Documentation

ModSecurity documentation

Two documentation tracks: understand Atomic WAF rules and master the ModSecurity engine, configuration, and rule language.

Start with the task in front of you

I need to…Go here
Understand an Atomic rule ID from an alertSearch the Atomic rule catalog
See tested protection associated with a CVEBrowse Atomicorp CVE research
Understand the parts of a SecRuleRule language fundamentals
Choose On, Off, or DetectionOnlyCore configuration
Work out why a request was blockedLogging and troubleshooting
Report a false positive in an Atomic ruleAtomic rule support and tuning
One engine, two kinds of documentation.

ModSecurity documentation explains how the WAF engine evaluates traffic. Atomic rules documentation explains the security policy running on that engine. Most real-world questions need one or the other—not a thousand-page manual all at once.