DNSBL - DNS-basierte Blacklist2 min read1 sections

CrowdSec Integration

Report attacks from CrowdSec to the Attack Defense Network via the HTTP plugin - one config file, done.

01

Setup with the HTTP Plugin

CrowdSec can report banned IPs to the network via its built-in http plugin. Create the plugin configuration:

# /etc/crowdsec/notifications/http.yaml
type: http
name: http_provider_tools
log_level: info
format: |
  {"ip":"{{.Alert.Source.IP}}","service":"{{.Alert.Scenario}}"}
url: https://reports.provider.tools/api/v1/abuse/report
method: POST
headers:
  Content-Type: application/json
  X-Report-Token: ar_YOURTOKEN   # optional

Then register the plugin in /etc/crowdsec/profiles.yaml:

name: report_to_provider_tools
filters:
  - Alert.Remediation == true && Alert.GetScope() == "Ip"
notifications:
  - http_provider_tools

Restart CrowdSec:

sudo systemctl restart crowdsec

CrowdSec scenario names (e.g. crowdsecurity/ssh-bf) are mapped to our service taxonomy automatically where possible. Unknown scenarios are ignored.