IN PROGRESS
Technical summary
NEXUS CrowdSec CTI queries the CrowdSec Cyber Threat Intelligence API (13B+ observed IPs) for IP reputation with an aggression score, classifications, behaviors, ASN and country. It uses a 24 h local cache, a daily query limit (community 50/day) and automatic enrichment through the Intelligence Hub.
Executed scope
- Plugin registration (
registerTab('crowdsec-cti','CrowdSec CTI','shield-alert',tab.php,'Threat Intel')+registerDoc) and DB migration viaPluginMigrationRunner(migrations/001_create_crowdsec_tables.php) creatingcrowdsec_cache(IP PK, result_json, overall_score, classification, expires_at with indexes) andcrowdsec_history(auto-increment, ip, score, classification, behaviors_json, source, cached, created_at with indexes). - 11 API actions:
crowdsec_status(stats + remaining queries),crowdsec_lookup(single check withforce),crowdsec_batch(batch via array or text),crowdsec_history(paginated by classification),crowdsec_alerts(suspicious+ IPs),crowdsec_blocklist(problematic IP check),crowdsec_enrich_task(extracts IPs from the task),crowdsec_settings/settings_save(key, tier, auto_enrich, daily_limit, alert_score),crowdsec_test_key(validates the key) andcrowdsec_purge(clears expired;all=1clears everything). - CrowdSec CTI API v2 integration (
/v2/smoke/{ip}): public base of 13B+ IPs; community tier with a 50 queries/day limit (automatic date reset) and premium with no local limit; key validated with a connection test in the panel. - Local classification:
crowdsec_signal_from_normalized()converts score/behaviors into a label — score ≥ 70 or ≥ 3 behaviors →malicious, score ≥ 30 →suspicious, others (or CTI 404) →clean. - 24 h TTL local cache:
crowdsec_cache_get/setanswer from the DB on valid cache (expires_at) andcrowdsec_can_query()enforces the daily budget before hitting the API. - Enrichment (Intelligence Hub):
nx_intel_register_enricher('crowdsec-cti', ['ip'], 'crowdsec_intel_enrich', 48)publishes signals totask.intel/comment.intel(sourcecrowdsec-cti) with an auto-enrich toggle. crowdsec_purgecronjob (tick, 12 h throttle) removing expired entries; allowlistedcli.phpruns the same purge and applies migrations viaPluginMigrationRunner.- Fast Responses:
fastr.jsonmanifest with/crowdsec <IP>(required arg),crowdsec_lookupaction. - UI (
tab.php, 556 lines, AlpinecrowdsecApp()): 6 tabs — Lookup, Batch, History, Alerts, Task and Settings (community/premium tier, alert_score, key test).
Stack and tools
- PHP 8 backend (no framework) + MySQL 8 (
crowdsec_cache,crowdsec_history) - CrowdSec CTI API v2 (
/v2/smoke/{ip}) with 24 h cache and daily budget - Core migration system (
PluginMigrationRunner) - Alpine.js + Tailwind CSS (
tab.php) - Internal Plugin API (PluginManager tabs/actions +
cronjob.json+fastr.json+ enricher)
Operational tags
- CrowdSec
- CTI
- IP
- Reputation
- Threat Intel
- Score
- Behaviors
- NEXUS Plugin
Operational result
- IP threat intel: aggression score, classifications and behaviors for any address found in NEXUS, straight from the panel or the task flow.
- 13B+ IP base: ASN, country and first/last seen context fuel decisions with CrowdSec community data.
- Controlled daily budget: 24 h cache + query limit (community 50/day, automatic reset) prevent free-tier overuse; premium tier lifts the local limit.
- Automatic enrichment: IPs in tasks/comments get security signals via the Intelligence Hub with no manual action.
- Alerts and blocklist: suspicious+ IPs surface in alerts and
crowdsec_blocklistanswers quick checks. - Cache hygiene: cron purge (12 h) and manual action/CLI keep the tables lean.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
Queries the CrowdSec Cyber Threat Intelligence API (13B+ observed IPs) for IP reputation with an aggression score, classifications, behaviors, ASN and country; uses a 24 h local cache, a daily query limit (community 50/day) and automatic enrichment through the Intelligence Hub.
Architecture and organization
- PHP 8
- MySQL 8
- CrowdSec CTI API
- Alpine.js
- Tailwind CSS
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.