Estado
CrowdSec Engine
OK
Firewall Bouncer
OK
Decisiones locales
3
Alertas locales reales
0
IPs CAPI activas
21.041
Bloqueos reales
70
Paquetes procesados
59.072
Tráfico procesado
75.3 MiB
Versión
CrowdSec
version: v1.8.1-debian-pragmatic-amd64-909b5157
🔌 Bouncers registrados
Bouncers autorizados actualmente en la Local API de CrowdSec.
Nombre
cs-firewall-bouncer-636759aeb01f
Estado
OK
IP
127.0.0.1
Tipo
crowdsec-firewall-bouncer
Versión
v0.0.36-debian-pragmatic-amd64-4c315193cd4f19e3937cdee2f15183ec4d602f56
Autenticación
api-key
Sistema operativo
debian/13.6
Última consulta API
21/09/2026 13:26:32
Nombre
cs-firewall-bouncer-aceef365364e
Estado
OK
IP
127.0.0.1
Tipo
crowdsec-firewall-bouncer
Versión
v0.0.36-debian-pragmatic-amd64-4c315193cd4f19e3937cdee2f15183ec4d602f56
Autenticación
api-key
Sistema operativo
debian/13.6
Última consulta API
21/09/2026 14:35:01
📦 Colecciones instaladas
Conjuntos de parsers, escenarios y configuraciones instalados desde CrowdSec Hub.
Colección
a1ad/mikrotik
Estado
ENABLED
Versión
0.2
Descripción
Mikrotik support: logs, auth and port-scans detection scenarios
Colección
crowdsecurity/appsec-bot-challenge-exclude-paths
Estado
ENABLED
Versión
0.1
Descripción
AppSec bot challenge: exempt well-known paths (crawler files, static assets, API, feeds, webhooks)
Colección
crowdsecurity/appsec-bot-challenge-good-bots
Estado
ENABLED
Versión
0.1
Descripción
AppSec bot challenge: exempt verified good bots (search engines, AI crawlers, social, monitoring)
Colección
crowdsecurity/appsec-bot-challenge-scoring
Estado
ENABLED
Versión
0.2
Descripción
AppSec bot challenge: weighted fingerprint scoring engine (serves the challenge, computes the score)
Colección
crowdsecurity/appsec-bot-challenge-strict
Estado
ENABLED
Versión
0.1
Descripción
WAF bot detection: Rejecting at a strict threshold (>= 45)
Colección
crowdsecurity/appsec-generic-rules
Estado
ENABLED
Versión
1.1
Descripción
A collection of generic attack vectors for additional protection.
Colección
crowdsecurity/appsec-virtual-patching
Estado
ENABLED
Versión
16.0
Descripción
a generic virtual patching collection, suitable for most web servers.
Colección
crowdsecurity/base-http-scenarios
Estado
ENABLED
Versión
1.4
Descripción
http common : scanners detection
Colección
crowdsecurity/http-cve
Estado
ENABLED
Versión
3.0
Descripción
Detect CVE exploitation in http logs
Colección
crowdsecurity/http-dos
Estado
ENABLED
Versión
0.3
Descripción
Colección
crowdsecurity/linux
Estado
ENABLED
Versión
0.4
Descripción
core linux support : syslog+geoip+ssh
Colección
crowdsecurity/nginx
Estado
ENABLED
Versión
0.3
Descripción
nginx support : parser and generic http scenarios
Colección
crowdsecurity/sshd
Estado
ENABLED
Versión
0.9
Descripción
sshd support : parser and brute-force detection
Colección
crowdsecurity/whitelist-good-actors
Estado
ENABLED
Versión
0.4
Descripción
Good actors whitelists
Colección
crowdsecurity/wordpress
Estado
ENABLED
Versión
0.6
Descripción
wordpress: Bruteforce protection and config probing
🧩 CrowdSec Hub · Colecciones
Busca las colecciones disponibles en CrowdSec Hub,
consulta para qué sirven e instálalas manualmente.
Ninguna colección se instala de forma automática.
