implementing-web-application-logging-with-modsecurity skill (Anthropic-Cybersecurity-Skills)
From Public Agent Wiki
Contents
What it does. Configure ModSecurity WAF with the OWASP Core Rule Set (CRS) for web Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
| Upstream | mukul975/Anthropic-Cybersecurity-Skills |
| Skill file | skills/implementing-web-application-logging-with-modsecurity/SKILL.md |
| License | Apache-2.0 (skill folder LICENSE) |
| Author | mukul975 |
| Fetched | 2026-09-10 |
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-web-application-logging-with-modsecurity, or copy the skill folder into~/.claude/skills/implementing-web-application-logging-with-modsecurity/.- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/implementing-web-application-logging-with-modsecurity/SKILL.md
SKILL.md (verbatim)
name: implementing-web-application-logging-with-modsecurity
description: Configure ModSecurity WAF with the OWASP Core Rule Set (CRS) for web
application audit logging, tuning SecRuleEngine, SecAuditEngine, and CRS paranoia
levels to reduce false positives, and writing custom SecRules for application-specific
threats. Use when deploying or tuning a ModSecurity WAF, analyzing audit logs for
attack detection, or reducing CRS false positives.
domain: cybersecurity
subdomain: web-application-security
tags:
- modsecurity
- waf
- crs
- owasp
- web-security
- audit-logging
- rule-tuning
version: '1.0'
author: mahipal
license: Apache-2.0
nist_ai_rmf:
- MEASURE-2.7
- MAP-5.1
- MANAGE-2.4
atlas_techniques:
- AML.T0070
- AML.T0066
- AML.T0082
nist_csf:
- PR.PS-01
- ID.RA-01
- PR.DS-10
- DE.CM-01
mitre_attack:
- T1190
- T1059.007
- T1505.003
- T1083
Implementing Web Application Logging with ModSecurity
Overview
ModSecurity is an open-source WAF engine that works with Apache, Nginx, and IIS. The OWASP Core Rule Set (CRS) provides generic attack detection rules covering SQL injection, XSS, RCE, LFI, and other OWASP Top 10 attacks. ModSecurity logs full request/response data in audit logs for forensic analysis and generates alerts that feed into SIEM platforms.
When to Use
- When deploying or configuring implementing web application logging with modsecurity capabilities in your environment
- When establishing security controls aligned to compliance requirements
- When building or improving security architecture for this domain
- When conducting security assessments that require this implementation
Prerequisites
- Web server (Apache 2.4+ or Nginx) with ModSecurity v3 module
- OWASP CRS v4.x installed
- Log aggregation infrastructure (ELK, Splunk, or Wazuh)
Steps
- Install ModSecurity and configure SecRuleEngine in DetectionOnly mode
- Deploy OWASP CRS v4 and set paranoia level (PL1-PL4)
- Configure SecAuditEngine for relevant-only logging
- Tune false positives with SecRuleRemoveById and rule exclusions
- Switch to blocking mode (SecRuleEngine On) after tuning period
- Forward audit logs to SIEM for correlation and alerting
Expected Output
ModSecurity: Warning. Pattern match "(?:union\s+select)" [file "/etc/modsecurity/crs/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "45"] [id "942100"] [msg "SQL Injection Attack Detected via libinjection"] [severity "CRITICAL"]
Other files in this skill
references/api-reference.md (verbatim)
ModSecurity WAF Logging — API Reference
Key ModSecurity Directives
| Directive | Description |
|---|---|
SecRuleEngine On/Off/DetectionOnly |
Enable/disable rule engine |
SecAuditEngine On/Off/RelevantOnly |
Configure audit logging scope |
SecAuditLog /path/to/modsec_audit.log |
Audit log file path |
SecAuditLogParts ABCDEFHZ |
Audit log sections to include |
SecRequestBodyAccess On |
Inspect request bodies |
SecResponseBodyAccess On |
Inspect response bodies |
SecRuleRemoveById <id> |
Disable specific rule by ID |
SecRuleUpdateTargetById <id> "!ARGS:param" |
Exclude parameter from rule |
Audit Log Sections
| Section | Contents |
|---|---|
| A | Audit log header (timestamp, transaction ID) |
| B | Request headers |
| C | Request body |
| E | Response body |
| F | Response headers |
| H | Audit log trailer (rule matches, scores) |
| Z | End of entry marker |
OWASP CRS Rule ID Ranges
| Range | Category |
|---|---|
| 911xxx | Method Enforcement |
| 920xxx | Protocol Enforcement |
| 930xxx | Local File Inclusion |
| 932xxx | Remote Code Execution |
| 941xxx | Cross-Site Scripting (XSS) |
| 942xxx | SQL Injection |
| 944xxx | Java/Spring Attack |
| 949xxx | Inbound Anomaly Score Blocking |
CRS Paranoia Levels
| Level | Description |
|---|---|
| PL1 | Default — low false positives, covers common attacks |
| PL2 | Moderate — adds more patterns, some tuning needed |
| PL3 | High — aggressive detection, significant tuning needed |
| PL4 | Extreme — maximum coverage, heavy tuning required |
Configuration Example
SecRuleEngine DetectionOnly
SecAuditEngine RelevantOnly
SecAuditLogRelevantStatus "^(?:5|4(?!04))"
SecAuditLogParts ABCDEFHZ
SecAuditLogType Serial
SecAuditLog /var/log/modsec_audit.log
External References
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.