CrowdSec
Collaborative behaviour-based intrusion prevention engine
CrowdSec's WAF is growing a bot-detection challenge — log analysis meets active interception.
◆Recent moves
- 7d ago
CrowdSec 1.8 RC adds WAF bot detection and a Kubernetes datasource
⚡ SPARKThe candidate that moves CrowdSec from inferring attacks out of logs to interrogating clients directly, via a challenge-and-fingerprint page in the WAF. Combined with a Kubernetes apiserver datasource and HTTP helpers in the expression language, it is the clearest step yet toward CrowdSec sitting in the request path rather than beside it.
View source ↗ - 3mo ago
1.7.8 RC: OpenAPI schema validation in the WAF
Adds OpenAPI schema validation and request body size limits to the WAF, and switches the decision stream to chunked transfer by default. Schema validation is the API-aware half of the WAF story that bot detection later complements.
View source ↗ - 4mo ago
1.7.7 RC: flexible WAF rule conditions and RE2 by default
Allows arbitrary mixing of AND and OR conditions in WAF rules, exposes more Coraza transformations, enables RE2 by default on Linux and adds LookupFile and FileMap expression helpers. Rule-authoring ergonomics, which is what determines whether a WAF gets tuned or left on defaults.
View source ↗ - 6mo ago
1.7.5 RC: acquisition and leaky-bucket refactoring
A candidate consisting entirely of internal refactoring — datasource registration, configuration validation, injected state dumpers, error-handling cleanup. No user-visible change, but it is the groundwork the later Kubernetes datasource sits on.
View source ↗ - 8mo ago
1.7.4 RC2: acquisition module split and lint cleanup
Another refactoring-only candidate, splitting acquisition modules per datasource and tightening lint rules. Housekeeping ahead of the datasource work that followed.
View source ↗