PHP code example of rilo-arbabillah / laravel-crowdsec
1. Go to this page and download the library: Download rilo-arbabillah/laravel-crowdsec library . Choose the download type require .
2. Extract the ZIP file and open the index.php.
3. Add this code to the index.php.
<?php
require_once('vendor/autoload.php');
/* Start to develop here. Best regards https://php-download.com/ */
rilo-arbabillah / laravel-crowdsec example snippets
use Illuminate\Support\Facades\Route;
Route::middleware('crowdsec')->group(function () {
Route::get('/admin', AdminController::class);
Route::post('/login', [AuthController::class, 'login']);
});
Route::middleware(['api', 'crowdsec'])->group(function () {
Route::get('/account', AccountController::class);
Route::post('/orders', [OrderController::class, 'store']);
});
Route::get('/health', HealthController::class)
->withoutMiddleware('crowdsec');
use Illuminate\Foundation\Configuration\Middleware;
use RiloArbabillah\LaravelCrowdSec\Http\Middleware\CrowdSecProtection;
->withMiddleware(function (Middleware $middleware): void {
$middleware->append(CrowdSecProtection::class);
})
protected $middleware = [
// ...
\RiloArbabillah\LaravelCrowdSec\Http\Middleware\CrowdSecProtection::class,
];
use RiloArbabillah\LaravelCrowdSec\Facades\CrowdSec;
$ip = request()->ip();
if (CrowdSec::isBlocked($ip)) {
abort(403, 'Your IP has been blocked.');
}
CrowdSec::blockIp($ip, 'Manual block for abusive traffic', 60);
CrowdSec::unblockIp($ip);
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Auth;
use RiloArbabillah\LaravelCrowdSec\Facades\CrowdSec;
public function login(Request $request)
{
if (! Auth::attempt($request->only('email', 'password'))) {
CrowdSec::trackLoginAttempt($request->ip());
return back()->withErrors(['email' => 'Invalid credentials.']);
}
return redirect('/dashboard');
}
use RiloArbabillah\LaravelCrowdSec\Facades\CrowdSec;
$threats = CrowdSec::analyzeRequest($request);
foreach ($threats as $threat) {
logger()->warning('Security threat detected', [
'type' => $threat['type'],
'severity' => $threat['severity'],
'matched' => $threat['matched'],
]);
}
use RiloArbabillah\LaravelCrowdSec\Facades\CrowdSec;
CrowdSec::registerScenario('api_abuse', [
'patterns' => ['/custom-api-abuse-signature/i'],
'severity' => 'high',
'weight' => 30,
'block_duration' => 720,
'mode' => 'monitor',
]);
return [
'enabled' => env('CROWDSEC_ENABLED', true),
'waf' => [
'default_mode' => 'enforce',
'scenario_modes' => [
// 'sql_injection' => 'monitor',
],
'exclusions' => [
[
'route_names' => ['webhooks.provider'],
'paths' => ['webhooks/provider'],
'methods' => ['POST'],
'skip_scenarios' => ['sql_injection'],
'ignore_body_fields' => ['payload.signature'],
],
],
],
'whitelist_ips' => [
'127.0.0.1',
'::1',
// '10.0.0.0/8',
],
'behavior' => [
'request_threshold' => 500,
'request_window_minutes' => 60,
'404_threshold' => 15,
'404_window_minutes' => 60,
'login_threshold' => 5,
'login_window_minutes' => 5,
'login_ignored_fields' => [
'password',
'password_confirmation',
'current_password',
],
'unblock_on_authentication' => false,
'reset_threat_score_on_authentication' => false,
'threat_score_threshold' => 50,
'block_duration' => 240,
'severity' => 'high',
],
];
// Programmatic
app('crowdsec')->whitelistIp('192.168.1.100', 'Home', 'office wifi', null, auth()->id(), auth()->user()->name);
app('crowdsec')->unwhitelistIp('192.168.1.100');
app('crowdsec')->isWhitelisted($request->ip()); // true if config OR DB layer matches
use Illuminate\Console\Scheduling\Schedule;
protected function schedule(Schedule $schedule): void
{
$schedule->command('crowdsec:cleanup --expired')->daily();
$schedule->command('crowdsec:cleanup --old-events')->weekly();
$schedule->command('crowdsec:cleanup --old-behaviors')->weekly();
$schedule->command('crowdsec:whitelist purge-expired')->daily();
}
bash
php artisan migrate
bash
php artisan vendor:publish --tag=crowdsec-config
bash
php artisan crowdsec:doctor
bash
php artisan vendor:publish --tag=crowdsec-views
bash
# Add
php artisan crowdsec:whitelist add 10.0.0.0/8 --label="Office VPN" --note="trusted internal" --expires="2026-12-31"
# List
php artisan crowdsec:whitelist list
# Remove
php artisan crowdsec:whitelist remove 10.0.0.0/8
# Purge expired rows (also runs daily via the schedule)
php artisan crowdsec:whitelist purge-expired
bash
php artisan crowdsec:doctor
php artisan crowdsec:doctor --json
php artisan crowdsec:stats
php artisan crowdsec:stats --json
bash
php artisan crowdsec:cleanup
bash
php artisan crowdsec:cleanup --dry-run
php artisan crowdsec:cleanup --expired
php artisan crowdsec:cleanup --old-events
php artisan crowdsec:cleanup --old-behaviors
bash
php artisan crowdsec:export --format=json
php artisan crowdsec:export --format=csv --from=2026-07-01 --to=2026-07-31
php artisan crowdsec:export --format=syslog --severity=critical
php artisan crowdsec:export --format=json --output=storage/app/crowdsec-events.json