OWASP CRS

CRS is a set of generic attack detection rules for use with ModSecurity or compatible web application firewalls. The CRS aims to protect web applications from a wide range of attacks, including the OWASP Top Ten, with a minimum of false alerts.

About OWASP CRS

OWASP CRS

The 1st Line of Defense Against Web Application Attacks

The OWASP CRS is a set of generic attack detection rules for use with ModSecurity or compatible web application firewalls. It aims to protect web applications from a wide range of attacks, including the OWASP Top Ten, with a minimum of false alerts. CRS provides protection against many common attack categories, including SQL Injection, Cross Site Scripting, Local File Inclusion, etc.

The official website of the project can be found at https://coreruleset.org.

Getting Started / Tutorials

To install CRS, you need first to select your engine, and then install the rules.

Licensing

OWASP CRS is free to use. It is licensed under the Apache Software License version 2 (ASLv2), so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.

Reporting Issues

  • If you think you’ve found a false positive in commercially available software and want us to take a look, submit an issue here on our Github

  • Have you found a false negative/bypass? See our policy first on how to contact us.

Logos

You can find the project logos in the OWASP Swag repository.

Sponsors

Project Gold Sponsors

Project Silver Sponsors

Project Leaders

Felipe Zipitria

Email

Max Leske

Email

Project Information

Flagship Project
Classification
Code
Language
Seclang
License
Apache 2.0
Latest Version
4.29.0
Contributors
135
GitHub Stars
3300
Related Projects
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.