Skip to content

Commit 0c58e83

Browse files
enhance: update comm bl with details and situations where lite happens (#731)
* enhance: update comm bl with details and situations where lite happens * enhance: add better formatting * enhance: add better formatting * enhance: formatting
1 parent e657527 commit 0c58e83

File tree

1 file changed

+29
-5
lines changed

1 file changed

+29
-5
lines changed

crowdsec-docs/docs/central_api/blocklist.md

Lines changed: 29 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -12,29 +12,53 @@ The "Community Blocklist" is a curated list of IP addresses identified as malici
1212
# Community Blocklist Variation and Eligibility
1313

1414
The rules are different for free and paying users:
15-
- Free users that **do not** contribute get the `Community Blocklist (Lite)`
16-
- Free users that **do** contribute get access to the `Community Blocklist`
15+
- Free users that **do not regularly** contribute get the `Community Blocklist (Lite)`
16+
- Free users that **do regularly** contribute get access to the `Community Blocklist`
1717
- Paying users get access to the `Community Blocklist (Premium)`, even if they don't contribute
1818

1919
Regardless of the blocklist "tier" you have access to (`Lite`, `Community`, `Premium`), each Security Engine gets a tailored blocklist based on the kind of behavior you're trying to detect.
2020

21-
# Community Blocklist
21+
## Community Blocklist
2222

2323
Free users that are actively contributing to the network (sending signal on a regular basis) have their Security Engines automatically subscribed to the *Community Blocklist*.
2424

2525
The content of the blocklist is unique to each Security Engine, as it mirrors the behaviours they report. For example, suppose you're running the Security Engine on a web server with WordPress. In that case, you will receive IPs performing generic attacks against web servers *and* IPs engaging in wordpress-specific attacks.
2626

2727
The *Community Blocklist* contains 15 thousand malicious IP's based on your reported scenarios.
2828

29-
# Community Blocklist (Premium)
29+
## Community Blocklist (Premium)
3030

3131
Paying users' Security Engine are automatically subscribed to the *Community Blocklist (Premium)*, which contains IPs that mirror their installed scenarios.
3232
Paying users' do not need to contribute to the network to be eligible to the blocklist.
3333

3434
The *Community Blocklist (Premium)* blocklist content has no size limit, unlike free users.
3535

36-
# Community Blocklist (Lite)
36+
## Community Blocklist (Lite)
3737

3838
Free users that are not actively contributing to the network or that have been flagged as cheating/abusing the system will receive the *Community Blocklist (Lite)*.
3939

4040
This Blocklist is capped at 3 thousand IPs.
41+
42+
### Why is my Security Engine on the Lite Blocklist?
43+
44+
Your Security Engine may be placed on the Lite Blocklist for various reasons, such as:
45+
46+
1. Low Visibility Services
47+
48+
Your services are self-hosted (e.g., for private video or image hosting) and primarily accessed by a small group. As a result, your Security Engine detects less malicious activity compared to public-facing services like blogs or e-commerce sites.
49+
50+
2. Comprehensive Security Setup
51+
52+
Your existing security measures reduce reliance on the Community Blocklist. These may include:
53+
- Geoblocking (restricting access to certain countries)
54+
- IP whitelisting with a default deny-all policy
55+
- VPN-only access
56+
- OAuth authentication (e.g., Authentik, Authelia, Keycloak)
57+
58+
This simply a result of your security model and access requirements, its neither an issue with your setup nor a limitation on our end.
59+
60+
3. Incomplete CrowdSec Configuration
61+
62+
Your Security Engine may not be monitoring all your services.
63+
64+
If you suspect this might be the case, refer to our [post-installation guide](/u/getting_started/next_steps) to ensure full coverage.

0 commit comments

Comments
 (0)