Skip to content
Open source

Library · Open source

SecLang Engine

A ModSecurity-compatible WAF library for the JVM.

An enterprise-grade, high-performance implementation of the ModSecurity SecLang language in Scala, passing 100% of the OWASP CRS v4 regression tests. The engine behind our threat protection.

Stars
1
Language
Java
License
Apache-2.0
Last update
2 days ago
Get started
// build.sbt
libraryDependencies += "com.cloud-apim" %% "seclang-engine" % "2.5.1"
// the OWASP Core Rule Set as an embeddable preset
libraryDependencies += "com.cloud-apim" %% "seclang-engine-coreruleset" % "2.5.1"

Features

What's inside

100% OWASP CRS v4

Passes the whole OWASP Core Rule Set v4 regression test suite.

JVM-native

No WASM, no native bindings. Pure Scala, cross-built for Scala 2.12, 2.13 and 3, with a Java DSL.

Multi-tenant by design

Presets and factories to run many rule sets side by side efficiently.

Pluggable

Host-pluggable geolocation and DNS blocklists, body processors for URL-encoded, multipart, XML and JSON.

From WASM to pure Scala

A WAF engine you can embed anywhere.

SecLang Engine implements the ModSecurity rule language as a library: compile rules once, evaluate requests and responses from any JVM application, and get a disposition back.

It powers the Threat Protection suite for Otoroshi and WebShield. Read the story behind it on our blog: Building a JVM-native WAF: a journey from WASM to pure Scala.

The companion seclang-engine-coreruleset library packages the OWASP Core Rule Set v4 as a preset you can import with a single line.

More open-source projects

Run it in productionwithout running Otoroshi.

Our extensions are available on Otoroshi Managed, fully operated by the people that wrote them. Or get professional support for your own clusters.