crowdsecurity/crowdsec
CrowdSec - the open-source and participative security solution offering crowdsourced protection against malicious IPs and access to the most advanced real-world CTI. observed · 2026-08-28
Health v2 · maintenance only
89/100
- Activity 99
- Release rhythm 71
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 40.5
- age_days: 2301
- days_rel: 114
- days_push: 7
- n_releases_24m: 17
Adoption not part of the score
14655 stars · 710 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
CrowdSec is an open-source, crowdsourced security engine that analyzes logs and HTTP requests to detect malicious behavior and block offending IPs, functioning as an IDS/IPS and WAF. It shares detected attacker IPs with a community network in exchange for a real-time community blocklist, with commercial curated threat intelligence available.
Use cases
- block malicious ips attacking my server
- fail2ban alternative with crowdsourced blocklist
- detect and ban brute force attempts from logs
- protect web server from scanners and bots
- waf to block web exploits
- share attack data and get community blocklist
- feed ip blocklists into firewall or cdn
- reduce alert noise from mass scanners
When to choose
- you need log-based intrusion detection with automatic IP remediation across Linux servers
- you want a modern, actively maintained fail2ban replacement with community threat intelligence
- you need to push curated blocklists into firewalls, CDNs, or reverse proxies
- you want both IDS/IPS behavior detection and a WAF/AppSec component in one engine
When to avoid
- you need endpoint antivirus or malware scanning rather than network/IP-based protection
- you require a fully self-contained solution with no external blocklist or community network dependency
- you need deep packet inspection of encrypted traffic or host-based EDR capabilities
Facets
application · maturity stable
security monitoring logging rate-limiting middleware security self-hosted networking go self-hosted cross-platform ids ips waf fail2ban-alternative threat-intelligence crowdsourced-blocklist log-analysis ip-reputation intrusion-detection firewall-integration devops linux docker
8 sources
- readme: https://github.com/crowdsecurity/crowdsec · fetched 2026-08-28 · f4f0db246194
- homepage: https://crowdsec.net · fetched 2026-08-29 · e1374768c0d3
- site_page: https://www.crowdsec.net/about · fetched 2026-08-29 · 29310e31e501
- site_page: https://www.crowdsec.net/pricing · fetched 2026-08-29 · 721c4c990fb6
- site_page: https://www.crowdsec.net/our-data · fetched 2026-08-29 · a607ad63234d
- site_page: https://www.crowdsec.net/integrations · fetched 2026-08-29 · 33f3135a3577
- site_page: https://doc.crowdsec.net/ · fetched 2026-08-29 · c7098805548e
- site_page: https://www.crowdsec.net/faq · fetched 2026-08-29 · ec6b1114cf1a
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| crowdsecurity/crowdsec | main | 89 |
For agents
markdown · JSON · MCP: product_card(name="crowdsecurity/crowdsec")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem