7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

CrowdSec

Open source

CrowdSec is an open-source IDS/IPS, WAF and bot detection engine that blocks malicious IPs using a crowdsourced community blocklist.

docs.crowdsec.net
CrowdSec homepage screenshot
GitHub stars
15k
Last commit
today
Repository age
6 years
Version
v1.8.1
Licence
MIT
Self-hosted
Yes

About CrowdSec

CrowdSec is an open-source and participative security solution that detects and blocks malicious behavior on servers. Its Security Engine acts as an all-in-one intrusion detection and prevention system and web application firewall, analyzing log sources and HTTP requests and enforcing decisions through separate remediation components. It runs on Linux, Windows, Docker and Kubernetes.

A Community Blocklist of IP addresses identified as malicious is shared among users, so an address that attacks one participant can be blocked for others before it arrives. Detection and remediation are decoupled, which means logs can be parsed on one machine while blocking happens at a firewall, reverse proxy or CDN elsewhere. A web console supports monitoring and automation.

The README compares it with fail2ban, which reads similar logs, and with ModSecurity, Coraza and naxsi, since the AppSec component is a WAF built on Coraza that loads SecLang rules and the OWASP Core Rule Set. It can also answer suspicious requests with a JavaScript proof-of-work challenge to stop headless scrapers. CrowdSec is written in Go and licensed under MIT.

Key features

  • Log and HTTP request analysis for attack detection
  • Crowdsourced community blocklist of malicious IPs
  • WAF component built on Coraza
  • Remediation at firewall, proxy or CDN
  • Bot detection with proof-of-work challenges
  • Linux, Windows, Docker and Kubernetes support

Good fit for

  • →Replacing or extending fail2ban
  • →Blocking scrapers and bots on public sites
Tags
security
ids-ips
waf
bot-detection
intrusion-detection
blocklist
fail2ban-alternative
golang

CrowdSec: questions and answers

What is CrowdSec used for?
CrowdSec is an open-source IDS/IPS, WAF and bot detection engine that blocks malicious IPs using a crowdsourced community blocklist. It is a good fit for replacing or extending fail2ban, and blocking scrapers and bots on public sites.
Is CrowdSec open source?
Yes. CrowdSec is open source under the MIT licence. Its source code is on GitHub at crowdsecurity/crowdsec and is written mainly in Go.
Is CrowdSec free?
Yes. CrowdSec is open source, so the software itself is free to use.
Can I self-host CrowdSec?
Yes. CrowdSec can be self-hosted on your own server or infrastructure.
What is CrowdSec an alternative to?
CrowdSec is an open-source alternative to Cloudflare, Microsoft Defender, Fastly and Akamai. Other open-source alternatives to Cloudflare include SafeLine, BunkerWeb and ModSecurity.
Is CrowdSec actively maintained?
Yes. The most recent commit to CrowdSec was on 2 October 2026, and the latest release is v1.8.1, published on 3 September 2026. The project has 15k stars on GitHub.

Open-source alternatives to CrowdSec

See all

SaaS alternatives to CrowdSec

See all