TL;DR CrowdSec
CloudSonic uses CrowdSec on every server, blocking malicious behaviour in real time using community-driven threat intelligence across millions of servers worldwide.
CrowdSec is an open source security engine that uses community-driven threat intelligence to identify and block malicious behaviour in real time. It is installed and active on every CloudSonic server, monitoring Nginx access logs, SSH authentication logs, and application logs simultaneously. CrowdSec works alongside AppArmor, UFW, and Fail2ban as one of four independent security layers on every CloudSonic server.
CrowdSec Threat Intelligence on CloudSonic
CrowdSec on CloudSonic monitors Nginx access logs, SSH authentication logs, and PHP-FPM logs simultaneously, identifying attack patterns and feeding block decisions directly into UFW via the iptables bouncer. The global CrowdSec blocklist, maintained by hundreds of thousands of deployments worldwide, means your server benefits from threat intelligence gathered across the entire CrowdSec network, blocking known malicious IP addresses before they even attempt an attack on your server. CrowdSec works alongside AppArmor, UFW, and Fail2ban as one of four independent security layers active on every CloudSonic server.
Useful Commands
sudo cscli decisions list
sudo cscli alerts list