I want to…
Detect & Block attacks on my servers
Locally identify and ban bad behaving IPs observed in your logs and requests with CrowdSec Detection Scenarios, and Virtual-Patching Collections.
→ Security Engine
akaIDPSWAFCrowdSec FOSS
Push a Blocklists into my firewall, CDN or WAF
You manage network perimeter devices and want a URL to subscribe to — no agent to install.
→ Blocklist Integration Endpoint
akaThreat FeedsIOC StreamsDeny-list
Investigate IPs Behaviors and Enrich Alerts
You're a security analyst or developer who wants IP context, behaviors, CVEs, Aggressivity... In a browser or via REST API.
→ IP Reputation & CTI
akaIoC LookupThreat Intel
Already running CrowdSec?
💡 how each path works