspect a header, the name of
+--     the header.
+-- -   'TextTransformation': Which text transformation, if any, to perform
+--     on the web request before inspecting the request for cross-site
+--     scripting attacks.
+--
+-- You use 'XssMatchSet' objects to specify which CloudFront requests you
+-- want to allow, block, or count. For example, if you\'re receiving
+-- requests that contain cross-site scripting attacks in the request body
+-- and you want to block the requests, you can create an 'XssMatchSet' with
+-- the applicable settings, and then configure AWS WAF to block the
+-- requests.
+--
+-- To create and configure an 'XssMatchSet', perform the following steps:
+--
+-- 1.  Submit a < CreateXssMatchSet> request.
+-- 2.  Use < GetChangeToken> to get the change token that you provide in
+--     the 'ChangeToken' parameter of an < UpdateIPSet> request.
+-- 3.  Submit an 'UpdateXssMatchSet' request to specify the parts of web
+--     requests that you want AWS WAF to inspect for cross-site scripting
+--     attacks.
+--
+-- For more information about how to use the AWS WAF API to allow or block
+-- HTTP requests, see the
+-- <http://docs.aws.amazon.com/waf/latest/developerguide/ AWS WAF Developer Guide>.
+module Network.AWS.WAF.UpdateXSSMatchSet
+    (
+    -- * Creating a Request
+      updateXSSMatchSet
+    , UpdateXSSMatchSet
+    -- * Request Lenses
+    , uxmsXSSMatchSetId
+    , uxmsChangeToken
+    , uxmsUpdates
+
+    -- * Destructuring the Response
+    , updateXSSMatchSetResponse
+    , UpdateXSSMatchSetResponse
+    -- * Response Lenses
+    , uxmsrsChangeToken
+    , uxmsrsResponseStatus
+    ) where
+
+import           Network.AWS.Lens
+import           Network.AWS.Prelude
+import           Network.AWS.Request
+import           Network.AWS.Response
+import           Network.AWS.WAF.Types
+import           Network.AWS.WAF.Types.Product
+
+-- | A request to update an < XssMatchSet>.
+--
+-- /See:/ 'updateXSSMatchSet' smart constructor.
+data UpdateXSSMatchSet = UpdateXSSMatchSet'
+    { _uxmsXSSMatchSetId :: !Text
+    , _uxmsChangeToken   :: !Text
+    , _uxmsUpdates       :: ![XSSMatchSetUpdate]
+    } deriving (Eq,Read,Show,Data,Typeable,Generic)
+
+-- | Creates a value of 'UpdateXSSMatchSet' with the minimum fields required to make a request.
+--
+-- Use one of the following lenses to modify other fields as desired:
+--
+-- * 'uxmsXSSMatchSetId'
+--
+-- * 'uxmsChangeToken'
+--
+-- * 'uxmsUpdates'
+updateXSSMatchSet
+    :: Text -- ^ 'uxmsXSSMatchSetId'
+    -> Text -- ^ 'uxmsChangeToken'
+    -> UpdateXSSMatchSet
+updateXSSMatchSet pXSSMatchSetId_ pChangeToken_ =
+    UpdateXSSMatchSet'
+    { _uxmsXSSMatchSetId = pXSSMatchSetId_
+    , _uxmsChangeToken = pChangeToken_
+    , _uxmsUpdates = mempty
+    }
+
+-- | The 'XssMatchSetId' of the 'XssMatchSet' that you want to update.
+-- 'XssMatchSetId' is returned by < CreateXssMatchSet> and by
+-- < ListXssMatchSets>.
+uxmsXSSMatchSetId :: Lens' UpdateXSSMatchSet Text
+uxmsXSSMatchSetId = lens _uxmsXSSMatchSetId (\ s a -> s{_uxmsXSSMatchSetId = a});
+
+-- | The value returned by the most recent call to < GetChangeToken>.
+uxmsChangeToken :: Lens' UpdateXSSMatchSet Text
+uxmsChangeToken = lens _uxmsChangeToken (\ s a -> s{_uxmsChangeToken = a});
+
+-- | An array of 'XssMatchSetUpdate' objects that you want to insert into or
+-- delete from a < XssMatchSet>. For more information, see the applicable
+-- data types:
+--
+-- -   < XssMatchSetUpdate>: Contains 'Action' and 'XssMatchTuple'
+-- -   < XssMatchTuple>: Contains 'FieldToMatch' and 'TextTransformation'
+-- -   < FieldToMatch>: Contains 'Data' and 'Type'
+uxmsUpdates :: Lens' UpdateXSSMatchSet [XSSMatchSetUpdate]
+uxmsUpdates = lens _uxmsUpdates (\ s a -> s{_uxmsUpdates = a}) . _Coerce;
+
+instance AWSRequest UpdateXSSMatchSet where
+        type Rs UpdateXSSMatchSet = UpdateXSSMatchSetResponse
+        request = postJSON waf
+        response
+          = receiveJSON
+              (\ s h x ->
+                 UpdateXSSMatchSetResponse' <$>
+                   (x .?> "ChangeToken") <*> (pure (fromEnum s)))
+
+instance Hashable UpdateXSSMatchSet
+
+instance NFData UpdateXSSMatchSet
+
+instance ToHeaders UpdateXSSMatchSet where
+        toHeaders
+          = const
+              (mconcat
+                 ["X-Amz-Target" =#
+                    ("AWSWAF_20150824.UpdateXssMatchSet" :: ByteString),
+                  "Content-Type" =#
+                    ("application/x-amz-json-1.1" :: ByteString)])
+
+instance ToJSON UpdateXSSMatchSet where
+        toJSON UpdateXSSMatchSet'{..}
+          = object
+              (catMaybes
+                 [Just ("XssMatchSetId" .= _uxmsXSSMatchSetId),
+                  Just ("ChangeToken" .= _uxmsChangeToken),
+                  Just ("Updates" .= _uxmsUpdates)])
+
+instance ToPath UpdateXSSMatchSet where
+        toPath = const "/"
+
+instance ToQuery UpdateXSSMatchSet where
+        toQuery = const mempty
+
+-- | The response to an < UpdateXssMatchSets> request.
+--
+-- /See:/ 'updateXSSMatchSetResponse' smart constructor.
+data UpdateXSSMatchSetResponse = UpdateXSSMatchSetResponse'
+    { _uxmsrsChangeToken    :: !(Maybe Text)
+    , _uxmsrsResponseStatus :: !Int
+    } deriving (Eq,Read,Show,Data,Typeable,Generic)
+
+-- | Creates a value of 'UpdateXSSMatchSetResponse' with the minimum fields required to make a request.
+--
+-- Use one of the following lenses to modify other fields as desired:
+--
+-- * 'uxmsrsChangeToken'
+--
+-- * 'uxmsrsResponseStatus'
+updateXSSMatchSetResponse
+    :: Int -- ^ 'uxmsrsResponseStatus'
+    -> UpdateXSSMatchSetResponse
+updateXSSMatchSetResponse pResponseStatus_ =
+    UpdateXSSMatchSetResponse'
+    { _uxmsrsChangeToken = Nothing
+    , _uxmsrsResponseStatus = pResponseStatus_
+    }
+
+-- | The 'ChangeToken' that you used to submit the 'UpdateXssMatchSet'
+-- request. You can also use this value to query the status of the request.
+-- For more information, see < GetChangeTokenStatus>.
+uxmsrsChangeToken :: Lens' UpdateXSSMatchSetResponse (Maybe Text)
+uxmsrsChangeToken = lens _uxmsrsChangeToken (\ s a -> s{_uxmsrsChangeToken = a});
+
+-- | The response status code.
+uxmsrsResponseStatus :: Lens' UpdateXSSMatchSetResponse Int
+uxmsrsResponseStatus = lens _uxmsrsResponseStatus (\ s a -> s{_uxmsrsResponseStatus = a});
+
+instance NFData UpdateXSSMatchSetResponse
diff --git a/test/Test/AWS/Gen/WAF.hs b/test/Test/AWS/Gen/WAF.hs
--- a/test/Test/AWS/Gen/WAF.hs
+++ b/test/Test/AWS/Gen/WAF.hs
@@ -73,6 +73,15 @@
 --         , testGetRule $
 --             getRule
 --
+--         , testDeleteXSSMatchSet $
+--             deleteXSSMatchSet
+--
+--         , testUpdateXSSMatchSet $
+--             updateXSSMatchSet
+--
+--         , testListXSSMatchSets $
+--             listXSSMatchSets
+--
 --         , testGetChangeToken $
 --             getChangeToken
 --
@@ -88,6 +97,9 @@
 --         , testCreateSqlInjectionMatchSet $
 --             createSqlInjectionMatchSet
 --
+--         , testGetXSSMatchSet $
+--             getXSSMatchSet
+--
 --         , testCreateByteMatchSet $
 --             createByteMatchSet
 --
@@ -106,6 +118,9 @@
 --         , testListIPSets $
 --             listIPSets
 --
+--         , testCreateXSSMatchSet $
+--             createXSSMatchSet
+--
 --         , testGetByteMatchSet $
 --             getByteMatchSet
 --
@@ -175,6 +190,15 @@
 --         , testGetRuleResponse $
 --             getRuleResponse
 --
+--         , testDeleteXSSMatchSetResponse $
+--             deleteXSSMatchSetResponse
+--
+--         , testUpdateXSSMatchSetResponse $
+--             updateXSSMatchSetResponse
+--
+--         , testListXSSMatchSetsResponse $
+--             listXSSMatchSetsResponse
+--
 --         , testGetChangeTokenResponse $
 --             getChangeTokenResponse
 --
@@ -190,6 +214,9 @@
 --         , testCreateSqlInjectionMatchSetResponse $
 --             createSqlInjectionMatchSetResponse
 --
+--         , testGetXSSMatchSetResponse $
+--             getXSSMatchSetResponse
+--
 --         , testCreateByteMatchSetResponse $
 --             createByteMatchSetResponse
 --
@@ -208,6 +235,9 @@
 --         , testListIPSetsResponse $
 --             listIPSetsResponse
 --
+--         , testCreateXSSMatchSetResponse $
+--             createXSSMatchSetResponse
+--
 --         , testGetByteMatchSetResponse $
 --             getByteMatchSetResponse
 --
@@ -309,6 +339,21 @@
     "GetRule"
     "fixture/GetRule.yaml"
 