🎯 Escenarios instalados
Escenarios utilizados por CrowdSec para detectar comportamientos maliciosos.
Resumen de escenarios
68 instalados ·
68 activos
| Escenario | Versión | Estado | Descripción |
|---|---|---|---|
| a1ad/mikrotik-bf | 0.2 | ENABLED | Detect Mikrotik bruteforce |
| a1ad/mikrotik-scan-multi_ports | 0.4 | ENABLED | Detect port scanning from single ip on MikroTik router |
| crowdsecurity/apache_log4j2_cve-2021-44228 | 0.7 | ENABLED | Detect cve-2021-44228 exploitation attempts |
| crowdsecurity/appsec-bot-challenge-too-many-requests | 0.2 | ENABLED | Client made too many request to challenge page |
| crowdsecurity/appsec-bot-challenge-too-many-submissions | 0.2 | ENABLED | Client made too many submissions for challenge |
| crowdsecurity/appsec-generic-test | 0.2 | ENABLED | Crowdsec Generic Test Scenario for AppSec: generate an alert for appsec out of band rule for testing |
| crowdsecurity/appsec-native | 0.3 | ENABLED | Identify attacks flagged by CrowdSec AppSec via native rules |
| crowdsecurity/appsec-vpatch | 0.7 | ENABLED | Identify attacks flagged by CrowdSec AppSec |
| crowdsecurity/CVE-2017-9841 | 0.2 | ENABLED | Detect CVE-2017-9841 exploits |
| crowdsecurity/CVE-2019-18935 | 0.2 | ENABLED | Detect Telerik CVE-2019-18935 exploitation attempts |
| crowdsecurity/CVE-2022-26134 | 0.4 | ENABLED | Confluence - RCE (CVE-2022-26134) |
| crowdsecurity/CVE-2022-35914 | 0.2 | ENABLED | Detect CVE-2022-35914 exploits |
| crowdsecurity/CVE-2022-37042 | 0.2 | ENABLED | Detect CVE-2022-37042 exploits |
| crowdsecurity/CVE-2022-40684 | 0.3 | ENABLED | Detect cve-2022-40684 exploitation attempts |
| crowdsecurity/CVE-2022-41082 | 0.4 | ENABLED | Detect CVE-2022-41082 exploits |
| crowdsecurity/CVE-2022-41697 | 0.2 | ENABLED | Detect CVE-2022-41697 enumeration |
| crowdsecurity/CVE-2022-42889 | 0.3 | ENABLED | Detect CVE-2022-42889 exploits (Text4Shell) |
| crowdsecurity/CVE-2022-44877 | 0.4 | ENABLED | Detect CVE-2022-44877 exploits |
| crowdsecurity/CVE-2022-46169 | 0.2 | ENABLED | Detect CVE-2022-46169 brute forcing |
| crowdsecurity/CVE-2023-22515 | 0.1 | ENABLED | Detect CVE-2023-22515 exploitation |
| crowdsecurity/CVE-2023-22518 | 0.3 | ENABLED | Detect CVE-2023-22518 exploits |
| crowdsecurity/CVE-2023-49103 | 0.3 | ENABLED | Detect owncloud CVE-2023-49103 exploitation attempts |
| crowdsecurity/CVE-2024-0012 | 0.1 | ENABLED | Detect CVE-2024-0012 exploitation attempts |
| crowdsecurity/CVE-2024-38475 | 0.1 | ENABLED | Detect CVE-2024-38475 exploitation attempts |
| crowdsecurity/CVE-2024-9474 | 0.1 | ENABLED | Detect CVE-2024-9474 exploitation attempts |
| crowdsecurity/f5-big-ip-cve-2020-5902 | 0.3 | ENABLED | F5 BIG-IP TMUI - RCE (CVE-2020-5902) |
| crowdsecurity/fortinet-cve-2018-13379 | 0.4 | ENABLED | Detect cve-2018-13379 exploitation attempts |
| crowdsecurity/grafana-cve-2021-43798 | 0.3 | ENABLED | Grafana - Arbitrary File Read (CVE-2021-43798) |
| crowdsecurity/http-admin-interface-probing | 0.5 | ENABLED | Detect generic HTTP admin interface probing |
| crowdsecurity/http-backdoors-attempts | 0.6 | ENABLED | Detect attempt to common backdoors |
| crowdsecurity/http-bad-user-agent | 1.2 | ENABLED | Detect usage of bad User Agent |
| crowdsecurity/http-bf-wordpress_bf | 0.7 | ENABLED | Detect WordPress bruteforce on admin interface |
| crowdsecurity/http-crawl-non_statics | 0.7 | ENABLED | Detect aggressive crawl on non static resources |
| crowdsecurity/http-cve-2021-41773 | 0.3 | ENABLED | Apache - Path Traversal (CVE-2021-41773) |
| crowdsecurity/http-cve-2021-42013 | 0.3 | ENABLED | Apache - Path Traversal (CVE-2021-42013) |
