Atomic protection

Atomic WAF rules documentation

Find Atomic rule IDs, families, CVE and CWE research, tuning guidance, updates, and false-positive support.

Atomic rules are the maintained security policy that turns ModSecurity into a practical production WAF. Documentation is split by the question you are trying to answer.

Look up a rule ID

An audit event normally includes a six-digit Atomic rule ID and message. Search or browse the public catalog to see the rule description, trigger behavior, false-positive notes, tuning guidance, related rules, and references.

Atomic WAF rule catalog

Start here when an alert includes an Atomic rule ID.

Browse documented rules

Understand the rule families

Rule families organize protection by purpose. The available set includes generic application attacks, anti-evasion, strict HTTP validation, anti-malware, advanced XSS, brute force, denial-of-service controls, anti-spam, reconnaissance, data-loss checks, rootkit indicators, search-engine validation, response redaction, threat intelligence, and just-in-time patching.

Read the complete rule-family reference

The exact families available and appropriate for a deployment depend on the Atomic product, ModSecurity version, connector, and server configuration. Do not load every file in an archive indiscriminately.

CVE and CWE research

Research notes are evidence of specific positive findings. They are not a complete coverage matrix, certification list, or census of everything the rules can protect.

False positives

If a supported Atomic rule blocks a legitimate action in a publicly available application, report the event with the rule ID, audit-log context, application name and version, and a safe reproduction. Commercial rules include Atomicorp’s Zero False Positive Guarantee: qualifying false positives are fixed the same day at no charge.

Custom, private, or unusually modified applications may require a paid tuning or development engagement. Atomicorp will still review the issue, but the guarantee is not free custom application engineering.

Contact Atomicorp support or review the false-positive reporting guide.

Updates and delivery

The Atomic Update Manager installs and refreshes local rule feeds. Remote rules can load a managed policy when the server starts. Use one supported delivery method, keep credentials protected, and avoid loading duplicate copies of rules with the same IDs.

Rule installation and delivery documentation