🛡 CrowdSec

NPMSOC-Dt4 · Mini-SOC · Actualizado 21/09/2026 14:35:05 · By: @PBerbel
Estado
CrowdSec Engine
OK
Firewall Bouncer
OK
Decisiones locales
3
Alertas locales reales
0
IPs CAPI activas
21.041
Bloqueos reales
70
Paquetes procesados
59.072
Tráfico procesado
75.3 MiB
Versión
CrowdSec
version: v1.8.1-debian-pragmatic-amd64-909b5157
🔌 Bouncers registrados
Bouncers autorizados actualmente en la Local API de CrowdSec.
Nombre
cs-firewall-bouncer-636759aeb01f
Estado
OK
IP
127.0.0.1
Tipo
crowdsec-firewall-bouncer
Versión
v0.0.36-debian-pragmatic-amd64-4c315193cd4f19e3937cdee2f15183ec4d602f56
Autenticación
api-key
Sistema operativo
debian/13.6
Última consulta API
21/09/2026 13:26:32
Nombre
cs-firewall-bouncer-aceef365364e
Estado
OK
IP
127.0.0.1
Tipo
crowdsec-firewall-bouncer
Versión
v0.0.36-debian-pragmatic-amd64-4c315193cd4f19e3937cdee2f15183ec4d602f56
Autenticación
api-key
Sistema operativo
debian/13.6
Última consulta API
21/09/2026 14:35:01
📦 Colecciones instaladas
Conjuntos de parsers, escenarios y configuraciones instalados desde CrowdSec Hub.
Colección
a1ad/mikrotik
Estado
ENABLED
Versión
0.2
Descripción
Mikrotik support: logs, auth and port-scans detection scenarios
Colección
crowdsecurity/appsec-bot-challenge-exclude-paths
Estado
ENABLED
Versión
0.1
Descripción
AppSec bot challenge: exempt well-known paths (crawler files, static assets, API, feeds, webhooks)
Colección
crowdsecurity/appsec-bot-challenge-good-bots
Estado
ENABLED
Versión
0.1
Descripción
AppSec bot challenge: exempt verified good bots (search engines, AI crawlers, social, monitoring)
Colección
crowdsecurity/appsec-bot-challenge-scoring
Estado
ENABLED
Versión
0.2
Descripción
AppSec bot challenge: weighted fingerprint scoring engine (serves the challenge, computes the score)
Colección
crowdsecurity/appsec-bot-challenge-strict
Estado
ENABLED
Versión
0.1
Descripción
WAF bot detection: Rejecting at a strict threshold (>= 45)
Colección
crowdsecurity/appsec-generic-rules
Estado
ENABLED
Versión
1.1
Descripción
A collection of generic attack vectors for additional protection.
Colección
crowdsecurity/appsec-virtual-patching
Estado
ENABLED
Versión
16.0
Descripción
a generic virtual patching collection, suitable for most web servers.
Colección
crowdsecurity/base-http-scenarios
Estado
ENABLED
Versión
1.4
Descripción
http common : scanners detection
Colección
crowdsecurity/http-cve
Estado
ENABLED
Versión
3.0
Descripción
Detect CVE exploitation in http logs
Colección
crowdsecurity/http-dos
Estado
ENABLED
Versión
0.3
Descripción
Colección
crowdsecurity/linux
Estado
ENABLED
Versión
0.4
Descripción
core linux support : syslog+geoip+ssh
Colección
crowdsecurity/nginx
Estado
ENABLED
Versión
0.3
Descripción
nginx support : parser and generic http scenarios
Colección
crowdsecurity/sshd
Estado
ENABLED
Versión
0.9
Descripción
sshd support : parser and brute-force detection
Colección
crowdsecurity/whitelist-good-actors
Estado
ENABLED
Versión
0.4
Descripción
Good actors whitelists
Colección
crowdsecurity/wordpress
Estado
ENABLED
Versión
0.6
Descripción
wordpress: Bruteforce protection and config probing
🧩 CrowdSec Hub · Colecciones
Busca las colecciones disponibles en CrowdSec Hub, consulta para qué sirven e instálalas manualmente. Ninguna colección se instala de forma automática.
