Cover image for project: NEXUS CrowdSec CTI IN PROGRESS

Technical summary

NEXUS CrowdSec CTI queries the CrowdSec Cyber Threat Intelligence API (13B+ observed IPs) for IP reputation with an aggression score, classifications, behaviors, ASN and country. It uses a 24 h local cache, a daily query limit (community 50/day) and automatic enrichment through the Intelligence Hub.

Executed scope

  • Plugin registration (registerTab('crowdsec-cti','CrowdSec CTI','shield-alert',tab.php,'Threat Intel') + registerDoc) and DB migration via PluginMigrationRunner (migrations/001_create_crowdsec_tables.php) creating crowdsec_cache (IP PK, result_json, overall_score, classification, expires_at with indexes) and crowdsec_history (auto-increment, ip, score, classification, behaviors_json, source, cached, created_at with indexes).
  • 11 API actions: crowdsec_status (stats + remaining queries), crowdsec_lookup (single check with force), crowdsec_batch (batch via array or text), crowdsec_history (paginated by classification), crowdsec_alerts (suspicious+ IPs), crowdsec_blocklist (problematic IP check), crowdsec_enrich_task (extracts IPs from the task), crowdsec_settings/settings_save (key, tier, auto_enrich, daily_limit, alert_score), crowdsec_test_key (validates the key) and crowdsec_purge (clears expired; all=1 clears everything).
  • CrowdSec CTI API v2 integration (/v2/smoke/{ip}): public base of 13B+ IPs; community tier with a 50 queries/day limit (automatic date reset) and premium with no local limit; key validated with a connection test in the panel.
  • Local classification: crowdsec_signal_from_normalized() converts score/behaviors into a label — score ≥ 70 or ≥ 3 behaviors → malicious, score ≥ 30 → suspicious, others (or CTI 404) → clean.
  • 24 h TTL local cache: crowdsec_cache_get/set answer from the DB on valid cache (expires_at) and crowdsec_can_query() enforces the daily budget before hitting the API.
  • Enrichment (Intelligence Hub): nx_intel_register_enricher('crowdsec-cti', ['ip'], 'crowdsec_intel_enrich', 48) publishes signals to task.intel/comment.intel (source crowdsec-cti) with an auto-enrich toggle.
  • crowdsec_purge cronjob (tick, 12 h throttle) removing expired entries; allowlisted cli.php runs the same purge and applies migrations via PluginMigrationRunner.
  • Fast Responses: fastr.json manifest with /crowdsec <IP> (required arg), crowdsec_lookup action.
  • UI (tab.php, 556 lines, Alpine crowdsecApp()): 6 tabs — Lookup, Batch, History, Alerts, Task and Settings (community/premium tier, alert_score, key test).

Stack and tools

  • PHP 8 backend (no framework) + MySQL 8 (crowdsec_cache, crowdsec_history)
  • CrowdSec CTI API v2 (/v2/smoke/{ip}) with 24 h cache and daily budget
  • Core migration system (PluginMigrationRunner)
  • Alpine.js + Tailwind CSS (tab.php)
  • Internal Plugin API (PluginManager tabs/actions + cronjob.json + fastr.json + enricher)

Operational tags

  • CrowdSec
  • CTI
  • IP
  • Reputation
  • Threat Intel
  • Score
  • Behaviors
  • NEXUS Plugin

Operational result

  • IP threat intel: aggression score, classifications and behaviors for any address found in NEXUS, straight from the panel or the task flow.
  • 13B+ IP base: ASN, country and first/last seen context fuel decisions with CrowdSec community data.
  • Controlled daily budget: 24 h cache + query limit (community 50/day, automatic reset) prevent free-tier overuse; premium tier lifts the local limit.
  • Automatic enrichment: IPs in tasks/comments get security signals via the Intelligence Hub with no manual action.
  • Alerts and blocklist: suspicious+ IPs surface in alerts and crowdsec_blocklist answers quick checks.
  • Cache hygiene: cron purge (12 h) and manual action/CLI keep the tables lean.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

Queries the CrowdSec Cyber Threat Intelligence API (13B+ observed IPs) for IP reputation with an aggression score, classifications, behaviors, ASN and country; uses a 24 h local cache, a daily query limit (community 50/day) and automatic enrichment through the Intelligence Hub.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.