Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A SecRule compares selected variables against an operator and then applies its actions. To make a rule predictable, choose its targets and operator explicitly, give it a unique ID, set its processing phase, and review both its inline actions and any inherited defaults. Syntax and behavior can vary by engine version and connector, so validate rules against the exact deployment rather than assuming a rule written for one engine will behave identically in another.

What does each part of a SecRule do?

A canonical Coraza rule has this form:

SecRule VARIABLES "@OPERATOR OPERATOR_ARGUMENTS" "ACTIONS"

For example:

SecRule REQUEST_HEADERS:User-Agent "@contains example" "id:10002,phase:1,pass,log,msg:'Explain the match'"
  • Variables identify the request or response data to inspect. A rule can target one variable or combine targets.
  • Operator defines how the selected values are compared with the operator argument.
  • Actions define what happens when the condition matches, such as logging, setting metadata, continuing processing, or taking a disruptive action.

The surrounding quotes and escaping rules depend on the configuration parser and where the rule is written. Treat the example as a readable rule shape, not a universal escaping recipe.

Give every rule a unique ID

Include a unique id in each rule. IDs make rules identifiable in logs and are also needed for rule-management and update workflows. Check the installed ruleset and local configuration to avoid reusing an existing ID.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set the phase deliberately

The phase determines when a rule runs, which affects what data is available to inspect. Coraza documents phase 2 as the default when phase is omitted. That means an apparently phase-less Coraza rule can run during request-body inspection rather than at the point its author intended. Put the phase in the rule when timing matters; do not rely on an unstated default when porting between engines.

#1 Best Overall
Fortinet Web Application Firewall - Virtual Appliance for All Supported Platforms. Supports up to 2 x vCPU core FWB-VM02
  • Fortinet Web Application Firewall - virtual appliance for all supported platforms. Supports up to 2 x vCPU core
  • Fortinet HW FWB-VM02
  • Manufacturer Part: FWB-VM02

How do variable selectors choose targets?

Selectors can narrow a rule to a particular key or combine and exclude targets. These examples illustrate the documented Coraza syntax:

SecRule REQUEST_HEADERS:User-Agent "@contains example" "id:10002,phase:1,pass,log
dSecRule &REQUEST_HEADERS:host "@eq 0" "id:10003,phase:1,deny,status:403"
SecRule REQUEST_HEADERS|!REQUEST_HEADERS:User-Agent "@detectSQLi" "id:10004,phase:1,pass,log"

Read the selector operators in context:

  • REQUEST_HEADERS:User-Agent selects the named header key.
  • | combines targets. In the third example, the broader request-header collection is used while the named User-Agent target is excluded with !.
  • & counts values in the selected collection. In the second example, the rule tests whether the selected host-header collection has zero values; it does not compare a header’s text to the string 0.

Mapped-variable-name regular-expression selection is version-sensitive in Coraza. Its syntax reference describes a PCRE-compatible selector as v2-only and says v3 supports RE2. Do not assume a selector expression will work unchanged across Coraza versions or in ModSecurity; confirm the syntax for the installed engine.

Which operator should a rule use?

Choose the operator according to the condition you mean to express. In Coraza, an omitted operator defaults to @rx, so a bare pattern is treated as a regular expression—not as literal equality or an ordinary substring. Writing the operator explicitly makes the intent easier to review and reduces surprises.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Fortinet Web Application Firewall - Virtual Appliance for All Supported Platforms. Supports up to 4 x vCPU core FWB-VM04
  • Fortinet Web Application Firewall - virtual appliance for all supported platforms. Supports up to 4 x vCPU core
  • Fortinet HW FWB-VM04
  • Manufacturer Part: FWB-VM04
Intent Operator example Behavior documented for Coraza
Exact text equality @streq Case-sensitive equality
Substring match @strmatch Case-sensitive substring matching
Regular-expression match @rx Regex matching using RE2 syntax

For case-insensitive matching with @strmatch, Coraza’s operator reference recommends applying t:lowercase. Do not assume every operator normalizes its input automatically.