🎯 Escenarios instalados
Escenarios utilizados por CrowdSec para detectar comportamientos maliciosos.
Resumen de escenarios
68 instalados · 68 activos
Escenario Versión Estado Descripción
a1ad/mikrotik-bf 0.2 ENABLED Detect Mikrotik bruteforce
a1ad/mikrotik-scan-multi_ports 0.4 ENABLED Detect port scanning from single ip on MikroTik router
crowdsecurity/apache_log4j2_cve-2021-44228 0.7 ENABLED Detect cve-2021-44228 exploitation attempts
crowdsecurity/appsec-bot-challenge-too-many-requests 0.2 ENABLED Client made too many request to challenge page
crowdsecurity/appsec-bot-challenge-too-many-submissions 0.2 ENABLED Client made too many submissions for challenge
crowdsecurity/appsec-generic-test 0.2 ENABLED Crowdsec Generic Test Scenario for AppSec: generate an alert for appsec out of band rule for testing
crowdsecurity/appsec-native 0.3 ENABLED Identify attacks flagged by CrowdSec AppSec via native rules
crowdsecurity/appsec-vpatch 0.7 ENABLED Identify attacks flagged by CrowdSec AppSec
crowdsecurity/CVE-2017-9841 0.2 ENABLED Detect CVE-2017-9841 exploits
crowdsecurity/CVE-2019-18935 0.2 ENABLED Detect Telerik CVE-2019-18935 exploitation attempts
crowdsecurity/CVE-2022-26134 0.4 ENABLED Confluence - RCE (CVE-2022-26134)
crowdsecurity/CVE-2022-35914 0.2 ENABLED Detect CVE-2022-35914 exploits
crowdsecurity/CVE-2022-37042 0.2 ENABLED Detect CVE-2022-37042 exploits
crowdsecurity/CVE-2022-40684 0.3 ENABLED Detect cve-2022-40684 exploitation attempts
crowdsecurity/CVE-2022-41082 0.4 ENABLED Detect CVE-2022-41082 exploits
crowdsecurity/CVE-2022-41697 0.2 ENABLED Detect CVE-2022-41697 enumeration
crowdsecurity/CVE-2022-42889 0.3 ENABLED Detect CVE-2022-42889 exploits (Text4Shell)
crowdsecurity/CVE-2022-44877 0.4 ENABLED Detect CVE-2022-44877 exploits
crowdsecurity/CVE-2022-46169 0.2 ENABLED Detect CVE-2022-46169 brute forcing
crowdsecurity/CVE-2023-22515 0.1 ENABLED Detect CVE-2023-22515 exploitation
crowdsecurity/CVE-2023-22518 0.3 ENABLED Detect CVE-2023-22518 exploits
crowdsecurity/CVE-2023-49103 0.3 ENABLED Detect owncloud CVE-2023-49103 exploitation attempts
crowdsecurity/CVE-2024-0012 0.1 ENABLED Detect CVE-2024-0012 exploitation attempts
crowdsecurity/CVE-2024-38475 0.1 ENABLED Detect CVE-2024-38475 exploitation attempts
crowdsecurity/CVE-2024-9474 0.1 ENABLED Detect CVE-2024-9474 exploitation attempts
crowdsecurity/f5-big-ip-cve-2020-5902 0.3 ENABLED F5 BIG-IP TMUI - RCE (CVE-2020-5902)
crowdsecurity/fortinet-cve-2018-13379 0.4 ENABLED Detect cve-2018-13379 exploitation attempts
crowdsecurity/grafana-cve-2021-43798 0.3 ENABLED Grafana - Arbitrary File Read (CVE-2021-43798)
crowdsecurity/http-admin-interface-probing 0.5 ENABLED Detect generic HTTP admin interface probing
crowdsecurity/http-backdoors-attempts 0.6 ENABLED Detect attempt to common backdoors
crowdsecurity/http-bad-user-agent 1.2 ENABLED Detect usage of bad User Agent
crowdsecurity/http-bf-wordpress_bf 0.7 ENABLED Detect WordPress bruteforce on admin interface
crowdsecurity/http-crawl-non_statics 0.7 ENABLED Detect aggressive crawl on non static resources
crowdsecurity/http-cve-2021-41773 0.3 ENABLED Apache - Path Traversal (CVE-2021-41773)
crowdsecurity/http-cve-2021-42013 0.3 ENABLED Apache - Path Traversal (CVE-2021-42013)
crowdsecurity/http-cve-probing 0.6 ENABLED Detect generic HTTP cve probing
crowdsecurity/http-dos-bypass-cache 0.5 ENABLED Detect DoS tools bypassing cache every request
crowdsecurity/http-dos-invalid-http-versions 0.7 ENABLED Detect DoS tools using invalid HTTP versions
crowdsecurity/http-dos-random-uri 0.4 ENABLED Detect DoS tools using random uri
crowdsecurity/http-dos-switching-ua 0.5 ENABLED Detect DoS tools switching user-agent too fast
crowdsecurity/http-generic-bf 0.9 ENABLED Detect generic http brute force
crowdsecurity/http-generic-test 0.2 ENABLED Crowdsec Generic Test Scenario: basic HTTP trigger
crowdsecurity/http-open-proxy 0.5 ENABLED Detect scan for open proxy
crowdsecurity/http-path-traversal-probing 0.4 ENABLED Detect path traversal attempt
crowdsecurity/http-probing 0.4 ENABLED Detect site scanning/probing from a single ip
crowdsecurity/http-sap-interface-probing 0.1 ENABLED Detect generic HTTP SAP interface probing
crowdsecurity/http-sensitive-files 0.4 ENABLED Detect attempt to access to sensitive files (.log, .db ..) or folders (.git)
crowdsecurity/http-sqli-probing 0.4 ENABLED A scenario that detects SQL injection probing with minimal false positives
crowdsecurity/http-technology-probing 0.1 ENABLED Detect HTTP technology/vendor probing
crowdsecurity/http-wordpress-scan 0.4 ENABLED Detect exploitation attempts against common WordPress endpoints
crowdsecurity/http-wordpress_user-enum 0.3 ENABLED Detect WordPress probing: authors enumeration
crowdsecurity/http-wordpress_wpconfig 0.3 ENABLED Detect WordPress probing: variations around wp-config.php by wpscan
crowdsecurity/http-xss-probing 0.4 ENABLED A scenario that detects XSS probing with minimal false positives
crowdsecurity/jira_cve-2021-26086 0.4 ENABLED Detect Atlassian Jira CVE-2021-26086 exploitation attempts
crowdsecurity/netgear_rce 0.4 ENABLED Detect Netgear RCE DGN1000/DGN220 exploitation attempts
crowdsecurity/nginx-req-limit-exceeded 0.3 ENABLED Detects IPs which violate nginx's user set request limit.
crowdsecurity/pulse-secure-sslvpn-cve-2019-11510 0.4 ENABLED Detect cve-2019-11510 exploitation attempts
crowdsecurity/spring4shell_cve-2022-22965 0.3 ENABLED Detect cve-2022-22965 probing
crowdsecurity/ssh-bf 0.3 ENABLED Detect ssh bruteforce
crowdsecurity/ssh-cve-2024-6387 0.2 ENABLED Detect exploitation attempt of CVE-2024-6387
crowdsecurity/ssh-generic-test 0.2 ENABLED Crowdsec Generic Test Scenario: SSH brute force trigger
crowdsecurity/ssh-refused-conn 0.1 ENABLED Detect sshd refused connections
crowdsecurity/ssh-slow-bf 0.4 ENABLED Detect slow ssh bruteforce
crowdsecurity/ssh-time-based-bf 0.3 ENABLED Detect time-based ssh bruteforce attempts that evade rate limiting (with false positive reduction)
crowdsecurity/thinkphp-cve-2018-20062 0.7 ENABLED Detect ThinkPHP CVE-2018-20062 exploitation attempts
crowdsecurity/vmware-cve-2022-22954 0.3 ENABLED Detect Vmware CVE-2022-22954 exploitation attempts
crowdsecurity/vmware-vcenter-vmsa-2021-0027 0.3 ENABLED Detect VMSA-2021-0027 exploitation attempts
ltsich/http-w00tw00t 0.3 ENABLED detect w00tw00t
🚫 Decisiones activas
Bloqueos y decisiones de remediación activas actualmente en este servidor. Las decisiones de la Community Blocklist se identifican como CAPI.
