CrowdSec delivers real-time, crowd-powered threat intelligence, with exclusive data and automated integration, to preemptively block cyberattacks and reduce alert fatigue. Know which CVE is trendy, where, when and why in real time. Sort out noise for emergency using our API.
CrowdSec Threat Intelligence offers a powerful, crowd-powered cybersecurity solution that delivers real-time, ultra-curated threat data to help organizations proactively defend against cyber attacks. Designed for security teams and IT professionals, it provides exclusive insights into malicious IPs and live exploitation activity, enabling preemptive blocking of threats before they impact your infrastructure.
Real-time AI-driven blocklists are updated multiple times per hour to block up to 95% of mass exploitation attempts
Live Exploit Tracker delivers ground-truth intelligence on active attacks and zero-day exploit visibility
Exclusive data sourced from a global network of over 100,000 users across 190 countries, ensuring diverse and accurate threat detection
Detailed indicators of compromise, including targeted URLs, payloads, and user agents for enhanced context
Automated integration with firewalls, CDNs, and security tools via API for seamless deployment and response automation
Open-source Security Engine compatible across various operating systems and infrastructures
Continuous updates with a 5% daily rotation of IPs to maintain up-to-date protection and reduce false positives
CrowdSec integrates smoothly with popular platforms such as Cisco, AWS, Fortinet, Cloudflare, and iptables, as well as SIEM and SOAR tools, enabling automated enrichment and incident response. This solution not only reduces alert fatigue by up to 80% but also lowers incident response workload and server resource usage, delivering immediate operational savings.
Empower your security operations with CrowdSecs collaborative intelligence and stay ahead of evolving cyber threats with confidence and ease.
Highlights
Live Exploit Tracker provides ground-truth insights on active attacks and zero-day exploit visibility
Seamless API integration with firewalls, CDNs, and SIEM/SOAR tools for automated response and reduced alert fatigue
CVSS, EPSS, CVE, and KVE scores estimate likelihood. Live Exploit Tracker shows reality.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing has one pricing dimension, billed as Units under a contract. Each Unit gives you access to Live Exploit Tracker, which reports on any CVE and lists the IPs actively exploiting it. Pricing scales with the number of Units you purchase, so you match the quantity to your needs. The intelligence draws from live attack activity observed across many production systems, delivering a per-CVE feed of exploiting IPs and related insights. There are no separate tiers or instance sizes to choose from within this listing.
Top-of-mind questions for buyers
What does one Unit of the Live Exploit Tracker actually give me access to?
Each Unit gives you access to per-CVE exploitation intelligence. You get a continuously updated list of IPs exploiting a given CVE, refreshed multiple times per hour. You also see a composite exploitation score, top targeted countries, and reconnaissance activity probing specific vendors or technologies before a CVE becomes public.
How can I route this exploitation data into my existing security tools?
You can pull exploitation intelligence through an API and route it into your own tools, such as security monitoring or automation systems. The IP data can serve as a raw threat intelligence feed or as an edge-consumable blocklist format for firewalls and similar devices.
Where does the exploitation intelligence come from, and how current is it?
The data comes from live attack activity observed across hundreds of thousands of production systems worldwide. IP data updates multiple times per hour, with IPs added or removed based on recent activity. Reconnaissance targeting specific vendors or technologies is sometimes observed weeks before a CVE is publicly disclosed.
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
For support with CrowdSec Threat Intelligence Platform, please contact us at support@crowdsec.net
Support is available during business hours.
Buyers can expect help via email or through our website for general inquiries, troubleshooting, and product guidance.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product has charges associated with it for seller support. CrowdSec is an open source, collaborative security platform that detects and mitigates cyber threats using behavior analysis and a shared threat intelligence network.
CrowdSec Security Engine provides a real-time, collaborative WAF / WAAP & IDS. When they block an IP address that attacked the protected workloads, that IP is curated and shared with all your other servers and every other network member to further protect everyone. It leverages open-source intelligence from a global user network to protect your infrastructure and applications. The WAF and IDS are provided as FOSS, along with their detection scenarios, virtual patches, and WAF rules. The Premium SaaS console provides extra security, compliance, QoL, centralisation, reporting, data retention and multi tenancy features.
CrowdSec stands out for its community-driven threat intelligence and its collaborative approach to security. It automatically detects malicious activity, such as brute-force attacks, and shares anonymized threat data with the global CrowdSec network so organizations can benefit from a stronger, collective defense.
What do you dislike about the product?
The effectiveness of certain protections also depends on the quality and volume of community-contributed threat intelligence. In addition, organizations that need robust enterprise reporting, compliance features, or more advanced centralized management may find that some capabilities are not yet as mature as those provided by larger commercial security platforms.
What problems is the product solving and how is that benefiting you?
This solution has reduced security incidents, eased the workload on our IT team, improved server and application availability, and strengthened our overall security posture—all without requiring significant additional investment in security infrastructure.
Samuel L.
Fantastic software with affordable options including free. Extremely extensive library of modules.
Reviewed on Jun 14, 2023
Review provided by G2
What do you like best about the product?
It's free and given I have two start ups in pre-seed round that is a god send. It is fantastic software that I use on all my servers. From basic ssh bouncers to more complex strategies.
What do you dislike about the product?
The UI is really nice, but things can get a bit hairy when you start deploying more complicated bouncers. It's no longer a click and deploy experience and many bouncers I use are community submitted so documentation is hit or miss.
What problems is the product solving and how is that benefiting you?
It is serving as a augmentation to the base firewall and also as an IDS system for all my servers. It is easy to use that dashboard to quickly get a glance at all my nodes and their security status.
Silvio M.
An useful instrument for cybersecurity
Reviewed on Jun 08, 2023
Review provided by G2
What do you like best about the product?
- Easy to use. - Many possibilities to integrate it, defining golang bouncer scripts. - Collaborative cyber threat intelligence.
What do you dislike about the product?
- It should offer Crowdsec Web Panel, also as self-hosted service, on the server where Crowdsec is installed. - Missing the ability to use custom blocklists in Web Panel, with the possibility to enable only two blocklists for free users. - A map summarizing the attacks collected and custom alert filters would be appreciated.
What problems is the product solving and how is that benefiting you?
It helps me to detect and manage intrusions.
Joe L.
Easy to install and configure crowd powered fail2ban
Reviewed on Jun 08, 2023
Review provided by G2
What do you like best about the product?
Simple to install and configure. Web gui shows useful stats and lookup for bad ip addresses. Running CrowdSec will help add to the community block list
What do you dislike about the product?
The most useful blocklist like the VPN list is paywalled. Pricing is a mystery.
What problems is the product solving and how is that benefiting you?
Blocks most bots and bad actors on all services on the server
Rei B.
It's a real life-saver in terms of hosting stuff
Reviewed on Jun 07, 2023
Review provided by G2
What do you like best about the product?
What I love about it is it's open source nature. By parsing logs you can block bad actors just like you would with fail2ban - but with grok patterns which are way easier to write and implement. New parsers are easily constructed and it's really easy to keep a ton of bad traffic out of your network.
What do you dislike about the product?
A bad thing about it is that you'd have to get a premium subscription in case you want more 'signals' than you share. Mostly ssh and http scenarios do although cover most of your bases.
What problems is the product solving and how is that benefiting you?
Crowdsec itself saves me a lot of CPU load by keeping nasty IP addresses at bay. I had a 15% load decrease on the hypervisor which may not sound like much. In my case it was around the CPU power that a complete Linux VM would need.