This repository always provides up-to-date lists of malicious IPv4 and IPv6 addresses from the CrowdSec CAPI which collects incident data from its users to create community-fueled block lists.
➤ Automatically updates once every 2 hours (Recommended minimum by CrowdSec)
➤ Maximum of 3000 unique IPs per file
➤ It contains a mix of mostly IPv4 addresses with some IPv6 addresses
➤ Can be used as import source for Fail2Ban or CrowdSec (without participating in the information sharing)
Scenario | JSON | TXT |
---|---|---|
crowdsecurity/nginx-req-limit-exceeded | JSON | TXT |
crowdsecurity/http-generic-bf | JSON | TXT |
crowdsecurity/mysql-bf | JSON | TXT |
crowdsecurity/ssh-bf | JSON | TXT |
Formats:
- JSON (raw output from the CAPI Endpoint)
- TXT (IPv4 & IPv6 list, no decision metadata)