IP / Valor Tipo Escenario Origen Duración
- - crowdsecurity/http-probing - -
- - crowdsecurity/jira_cve-2021-26086 - -
- - crowdsecurity/http-probing - -
🚨 Últimas 20 alertas locales
Detecciones locales registradas por el Mini-SOC. Las actualizaciones CAPI y los eventos de prueba no se contabilizan como ataques.
Sin ataques locales reales registrados.

Las actualizaciones de CrowdSec Community Blocklist (CAPI) no se contabilizan como ataques contra este servidor.
Los eventos TEST-MINISOC, TEST-MINISOC-TELEGRAM y PRUEBA-BOUNCER tampoco se incluyen.
📊 Métricas
Actividad local de adquisición, parsers, Local API, decisiones y bouncers.
+-----------------------------------------------------------------------------------------------------------------------------------------------------------+
| Acquisition Metrics                                                                                                                                       |
+-----------------------------------------------------------------+------------+--------------+----------------+------------------------+-------------------+
| Source                                                          | Lines read | Lines parsed | Lines unparsed | Lines poured to bucket | Lines whitelisted |
+-----------------------------------------------------------------+------------+--------------+----------------+------------------------+-------------------+
| file:/opt/nginx-proxy-manager/data/logs/proxy-host-6_access.log | 156        | 155          | 1              | 114                    | 7                 |
| file:/opt/nginx-proxy-manager/data/logs/proxy-host-7_access.log | 232        | 231          | 1              | 174                    | 5                 |
| file:/var/log/kern.log                                          | 255        | -            | 255            | -                      | -                 |
| file:/var/log/syslog                                            | 2.71k      | -            | 2.71k          | -                      | -                 |
| journalctl:journalctl-_SYSTEMD_UNIT=ssh.service                 | 5          | 2            | 3              | -                      | 2                 |
+-----------------------------------------------------------------+------------+--------------+----------------+------------------------+-------------------+
+---------------------------------------------+
| Local API Alerts                            |
+-------------------------------------+-------+
| Reason                              | Count |
+-------------------------------------+-------+
| crowdsecurity/http-probing          | 2     |
| crowdsecurity/jira_cve-2021-26086   | 1     |
| crowdsecurity/vpatch-CVE-2025-55182 | 2     |
| crowdsecurity/vpatch-env-access     | 3     |
| crowdsecurity/http-cve-probing      | 1     |
+-------------------------------------+-------+
+---------------------------------+
| Bot Detection Infrastructure Me |
| trics                           |
+-------------------------+-------+
| Metric                  | Count |
+-------------------------+-------+
| Signing key regenerated | 0     |
| Signing key evicted     | 0     |
| Dynamic module evicted  | 0     |
+-------------------------+-------+
+-------------------------------------------------------------------------------------+
| Bouncer Metrics (cs-firewall-bouncer-1788941154) since 2026-09-14 12:41:50 +0000 UT |
| C                                                                                   |
+----------------------------+------------------+-----------------+-------------------+
| Origin                     | active_decisions |     dropped     |     processed     |
|                            |        IPs       | bytes | packets |  bytes  | packets |
+----------------------------+------------------+-------+---------+---------+---------+
| CAPI (community blocklist) |           24.08k | 4.20k |      70 |       - |       - |
| crowdsec (security engine) |                0 |     0 |       0 |       - |       - |
+----------------------------+------------------+-------+---------+---------+---------+
|                      Total |           24.08k | 4.20k |      70 | 557.01M |   1.27M |
+----------------------------+------------------+-------+---------+---------+---------+
+-------------------------------------------------------------------------------------+
| Bouncer Metrics (cs-firewall-bouncer-636759aeb01f) since 2026-09-17 10:19:43 +0000  |
| UTC                                                                                 |
+----------------------------+------------------+-----------------+-------------------+
| Origin                     | active_decisions |     dropped     |     processed     |