Check regex compatibility before porting

Coraza documents @rx as using RE2 syntax, supporting up to nine capture groups for action use, and enabling dotall mode by default. In dotall mode, a dot can match a newline. A PCRE-specific construct may therefore fail or behave differently when moved to Coraza, and a pattern that appears line-oriented may match across a newline. Test the expression on the target engine with representative inputs, including line breaks where relevant.

What do actions do, and what can defaults change?

Actions are comma-separated. Coraza groups them into categories that describe their role:

Rank #3
Fortinet Web Application Firewall - Virtual Appliance for All Supported Platforms. Supports up to 8 x vCPU core FWB-VM08
  • Fortinet Web Application Firewall - virtual appliance for all supported platforms. Supports up to 8 x vCPU core
  • Fortinet HW FWB-VM08
  • Manufacturer Part: FWB-VM08
  • Disruptive: examples include deny, drop, redirect, allow, block, and pass.
  • Non-disruptive: examples include logging, metadata, and setvar actions.
  • Flow: examples include chain, skip, and skipAfter.
  • Metadata: examples include id, rev, and severity.
  • Data: an example is status.

Coraza documents that only one disruptive action applies to a rule; if multiple disruptive actions are specified, the last takes precedence. Disruptive actions are not executed when SecRuleEngine is set to DetectionOnly. A rule that logs a match in that mode should not be mistaken for one that is actively denying the request.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Review SecDefaultAction as part of the rule

SecDefaultAction supplies defaults that combine with actions on individual rules, with rule actions overriding applicable defaults. As a result, reading only a short inline action list may not reveal the rule’s effective phase, logging behavior, or disruption behavior. When reviewing a rule, inspect the relevant defaults in the configuration context where that rule is loaded.

Do not treat pass as an allowlist decision

pass means continue processing; it does not by itself mean that a request has been allowlisted or exempted from later rules. Understand the surrounding rule flow and effective defaults before interpreting what a pass rule permits.

Rank #4
Cisco Meraki MX100 Security Appliance, Firewall, GigE, 1U, Rack-Mountable
  • Meraki MX100: A building block for SASE in a rack-mountable form factor. Medium- to large-branch security and SD-WAN appliance for up to 500 users.
  • WAN: 1 x GbE RJ45, 1 x USB (cellular failover), Dual-purpose: 1 x GbE RJ45 +++ LAN: 8 x GbE RJ45, 2 x GbE SFP
  • Stateful firewall throughput: 750 Mbps +++ 500 Mbps site-to-site VPN throughput
  • Unified management for security, SD-WAN, Wi-Fi, switching, MDM, and IoT +++ Centralized management via web-based dashboard or API
  • True zero-touch provisioning +++ Smartphone-like firmware updates

How do chained SecRules work?

A chain combines conditions: the chain succeeds only when its conditions match together. Read the starter and its members as parts of one combined rule, not as independent lines where every member has its own blocking decision.

Action-placement details are engine- and version-specific. The OWASP ModSecurity 2.x manual places disruptive, phase, metadata, and flow actions on the chain starter; non-disruptive actions may appear on members. The disruptive action takes effect only when the chain succeeds. Before copying a chain between ModSecurity 2.x, libModSecurity 3.x, or Coraza, check the reference for the exact engine and release, especially for which actions are permitted on members.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How should macros and dynamic values be used?

Coraza documents macro expansion in the form %{VARIABLE.KEY}. For example, a rule can use a variable’s value in an action such as logdata or setvar. That expansion supplies dynamic data to the action value; it is distinct from the operator’s match input, which comes from the rule’s selected variables.

