toutes les options
bullseye  ] [  bookworm  ] [  trixie  ] [  sid  ]
[ Paquet source : crowdsec  ]

Paquet : crowdsec (1.4.6-7)

Liens pour crowdsec

Screenshot

Ressources Debian :

Télécharger le paquet source crowdsec :

Responsables :

Ressources externes :

Paquets similaires :

lightweight and collaborative security engine

CrowdSec is a lightweight security engine, able to detect and remedy aggressive network behavior. It can leverage and also enrich a global community-wide IP reputation database, to help fight online cybersec aggressions in a collaborative manner.

CrowdSec can read many log sources, parse and also enrich them, in order to detect specific scenarios, that usually represent malevolent behavior. Parsers, Enrichers, and Scenarios are YAML files that can be shared and downloaded through a specific Hub, as well as be created or adapted locally.

Detection results are available for CrowdSec, its CLI tools and bouncers via an HTTP API. Triggered scenarios lead to an alert, which often results in a decision (e.g. IP banned for 4 hours) that can be consumed by bouncers (software components enforcing a decision, such as an iptables ban, an nginx lua script, or any custom user script).

The CLI allows users to deploy a Metabase Docker image to provide simple-to-deploy dashboards of ongoing activity. The CrowdSec daemon is also instrumented with Prometheus to provide observability.

CrowdSec can be used against live logs (“à la fail2ban”), but can also work on cold logs to help, in a forensic context, to build an analysis for past events.

On top of that, CrowdSec aims at sharing detection signals amongst all participants, to pre-emptively allow users to block likely attackers. To achieve this, minimal meta-information about the attack is shared with the CrowdSec organization for further retribution.

Users can also decide not to take part into the collective effort via the central API, but to register on a local API instead.

Autres paquets associés à crowdsec

  • dépendances
  • recommandations
  • suggestions
  • enhances

Télécharger crowdsec

Télécharger pour toutes les architectures proposées
Architecture Taille du paquet Espace occupé une fois installé Fichiers
amd64 32 409,8 ko116 911,0 ko [liste des fichiers]
arm64 27 726,9 ko112 557,0 ko [liste des fichiers]
armel 27 528,3 ko111 671,0 ko [liste des fichiers]
armhf 27 477,8 ko111 355,0 ko [liste des fichiers]
i386 29 307,9 ko110 902,0 ko [liste des fichiers]
mips64el 24 753,8 ko127 923,0 ko [liste des fichiers]
ppc64el 27 344,8 ko115 683,0 ko [liste des fichiers]
s390x 29 286,6 ko124 134,0 ko [liste des fichiers]