MirrorNest
← Tutte le guide

CrowdSec

CrowdSec is a collaborative, behavior-based intrusion detection engine that parses logs for attack patterns and shares anonymized threat signals across its community, then relies on separate 'bouncer' components to actually block traffic.

Sistema: Debian / Ubuntu / RHEL / Fedora LinuxSecuritySito ufficiale ↗Documentazione ufficiale ↗
Questa guida è redatta a partire dalla documentazione ufficiale di CrowdSec, linkata sopra — verifica sempre lì i nomi esatti di pacchetti/versioni prima di eseguire questi comandi su un server di produzione, poiché le versioni della distribuzione e del progetto cambiano nel tempo.
  1. 1Install the Security Engine via the official repository script

    curl -s https://install.crowdsec.net | sudo sh
    sudo apt install crowdsec

    The script only registers the official CrowdSec package repository; you still install the package explicitly afterward.

  2. 2Verify the service is running

    sudo systemctl status crowdsec
  3. 3Add a Remediation Component

    CrowdSec's Security Engine only detects and decides — you need a bouncer (e.g. firewall or Nginx bouncer) installed separately to enforce bans.