Edit file:
# /etc/apache2/conf.d/modsec/modsec2.user.conf
Add line:
SecRemoteRules (serial key) https://rules.malware.expert/download.php?rules=generic
And replace (serial key) with your subscription serial key!
Full example /etc/apache2/conf.d/modsec/modsec2.user.conf
SecUploadDir /tmp SecTmpDir /tmp SecUploadFileMode 0644 # Needed to Clamav scan SecTmpSaveUploadedFiles on SecRequestBodyAccess On SecRule FILES_TMPNAMES "@inspectFile /usr/local/bin/runav.pl" \ "phase:2,t:none,block,msg:'Virus found in uploaded file',id:'399999'" SecRemoteRules (serial key) https://rules.malware.expert/download.php?rules=generic