Free WAF rules

Free ModSecurity rules

Download free WAF rules for ModSecurity on Apache, Nginx, Linux, Windows, and IIS, with automatic installation and update guidance.

ModSecurity is the inspection engine. A rule set tells it which requests represent attacks and what to do when a rule matches. Atomicorp provides a free WAF rule feed so you can build a working ModSecurity deployment without writing every rule yourself.

Get the free rule feed

Install the Atomic Update Manager, select the free feed during configuration, and download the rules.

Install free rules

What the free ModSecurity rules include

The free feed is a delayed subset of the Atomic commercial rule set. It provides baseline protection for common web attacks and a practical starting point for labs, home servers, evaluations, and lower-risk deployments.

The free feed does not include the current real-time protection stream or ticket-backed commercial rule support. Production systems exposed to active threats should compare the real-time Atomic rules.

Install free ModSecurity rules

Install and configure Atomic Update Manager, choose the free feed when prompted, and retrieve the rules:

sudo wget -q -O - https://updates.atomicorp.com/installers/aum | sudo bash
sudo aum configure
sudo aum -u

Load the downloaded rule files from your ModSecurity configuration, restart or reload the web server, and validate the configuration before sending production traffic through it.

Choose a platform-specific guide if you still need the engine or connector:

Free rules versus real-time rules

CapabilityFree Atomic rulesReal-time Atomic rules
Rule deliveryDelayed subsetCurrent feed with daily updates
Best fitLabs, evaluation, home systemsInternet-facing production systems
CVE and emerging-threat responseDelayedCurrent virtual patches and research-driven updates
Commercial supportDocumentation and community resourcesTicket-backed rule and false-positive support
False-positive fixesNo service guaranteeZero False Positive Guarantee for qualifying reports

Compare every Atomic rule option when you need faster updates, broader protection, or help with production traffic.

Frequently asked questions

Are ModSecurity rules free?

Yes. Atomicorp provides a free delayed rule feed, and OWASP CRS is also open source. Atomicorp additionally offers a current commercial feed with daily updates and ticket-backed support.

Does ModSecurity protect a server without rules?

The engine can inspect and process HTTP traffic, but it needs configuration and security rules to recognize attacks and enforce a useful WAF policy.

Do the free rules work with Apache and Nginx?

They can be used with supported ModSecurity deployments on Apache and with libmodsecurity connectors on Nginx. Engine version, connector support, and rule configuration still need to match the platform.

Can I use free rules on Windows and IIS?

Yes. Follow the Windows and IIS installation guide for the supported 64-bit installer and rule-loading steps.

Where can I get help with ModSecurity rules?

Atomicorp has written and supported ModSecurity rules since 2005. Commercial subscriptions provide an active, ticket-backed support path for rule behavior, false positives, compatibility, and deployment questions.

Need current protection and accountable support?

Move from the delayed free feed to daily Atomic rules with commercial support and qualifying same-day false-positive fixes.

Compare commercial rules Talk to Atomicorp →