Open source engine. Production-ready path.

Download ModSecurity.
Get free WAF rules.

Install ModSecurity for Linux, Nginx, Apache, Windows, or IIS, then add maintained rules that work.

✓ Apache✓ Nginx✓ IIS✓ Linux & Windows
terminal
# Add the Atomic repository$ sudo wget -q -O -
https://updates.atomicorp.com/installers/atomic
| sudo bash
# Install for Apache on RHEL-family Linux$ sudo yum -y install httpd mod_security
WAF engine ready
Pick your finish line

From engine to fully managed

Start free. Add faster protection, broader rules, hands-on false-positive fixes, or a complete management layer when you need them.

01

ModSecurity engine

Download free WAF as pre-built Linux and Windows packages. Get ModSecurity without a source build.

Get the engine →
03

Complete Atomic WAF

Add centralized management, reporting, tuning, and support when you need a turnkey operational WAF.

Explore Atomic WAF →
Rules built for real traffic

Block attacks.
Keep the site working.

A WAF is useful only when it protects applications without becoming someone’s full-time tuning project. Atomic rules emphasize broad attack coverage, virtual patching, and low operational friction.

See rule options
Request evaluationlive
  • Known-safe requestPassed without friction

    ALLOW
  • !

    SQL injection patternAtomic rule 340016

    BLOCK
  • !

    Traversal attemptVirtual patch protection

    BLOCK
  • Application API callPassed without friction

    ALLOW
Atomicorp + Varnish

Put the WAF at the edge.

Get Atomic ModSecurity rules, Layer 7 DDoS protection, proof-of-work challenges, CDN delivery, and origin shielding as a hosted service.

VisitorVarnish CDN
Atomic WAF rules
Your origin
Useful depth, when you need it

Documentation for the engine and the rules

Ready when you are

Get a WAF running today.

Choose your operating system. We’ll take you straight to the shortest reliable path.

Install on LinuxInstall on Windows