| crowdsecurity/http-cve-probing | 0.6 | ENABLED | Detect generic HTTP cve probing |
| crowdsecurity/http-dos-bypass-cache | 0.5 | ENABLED | Detect DoS tools bypassing cache every request |
| crowdsecurity/http-dos-invalid-http-versions | 0.7 | ENABLED | Detect DoS tools using invalid HTTP versions |
| crowdsecurity/http-dos-random-uri | 0.4 | ENABLED | Detect DoS tools using random uri |
| crowdsecurity/http-dos-switching-ua | 0.5 | ENABLED | Detect DoS tools switching user-agent too fast |
| crowdsecurity/http-generic-bf | 0.9 | ENABLED | Detect generic http brute force |
| crowdsecurity/http-generic-test | 0.2 | ENABLED | Crowdsec Generic Test Scenario: basic HTTP trigger |
| crowdsecurity/http-open-proxy | 0.5 | ENABLED | Detect scan for open proxy |
| crowdsecurity/http-path-traversal-probing | 0.4 | ENABLED | Detect path traversal attempt |
| crowdsecurity/http-probing | 0.4 | ENABLED | Detect site scanning/probing from a single ip |
| crowdsecurity/http-sap-interface-probing | 0.1 | ENABLED | Detect generic HTTP SAP interface probing |
| crowdsecurity/http-sensitive-files | 0.4 | ENABLED | Detect attempt to access to sensitive files (.log, .db ..) or folders (.git) |
| crowdsecurity/http-sqli-probing | 0.4 | ENABLED | A scenario that detects SQL injection probing with minimal false positives |
| crowdsecurity/http-technology-probing | 0.1 | ENABLED | Detect HTTP technology/vendor probing |
| crowdsecurity/http-wordpress-scan | 0.4 | ENABLED | Detect exploitation attempts against common WordPress endpoints |
| crowdsecurity/http-wordpress_user-enum | 0.3 | ENABLED | Detect WordPress probing: authors enumeration |
| crowdsecurity/http-wordpress_wpconfig | 0.3 | ENABLED | Detect WordPress probing: variations around wp-config.php by wpscan |
| crowdsecurity/http-xss-probing | 0.4 | ENABLED | A scenario that detects XSS probing with minimal false positives |
| crowdsecurity/jira_cve-2021-26086 | 0.4 | ENABLED | Detect Atlassian Jira CVE-2021-26086 exploitation attempts |
| crowdsecurity/netgear_rce | 0.4 | ENABLED | Detect Netgear RCE DGN1000/DGN220 exploitation attempts |
| crowdsecurity/nginx-req-limit-exceeded | 0.3 | ENABLED | Detects IPs which violate nginx's user set request limit. |
| crowdsecurity/pulse-secure-sslvpn-cve-2019-11510 | 0.4 | ENABLED | Detect cve-2019-11510 exploitation attempts |
| crowdsecurity/spring4shell_cve-2022-22965 | 0.3 | ENABLED | Detect cve-2022-22965 probing |
| crowdsecurity/ssh-bf | 0.3 | ENABLED | Detect ssh bruteforce |
| crowdsecurity/ssh-cve-2024-6387 | 0.2 | ENABLED | Detect exploitation attempt of CVE-2024-6387 |
| crowdsecurity/ssh-generic-test | 0.2 | ENABLED | Crowdsec Generic Test Scenario: SSH brute force trigger |
| crowdsecurity/ssh-refused-conn | 0.1 | ENABLED | Detect sshd refused connections |
| crowdsecurity/ssh-slow-bf | 0.4 | ENABLED | Detect slow ssh bruteforce |
| crowdsecurity/ssh-time-based-bf | 0.3 | ENABLED | Detect time-based ssh bruteforce attempts that evade rate limiting (with false positive reduction) |
| crowdsecurity/thinkphp-cve-2018-20062 | 0.7 | ENABLED | Detect ThinkPHP CVE-2018-20062 exploitation attempts |
| crowdsecurity/vmware-cve-2022-22954 | 0.3 | ENABLED | Detect Vmware CVE-2022-22954 exploitation attempts |
| crowdsecurity/vmware-vcenter-vmsa-2021-0027 | 0.3 | ENABLED | Detect VMSA-2021-0027 exploitation attempts |
| ltsich/http-w00tw00t | 0.3 | ENABLED | detect w00tw00t |
🚫 Decisiones activas
Bloqueos y decisiones de remediación activas actualmente en este servidor.
Las decisiones de la Community Blocklist se identifican como CAPI.
