Uploaded December 2025 | Updated September 2026, 3 weeks ago
The goal of OWASP CRS is to define rules for web attacks that can be used by WAF engines to protect web applications. The current implementation of CRS rules depends on the ModSecurity Rule Language (a.k.a. Seclang) syntax. As a consequence, rules are not portable to other WAF technologies without heavy lifting. Furthermore, they include the configuration specifics of the ModSecurity engine within their definitions. As a result, anyone trying to use CRS must be familiar with security concepts and subtleties needed to define the rules, using Seclang syntax and with the ModSecurity engine configurations.
The Seclang was created to satisfy constraints that arose when ModSecurity was confined to the Apache engine. These limitations are long gone now, but the behavior and particular syntax hasn't changed in more than fifteen or twenty years.
In this presentation we introduce a new language agnostic to the WAF technology used, opening OWASP CRS to new ecosystems and tools. At the same time, we aim to reduce the learning curve for contributors and simplify the rule definition process, while being able to automatically translate rules in this new language to and from Seclang for maximum compatibility.
We will cover the new language concepts and definitions, the challenges faced and the solutions proposed. We needed to capture the information present in the Seclang rules to extract and transform the current CRS rules to the new language. This means that the new rule representation must be able to represent at least the minimum set of Seclang features needed to write a rule, so that existing tools based on Seclang can be used with the new language, while remaining generic enough to be used by different programming languages.
Felipe Zipitria
Life360
OWASP CRS project co-leader
Uruguay
uy.linkedin.com/in/felipezipitria
Felipe Zipitria is an expert in computer security, graduated with an MSc from the Universidad de la República in Uruguay. With over 20 years of experience in SRE, DevOps, and SysAdmin roles, Felipe has transitioned into specialized areas, dedicating the past 5 years to AppSec and Cloud SecOps. His extensive expertise spans security consulting for over a decade. Passionate about education, Felipe instructs pregraduate students in Computer Security Fundamentals and guides postgraduates in Web Application Security at the local public University, with the help of OWASP published materials. He started as the Uruguay Co-Chapter Leader in 2013, and started engaging in projects with global outreach. He is a longstanding contributor to OWASP CRS, serving as a developer and co-leader since 2021 and he is part of the OWASP Coraza leadership team, focusing on the development of new Web Application Firewalls (WAFs). Committed to fostering open-source engagement, he has served as a Google Summer of Code mentor for four consecutive years, nurturing students involvement in open-source and OWASP initiatives.
Agustín de León
Universidad de la República (UdelaR)
Computer Engineer, FIng
Agustín de León is a Computer Engineer, cybersecurity consultant, and a member of the Computer Security team at the Facultad de Ingeniería, Universidad de la República (UdelaR), Uruguay. He is currently pursuing a Master's degree in Information Security to expand his knowledge and build a solid academic foundation in the field. His areas of interest include Web Security, Web Application Firewalls (WAFs), and Formal Methods. As a member of the Computer Security team, he has been working on a new schema for defining WAF rules.
Managed by the OWASP® Foundation
owasp.org
The goal of OWASP CRS is to define rules for web attacks that can be used by WAF engines to protect web applications. The current implementation of CRS rules depends on the ModSecurity Rule Language (a.k.a. Seclang) syntax. As a consequence, rules are not portable to other WAF technologies without heavy lifting. Furthermore, they include the configuration specifics of the ModSecurity engine within their definitions. As a result, anyone trying to use CRS must be familiar with security concepts and subtleties needed to define the rules, using Seclang syntax and with the ModSecurity engine configurations.
The Seclang was created to satisfy constraints that arose when ModSecurity was confined to the Apache engine. These limitations are long gone now, but the behavior and particular syntax hasn't changed in more than fifteen or twenty years.
In this presentation we introduce a new language agnostic to the WAF technology used, opening OWASP CRS to new ecosystems and tools. At the same time, we aim to reduce the learning curve for contributors and simplify the rule definition process, while being able to automatically translate rules in this new language to and from Seclang for maximum compatibility.
We will cover the new language concepts and definitions, the challenges faced and the solutions proposed. We needed to capture the information present in the Seclang rules to extract and transform the current CRS rules to the new language. This means that the new rule representation must be able to represent at least the minimum set of Seclang features needed to write a rule, so that existing tools based on Seclang can be used with the new language, while remaining generic enough to be used by different programming languages.
Felipe Zipitria
Life360
OWASP CRS project co-leader
Uruguay
uy.linkedin.com/in/felipezipitria
Felipe Zipitria is an expert in computer security, graduated with an MSc from the Universidad de la República in Uruguay. With over 20 years of experience in SRE, DevOps, and SysAdmin roles, Felipe has transitioned into specialized areas, dedicating the past 5 years to AppSec and Cloud SecOps. His extensive expertise spans security consulting for over a decade. Passionate about education, Felipe instructs pregraduate students in Computer Security Fundamentals and guides postgraduates in Web Application Security at the local public University, with the help of OWASP published materials. He started as the Uruguay Co-Chapter Leader in 2013, and started engaging in projects with global outreach. He is a longstanding contributor to OWASP CRS, serving as a developer and co-leader since 2021 and he is part of the OWASP Coraza leadership team, focusing on the development of new Web Application Firewalls (WAFs). Committed to fostering open-source engagement, he has served as a Google Summer of Code mentor for four consecutive years, nurturing students involvement in open-source and OWASP initiatives.
Agustín de León
Universidad de la República (UdelaR)
Computer Engineer, FIng
Agustín de León is a Computer Engineer, cybersecurity consultant, and a member of the Computer Security team at the Facultad de Ingeniería, Universidad de la República (UdelaR), Uruguay. He is currently pursuing a Master's degree in Information Security to expand his knowledge and build a solid academic foundation in the field. His areas of interest include Web Security, Web Application Firewalls (WAFs), and Formal Methods. As a member of the Computer Security team, he has been working on a new schema for defining WAF rules.
Managed by the OWASP® Foundation
owasp.org










