I just found an easy way to check whether ModSecurity is present. Just add cmd.exe somewhere in the URL.
For example: DOMAIN/forums/ubbthreads.php/cmd.exe
This will trigger one of the more ridiculous ModSecurity rules and should return 403 Forbidden on server with enabled ModSecurity. Servers without ModSecurity will ignore this.
that results in Forbidden
You don't have permission to access this resource.