ModSecurity integration
Optional compensating rules in ModSecurity, for cover while the pull request that fixes the finding ships.
Integration details
Primary category
Web Application Firewall
Sync direction
ModSecurity ↔ Konvu
Findings are ingested from ModSecurity into Konvu. What Konvu writes back to ModSecurity depends on the integration.
Status
Coming soon
What is ModSecurity?
ModSecurity is an open-source web application firewall engine, originally for Apache and now maintained as a CRS-compatible engine that runs in front of HTTP traffic to block attacks via configurable rules.
Why connect ModSecurity to Konvu
- Add a temporary ModSecurity rule for a finding Konvu has already proven exploitable, so exposure narrows while the upgrade goes through review.
- Test every rule against known exploit signatures and a sample of legitimate traffic before deployment, with rollback if false-positive rates go bad.
- Retire rules once Konvu confirms the upstream fix has shipped, so compensating controls don't silently become permanent.
How it works
Receive exploit conditions
Konvu reads the verified exploit path from a finding it has already proven exploitable.
Draft & test rule
A ModSecurity rule is drafted scoped to the vulnerable code path and tested against the exploit signature and your legitimate traffic.
Deploy with approval flow
The rule is deployed to your ModSecurity instance via the approval flow your team has configured.
Monitor & retire
Blocks and false positives are monitored in production; the rule is removed once Konvu confirms the upstream fix is live.
Quick setup
When ModSecurity is available, you’ll configure it from the integrations list in Konvu.
- 1Go to /configuration/integrations in Konvu and choose ModSecurity.
- 2Authorize access and confirm the data sources you want to sync.
- 3Save the configuration to start syncing.
Sync direction
ModSecurity ↔ Konvu
Findings are ingested from ModSecurity into Konvu. What Konvu writes back to ModSecurity depends on the integration.
Join the waitlist
We’ll let you know when the ModSecurity integration is ready. Leave your email to get updates.
More integrations
View allAWS WAF
Optional compensating rules in AWS WAF, for cover while the pull request that fixes the finding ships.
- WAF
Cloudflare WAF
Optional compensating rules in Cloudflare WAF, for cover while the pull request that fixes the finding ships.
- WAF
Arnica
Add exploitability verdicts with evidence to Arnica SCA and SAST findings, and send approved SCA dismissals back to Arnica.
- SCA
- SAST
- ASPM
AWS Inspector
Check whether the vulnerabilities AWS Inspector finds in your ECR container images are exploitable.
- Cloud Security
AWS Security Hub
Get exploitability verdicts for the AWS Inspector container findings in Security Hub, read directly from Inspector.
- Cloud Security
Black Duck
Get an exploitability verdict with evidence for Black Duck Polaris SCA findings and Coverity SAST findings.
- SCA
- SAST