ATOMIC PROTECTION
Atomic rules documentation
Find individual rule behavior, rule families, CVE research, CWE coverage, tuning guidance, and false-positive support.
Explore Atomic rules →ENGINE REFERENCE
ModSecurity documentation
Understand configuration directives, processing phases, SecRule syntax, variables, operators, transformations, actions, and logs.
Learn ModSecurity →Start with the task in front of you
| I need to… | Go here |
|---|---|
| Understand an Atomic rule ID from an alert | Search the Atomic rule catalog |
| See tested protection associated with a CVE | Browse Atomicorp CVE research |
Understand the parts of a SecRule | Rule language fundamentals |
Choose On, Off, or DetectionOnly | Core configuration |
| Work out why a request was blocked | Logging and troubleshooting |
| Report a false positive in an Atomic rule | Atomic rule support and tuning |
One engine, two kinds of documentation.
ModSecurity documentation explains how the WAF engine evaluates traffic. Atomic rules documentation explains the security policy running on that engine. Most real-world questions need one or the other—not a thousand-page manual all at once.