MISP Integration
The optional MISP Feed Generator polls CrowdSec decisions and exposes them as a MISP feed over HTTP(S). Requires a CrowdSec Local API key and a separately configured feed subscription in MISP.
An independent tool index
for incident response teams
Detection and monitoring EU-developed
Parses system and application logs to detect hostile behavior, generate local decisions and feed remediation components for blocking or challenging attackers.
By CrowdSec · France
The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.
CrowdSec's own account says French Grand Défi Cyber funding supported development of its open-source software and expansion of its R&D team; the publisher is registered in Montrouge, France.
The self-hosted Security Engine is MIT-licensed; CrowdSec-supplied community blocklist and other vendor threat data have separate terms restricting redistribution, and the optional hosted Console is a distinct service. Blocking requires a configured remediation component; the engine alone detects and makes local decisions. The France label reflects documented French R&D and the French SAS legal notice, not every current contributor, data host or ultimate owner.
origin
CrowdSec's September 2021 account says France's Grand Défi Cyber funded development of essential components of the open-source software and planned expansion of its existing R&D team. This is historical French development evidence, not a claim that all current contributors are French.
Read sourceidentity / capabilities / deployment
Upstream repository describes installable IDS/IPS, WAF and bot detection software with detection scenarios for brute force, port scans and web scans on Linux, Windows, Docker and Kubernetes.
Read sourcecapabilities / deployment
Official documentation distinguishes the server-installed Security Engine, which parses logs and applies scenarios, from optional hosted Console, blocklists, and remediation integrations.
Read sourcelicense / origin
Actual root LICENSE contains the MIT grant and CrowdSec copyright; it governs the software repository, not the separately licensed threat data.
Read sourcelicense
CrowdSec's FAQ explicitly says the software is MIT-licensed but data received through it is subject to a separate EULA with redistribution and marketing restrictions.
Read sourcecountry / origin
Publisher's legal notice identifies CrowdSec SAS and its registered office in Montrouge, France; this is paired with the official code repository, rather than treated as proof of all engineering locations.
Read sourcemaintenance
The upstream v1.8.1 release is marked latest and dated 3 September on the release page during the 2026 release series; release activity is not a support guarantee.
Read sourceThis profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
The optional MISP Feed Generator polls CrowdSec decisions and exposes them as a MISP feed over HTTP(S). Requires a CrowdSec Local API key and a separately configured feed subscription in MISP.
Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.
From Sigma rule to a tested detection