I'm trying to just have mod_security shoot the offending IP into the csf firewall we have set up.

Trying stuff like this (following) but so far nothing seems to work:

SecFilter viagra "exec:/etc/csf/csf.pl -d 'REMOTE_ADDR'"

Any ideas?