Choose the download that matches the job
| You need | Best starting point | Destination |
|---|---|---|
| ModSecurity on Linux | Distribution packages from the Atomic repository | Linux install guide |
| ModSecurity for Windows IIS | Pre-built 64-bit MSI | Windows binary archive |
| Atomic WAF rules | Free or production feed via AUM | Compare rule options |
| Package files for manual deployment | Atomic RPM/DEB archive | Package archive |
| Upstream source code | ModSecurity project repositories | ModSecurity on GitHub |
Verify what you download
Use the checksum published beside a binary, obtain packages over HTTPS, and keep the repository or update manager configured so security fixes and rule updates do not become manual chores.
Engine versions
ModSecurity 2 is the embedded Apache/IIS generation. libmodsecurity 3 separates the engine from web-server connectors and is commonly used with Nginx. They are related, but configuration and feature behavior are not identical. Compare ModSecurity 2 and 3 before choosing a manual build.