Harden infrastructure security.

Logo CrowdSec

CrowdSec

Collaborative protection against attacks — behavioural detection and shared threat intelligence.

1 GB RAM 1 vCPU Available

Tech stack

CrowdSecFirewall Bounceriptables
Minimum RAM1 GB
Minimum CPU1 vCPU
Compatible OSubuntu-24.04

CrowdSec is an open-source security engine that analyses the logs of your services (SSH, web, applications) to detect malicious behaviour, then blocks the offending IPs through a "bouncer". Its strength is collaborative: every reported IP feeds a community threat-intelligence database, and in return you benefit from the reports of thousands of other instances.

Deployed on your VPS, CrowdSec installs the detection agent, the scenarios (collections) suited to your services, and a firewall bouncer (iptables) that enforces the blocking decisions. Where fail2ban acts locally, CrowdSec adds a network dimension: you proactively block IPs known to be malicious before they even attack you.

Key features

Behavioural detection through log analysis (SSH, web, applications)
Collaborative threat intelligence: benefit from the community's reports
Firewall bouncer (iptables) that applies blocks automatically
Ready-to-use scenarios and collections tailored to your services
Optional centralised console to supervise multiple machines
Lightweight and production-ready, complementary to fail2ban

When to use this solution?

1

Protect an exposed server

Automatically detect and block SSH brute-force attacks and web scans on your public servers.

2

Proactive blocking

Leverage the community list of malicious IPs to block known threats before they target you.

3

Server fleet

Centralise the monitoring of multiple machines through the CrowdSec console and share blocking decisions.

Deploy CrowdSec on your VPS

Guide optimized for ServOrbit Cloud VPS.

01

Create the VPS

A VPS with 1 GB RAM, Ubuntu 22.04. The "CrowdSec" template installs the agent and the iptables firewall bouncer automatically.

02

Check detection

Check the status with cscli metrics and cscli decisions list: the agent is already analysing the SSH and system logs.

03

Add collections

Install the scenarios suited to your services (cscli collections install crowdsecurity/nginx, etc.) according to what you host.

04

Connect the console (optional)

Register the instance with the CrowdSec console to supervise alerts and decisions from a centralised interface.

Frequently asked questions

CrowdSec is an open-source security engine that detects malicious behaviour in logs and blocks the offending IPs, drawing on a collaborative threat-intelligence database.

Harden infrastructure security.

Activate CrowdSec on your infrastructure.

Dedicated Cloud VPS — IPv4 included, European datacenter, support included. Your data never leaves your server.

Recommended configuration: 1 GB RAM · 1 vCPU

Need help?

Browse our help center and FAQ, or write to our team — support in French, English and Arabic.