You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The [CrowdSec Security Engine](https://github.com/crowdsecurity/crowdsec) is an open-source, lightweight software that detects and blocks malicious actors from accessing your systems at various levels, using log analysis and threat patterns called scenarios.
26
+
The [CrowdSec Security Engine](https://github.com/crowdsecurity/crowdsec) is an open-source, lightweight software that detects and blocks malicious actors from accessing your systems at various levels, using log and HTTP Requests analysis with threat patterns called scenarios.
19
27
20
-
CrowdSec is a modular framework, offering a variety of [popular scenarios](https://app.crowdsec.net/hub/collections). Users can choose their protection scenarios and deploy [Remediation Components](https://app.crowdsec.net/hub/bouncers) to block malicious access.
28
+
CrowdSec is a modular framework, offering a variety of [scenarios](https://app.crowdsec.net/hub/collections). Users can choose their protection scenarios and deploy [Remediation Components](https://app.crowdsec.net/hub/bouncers) to block malicious access.
21
29
22
30
The crowd-sourced aspect allows sharing attack information among users, enhancing real-time attack detection and preemptive blocking of known bad actors from your system.
23
31
@@ -26,8 +34,9 @@ The crowd-sourced aspect allows sharing attack information among users, enhancin
26
34
In addition to the core "detect and react" mechanism, CrowdSec is committed to several other key aspects:
27
35
28
36
-**Easy Installation**: Effortless out-of-the-box installation on all [supported platforms](/getting_started/versions_matrix.md).
29
-
-**Simplified Daily Operations**: Use [cscli](/cscli/cscli.md) and the [hub](http://hub.crowdsec.net) for effortless maintenance and keeping your detection mechanisms up-to-date.
37
+
-**Simplified Daily Operations**: Use the [console](http://app.crowdsec.net) and [cscli](/cscli/cscli.md) for effortless maintenance and keeping your detection mechanisms up-to-date.
30
38
-**Reproducibility**: The Security Engine can analyze not only live logs but also [cold logs](/u/user_guides/replay_mode), making it easier to detect potential false triggers, conduct forensic analysis, or generate reports.
39
+
-**Versatile**: The Security Engine can analyze [system logs](/docs/data_sources/intro) and [HTTP Requests](/docs/next/appsec/intro) to exhaustively protect your perimeter.
31
40
-**Observability**: Providing valuable insights into the system's activity:
32
41
- Users can view/manage alerts from the ([Console](https://app.crowdsec.net/signup)).
33
42
- Operations personnel have access to detailed Prometheus metrics ([Prometheus](/observability/prometheus.md)).
@@ -38,12 +47,36 @@ In addition to the core "detect and react" mechanism, CrowdSec is committed to s
Under the hood, the Security Engine has various components:
62
+
63
+
- The [Log Processor](...) is in charge of detection: it analyzes logs from various data sources or HTTP requests from web servers.
64
+
- The [Local API](...) acts as a middle man between the [Log Processors](...) and the [Remediation Components](...) which are in charge of enforcing decisions.
65
+
- The [Remediation Components](...) - also known as bouncers - are in charge of blocking bad IPs by using the components already available.
0 commit comments