CrowdSec is a CTI tool leveraging crowdsourced data to identify malevolent IPs in real time worldwide. This product allows you to subscribe to CrowdSec's CTI API.
Introducing the CrowdSec CTI, the largest and most diverse CTI network. The CrowdSec CTI distributes IP reputation intelligence and delivers key contextualized and curated benchmarking insights from real users across the globe making it an essential tool for threat hunters. Access the CrowdSec CTI with two endpoints:
- CrowdSec Intelligence BL: Our flagship feature offers a real-time, crowd-powered list of the most aggressive IPs involved in malicious activities. It is dynamically updated and curated on the world's largest CTI network, ensuring unparalleled accuracy and actionable defense against emerging threats.
- CrowdSec CTI: This endpoint provides enriched intelligence on specific IP addresses. It offers detailed insights into the duration of malicious activities, types of attacks, and a thorough classification of compromise status. Additionally, it reveals if an IP is associated with a VPN, proxy, botnet, etc., offering an in-depth understanding of potential risks.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing offers two independent product families. The three CrowdSec TI tiers price IP enrichment queries against CrowdSec Threat Intelligence, sized by monthly query volume of 2k, 10k, or 50k. You pick the tier that matches your expected query count. The Blocklists Platinium Subscription is a separate option giving access to all CrowdSec Blocklists for your own use, not for resale. The extra_service dimension covers user-approved add-ons beyond the standard scope. You can combine these dimensions based on your needs.
Top-of-mind questions for buyers
What counts as one query against my CrowdSec TI monthly allowance?
Each query is one IP enrichment lookup against CrowdSec Threat Intelligence. A lookup returns details on a single IP address, including reputation signals, attack behaviors, activity over the last three months, and threat classifications. Your tier caps how many of these lookups you can make each month.
What happens if I reach my monthly query limit before the month ends?
Each TI tier sets a fixed monthly query count of 2k, 10k, or 50k. Once you hit that cap, you move to a higher tier to raise your limit. The extra_service dimension covers user-approved add-ons if you need capacity beyond the standard scope.
How do the TI query tiers and the Blocklists Platinium Subscription bill together?
They bill independently and can be purchased separately. TI tiers charge for IP enrichment queries by monthly volume. The Blocklists Platinium Subscription charges for access to all CrowdSec Blocklists for your own use, not resale. You pay for each dimension you select; they do not share a metric.
www.crowdsec.net+1
Helpful?
Vendor refund policy
All fees are non-refundable and non-cancellable except as required by law.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product has charges associated with it for seller support. CrowdSec is an open source, collaborative security platform that detects and mitigates cyber threats using behavior analysis and a shared threat intelligence network.
CrowdSec Security Engine provides a real-time, collaborative WAF / WAAP & IDS. When they block an IP address that attacked the protected workloads, that IP is curated and shared with all your other servers and every other network member to further protect everyone. It leverages open-source intelligence from a global user network to protect your infrastructure and applications. The WAF and IDS are provided as FOSS, along with their detection scenarios, virtual patches, and WAF rules. The Premium SaaS console provides extra security, compliance, QoL, centralisation, reporting, data retention and multi tenancy features.
CrowdSec delivers real-time, crowd-powered threat intelligence, with exclusive data and automated integration, to preemptively block cyberattacks and reduce alert fatigue. Know which CVE is trendy, where, when and why in real time. Sort out noise for emergency using our API.
CrowdSec stands out for its community-driven threat intelligence and its collaborative approach to security. It automatically detects malicious activity, such as brute-force attacks, and shares anonymized threat data with the global CrowdSec network so organizations can benefit from a stronger, collective defense.
What do you dislike about the product?
The effectiveness of certain protections also depends on the quality and volume of community-contributed threat intelligence. In addition, organizations that need robust enterprise reporting, compliance features, or more advanced centralized management may find that some capabilities are not yet as mature as those provided by larger commercial security platforms.
What problems is the product solving and how is that benefiting you?
This solution has reduced security incidents, eased the workload on our IT team, improved server and application availability, and strengthened our overall security posture—all without requiring significant additional investment in security infrastructure.
Samuel L.
Fantastic software with affordable options including free. Extremely extensive library of modules.
Reviewed on Jun 14, 2023
Review provided by G2
What do you like best about the product?
It's free and given I have two start ups in pre-seed round that is a god send. It is fantastic software that I use on all my servers. From basic ssh bouncers to more complex strategies.
What do you dislike about the product?
The UI is really nice, but things can get a bit hairy when you start deploying more complicated bouncers. It's no longer a click and deploy experience and many bouncers I use are community submitted so documentation is hit or miss.
What problems is the product solving and how is that benefiting you?
It is serving as a augmentation to the base firewall and also as an IDS system for all my servers. It is easy to use that dashboard to quickly get a glance at all my nodes and their security status.
Silvio M.
An useful instrument for cybersecurity
Reviewed on Jun 08, 2023
Review provided by G2
What do you like best about the product?
- Easy to use. - Many possibilities to integrate it, defining golang bouncer scripts. - Collaborative cyber threat intelligence.
What do you dislike about the product?
- It should offer Crowdsec Web Panel, also as self-hosted service, on the server where Crowdsec is installed. - Missing the ability to use custom blocklists in Web Panel, with the possibility to enable only two blocklists for free users. - A map summarizing the attacks collected and custom alert filters would be appreciated.
What problems is the product solving and how is that benefiting you?
It helps me to detect and manage intrusions.
Joe L.
Easy to install and configure crowd powered fail2ban
Reviewed on Jun 08, 2023
Review provided by G2
What do you like best about the product?
Simple to install and configure. Web gui shows useful stats and lookup for bad ip addresses. Running CrowdSec will help add to the community block list
What do you dislike about the product?
The most useful blocklist like the VPN list is paywalled. Pricing is a mystery.
What problems is the product solving and how is that benefiting you?
Blocks most bots and bad actors on all services on the server
Rei B.
It's a real life-saver in terms of hosting stuff
Reviewed on Jun 07, 2023
Review provided by G2
What do you like best about the product?
What I love about it is it's open source nature. By parsing logs you can block bad actors just like you would with fail2ban - but with grok patterns which are way easier to write and implement. New parsers are easily constructed and it's really easy to keep a ton of bad traffic out of your network.
What do you dislike about the product?
A bad thing about it is that you'd have to get a premium subscription in case you want more 'signals' than you share. Mostly ssh and http scenarios do although cover most of your bases.
What problems is the product solving and how is that benefiting you?
Crowdsec itself saves me a lot of CPU load by keeping nasty IP addresses at bay. I had a 15% load decrease on the hypervisor which may not sound like much. In my case it was around the CPU power that a complete Linux VM would need.