MirrorNest
← All guides

CrowdSec

CrowdSec is a collaborative, behavior-based intrusion detection engine that parses logs for attack patterns and shares anonymized threat signals across its community, then relies on separate 'bouncer' components to actually block traffic.

Target: Debian / Ubuntu / RHEL / Fedora LinuxSecurityOfficial homepage ↗Official docs ↗
This guide is synthesized from CrowdSec's own official documentation, linked above — always cross-check exact package/version names there before running these commands on a production server, since distro and project versions move over time.
  1. 1Install the Security Engine via the official repository script

    curl -s https://install.crowdsec.net | sudo sh
    sudo apt install crowdsec

    The script only registers the official CrowdSec package repository; you still install the package explicitly afterward.

  2. 2Verify the service is running

    sudo systemctl status crowdsec
  3. 3Add a Remediation Component

    CrowdSec's Security Engine only detects and decides — you need a bouncer (e.g. firewall or Nginx bouncer) installed separately to enforce bans.