Atomic rules

ModSecurity rules that fit the job

Start free, then move to real-time Atomic rules for faster protection, broader coverage, and hands-on false-positive support.

The engine inspects traffic; rules tell it what to recognize and what action to take. Choose based on the risk and operational support your application actually needs.

OptionBest forProtection updatesSupport
Free / delayed Atomic rulesLabs, home systems, evaluationDelayed subsetCommunity and documentation
Real-time Atomic rulesProduction web serversDaily, current feedCommercial support and false-positive fixes
Atomic WAFTeams wanting a turnkey operational layerManagedManagement, reporting, tuning, and support
Atomicorp + Varnish CDN/WAFHosted edge protection and white-label servicesManaged at the edgeSaaS delivery, CDN, and origin shielding

Start free

Install the Atomic Update Manager, choose the free feed during configuration, and let it place and update the rule files for you.

See what the free ModSecurity rules include and follow the installation guide.

sudo wget -q -O - https://updates.atomicorp.com/installers/aum | sudo bash
sudo aum configure
sudo aum -u

Why production systems move to real-time rules

Zero False Positive Guarantee

Report a false positive in a supported Atomic rule and Atomicorp will fix it the same day at no charge. You get a usable fix upstream instead of accumulating a private pile of rule disables and exceptions.

Applies to publicly available applications and reproducible false positives in supported Atomic rules. Custom, private, or unusually modified applications may require a paid tuning or development engagement. We will still take a look—we just cannot promise free custom application engineering.

CVE and zero-day protection

The vulnerability stream keeps getting faster. Atomicorp continuously turns new attack techniques and vulnerability research into virtual patches, including protections delivered before an application vendor has shipped—or you have installed—a code fix. The real-time feed gets current protections rather than the delayed subset.

Explore Atomicorp’s published WAF research to see selected CVE-associated exploit testing and observed rule interactions.

More than injection rules

The commercial policy covers more of the traffic and abuse problems that consume an operator’s day:

Application attacksSQL injection, XSS, code and command injection, XML attacks, traversal, protocol violations, and evasion.
Virtual patchingJust-in-time protections for vulnerable applications and newly discovered exploit techniques.
Layer 7 DDoSApplication-aware rate controls, automated challenges, proof of work, and defenses against slow and fast HTTP abuse.
Threat intelligenceIdentify known attackers associated with brute force, spam, denial-of-service activity, and advanced threats.
Abuse and automationBrute-force detection, reconnaissance controls, unwanted user agents, open proxies, and anti-spam policy.
Malware and dataMalicious payloads and uploads, rootkit indicators, sensitive-data leakage checks, and malicious response content.
Search protectionVerify real search crawlers, detect impersonators, and automatically accesslist legitimate engines to protect indexing and rank.
Operational controlsAutomatic updates, local allowlists and blocklists, supported configurations, and help when production traffic gets complicated.

The exact classes and response controls available depend on the Atomic product, ModSecurity version, connector, and configuration. Review every Atomic WAF rule family.

Updates and support are part of the product

Automated delivery keeps the engine and rule feed from becoming another hand-maintained security dependency. Commercial users also have a support path for rule behavior, compatibility, and deployment questions—valuable when the alternative is debugging production traffic alone.

Protect all the sites on the licensed server

Atomic rules are licensed by server or workload rather than by named virtual host. That makes them a practical fit for hosting systems and servers with many domains. Reverse-proxy and edge deployments have separate licensing; contact Atomicorp for the right model.

Current protection, fewer tuning chores.

Use real-time rules on your servers, add the complete Atomic WAF management layer, or consume the protection as a hosted Varnish CDN/WAF service.

Compare paid Atomic rules Talk to a WAF specialist →

Layer 7 DDoS protection

Atomic protection can identify application-layer floods and abusive HTTP behavior, then apply controls such as proof-of-work challenges before expensive requests reach the application. This is distinct from volumetric Layer 3/4 scrubbing: extremely large network floods still need sufficient upstream capacity or edge filtering. Through its Varnish partnership, Atomicorp extends its ModSecurity rules, Layer 7 enforcement, caching, and origin shielding to a hosted edge service.

Learn about the edge WAF architecture

Evidence behind the rules

Atomicorp WAF Research Notes publish selected engineering observations, exploit-technique testing, and rule interactions. They are research notes—not a marketing coverage census.