Setup with the HTTP Plugin
CrowdSec can report banned IPs to the network via its built-in http plugin. Create the plugin configuration:
# /etc/crowdsec/notifications/http.yaml
type: http
name: http_provider_tools
log_level: info
format: |
{"ip":"{{.Alert.Source.IP}}","service":"{{.Alert.Scenario}}"}
url: https://reports.provider.tools/api/v1/abuse/report
method: POST
headers:
Content-Type: application/json
X-Report-Token: ar_YOURTOKEN # optional
Then register the plugin in /etc/crowdsec/profiles.yaml:
name: report_to_provider_tools
filters:
- Alert.Remediation == true && Alert.GetScope() == "Ip"
notifications:
- http_provider_tools
Restart CrowdSec:
sudo systemctl restart crowdsec
CrowdSec scenario names (e.g. crowdsecurity/ssh-bf) are mapped to our service taxonomy automatically where possible. Unknown scenarios are ignored.
Related articles
Attack Defense - moved to its own category
The Attack Defense guide has moved to its own KB category with articles for servers, firewalls, IP checks, API and GDPR.
ReadFalse-Positive Protection (Whitelists, Tor & dnswl)
How the network avoids mis-listing legitimate infrastructure: internal whitelists, dnswl.org reputation, tor exit handling and automatic score decay.
Read