crowdsec.md 1.6 KB

CrowdSec

Description

CrowdSec

CrowdSec is a free, modern, and collaborative behavior detection engine coupled with a global IP reputation network. It stacks on fail2ban's philosophy but is IPV6 compatible and 60x faster (Go vs. Python) and uses Grok patterns to parse logs. CrowdSec is engineered for modern Cloud / Containers / VM-based infrastructures (by decoupling detection and remediation). Once detected, you can remedy threats with various methods (firewall block, Nginx HTTP 403, Captchas, …) while sharing the aggressive IP to CrowdSec Network and improving everyone's security further.

Categories

  • Network Defense
  • Incident Response
  • Data forensics

Black Hat sessions

Arsenal Arsenal

Code

https://github.com/crowdsecurity/crowdsec

Lead Developer(s)

Social Media