ModSecurity Solutions

ModSecurity Rules for Azure, AWS, WordPress, and Kubernetes Environments

Atomicorp develops and provides ModSecurity solution technology, ModSecurity Rules for large and complex implementations, and advanced ModSecurity- and libmodsecurity-based WAFs, as well as basic free ModSecurity downloads for hobbyists. The Atomic ModSecurity Rules and WAF commercial offerings contain thousands of security controls designed to protect web applications such as WordPress, Joomla, and Drupal, ecommerce platforms including Magento, WooCommerce, PrestaShop, OpenCart, Kubernetes and containers, web APIs, and Apache, Nginx, Litespeed, and Windows IIS web servers, and more.

Our popular Atomic ModSecurity Rules offers advanced rules, daily updates, professional technical support, real-time threat intelligence, and a ModSecurity rule set ready and tuned to defend your web architecture. Learn more about this Atomic ModSecurity Rules subscription service by visiting the Atomic ModSecurity Rules page

Atomic ModSecurity is also available in an enterprise web application firewall (WAF) called Atomic WAF. Atomic WAF is loaded with evolving ModSecurity and Atomicorp cybersecurity rules, false positive and false negative-reduction machine learning logic and professional support, and capabilities and features including MFA SSO, Cloudflare integration, a management console and GUI, compliance reports, and more. 

ModSecurity Solutions

Or, discover how our premium but easy and affordable Atomic ModSecurity Integrator can help you rapidly integrate advanced ModSecurity Rules into your security system or web content environment. Learn more about Atomic ModSecurity Rules for system integrators, VARs, managed security service providers (MSSPs), CDNs and reverse proxy providers, and OEMs. Read more on the Atomic ModSecurity Rules page. 

 

An Open Source WAF Enhanced for Enterprise-Strength

Atomicorp offers ModSecurity in a few easy options.

Angled border

Atomic ModSecurity Rules

Get the convenience of a consumer-level security application but with the strength and sophistication of an enterprise web application firewall, plus technical service management and support that makes web security management painless. The security software is maintained and updated automatically, and the customer only has to run a one time installer on its system to be able to employ the rules across web servers and get reports.Learn More


Atomic WAF


The Atomic WAF software solution is a full enterprise web application firewall (WAF) you won’t have to build yourself. It includes thousands of advanced ModSecurity WAF rules, daily updates, a management console, role-based GUI, MFA SSO, management and compliance reports, and Cloudflare integration. Find out if the powerful Atomic WAF solution is right for you.

Schedule a demo or Learn More


Atomic ModSecurity Integrator

The ModSecurity Integrator provides a tool suite that includes libraries and APIs that enable system integrators, developers, VARs, OEMs, web hosting companies, and web and cloud server load balancers to download Atomic ModSecurity Rules and better customize WAFs for their customers’ needs. We make it easy to plug advanced WAF rules into your offerings without the fuss of developing the rules themselves.
Learn More

Contact us to learn more about premium Atomic ModSecurity Rules.


Atomicorp ModSecurity Rules and ModSecurity-based solutions are commonly used in the following use cases, and a free ModSecurity download is available below.

ModSecurity for CMSs and cPanel and Plesk Web Hosting

Atomic ModSecurity Rules contains thousands of security controls designed to protect your web applications, APIs, and servers from harm. Many web hosting companies favor ModSecurity when deploying firewalls for their control panels, including WordPress, and cPanel and/or Plesk environments. However, to get the most out of ModSecurity and wield an effective ModSecurity WAF, an organization must have fairly technical security application development skills or partner up for these skills. It is not easy to do it yourself.
We’ve made ModSecurity easier to both use or integrate, and very inexpensive.


Start with a monthly subscription.   Contact us to inquire about our premium Atomic ModSecurity Rules offer.


