Stars
Forks
Watchers
Developer links
CrowdSec
With over 14,000 GitHub stars and a growing global network of security deployments, CrowdSec turns every attack on any participating server into protection for the entire community. The security engine operates as a combined IDS/IPS and WAF, analyzing log sources from Nginx, Apache, SSH, WordPress, and over 50 other services to detect brute force attacks, port scans, web vulnerability exploitation, and credential stuffing in real time. When one server detects a new threat, the attacker's IP is shared through the community blocklist, proactively protecting thousands of other installations before the attacker can reach them. The built-in WAF powered by Coraza v3 inspects HTTP requests at the application layer, validates against OpenAPI schemas, and applies custom rules with flexible AND/OR condition mixing for precise threat detection. Bot detection serves challenge pages with client fingerprinting to distinguish legitimate traffic from automated scrapers and scanners. Remediation components block malicious IPs at multiple infrastructure layers including iptables, nftables, Nginx, HAProxy, Cloudflare, and AWS Security Groups through the detect-here-remedy-there architecture. The scenario-based detection system ships with default rules for common attack patterns and supports custom scenarios written in YAML with an expressive filter language. A centralized console provides real-time visualization of alerts, threat intelligence analysis, and management of multiple distributed security engines. GDPR compliant by design, all log analysis happens locally and raw logs never leave your infrastructure. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Benefits
- Community-Powered Threat Intelligence
- Every participating deployment shares detected threats, building a real-time global blocklist that proactively protects all users against known malicious IPs before attacks reach their infrastructure.
- Combined IDS/IPS and WAF Protection
- Single security engine provides both log-based intrusion detection with active remediation and HTTP-level web application firewall protection, eliminating the need for separate security tools and configurations.
- GDPR-Compliant Local Analysis
- All log analysis and threat detection happens locally on your infrastructure with raw logs never leaving your server, ensuring compliance with data protection regulations while contributing anonymized threat signals.
- Multi-Layer Remediation Architecture
- Detect threats in one location and block them across iptables, nftables, Nginx, HAProxy, Cloudflare, and AWS Security Groups simultaneously using the detect-here-remedy-there approach.
Features
- Scenario-Based Detection
- YAML-defined detection scenarios for brute force, port scans, web scans, and credential stuffing with an expressive filter language and community hub.
- Web Application Firewall
- Coraza v3 powered WAF inspects HTTP requests, validates OpenAPI schemas, and applies custom rules with flexible AND/OR condition logic.
- Bot Detection Challenge
- Client fingerprinting and challenge pages distinguish legitimate users from automated scrapers, scanners, and credential-stuffing bots.
- Centralized Security Console
- Real-time dashboard visualizes alerts, threat intelligence, IP reputation metrics, and manages multiple distributed security engines from one interface.
- Kubernetes Native Support
- Dedicated Kubernetes datasource fetches logs directly from the API server with Helm chart deployment for cloud-native security monitoring.