ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Anyone using CrowdSec?

    IT Discussion
    4
    4
    485
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DanpD
      Danp
      last edited by Danp

      Just read about it here and was wondering if anyone has tried it out yet?

      From their GitHub repo --

      A modern behavior detection system, written in Go. It stacks on Fail2ban's philosophy, but uses Grok patterns & YAML grammar to analyse logs, a modern decoupled approach (detect here, remedy there) for Cloud/Containers/VM based infrastructures. Once detected you can remedy threats with various bouncers (block, 403, Captchas, etc.) and blocked IPs are shared among all users to further improve their security.

      1 Reply Last reply Reply Quote 0
      • scottalanmillerS
        scottalanmiller
        last edited by

        Have not used it nor seen it. But was thinking just this morning about the need for something like this. I like the idea.

        1 Reply Last reply Reply Quote 0
        • JaredBuschJ
          JaredBusch
          last edited by

          This looks like a good tool. If it is performant at high volume that will be a huge improvment over fail2ban.

          I am a little concerned about the global block process. But I assume they have that addressed someplace. I only read this page, nothing else yet.

          DashrenderD 1 Reply Last reply Reply Quote 0
          • DashrenderD
            Dashrender @JaredBusch
            last edited by

            @JaredBusch said in Anyone using CrowdSec?:

            This looks like a good tool. If it is performant at high volume that will be a huge improvment over fail2ban.

            I am a little concerned about the global block process. But I assume they have that addressed someplace. I only read this page, nothing else yet.

            yeah, that's what gave me pause too.

            But definitely seems like a cool idea.

            What I want to know is who's footing the bill for the centralized collection of these IPs and redistribution.

            1 Reply Last reply Reply Quote 0
            • 1 / 1
            • First post
              Last post