CrowdSec logo
Security · self-hosted

CrowdSec in one click.

CrowdSec is a crowdsourced intrusion detection and prevention you can run on your own machine. Launch it in Even Stacks in one click, serve it over trusted HTTPS, and let your AI agents operate it.

What is CrowdSec?

CrowdSec is an open-source intrusion detection system that analyzes logs for attack patterns and shares threat intelligence across its community network. It blocks detected IPs via bouncers that integrate with firewalls and reverse proxies.

CategorySecurity
Default port8621
Container imagecrowdsecurity/crowdsec:v1.6.4
Official sitewww.crowdsec.net

Run CrowdSec in Even

Even Stacks launches CrowdSec as a managed container on your own machine. No compose files, no manual setup.

  1. Open the Even Stacks panel in Even. The container engine starts on demand.
  2. Find CrowdSec in the one-click services and click Launch.
  3. Even pulls the image, starts it on port 8621, and serves it over trusted HTTPS at https://crowdsec.localhost.

Drive CrowdSec with your AI agents

Even ships an MCP, so any agent you run inside Even (Claude Code, Codex, and more) can operate CrowdSec directly, at both the UI level and the container level.

Through the Even MCP an agent can run commands inside it, manage entries, and read its logs. It runs commands inside the container, reads its logs, and for web apps opens and clicks through the interface in Even's own browser pane. Ask once, for example "set up CrowdSec and get it ready", and the agent handles it end to end.

How agents reach it: No web UI. Use docker exec with cscli: cscli decisions list to see active bans, cscli alerts list for triggered alerts, cscli bouncers list for registered bouncers. Config is in /etc/crowdsec; hub scenarios and parsers are in /var/lib/crowdsec.

More Security services

Other one-click services you can launch in Even Stacks.