CrowdSec Threat Intelligence offers a collaborative, crowd-powered approach to cybersecurity, delivering real-time, ultra-curated threat data to help organizations proactively block malicious IPs and defend against evolving cyber threats. Designed for security teams, IT professionals, and managed service providers, it enhances threat detection and response with exclusive insights and seamless integration.
Provides real-time blocklists updated daily with high exclusivity, detecting threats up to 760 days ahead of competitors
Features a Live Exploit Tracker and contextualized IP reputation intelligence for detailed threat analysis
Includes an open-source Security Engine and CrowdSec Console for flexible deployment and management
Automates integration with firewalls and CDNs for immediate blocking of malicious traffic
Reduces alert fatigue by up to 80% with zero false positives through advanced trust scoring and data cross-checking
Supports OS and infrastructure-agnostic deployment, fitting diverse environments and workflows
Accesses the largest crowd-powered threat intelligence network with over 70,000 active users worldwide
CrowdSec integrates smoothly with existing security infrastructure and offers API access for custom automation, empowering organizations to strengthen their defenses efficiently and confidently.
Highlights
Crowd-powered threat intelligence with real-world data from hundreds of thousands of servers worldwide, enabling faster and more accurate threat detection
Offers an unparalleled precision of 32 fields per IP address, IP range & AS reputation, classification (VPN, Proxy, Residential proxy, etc), geolocation, targeted industry & country, CVE leveraged, and much more.
Seamless integration with SIEM, SOAR, TIG and TIP.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You choose from three independent ways to access CrowdSec threat intelligence. Two options give you offline data synchronization: the TOP1M feed covers the top 1 million IPs CrowdSec observes in its network, while the Full feed covers all IPs it sees. Both replicate the data locally on a per-unit basis. The third option is API-based, giving you a quota of 10,000 monthly queries against the CTI. You can pick the delivery method that fits your setup — bulk offline sync or on-demand API lookups — and scale by adding units.
Top-of-mind questions for buyers
What is the difference between the offline synchronization feeds and the API query option?
The two offline feeds replicate CrowdSec's threat data locally to your own systems, so you hold a copy of the IP list. The API option instead lets you send individual lookup queries against the CTI, drawing down from your monthly quota. Offline sync suits bulk local matching; API suits on-demand investigation of specific IPs.
What determines the scope of the two offline synchronization feeds?
The TOP1M feed contains the top 1 million IPs CrowdSec observes across its network. The Full feed contains every IP CrowdSec sees, so it covers a wider set of addresses. Both replicate locally on a per-unit basis; the difference is how many IP records you receive.
What happens to my API access after I use all 10,000 monthly queries?
The dimension provides a set quota of 10,000 CTI API queries per month. Each lookup you send counts against this allowance. Once the monthly quota is reached, contact CrowdSec about adding query capacity, as the listing does not specify overage handling within this single quota unit.
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Buyers can expect help via email or through our website for general inquiries, troubleshooting, and product guidance.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product has charges associated with it for seller support. CrowdSec is an open source, collaborative security platform that detects and mitigates cyber threats using behavior analysis and a shared threat intelligence network.
CrowdSec Security Engine provides a real-time, collaborative WAF / WAAP & IDS. When they block an IP address that attacked the protected workloads, that IP is curated and shared with all your other servers and every other network member to further protect everyone. It leverages open-source intelligence from a global user network to protect your infrastructure and applications. The WAF and IDS are provided as FOSS, along with their detection scenarios, virtual patches, and WAF rules. The Premium SaaS console provides extra security, compliance, QoL, centralisation, reporting, data retention and multi tenancy features.
CrowdSec delivers real-time, crowd-powered threat intelligence, with exclusive data and automated integration, to preemptively block cyberattacks and reduce alert fatigue. Know which CVE is trendy, where, when and why in real time. Sort out noise for emergency using our API.
CrowdSec stands out for its community-driven threat intelligence and its collaborative approach to security. It automatically detects malicious activity, such as brute-force attacks, and shares anonymized threat data with the global CrowdSec network so organizations can benefit from a stronger, collective defense.
What do you dislike about the product?
The effectiveness of certain protections also depends on the quality and volume of community-contributed threat intelligence. In addition, organizations that need robust enterprise reporting, compliance features, or more advanced centralized management may find that some capabilities are not yet as mature as those provided by larger commercial security platforms.
What problems is the product solving and how is that benefiting you?
This solution has reduced security incidents, eased the workload on our IT team, improved server and application availability, and strengthened our overall security posture—all without requiring significant additional investment in security infrastructure.
Samuel L.
Fantastic software with affordable options including free. Extremely extensive library of modules.
Reviewed on Jun 14, 2023
Review provided by G2
What do you like best about the product?
It's free and given I have two start ups in pre-seed round that is a god send. It is fantastic software that I use on all my servers. From basic ssh bouncers to more complex strategies.
What do you dislike about the product?
The UI is really nice, but things can get a bit hairy when you start deploying more complicated bouncers. It's no longer a click and deploy experience and many bouncers I use are community submitted so documentation is hit or miss.
What problems is the product solving and how is that benefiting you?
It is serving as a augmentation to the base firewall and also as an IDS system for all my servers. It is easy to use that dashboard to quickly get a glance at all my nodes and their security status.
Silvio M.
An useful instrument for cybersecurity
Reviewed on Jun 08, 2023
Review provided by G2
What do you like best about the product?
- Easy to use. - Many possibilities to integrate it, defining golang bouncer scripts. - Collaborative cyber threat intelligence.
What do you dislike about the product?
- It should offer Crowdsec Web Panel, also as self-hosted service, on the server where Crowdsec is installed. - Missing the ability to use custom blocklists in Web Panel, with the possibility to enable only two blocklists for free users. - A map summarizing the attacks collected and custom alert filters would be appreciated.
What problems is the product solving and how is that benefiting you?
It helps me to detect and manage intrusions.
Joe L.
Easy to install and configure crowd powered fail2ban
Reviewed on Jun 08, 2023
Review provided by G2
What do you like best about the product?
Simple to install and configure. Web gui shows useful stats and lookup for bad ip addresses. Running CrowdSec will help add to the community block list
What do you dislike about the product?
The most useful blocklist like the VPN list is paywalled. Pricing is a mystery.
What problems is the product solving and how is that benefiting you?
Blocks most bots and bad actors on all services on the server
Rei B.
It's a real life-saver in terms of hosting stuff
Reviewed on Jun 07, 2023
Review provided by G2
What do you like best about the product?
What I love about it is it's open source nature. By parsing logs you can block bad actors just like you would with fail2ban - but with grok patterns which are way easier to write and implement. New parsers are easily constructed and it's really easy to keep a ton of bad traffic out of your network.
What do you dislike about the product?
A bad thing about it is that you'd have to get a premium subscription in case you want more 'signals' than you share. Mostly ssh and http scenarios do although cover most of your bases.
What problems is the product solving and how is that benefiting you?
Crowdsec itself saves me a lot of CPU load by keeping nasty IP addresses at bay. I had a 15% load decrease on the hypervisor which may not sound like much. In my case it was around the CPU power that a complete Linux VM would need.