[{"data":1,"prerenderedAt":88},["ShallowReactive",2],{"seo-verification":3,"marketplace-app-en-crowdsec":6},{"google":4,"bing":5},"EycwPY2XMyTkVzas3n1ygeNJFGAH513qrMjfDljzsMQ","",{"slug":7,"name":8,"description":9,"phase":10,"docsUrl":11,"logo":12,"github":13,"tagline":14,"longDescription":15,"features":16,"useCases":23,"steps":33,"faq":46,"specs":59,"compatibleOs":65,"relatedApps":67,"relatedPosts":83,"category":85},"crowdsec","CrowdSec","Collaborative protection against attacks. Behavioural detection and threat-intelligence sharing with the community.",1,"https:\u002F\u002Fservorbit.com\u002Fblog\u002Fsecuriser-vps-crowdsec","https:\u002F\u002Fcdn.jsdelivr.net\u002Fgh\u002Fselfhst\u002Ficons\u002Fsvg\u002Fcrowdsec.svg","https:\u002F\u002Fgithub.com\u002Fcrowdsecurity\u002Fcrowdsec","Collaborative protection against attacks — behavioural detection and shared threat intelligence.","CrowdSec is an open-source security engine that analyses the logs of your services (SSH, web, applications) to detect malicious behaviour, then blocks the offending IPs through a \"bouncer\". Its strength is collaborative: every reported IP feeds a community threat-intelligence database, and in return you benefit from the reports of thousands of other instances.\n\nDeployed on your VPS, CrowdSec installs the detection agent, the scenarios (collections) suited to your services, and a firewall bouncer (iptables) that enforces the blocking decisions. Where fail2ban acts locally, CrowdSec adds a network dimension: you proactively block IPs known to be malicious before they even attack you.",[17,18,19,20,21,22],"Behavioural detection through log analysis (SSH, web, applications)","Collaborative threat intelligence: benefit from the community's reports","Firewall bouncer (iptables) that applies blocks automatically","Ready-to-use scenarios and collections tailored to your services","Optional centralised console to supervise multiple machines","Lightweight and production-ready, complementary to fail2ban",[24,27,30],{"title":25,"body":26},"Protect an exposed server","Automatically detect and block SSH brute-force attacks and web scans on your public servers.",{"title":28,"body":29},"Proactive blocking","Leverage the community list of malicious IPs to block known threats before they target you.",{"title":31,"body":32},"Server fleet","Centralise the monitoring of multiple machines through the CrowdSec console and share blocking decisions.",[34,37,40,43],{"title":35,"body":36},"Create the VPS","A VPS with 1 GB RAM, Ubuntu 22.04. The \"CrowdSec\" template installs the agent and the iptables firewall bouncer automatically.",{"title":38,"body":39},"Check detection","Check the status with `cscli metrics` and `cscli decisions list`: the agent is already analysing the SSH and system logs.",{"title":41,"body":42},"Add collections","Install the scenarios suited to your services (`cscli collections install crowdsecurity\u002Fnginx`, etc.) according to what you host.",{"title":44,"body":45},"Connect the console (optional)","Register the instance with the CrowdSec console to supervise alerts and decisions from a centralised interface.",[47,50,53,56],{"q":48,"a":49},"What is CrowdSec?","CrowdSec is an open-source security engine that detects malicious behaviour in logs and blocks the offending IPs, drawing on a collaborative threat-intelligence database.",{"q":51,"a":52},"How is it different from fail2ban?","fail2ban blocks locally after repeated failures. CrowdSec adds a collaborative dimension (a community list of malicious IPs) and a more modular agent\u002Fbouncer architecture. The two are complementary.",{"q":54,"a":55},"Does CrowdSec share my data?","CrowdSec shares only malicious-IP signals (address, attack type, timestamp), not the contents of your logs. Community sharing can be disabled.",{"q":57,"a":58},"Which services does CrowdSec protect?","SSH, web servers (Nginx, Apache), firewalls and many applications, via scenario collections you can install according to your needs.",{"ram":60,"cpu":61,"stack":62},"1 GB","1 vCPU",[8,63,64],"Firewall Bouncer","iptables",[66],"ubuntu-24.04",[68,77],{"name":69,"slug":70,"categorySlug":71,"categoryName":72,"categoryColor":73,"logo":74,"tagline":75,"description":76},"Fail2Ban Enhanced","fail2ban-enhanced","cybersecurity","Cybersecurity & Bastion","text-red-400 bg-red-500\u002F10","https:\u002F\u002Fcdn.jsdelivr.net\u002Fgh\u002Fselfhst\u002Ficons\u002Fpng\u002Ffail2ban.png","Automatic intrusion blocking — a hardened, production-ready configuration out of the box.","Automatic blocking of intrusion attempts, with a production-optimised configuration and real-time alerts.",{"name":78,"slug":79,"categorySlug":71,"categoryName":72,"categoryColor":73,"logo":80,"tagline":81,"description":82},"Bastion Host","bastion-host","\u002Fbrand\u002Flogo\u002Fservorbit-m.svg","A secure, hardened SSH entry point to your infrastructure, with centralised auditing.","A secure entry point to your infrastructure. A configured, hardened SSH jump host with centralised audit logs.",[84],"securiser-vps-crowdsec",{"key":86,"slug":71,"name":72,"objective":87,"icon":86,"color":73},"security","Harden infrastructure security.",1785628467737]