| IP / Valor | Tipo | Escenario | Origen | Duración |
|---|---|---|---|---|
| - | - | crowdsecurity/http-probing | - | - |
| - | - | crowdsecurity/jira_cve-2021-26086 | - | - |
| - | - | crowdsecurity/http-probing | - | - |
🚨 Últimas 20 alertas locales
Detecciones locales registradas por el Mini-SOC. Las actualizaciones CAPI y los eventos de prueba no se contabilizan como ataques.
Sin ataques locales reales registrados. Las actualizaciones de CrowdSec Community Blocklist (CAPI) no se contabilizan como ataques contra este servidor. Los eventos TEST-MINISOC, TEST-MINISOC-TELEGRAM y PRUEBA-BOUNCER tampoco se incluyen.
📊 Métricas
Actividad local de adquisición, parsers, Local API, decisiones y bouncers.
+-----------------------------------------------------------------------------------------------------------------------------------------------------------+ | Acquisition Metrics | +-----------------------------------------------------------------+------------+--------------+----------------+------------------------+-------------------+ | Source | Lines read | Lines parsed | Lines unparsed | Lines poured to bucket | Lines whitelisted | +-----------------------------------------------------------------+------------+--------------+----------------+------------------------+-------------------+ | file:/opt/nginx-proxy-manager/data/logs/proxy-host-6_access.log | 156 | 155 | 1 | 114 | 7 | | file:/opt/nginx-proxy-manager/data/logs/proxy-host-7_access.log | 232 | 231 | 1 | 174 | 5 | | file:/var/log/kern.log | 255 | - | 255 | - | - | | file:/var/log/syslog | 2.71k | - | 2.71k | - | - | | journalctl:journalctl-_SYSTEMD_UNIT=ssh.service | 5 | 2 | 3 | - | 2 | +-----------------------------------------------------------------+------------+--------------+----------------+------------------------+-------------------+ +---------------------------------------------+ | Local API Alerts | +-------------------------------------+-------+ | Reason | Count | +-------------------------------------+-------+ | crowdsecurity/http-probing | 2 | | crowdsecurity/jira_cve-2021-26086 | 1 | | crowdsecurity/vpatch-CVE-2025-55182 | 2 | | crowdsecurity/vpatch-env-access | 3 | | crowdsecurity/http-cve-probing | 1 | +-------------------------------------+-------+ +---------------------------------+ | Bot Detection Infrastructure Me | | trics | +-------------------------+-------+ | Metric | Count | +-------------------------+-------+ | Signing key regenerated | 0 | | Signing key evicted | 0 | | Dynamic module evicted | 0 | +-------------------------+-------+ +-------------------------------------------------------------------------------------+ | Bouncer Metrics (cs-firewall-bouncer-1788941154) since 2026-09-14 12:41:50 +0000 UT | | C | +----------------------------+------------------+-----------------+-------------------+ | Origin | active_decisions | dropped | processed | | | IPs | bytes | packets | bytes | packets | +----------------------------+------------------+-------+---------+---------+---------+ | CAPI (community blocklist) | 24.08k | 4.20k | 70 | - | - | | crowdsec (security engine) | 0 | 0 | 0 | - | - | +----------------------------+------------------+-------+---------+---------+---------+ | Total | 24.08k | 4.20k | 70 | 557.01M | 1.27M | +----------------------------+------------------+-------+---------+---------+---------+ +-------------------------------------------------------------------------------------+ | Bouncer Metrics (cs-firewall-bouncer-636759aeb01f) since 2026-09-17 10:19:43 +0000 | | UTC | +----------------------------+------------------+-----------------+-------------------+ | Origin | active_decisions | dropped | processed | | | IPs | bytes | packets | bytes | packets | +----------------------------+------------------+-------+---------+---------+---------+ | CAPI (community blocklist) | 21.60k | 1.50k | 25 | - | - | +----------------------------+------------------+-------+---------+---------+---------+ | Total | 21.60k | 1.50k | 25 | 114.89M | 219.08k | +----------------------------+------------------+-------+---------+---------+---------+ +-------------------------------------------------------------------------------------+ | Bouncer Metrics (cs-firewall-bouncer-aceef365364e) since 2026-09-21 11:42:01 +0000 | | UTC | +----------------------------+------------------+------------------+------------------+ | Origin | active_decisions | dropped | processed | | | IPs | bytes | packets | bytes | packets | +----------------------------+------------------+--------+---------+--------+---------+ | CAPI (community blocklist) | 21.57k | 3.30k | 55 | - | - | | crowdsec (security engine) | - | 17.98k | 250 | - | - | +----------------------------+------------------+--------+---------+--------+---------+ | Total | 21.57k | 21.28k | 305 | 43.24M | 51.56k | +----------------------------+------------------+--------+---------+--------+---------+ +--------------------------------------------------+ | Bouncer Metrics (minisoc-openresty-20260913-0045 | | 05) since 2026-09-14 12:41:42 +0000 UTC | +----------------------------+---------+-----------+ | Origin | dropped | processed | | | request | request | +----------------------------+---------+-----------+ | crowdsec (security engine) | 2 | - | +----------------------------+---------+-----------+ | Total | 2 | 3.99k | +----------------------------+---------+-----------+ +---------------------------------------------------------------+ | Local API Decisions | +-----------------------------------+----------+--------+-------+ | Reason | Origin | Action | Count | +-----------------------------------+----------+--------+-------+ | crowdsecurity/http-probing | crowdsec | ban | 2 | | crowdsecurity/jira_cve-2021-26086 | crowdsec | ban | 1 | | http:bruteforce | CAPI | ban | 332 | | http:crawl | CAPI | ban | 13 | | http:exploit | CAPI | ban | 429 | | http:scan | CAPI | ban | 20771 | +-----------------------------------+----------+--------+-------+ +------------------------------------------------+ | Local API Metrics | +--------------------------------+--------+------+ | Route | Method | Hits | +--------------------------------+--------+------+ | /v1/alerts | GET | 345 | | /v1/alerts | POST | 3 | | /v1/allowlists | GET | 69 | | /v1/allowlists/:allowlist_name | GET | 1 | | /v1/decisions | GET | 1294 | | /v1/decisions/stream | GET | 409 | | /v1/decisions/stream | HEAD | 1253 | | /v1/heartbeat | GET | 68 | | /v1/usage-metrics | POST | 9 | | /v1/watchers/login | POST | 348 | +--------------------------------+--------+------+ +-------------------------------------------------------------------------+ | Local API Bouncers Metrics | +----------------------------------+----------------------+--------+------+ | Bouncer | Route | Method | Hits | +----------------------------------+----------------------+--------+------+ | cs-firewall-bouncer-aceef365364e | /v1/decisions/stream | GET | 409 | +----------------------------------+----------------------+--------+------+ +----------------------------------------------------------------------------------------------------+ | Local API Machines Metrics | +---------------------------------------------------+--------------------------------+--------+------+ | Machine | Route | Method | Hits | +---------------------------------------------------+--------------------------------+--------+------+ | 8a0f066a716d4ef291b76f562f2d5406-38406241e6a2d649 | /v1/allowlists/:allowlist_name | GET | 1 | | 8a0f066a716d4ef291b76f562f2d5406-38406241e6a2d649 | /v1/heartbeat | GET | 68 | | 8a0f066a716d4ef291b76f562f2d5406-38406241e6a2d649 | /v1/alerts | GET | 345 | | 8a0f066a716d4ef291b76f562f2d5406-38406241e6a2d649 | /v1/alerts | POST | 3 | | 8a0f066a716d4ef291b76f562f2d5406-38406241e6a2d649 | /v1/allowlists | GET | 69 | +---------------------------------------------------+--------------------------------+--------+------+ +-----------------------------------------------------------------------------+ | Parser Metrics | +-------------------------------------------------+-------+--------+----------+ | Parsers | Hits | Parsed | Unparsed | +-------------------------------------------------+-------+--------+----------+ | child-crowdsecurity/http-logs | 1.16k | 818 | 340 | | child-crowdsecurity/nginx-logs | 2.33k | 386 | 1.94k | | child-crowdsecurity/sshd-logs | 54 | 2 | 52 | | child-crowdsecurity/syslog-logs | 2.97k | 2.97k | - | | crowdsecurity/cdn-whitelist | 3 | 3 | - | | crowdsecurity/dateparse-enrich | 388 | 388 | - | | crowdsecurity/geoip-enrich | 374 | 374 | - | | crowdsecurity/google-special-crawlers-whitelist | 3 | 3 | - | | crowdsecurity/http-logs | 386 | 386 | - | | crowdsecurity/nginx-logs | 388 | 386 | 2 | | crowdsecurity/non-syslog | 388 | 388 | - | | crowdsecurity/public-dns-allowlist | 388 | 388 | - | | crowdsecurity/rdns | 3 | 3 | - | | crowdsecurity/seo-bots-whitelist | 3 | 3 | - | | crowdsecurity/sshd-logs | 5 | 2 | 3 | | crowdsecurity/syslog-logs | 2.97k | 2.97k | - | | crowdsecurity/whitelists | 388 | 388 | - | +-------------------------------------------------+-------+--------+----------+ +----------------------------------------------------------------------------------------------------+ | Scenario Metrics | +--------------------------------------+---------------+-----------+--------------+--------+---------+ | Scenario | Current Count | Overflows | Instantiated | Poured | Expired | +--------------------------------------+---------------+-----------+--------------+--------+---------+ | crowdsecurity/http-crawl-non_statics | - | - | 79 | 172 | 79 | | crowdsecurity/http-dos-swithcing-ua | 2 | - | 60 | 64 | 58 | | crowdsecurity/http-probing | 1 | 2 | 25 | 47 | 22 | | crowdsecurity/http-sensitive-files | - | - | 4 | 5 | 4 | | crowdsecurity/jira_cve-2021-26086 | - | 1 | 1 | - | - | +--------------------------------------+---------------+-----------+--------------+--------+---------+ +-----------------------------------------------------------------------------------------------------------+ | Whitelist Metrics | +-------------------------------------------------+------------------------------------+------+-------------+ | Whitelist | Reason | Hits | Whitelisted | +-------------------------------------------------+------------------------------------+------+-------------+ | crowdsecurity/cdn-whitelist | CDN provider | 3 | - | | crowdsecurity/google-special-crawlers-whitelist | Google special crawlers ip range | 3 | - | | crowdsecurity/public-dns-allowlist | public DNS server | 388 | - | | crowdsecurity/seo-bots-whitelist | good bots (search engine crawlers) | 3 | - | | crowdsecurity/whitelists | private ipv4/ipv6 ip/ranges | 388 | 14 | +-------------------------------------------------+------------------------------------+------+-------------+