Centralized security log collection, automatic threat detection, smart banning and a full dashboard.
Lightweight, self-hosted, no external dependencies.
A complete system for detection, analysis and automatic response
Rules configurable per attack type. Ban graduation, repeat offenders, permanent ban. Reduced thresholds for Tor/VPN and malicious ranges.
Score 0-100 across 3 axes: aggressiveness, diversity, persistence. Reputation per /24 range and AS. Noise vs targeted classification.
SSH, HTTP, FTP, SMTP, MySQL, PAM, Firewall. One-command install. 1080+ CrowdSec patterns.
Geographic map, statistics, charts, advanced filters. Dark theme. CSV/JSON export.
Email, Telegram, Webhook. Interactive bot with 8 commands. Anti-flood cooldown. Configurable triggers.
Automatic import from Firehol, Blocklist.de, Spamhaus, Tor. Ban enrichment. Export API in 8 formats.
2FA TOTP, CSRF, rate limiting, anti-SSRF, AES-256-GCM, HSTS/CSP headers. Full audit applied.
Batch INSERT, optimized indexes, persistent connections, flock-protected crons. Production ready.
Each plugin monitors a specific service and reports events to the central server
Deploy on a new machine in under a minute — with automatic approval
Sign in to the dashboard to start monitoring your machines.
Open the dashboard