|                            |        IPs       | bytes | packets |  bytes  | packets |
+----------------------------+------------------+-------+---------+---------+---------+
| CAPI (community blocklist) |           21.60k | 1.50k |      25 |       - |       - |
+----------------------------+------------------+-------+---------+---------+---------+
|                      Total |           21.60k | 1.50k |      25 | 114.89M | 219.08k |
+----------------------------+------------------+-------+---------+---------+---------+
+-------------------------------------------------------------------------------------+
| Bouncer Metrics (cs-firewall-bouncer-aceef365364e) since 2026-09-21 11:42:01 +0000  |
| UTC                                                                                 |
+----------------------------+------------------+------------------+------------------+
| Origin                     | active_decisions |      dropped     |     processed    |
|                            |        IPs       |  bytes | packets |  bytes | packets |
+----------------------------+------------------+--------+---------+--------+---------+
| CAPI (community blocklist) |           21.57k |  3.30k |      55 |      - |       - |
| crowdsec (security engine) |                - | 17.98k |     250 |      - |       - |
+----------------------------+------------------+--------+---------+--------+---------+
|                      Total |           21.57k | 21.28k |     305 | 43.24M |  51.56k |
+----------------------------+------------------+--------+---------+--------+---------+
+--------------------------------------------------+
| Bouncer Metrics (minisoc-openresty-20260913-0045 |
| 05) since 2026-09-14 12:41:42 +0000 UTC          |
+----------------------------+---------+-----------+
| Origin                     | dropped | processed |
|                            | request |  request  |
+----------------------------+---------+-----------+
| crowdsec (security engine) |       2 |         - |
+----------------------------+---------+-----------+
|                      Total |       2 |     3.99k |
+----------------------------+---------+-----------+
+---------------------------------------------------------------+
| Local API Decisions                                           |
+-----------------------------------+----------+--------+-------+
| Reason                            | Origin   | Action | Count |
+-----------------------------------+----------+--------+-------+
| crowdsecurity/http-probing        | crowdsec | ban    | 2     |
| crowdsecurity/jira_cve-2021-26086 | crowdsec | ban    | 1     |
| http:bruteforce                   | CAPI     | ban    | 332   |
| http:crawl                        | CAPI     | ban    | 13    |
| http:exploit                      | CAPI     | ban    | 429   |
| http:scan                         | CAPI     | ban    | 20771 |
+-----------------------------------+----------+--------+-------+
+------------------------------------------------+
| Local API Metrics                              |
+--------------------------------+--------+------+
| Route                          | Method | Hits |
+--------------------------------+--------+------+
| /v1/alerts                     | GET    | 345  |
| /v1/alerts                     | POST   | 3    |
| /v1/allowlists                 | GET    | 69   |
| /v1/allowlists/:allowlist_name | GET    | 1    |
| /v1/decisions                  | GET    | 1294 |
| /v1/decisions/stream           | GET    | 409  |
| /v1/decisions/stream           | HEAD   | 1253 |
| /v1/heartbeat                  | GET    | 68   |
| /v1/usage-metrics              | POST   | 9    |
| /v1/watchers/login             | POST   | 348  |
+--------------------------------+--------+------+
+-------------------------------------------------------------------------+
| Local API Bouncers Metrics                                              |
+----------------------------------+----------------------+--------+------+
| Bouncer                          | Route                | Method | Hits |
+----------------------------------+----------------------+--------+------+
| cs-firewall-bouncer-aceef365364e | /v1/decisions/stream | GET    | 409  |
+----------------------------------+----------------------+--------+------+
+----------------------------------------------------------------------------------------------------+
| Local API Machines Metrics                                                                         |
+---------------------------------------------------+--------------------------------+--------+------+
| Machine                                           | Route                          | Method | Hits |
+---------------------------------------------------+--------------------------------+--------+------+
