ModSecurity is an open source, cross-platform web application firewall (WAF) module.
Known as the “Swiss Army Knife” of WAFs, it enables web application defenders to gain
visibility into HTTP(S) traffic and provides a power rules language and API to implement
advanced protections.
Used by businesses, government organizations, internet service providers, and commercial WAF vendors alike on
millions of domains all over the world. The engine, coupled with OWASP CRS - the dominant WAF rule set,
undeniably raises the level of protection against HTTP attacks to a higher level.
OWASP® Foundation, the leading open community dedicated to application security, is already responsible for the Core Rule Set,
the dominant WAF rule set on the market. By joining the ModSecurity WAF to their repertoire, OWASP can now steer ModSecurity’s
development with a holistic view, fostering even tighter integration between the core rule set and the underlying framework.
Getting Started
Usage scenarios
Real-time application security monitoring and access control