+testDeleteXSSMatchSet :: DeleteXSSMatchSet -> TestTree
+testDeleteXSSMatchSet = req
+    "DeleteXSSMatchSet"
+    "fixture/DeleteXSSMatchSet.yaml"
+
+testUpdateXSSMatchSet :: UpdateXSSMatchSet -> TestTree
+testUpdateXSSMatchSet = req
+    "UpdateXSSMatchSet"
+    "fixture/UpdateXSSMatchSet.yaml"
+
+testListXSSMatchSets :: ListXSSMatchSets -> TestTree
+testListXSSMatchSets = req
+    "ListXSSMatchSets"
+    "fixture/ListXSSMatchSets.yaml"
+
 testGetChangeToken :: GetChangeToken -> TestTree
 testGetChangeToken = req
     "GetChangeToken"
@@ -334,6 +379,11 @@
     "CreateSqlInjectionMatchSet"
     "fixture/CreateSqlInjectionMatchSet.yaml"
 
+testGetXSSMatchSet :: GetXSSMatchSet -> TestTree
+testGetXSSMatchSet = req
+    "GetXSSMatchSet"
+    "fixture/GetXSSMatchSet.yaml"
+
 testCreateByteMatchSet :: CreateByteMatchSet -> TestTree
 testCreateByteMatchSet = req
     "CreateByteMatchSet"
@@ -364,6 +414,11 @@
     "ListIPSets"
     "fixture/ListIPSets.yaml"
 
+testCreateXSSMatchSet :: CreateXSSMatchSet -> TestTree
+testCreateXSSMatchSet = req
+    "CreateXSSMatchSet"
+    "fixture/CreateXSSMatchSet.yaml"
+
 testGetByteMatchSet :: GetByteMatchSet -> TestTree
 testGetByteMatchSet = req
     "GetByteMatchSet"
@@ -506,6 +561,27 @@
     waf
     (Proxy :: Proxy GetRule)
 
+testDeleteXSSMatchSetResponse :: DeleteXSSMatchSetResponse -> TestTree
+testDeleteXSSMatchSetResponse = res
+    "DeleteXSSMatchSetResponse"
+    "fixture/DeleteXSSMatchSetResponse.proto"
+    waf
+    (Proxy :: Proxy DeleteXSSMatchSet)
+
+testUpdateXSSMatchSetResponse :: UpdateXSSMatchSetResponse -> TestTree
+testUpdateXSSMatchSetResponse = res
+    "UpdateXSSMatchSetResponse"
+    "fixture/UpdateXSSMatchSetResponse.proto"
+    waf
+    (Proxy :: Proxy UpdateXSSMatchSet)
+
+testListXSSMatchSetsResponse :: ListXSSMatchSetsResponse -> TestTree
+testListXSSMatchSetsResponse = res
+    "ListXSSMatchSetsResponse"
+    "fixture/ListXSSMatchSetsResponse.proto"
+    waf
+    (Proxy :: Proxy ListXSSMatchSets)
+
 testGetChangeTokenResponse :: GetChangeTokenResponse -> TestTree
 testGetChangeTokenResponse = res
     "GetChangeTokenResponse"
@@ -541,6 +617,13 @@
     waf
     (Proxy :: Proxy CreateSqlInjectionMatchSet)
 
+testGetXSSMatchSetResponse :: GetXSSMatchSetResponse -> TestTree
+testGetXSSMatchSetResponse = res
+    "GetXSSMatchSetResponse"
+    "fixture/GetXSSMatchSetResponse.proto"
+    waf
+    (Proxy :: Proxy GetXSSMatchSet)
+
 testCreateByteMatchSetResponse :: CreateByteMatchSetResponse -> TestTree
 testCreateByteMatchSetResponse = res
     "CreateByteMatchSetResponse"
@@ -582,6 +665,13 @@
     "fixture/ListIPSetsResponse.proto"
     waf
     (Proxy :: Proxy ListIPSets)
+
+testCreateXSSMatchSetResponse :: CreateXSSMatchSetResponse -> TestTree
+testCreateXSSMatchSetResponse = res
+    "CreateXSSMatchSetResponse"
+    "fixture/CreateXSSMatchSetResponse.proto"
+    waf
+    (Proxy :: Proxy CreateXSSMatchSet)
 
 testGetByteMatchSetResponse :: GetByteMatchSetResponse -> TestTree
 testGetByteMatchSetResponse = res
