CrowdSec
Crowdsourced IDS/IPS and WAF with shared malicious IP intelligence
14.3k stars 688 forks last commit first released MIT
Actively maintained
Last commit 27 Jul 2026.

CrowdSec is an open-source, community-driven security engine that detects malicious behavior by analyzing logs and HTTP requests. It combines local detection with shared threat intelligence so you can block attackers across your stack.
Key Features
- IDS/IPS-style detection based on behavior analysis from log sources
- Optional WAF-style application security for analyzing HTTP requests
- “Detect here, remedy there” architecture with pluggable remediation components (bouncers)
- Community blocklist of malicious IPs built from real-world signals contributed by users
- Extensible detection scenarios and parsers available via a shared hub
- Broad platform support, including common Linux deployments and containerized setups
Use Cases
- Block brute-force attempts, scanning, and abusive automation at the host or edge
- Reduce security alert noise by preemptively blocking known malicious IPs
- Centralize detection from multiple services while enforcing remediation on firewalls, proxies, or applications
Limitations and Considerations
- Effectiveness depends on correct log ingestion/parsing and properly tuned scenarios to avoid missed detections
- Remediation requires deploying and maintaining compatible bouncers for your chosen enforcement points
CrowdSec fits teams that want practical intrusion detection and automated blocking without replacing their existing infrastructure. Its value increases with community participation by continuously improving shared attacker intelligence.
Categories:
Tags:
Tech Stack:
Similar to CrowdSec

Fail2Ban
Log-monitoring daemon that bans abusive IPs via firewall rules
Fail2Ban monitors service logs for repeated failures and automatically bans abusive IP addresses by updating firewall rules for a configurable time.

SafeLine
Self-hosted WAF and reverse proxy for securing web apps
SafeLine is a self-hosted Web Application Firewall (WAF) and reverse proxy that defends web apps from SQL injection, XSS, bot abuse, and DDoS using ML-powered threat detection and configurable policies.
Fail2Ban-Report
Web dashboard for Fail2Ban logs and centralized UFW blocklist management
Lightweight PHP dashboard that converts Fail2Ban logs into searchable JSON reports and centralizes UFW-based blocklist control with HTTPS-based multi-server sync.

Beelzebub
Low-code honeypot framework using LLMs for safe system deception
Secure low-code honeypot framework that uses LLMs to simulate high-interaction systems across SSH/HTTP/TCP and MCP, with metrics and cloud-native deployment options.
NetAlertX
Network device scanner and presence detection with alerts
Self-hosted network visibility and presence scanner that discovers connected devices and alerts on new, unknown, or changed hosts across your LAN/Wi‑Fi.

Canarytokens
Honeytokens that alert when accessed or executed
Canarytokens generates honeytokens (URLs, files, credentials, docs) that alert you when an attacker touches them, helping detect breaches early.




