I want to…
Detect and block attacks on systems I run
You operate servers, VMs, or containers and want active threat detection — not just a blocklist.
→ Security Engine→
Push a threat feed into my firewall, router, or CDN
You manage network perimeter devices and want a URL to subscribe to — no agent to install.
→ Blocklist Feed Endpoints→
Look up an IP or enrich my security tools
You're a security analyst or developer who wants IP context — in a browser or via REST API.
→ IP Reputation & CTI→
Already running CrowdSec?
how each path works