Since ModSecurity understands the HTTP protocol, it is able to perform fine-grained filtering on any section of the HTTP request or response, including the request line, individual parameters, named headers or cookies, POST payloads, and even the response body. This allows any malicious requests and evasion techniques to be captured before they reach the web server, and any unexpected errors or output being generated by the web server or web application is able to be captured or sanitized.