ModSecurity WAFs for New and Legacy Application Environments

Combine Atomic ModSecurity Rules with Atomicorp technology and features in a military-grade, enterprise strength web application firewall (WAF) to protect web server applications, including difficult to guard legacy web application frameworks and legacy custom web applications. Atomic ModSecurity Rules and Atomic WAF both protect modern applications infrastructure such as cloud and container environments such as Kubernetes, as well as vulnerable EOL web applications, which no longer have to be such a risk and potential liability. Get them secured with advanced attack blocking and a WAF UI for visibility into this legacy web application attack surface and vulnerabilities.


Visit the Atomic WAF page.


ModSecurity for Kubernetes

Atomic ModSecurity Rules and Atomic WAF can be used to protect Kubernetes container environments. We provide both baked-in containerized solutions and integrator packages to add web protection to your containers. We formalize this in an enterprise-ready turnkey solution and provide the technical support your organization or agency needs.


ModSecurity for Windows IIS, Apache, LiteSpeed and Ngnix Servers

Web servers and your web applications won’t protect themselves so you need to put a firewall in front of, or on, each one of them. Atomicorp provides on-device and hosted WAF web application security for Apache, Windows IIS, Nginx, and LiteSpeed and Varnish server deployments.


Free ModSecurity Rules

To get the free ModSecurity open-source WAF technology, visit the ModSecurity Rules page.

Trustwave Discontinues ModSecurity Support

Trustwave announced in August 2021 that it would no longer be supporting ModSecurity. Trustwave also set a date for end-of-support for its ModSecurity rule set. The move leaves Atomicorp as the primary commercial ModSecurity rules provider in the industry. Atomicorp will continue its 20-year commitment to the still quite active ModSec user community.

“We’ve been with ModSecurity the longest – since the very beginning – and we are committed to continue to enthusiastically support it for the foreseeable future. We are more than happy to support Trustwave ModSecurity users, whether they wish to keep the Trustwave rules or upgrade to an Atomicorp commercial rules feed.” — Michael Shinn, the founder and CEO of Atomicorp.

Read the press release.

ModSecurity Comparison

Feature Free ModSecurity Rules Remote ModSecurity Rules Atomic ModSecurity Rules (Local) Atomic WAF
Cost Free $22.50 per server per month. $225 per server per year. Bulk discounts avail. $300 per IP/Server. Bulk discounts avail.
Enterprise-level Support        
Number of Rules Hundreds Thousands Thousands Thousands
Supports Unlimited Custom Rules        
Update Frequency Periodically Daily Daily Daily
Response Time for False Positives Community support Within the hour Within the hour Within the hour
Support Model Community 24/7/365 24/7/365 24/7/365
Basic Attack Blocking        
Scanner Blocker        
Proxy Abuse        
Custom White/Blacklists        
Supports Third Party RBLs        
Easy Geoblocking        
Virtual Patches        
PageRank Protection        
Brute Force Attacks        
Advanced Attacks Blocked (SSRF, XXE)        
Data Loss Prevention        
Realtime Malware Protection        
Content Scraping Protection        
Layer 7 DOS Protection        
Realtime Malware Removal System        
Automatic Whitelisting        
Machine Learning        
AntiSpam Protection        
Real Time Threat Intelligence        
Management Console        
Rules Editing Command Line   Command Line GUI
Management Reports        
Compliance Reports        
Role based access control GUI        
MFA SSO integration in GUI        
Cloudflare Integration        
Included Software Rules only   Modsecurity, Rule Updater, Rules, Libraries Modsecurity, Rule Updater, Rules, Libraries, Full management GUI and CWPP for appliance
Setup Process Manual Simple One Step Automated One Step Automated
Update Process Manual Automated Automated Automated

Agented ModSecurity Rules vs. Remote ModSecurity Rules

Download our solution overview on the difference between monthly remote rules and traditional on-premise ModSecurity

Read Our Solution Brief for WAF and Web Application Security

Attacks come virtually, across the cloud and internet, putting your communicative web entities at risk. Secure your web servers, websites, endpoints, and data, with Atomicorp zero trust cloud workload protection and ModSecurity WAF.

Read the Atomicorp ModSecurity Rules and WAF solution brief.

Angled border

Request a Demo