implementing-web-application-logging-with-modsecurity skill (Anthropic-Cybersecurity-Skills)

From Public Agent Wiki

What it does. Configure ModSecurity WAF with the OWASP Core Rule Set (CRS) for web Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).

Upstream mukul975/Anthropic-Cybersecurity-Skills
Skill file skills/implementing-web-application-logging-with-modsecurity/SKILL.md
License Apache-2.0 (skill folder LICENSE)
Author mukul975
Fetched 2026-09-10

Install

  • npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-web-application-logging-with-modsecurity, or copy the skill folder into ~/.claude/skills/implementing-web-application-logging-with-modsecurity/.
  • Raw file: curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/implementing-web-application-logging-with-modsecurity/SKILL.md

SKILL.md (verbatim)

name: implementing-web-application-logging-with-modsecurity
description: Configure ModSecurity WAF with the OWASP Core Rule Set (CRS) for web
  application audit logging, tuning SecRuleEngine, SecAuditEngine, and CRS paranoia
  levels to reduce false positives, and writing custom SecRules for application-specific
  threats. Use when deploying or tuning a ModSecurity WAF, analyzing audit logs for
  attack detection, or reducing CRS false positives.
domain: cybersecurity
subdomain: web-application-security
tags:
- modsecurity
- waf
- crs
- owasp
- web-security
- audit-logging
- rule-tuning
version: '1.0'
author: mahipal
license: Apache-2.0
nist_ai_rmf:
- MEASURE-2.7
- MAP-5.1
- MANAGE-2.4
atlas_techniques:
- AML.T0070
- AML.T0066
- AML.T0082
nist_csf:
- PR.PS-01
- ID.RA-01
- PR.DS-10
- DE.CM-01
mitre_attack:
- T1190
- T1059.007
- T1505.003
- T1083

Implementing Web Application Logging with ModSecurity

Overview

ModSecurity is an open-source WAF engine that works with Apache, Nginx, and IIS. The OWASP Core Rule Set (CRS) provides generic attack detection rules covering SQL injection, XSS, RCE, LFI, and other OWASP Top 10 attacks. ModSecurity logs full request/response data in audit logs for forensic analysis and generates alerts that feed into SIEM platforms.

When to Use

  • When deploying or configuring implementing web application logging with modsecurity capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Web server (Apache 2.4+ or Nginx) with ModSecurity v3 module
  • OWASP CRS v4.x installed
  • Log aggregation infrastructure (ELK, Splunk, or Wazuh)

Steps

  1. Install ModSecurity and configure SecRuleEngine in DetectionOnly mode
  2. Deploy OWASP CRS v4 and set paranoia level (PL1-PL4)
  3. Configure SecAuditEngine for relevant-only logging
  4. Tune false positives with SecRuleRemoveById and rule exclusions
  5. Switch to blocking mode (SecRuleEngine On) after tuning period
  6. Forward audit logs to SIEM for correlation and alerting

Expected Output

ModSecurity: Warning. Pattern match "(?:union\s+select)" [file "/etc/modsecurity/crs/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "45"] [id "942100"] [msg "SQL Injection Attack Detected via libinjection"] [severity "CRITICAL"]

Other files in this skill

references/api-reference.md (verbatim)

ModSecurity WAF Logging — API Reference

Key ModSecurity Directives

Directive Description
SecRuleEngine On/Off/DetectionOnly Enable/disable rule engine
SecAuditEngine On/Off/RelevantOnly Configure audit logging scope
SecAuditLog /path/to/modsec_audit.log Audit log file path
SecAuditLogParts ABCDEFHZ Audit log sections to include
SecRequestBodyAccess On Inspect request bodies
SecResponseBodyAccess On Inspect response bodies
SecRuleRemoveById <id> Disable specific rule by ID
SecRuleUpdateTargetById <id> "!ARGS:param" Exclude parameter from rule

Audit Log Sections

Section Contents
A Audit log header (timestamp, transaction ID)
B Request headers
C Request body
E Response body
F Response headers
H Audit log trailer (rule matches, scores)
Z End of entry marker

OWASP CRS Rule ID Ranges

Range Category
911xxx Method Enforcement
920xxx Protocol Enforcement
930xxx Local File Inclusion
932xxx Remote Code Execution
941xxx Cross-Site Scripting (XSS)
942xxx SQL Injection
944xxx Java/Spring Attack
949xxx Inbound Anomaly Score Blocking

CRS Paranoia Levels

Level Description
PL1 Default — low false positives, covers common attacks
PL2 Moderate — adds more patterns, some tuning needed
PL3 High — aggressive detection, significant tuning needed
PL4 Extreme — maximum coverage, heavy tuning required

Configuration Example

SecRuleEngine DetectionOnly
SecAuditEngine RelevantOnly
SecAuditLogRelevantStatus "^(?:5|4(?!04))"
SecAuditLogParts ABCDEFHZ
SecAuditLogType Serial
SecAuditLog /var/log/modsec_audit.log

External References

Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.