Deploy Now

Stars

692

Forks

37

Watchers

3

Developer links

CrowdSec Web UI

CrowdSec Web UI provides a centralized web console for monitoring intrusion detection telemetry, managing firewall remediation decisions, and auditing security events across multiple CrowdSec security engines. Administrators can connect several CrowdSec Local API endpoints simultaneously, aggregating threat intelligence and active bans into a unified visual interface. The dashboard displays geographic origins of attacking IP addresses, active remediation durations, and specific scenario triggers such as brute-force authentication attacks or web vulnerability probes. Operators can search through historical alert logs, inspect raw HTTP request details, and drill down into individual IP behaviors to differentiate authentic threats from false positives. Manual intervention tools let security teams enforce custom IP bans, adjust expiration timers, or immediately revoke erroneous bans across all connected bouncers with a single click. Integrated notification pipelines dispatch real-time security alerts to external destinations including ntfy, Gotify, and MQTT message brokers whenever critical thresholds are breached. Built-in Prometheus metrics dashboards visualize processing latencies, parser throughput, and decision counts over customizable time windows. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.

CrowdSec Web UI
CrowdSec Web UI
CrowdSec Web UI
CrowdSec Web UI
CrowdSec Web UI

Benefits

  • Multi-Instance Local API Aggregation
  • Connect multiple distributed CrowdSec Local API nodes into a centralized dashboard to track intrusion alerts, synchronize remediation decisions, and supervise perimeter defenses across your infrastructure from one single interface.
  • Rapid Manual Remediation Control
  • Enforce immediate IP address or CIDR range bans with custom expiration durations, or instantly revoke false-positive decisions across all connected remediation bouncers without accessing host terminal sessions.
  • Granular Attack Scenario Forensics
  • Inspect detailed alert records including offending IP addresses, geographical country tags, triggered detection scenarios, and associated HTTP requests or log events to rapidly identify adversarial attack vectors.
  • Automated Push Alert Dispatching
  • Route instant notifications for critical security events and new decisions directly to mobile and desktop channels using native webhooks for ntfy, Gotify servers, and MQTT message brokers.

Features

  • LAPI Multi-Node Management
  • Connects securely to CrowdSec Local API instances using machine credentials or mTLS certificates with support for per-instance synchronization intervals.
  • Interactive Threat Dashboard
  • Visualizes alert volumes, active decision counts, top targeted services, and country-level geographic distributions using responsive data charts.
  • Decisions Management Table
  • Provides full search and filtering capabilities across active remediation decisions with options to add custom IP bans or remove existing restrictions.
  • Prometheus Metrics Integration
  • Ingests runtime metrics from CrowdSec Prometheus endpoints to display parser throughput, acquisition processing rates, and local engine health.
  • Multi-Channel Push Notifications
  • Integrates with ntfy push servers, Gotify notification instances, and MQTT brokers to deliver real-time security alerts based on customizable severity filters.