Ross ROSS = Recommend OSS · open-source software intelligence for agents

crowdsecurity/crowdsec

CrowdSec - the open-source and participative security solution offering crowdsourced protection against malicious IPs and access to the most advanced real-world CTI. observed · 2026-08-28

github.com/crowdsecurity/crowdsec · homepage · Go · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

89/100

  • Activity 99
  • Release rhythm 71
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 40.5
  • age_days: 2301
  • days_rel: 114
  • days_push: 7
  • n_releases_24m: 17

Full methodology

Adoption not part of the score

14655 stars · 710 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

CrowdSec is an open-source, crowdsourced security engine that analyzes logs and HTTP requests to detect malicious behavior and block offending IPs, functioning as an IDS/IPS and WAF. It shares detected attacker IPs with a community network in exchange for a real-time community blocklist, with commercial curated threat intelligence available.

Use cases

  • block malicious ips attacking my server
  • fail2ban alternative with crowdsourced blocklist
  • detect and ban brute force attempts from logs
  • protect web server from scanners and bots
  • waf to block web exploits
  • share attack data and get community blocklist
  • feed ip blocklists into firewall or cdn
  • reduce alert noise from mass scanners

When to choose

  • you need log-based intrusion detection with automatic IP remediation across Linux servers
  • you want a modern, actively maintained fail2ban replacement with community threat intelligence
  • you need to push curated blocklists into firewalls, CDNs, or reverse proxies
  • you want both IDS/IPS behavior detection and a WAF/AppSec component in one engine

When to avoid

  • you need endpoint antivirus or malware scanning rather than network/IP-based protection
  • you require a fully self-contained solution with no external blocklist or community network dependency
  • you need deep packet inspection of encrypted traffic or host-based EDR capabilities

Facets

application · maturity stable

security monitoring logging rate-limiting middleware security self-hosted networking go self-hosted cross-platform ids ips waf fail2ban-alternative threat-intelligence crowdsourced-blocklist log-analysis ip-reputation intrusion-detection firewall-integration devops linux docker

8 sources

Member repositories

RepositoryRoleHealth v2
crowdsecurity/crowdsecmain89

For agents

markdown · JSON · MCP: product_card(name="crowdsecurity/crowdsec")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem