Atomic rules are the maintained security policy that turns ModSecurity into a practical production WAF. Documentation is split by the question you are trying to answer.
Look up a rule ID
An audit event normally includes a six-digit Atomic rule ID and message. Search or browse the public catalog to see the rule description, trigger behavior, false-positive notes, tuning guidance, related rules, and references.
Start here when an alert includes an Atomic rule ID.
Browse documented rulesUnderstand the rule families
Rule families organize protection by purpose. The available set includes generic application attacks, anti-evasion, strict HTTP validation, anti-malware, advanced XSS, brute force, denial-of-service controls, anti-spam, reconnaissance, data-loss checks, rootkit indicators, search-engine validation, response redaction, threat intelligence, and just-in-time patching.
Read the complete rule-family reference
The exact families available and appropriate for a deployment depend on the Atomic product, ModSecurity version, connector, and server configuration. Do not load every file in an archive indiscriminately.
CVE and CWE research
- CVE research documents selected positive findings from exploit-technique testing and observed Atomic rule interactions.
- CWE research groups findings by weakness class so you can understand protection patterns beyond a single vulnerability.
- Research updates show the ongoing testing and publication work behind the rules.
Research notes are evidence of specific positive findings. They are not a complete coverage matrix, certification list, or census of everything the rules can protect.
False positives
If a supported Atomic rule blocks a legitimate action in a publicly available application, report the event with the rule ID, audit-log context, application name and version, and a safe reproduction. Commercial rules include Atomicorp’s Zero False Positive Guarantee: qualifying false positives are fixed the same day at no charge.
Custom, private, or unusually modified applications may require a paid tuning or development engagement. Atomicorp will still review the issue, but the guarantee is not free custom application engineering.
Contact Atomicorp support or review the false-positive reporting guide.
Updates and delivery
The Atomic Update Manager installs and refreshes local rule feeds. Remote rules can load a managed policy when the server starts. Use one supported delivery method, keep credentials protected, and avoid loading duplicate copies of rules with the same IDs.