Thoughts on crowdsec
2026-07-14 00:03 UTC
I have been running crowdsec on my OpenWRT firewall for a bit now, I am just curious as to what others think about it?
Thank you @irmadlad the webui you suggested is showing the logs a lot better than my vibe coded HA plug ins (both my ssh honey pot and my plug in showed nothing) looking over the logs shows so much activity that is happening.
Replies (2)
-
@The_Zen_Cow_Says_Mu@infosec.pub 2026-07-14 00:35
i run it on opnsense. When my services were on individual subdomains each with their own certificate, they got hit a lot and crowdsec blocked lots of bots and scripts I ultimately moved all my services to a wildcard sub-subdomain, and poof all the bots went away and now crowdsec doesn’t do much other than block port scanners which the firewall does anyway. it’s not worth the hassle to uninstall though.
-
@Mio@feddit.nu 2026-07-14 07:17
I believe it is a good start with crowdsec but feels like it gives false protection. The blocking only happens after they have done a couple of attempts and not before.