ModSecurity engine
Download free WAF as pre-built Linux and Windows packages. Get ModSecurity without a source build.
Get the engine →Install ModSecurity for Linux, Nginx, Apache, Windows, or IIS, then add maintained rules that work.
$ sudo wget -q -O -
https://updates.atomicorp.com/installers/atomic
| sudo bash# Install for Apache on RHEL-family Linux$ sudo yum -y install httpd mod_securityStart with what you run
Start free. Add faster protection, broader rules, hands-on false-positive fixes, or a complete management layer when you need them.
Download free WAF as pre-built Linux and Windows packages. Get ModSecurity without a source build.
Get the engine →Daily CVE and zero-day protections, Layer 7 DDoS defenses, automatic updates, and our Zero False Positive Guarantee.
Why production rules →Add centralized management, reporting, tuning, and support when you need a turnkey operational WAF.
Explore Atomic WAF →A WAF is useful only when it protects applications without becoming someone’s full-time tuning project. Atomic rules emphasize broad attack coverage, virtual patching, and low operational friction.
See rule optionsKnown-safe requestPassed without friction
ALLOWSQL injection patternAtomic rule 340016
BLOCKTraversal attemptVirtual patch protection
BLOCKApplication API callPassed without friction
ALLOWGet Atomic ModSecurity rules, Layer 7 DDoS protection, proof-of-work challenges, CDN delivery, and origin shielding as a hosted service.
Configuration, rule language, processing phases, logging, and troubleshooting.
ATOMIC PROTECTIONRule IDs, families, CVE research, tuning, updates, and false-positive support.
RESEARCHSee tested exploit techniques and observed rule interactions.
Choose your operating system. We’ll take you straight to the shortest reliable path.