Categories

Tools

How to enable CrowdSec 1.8 bot detection

CrowdSec 1.8 adds bot detection to its WAF, still in alpha, which serves every visitor a page with a proof of work and a browser fingerprint. You enable it with the appsec-bot-challenge collection and its configs in the AppSec acquisition, always behind a compatible bouncer such as OpenResty 1.2.3.

How to Install

How to Install CrowdSec as a Community WAF

CrowdSec 1.8.1 replaces fail2ban by separating detection (agent plus LAPI) from blocking (bouncers). Install the agent with the official script on Debian or Ubuntu and review the acquisition the installer generates. Then add the Traefik or firewall bouncer, the AppSec WAF with its two collections and, optionally, Cloudflare Turnstile captcha.