PHP code example of rilo-arbabillah / laravel-crowdsec

1. Go to this page and download the library: Download rilo-arbabillah/laravel-crowdsec library. Choose the download type require.

2. Extract the ZIP file and open the index.php.

3. Add this code to the index.php.
    
        
<?php
require_once('vendor/autoload.php');

/* Start to develop here. Best regards https://php-download.com/ */

    

rilo-arbabillah / laravel-crowdsec example snippets


use Illuminate\Support\Facades\Route;

Route::middleware('crowdsec')->group(function () {
    Route::get('/admin', AdminController::class);
    Route::post('/login', [AuthController::class, 'login']);
});

Route::middleware(['api', 'crowdsec'])->group(function () {
    Route::get('/account', AccountController::class);
    Route::post('/orders', [OrderController::class, 'store']);
});

Route::get('/health', HealthController::class)
    ->withoutMiddleware('crowdsec');

use Illuminate\Foundation\Configuration\Middleware;
use RiloArbabillah\LaravelCrowdSec\Http\Middleware\CrowdSecProtection;

->withMiddleware(function (Middleware $middleware): void {
    $middleware->append(CrowdSecProtection::class);
})

protected $middleware = [
    // ...
    \RiloArbabillah\LaravelCrowdSec\Http\Middleware\CrowdSecProtection::class,
];

use RiloArbabillah\LaravelCrowdSec\Facades\CrowdSec;

$ip = request()->ip();

if (CrowdSec::isBlocked($ip)) {
    abort(403, 'Your IP has been blocked.');
}

CrowdSec::blockIp($ip, 'Manual block for abusive traffic', 60);
CrowdSec::unblockIp($ip);

use Illuminate\Http\Request;
use Illuminate\Support\Facades\Auth;
use RiloArbabillah\LaravelCrowdSec\Facades\CrowdSec;

public function login(Request $request)
{
    if (! Auth::attempt($request->only('email', 'password'))) {
        CrowdSec::trackLoginAttempt($request->ip());

        return back()->withErrors(['email' => 'Invalid credentials.']);
    }

    return redirect('/dashboard');
}

use RiloArbabillah\LaravelCrowdSec\Facades\CrowdSec;

$threats = CrowdSec::analyzeRequest($request);

foreach ($threats as $threat) {
    logger()->warning('Security threat detected', [
        'type' => $threat['type'],
        'severity' => $threat['severity'],
        'matched' => $threat['matched'],
    ]);
}

use RiloArbabillah\LaravelCrowdSec\Facades\CrowdSec;

CrowdSec::registerScenario('api_abuse', [
    'patterns' => ['/custom-api-abuse-signature/i'],
    'severity' => 'high',
    'weight' => 30,
    'block_duration' => 720,
    'mode' => 'monitor',
]);

return [
    'enabled' => env('CROWDSEC_ENABLED', true),

    'waf' => [
        'default_mode' => 'enforce',
        'scenario_modes' => [
            // 'sql_injection' => 'monitor',
        ],
        'exclusions' => [
            [
                'route_names' => ['webhooks.provider'],
                'paths' => ['webhooks/provider'],
                'methods' => ['POST'],
                'skip_scenarios' => ['sql_injection'],
                'ignore_body_fields' => ['payload.signature'],
            ],
        ],
    ],

    'whitelist_ips' => [
        '127.0.0.1',
        '::1',
        // '10.0.0.0/8',
    ],

    'behavior' => [
        'request_threshold' => 500,
        'request_window_minutes' => 60,
        '404_threshold' => 15,
        '404_window_minutes' => 60,
        'login_threshold' => 5,
        'login_window_minutes' => 5,
        'login_ignored_fields' => [
            'password',
            'password_confirmation',
            'current_password',
        ],
        'unblock_on_authentication' => false,
        'reset_threat_score_on_authentication' => false,
        'threat_score_threshold' => 50,
        'block_duration' => 240,
        'severity' => 'high',
    ],
];

// Programmatic
app('crowdsec')->whitelistIp('192.168.1.100', 'Home', 'office wifi', null, auth()->id(), auth()->user()->name);
app('crowdsec')->unwhitelistIp('192.168.1.100');
app('crowdsec')->isWhitelisted($request->ip()); // true if config OR DB layer matches

use Illuminate\Console\Scheduling\Schedule;

protected function schedule(Schedule $schedule): void
{
    $schedule->command('crowdsec:cleanup --expired')->daily();
    $schedule->command('crowdsec:cleanup --old-events')->weekly();
    $schedule->command('crowdsec:cleanup --old-behaviors')->weekly();
    $schedule->command('crowdsec:whitelist purge-expired')->daily();
}
bash
php artisan migrate
bash
php artisan vendor:publish --tag=crowdsec-config
bash
php artisan crowdsec:doctor
bash
php artisan vendor:publish --tag=crowdsec-views
bash
# Add
php artisan crowdsec:whitelist add 10.0.0.0/8 --label="Office VPN" --note="trusted internal" --expires="2026-12-31"

# List
php artisan crowdsec:whitelist list

# Remove
php artisan crowdsec:whitelist remove 10.0.0.0/8

# Purge expired rows (also runs daily via the schedule)
php artisan crowdsec:whitelist purge-expired
bash
php artisan crowdsec:doctor
php artisan crowdsec:doctor --json

php artisan crowdsec:stats
php artisan crowdsec:stats --json
bash
php artisan crowdsec:cleanup
bash
php artisan crowdsec:cleanup --dry-run
php artisan crowdsec:cleanup --expired
php artisan crowdsec:cleanup --old-events
php artisan crowdsec:cleanup --old-behaviors
bash
php artisan crowdsec:export --format=json
php artisan crowdsec:export --format=csv --from=2026-07-01 --to=2026-07-31
php artisan crowdsec:export --format=syslog --severity=critical
php artisan crowdsec:export --format=json --output=storage/app/crowdsec-events.json