The ModSecurity Web application firewall (WAF) engine provides powerful protection against threats to data via applications. However, in order to become really effective, ModSecurity must be configured with rules that help it recognize threats and defend against them. Trustwave® SpiderLabs® provides a commercial certified rule set for ModSecurity v2.9 and above that protects against known attacks that target vulnerabilities in public software.
ModSecurity Rules from Trustwave® SpiderLabs® complement the open source OWASP ModSecurity Core Rules Set (CRS) by enhancing the basic payload protection offered by CRS. But CRS does not correlate specific attack vector locations (such as URL and parameters) from publicly disclosed vulnerabilities. This is where ModSecurity Rules from Trustwave® SpiderLabs® can help; these rules create custom virtual patches for public vulnerabilities.
Trustwave® SpiderLabs® correlates data from numerous sources to generate the commercial rules, automatically updating daily and as needed.
Annual prices are listed above. Three-year subscriptions receive a 10% additional discount. Upon completion of the shopping cart purchase, an email will be sent out with instructions for accessing the ModSecurity Dashboard portal site where you can configure the Trustwave® ModSecurity rule profiles.