| 8a0f066a716d4ef291b76f562f2d5406-38406241e6a2d649 | /v1/allowlists/:allowlist_name | GET    | 1    |
| 8a0f066a716d4ef291b76f562f2d5406-38406241e6a2d649 | /v1/heartbeat                  | GET    | 68   |
| 8a0f066a716d4ef291b76f562f2d5406-38406241e6a2d649 | /v1/alerts                     | GET    | 345  |
| 8a0f066a716d4ef291b76f562f2d5406-38406241e6a2d649 | /v1/alerts                     | POST   | 3    |
| 8a0f066a716d4ef291b76f562f2d5406-38406241e6a2d649 | /v1/allowlists                 | GET    | 69   |
+---------------------------------------------------+--------------------------------+--------+------+
+-----------------------------------------------------------------------------+
| Parser Metrics                                                              |
+-------------------------------------------------+-------+--------+----------+
| Parsers                                         | Hits  | Parsed | Unparsed |
+-------------------------------------------------+-------+--------+----------+
| child-crowdsecurity/http-logs                   | 1.16k | 818    | 340      |
| child-crowdsecurity/nginx-logs                  | 2.33k | 386    | 1.94k    |
| child-crowdsecurity/sshd-logs                   | 54    | 2      | 52       |
| child-crowdsecurity/syslog-logs                 | 2.97k | 2.97k  | -        |
| crowdsecurity/cdn-whitelist                     | 3     | 3      | -        |
| crowdsecurity/dateparse-enrich                  | 388   | 388    | -        |
| crowdsecurity/geoip-enrich                      | 374   | 374    | -        |
| crowdsecurity/google-special-crawlers-whitelist | 3     | 3      | -        |
| crowdsecurity/http-logs                         | 386   | 386    | -        |
| crowdsecurity/nginx-logs                        | 388   | 386    | 2        |
| crowdsecurity/non-syslog                        | 388   | 388    | -        |
| crowdsecurity/public-dns-allowlist              | 388   | 388    | -        |
| crowdsecurity/rdns                              | 3     | 3      | -        |
| crowdsecurity/seo-bots-whitelist                | 3     | 3      | -        |
| crowdsecurity/sshd-logs                         | 5     | 2      | 3        |
| crowdsecurity/syslog-logs                       | 2.97k | 2.97k  | -        |
| crowdsecurity/whitelists                        | 388   | 388    | -        |
+-------------------------------------------------+-------+--------+----------+
+----------------------------------------------------------------------------------------------------+
| Scenario Metrics                                                                                   |
+--------------------------------------+---------------+-----------+--------------+--------+---------+
| Scenario                             | Current Count | Overflows | Instantiated | Poured | Expired |
+--------------------------------------+---------------+-----------+--------------+--------+---------+
| crowdsecurity/http-crawl-non_statics | -             | -         | 79           | 172    | 79      |
| crowdsecurity/http-dos-swithcing-ua  | 2             | -         | 60           | 64     | 58      |
| crowdsecurity/http-probing           | 1             | 2         | 25           | 47     | 22      |
| crowdsecurity/http-sensitive-files   | -             | -         | 4            | 5      | 4       |
| crowdsecurity/jira_cve-2021-26086    | -             | 1         | 1            | -      | -       |
+--------------------------------------+---------------+-----------+--------------+--------+---------+
+-----------------------------------------------------------------------------------------------------------+
| Whitelist Metrics                                                                                         |
+-------------------------------------------------+------------------------------------+------+-------------+
| Whitelist                                       | Reason                             | Hits | Whitelisted |
+-------------------------------------------------+------------------------------------+------+-------------+
| crowdsecurity/cdn-whitelist                     | CDN provider                       | 3    | -           |
| crowdsecurity/google-special-crawlers-whitelist | Google special crawlers ip range   | 3    | -           |
| crowdsecurity/public-dns-allowlist              | public DNS server                  | 388  | -           |
| crowdsecurity/seo-bots-whitelist                | good bots (search engine crawlers) | 3    | -           |
| crowdsecurity/whitelists                        | private ipv4/ipv6 ip/ranges        | 388  | 14          |
+-------------------------------------------------+------------------------------------+------+-------------+