Best Value
UDPTCP Firewall, Intelligent Soft Routing Micro Appliance/Fanless Mini PC • Celeron N2840, 2 x RJ45(1000M), USB 3.0,HDMI,VGA,NO RAM NO mSATA SSD (8GB RAM 256GB SSD)
  • ◆Powerful Celeron N2840 Processor: N2840 Processor, 2 Cores 2 Threads, 1M Cache, Max Turbo Frequency 2.58 GHz, TDP 7.5 W. Whether you need a robust home server, a versatile tool for school education, seamless web browsing, or even efficient business office or industrial tasks, providing efficient performance for everyday tasks.
  • ◆Dual 1000M LAN: Mini Router PC with 2*Realtek RTL8111H network card chip full UDE 1000M with filter connector.Soft Router can monitor network data, improve network security, powerful and widely used.
  • ◆DDR3L Memory & Large Storage Capacity: Firewall box computer with 1 x DDR3L SO-DIMM memory 1333/1600MHz, 1xMSATA3.0 SSD.
  • ◆UHD Graphics & 4K Dual Screen Display: N2840 processor integrated UHD Graphics, HD and VGA dual display interfaces support 4K@60Hz. 
  • ◆Versatile Connections ports: 2 x1000M Realtek RTL8111H-LAN,2 xUSB3.0, 4 xUSB2.0, HDMI,VGA,AUDIO supports data storage and system boot.Mini desktop computer with WIFI dual antenna, which providing high-speed transmission and reliable connectivity. Support Dual Band Wifi, Internet, streaming media and audio can be used perfectly without interrupting the connection. Enjoy faster file transfers and smoother online experiences.

Quote values containing punctuation carefully in the configuration context in which the rule is parsed. Macro support does not establish a single escaping rule that is safe for every connector or configuration format, so verify the parsed result in the actual deployment.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why might a SecRule behave unexpectedly?

  • It runs at an unexpected time: check the explicit phase and any applicable SecDefaultAction. Coraza’s documented phase-2 default can matter when phase is omitted.
  • A pattern is treated as regex: an omitted operator defaults to @rx in Coraza. Use an explicit operator for literal equality or substring matching.
  • A regex fails after migration: check whether it relies on PCRE-specific syntax and account for Coraza’s documented RE2 implementation and default dotall behavior.
  • A mapped-key selector changes across versions: verify the selector against the installed Coraza version instead of assuming regex selection is portable.
  • A rule logs but does not block: check whether the engine is in DetectionOnly mode and review effective defaults.
  • A chain does not block when expected: confirm that the full chain matched and that disruptive actions are placed where the target engine permits them.
  • A broad rule causes false positives: investigate whether a narrow target exclusion or a ruleset update can address the issue before disabling a larger set of protections. Coraza documents target-update directives, but their exact use depends on the installed ruleset and engine.

What should you verify before enabling a rule?

  1. Confirm the engine, release, and connector. Record whether the deployment uses ModSecurity 2.x, libModSecurity 3.x, or a particular Coraza release; do not assume identical parsing or behavior.
  2. Make the match explicit. Review each target, selector, operator, and argument. Confirm that the target scope is no broader than needed.
  3. Set identity and timing. Use a unique rule ID and an intentional phase rather than relying on defaults.
  4. Resolve the effective actions. Read both the inline action list and applicable SecDefaultAction settings, and confirm the engine mode.
  5. Exercise the condition and its boundaries. Test matching and non-matching inputs, including relevant casing, newlines, missing keys, and chain combinations.
  6. Review operational effects in the deployment context. Verify the logs and the actual result through the configured connector before relying on blocking behavior.

There is no universally best operator or selector. Prefer the narrowest clear expression that matches the intended data, then validate syntax and effects on the exact engine and connector that will run it.

Quick Recap

Bestseller No. 4
Cisco Meraki MX100 Security Appliance, Firewall, GigE, 1U, Rack-Mountable
Cisco Meraki MX100 Security Appliance, Firewall, GigE, 1U, Rack-Mountable
Stateful firewall throughput: 750 Mbps +++ 500 Mbps site-to-site VPN throughput; True zero-touch provisioning +++ Smartphone-like firmware updates
$344.00

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.