No description
Find a file
Christin Löhner 4089a930a7 feat: add faker user-agent scenario and bot account guide
New trigger scenario r3y/mastodon-faker-user-agent bans Faker-generated user agents used by spam bots after registration. The test harness accepts an optional user-agent column and has a wider ban duration tolerance; 35 test cases cover bot and real clients. Add a guide for finding and suspending bot accounts and a note on manual range bans.
2026-10-10 10:29:16 +02:00
allowlists feat: add CrowdSec rules, parsers, profiles and tooling for Fediverse servers 2026-10-10 10:06:32 +02:00
decisions feat: add CrowdSec rules, parsers, profiles and tooling for Fediverse servers 2026-10-10 10:06:32 +02:00
docker/crowdsec-web-ui feat: add CrowdSec rules, parsers, profiles and tooling for Fediverse servers 2026-10-10 10:06:32 +02:00
docs feat: add faker user-agent scenario and bot account guide 2026-10-10 10:29:16 +02:00
etc feat: add faker user-agent scenario and bot account guide 2026-10-10 10:29:16 +02:00
scripts feat: add faker user-agent scenario and bot account guide 2026-10-10 10:29:16 +02:00
tests feat: add faker user-agent scenario and bot account guide 2026-10-10 10:29:16 +02:00
.gitignore feat: add CrowdSec rules, parsers, profiles and tooling for Fediverse servers 2026-10-10 10:06:32 +02:00
LICENSE chore: license under AGPL-3.0-or-later 2026-10-10 10:12:40 +02:00
README.en.md chore: license under AGPL-3.0-or-later 2026-10-10 10:12:40 +02:00
README.md feat: add faker user-agent scenario and bot account guide 2026-10-10 10:29:16 +02:00

CrowdSec scenarios for Fediverse servers

Tested CrowdSec scenarios, parsers, profiles and operations helpers for Fediverse instances (focus: Mastodon) and the servers around them. The directory layout mirrors CrowdSec's own (etc/crowdsec/...), so you can clone the repository and copy the files into place.

Everything here runs in production on one Mastodon instance and five more servers with a central LAPI. The rules are built so that they do not ban federation traffic, detect bots while registration is closed or approval-based, and avoid hitting real users. All rule sets ship with tests (tests/) that run in an isolated CrowdSec instance.

The documentation is in German (see README.md and docs/). Quick start:

git clone https://forge.chrislo.de/FediSuite/CrowdSec-Szenarien.git && cd CrowdSec-Szenarien
sudo cscli collections install crowdsecurity/nginx crowdsecurity/base-http-scenarios crowdsecurity/http-cve
sudo scripts/install.sh --domain social.example.org --dry-run
sudo scripts/install.sh --domain social.example.org --restart

# optional: test scenarios and profiles in an isolated instance first
sudo scripts/test-scenarios.sh --cases tests/mastodon-registration.tsv \
     --rules etc/crowdsec --profiles etc/crowdsec/profiles.yaml.local

Requirements: CrowdSec 1.7 or newer, Nginx in front of Mastodon writing a per-domain access log (/var/log/nginx/<domain>.access.log, default format). Scenario names start with r3y/; the profiles match on that prefix.

License

AGPL-3.0-or-later, see LICENSE. Copyright (C) 2026 Christin Löhner.