
Connector
CrowdSec
API credential, entered client by client.
Behaviour-based, open-source and collaborative Intrusion Prevention System (IPS), self-hosted, developed and operated from France — a sovereign alternative to proprietary intrusion detection/prevention solutions. Vigicap queries CrowdSec's Local API (LAPI) to check that it is reachable and to read the active decisions (bans, captchas) in order to evaluate the ReCyF objective « Détection des incidents ».
01
What to create in the tool
The access is created in CrowdSec, not in Vigicap. Vigicap never asks for an administrator's password: it expects an API credential that you create, that you can see, and that you can revoke without us.
Where to generate it
On the CrowdSec machine: generate a bouncer API key from the command line with `cscli bouncers add <name>` — the key is shown only once, copy it immediately.
Minimum role
Une clé de bouncer (« cscli bouncers add »), jamais un compte machine : CrowdSec limite les clés d'API à la LECTURE des décisions, là où un couple identifiant/mot de passe de machine peut aussi en créer et en supprimer.
Taken from the vendor's own role model, and checked before publication.
02
What to enter in Vigicap
The exact fields of the connection form, in the order they appear. Values marked “secret” never travel back to the browser: they are encrypted at rest and deleted on disconnection.
The form starts with the instance address, entered separately from the fields below. The public catalogue does not yet publish whether this connector needs one, or what it looks like — so this list is exact about everything else, and silent about that first field.
- API key (bouncer)secret
Generated via `cscli bouncers add <name>` on the CrowdSec instance.
Clé API CrowdSec
03
Per-client routing
The connection is made client by client: one credential per client, entered on that client's record. Nothing is shared between two clients, and disconnecting one leaves the other untouched.
04
What it does, and what it does not do
ReCyF objectives it pre-fills
A reading feeds one objective of the ANSSI ReCyF framework. It PROPOSES it: the level only counts once a consultant has confirmed it.
- #12 Identification et réaction aux incidents de sécuritéIdentification of and response to security incidents
Read-only
The reads are read-only: Vigicap writes nothing into the tool while reading it.
What is read, what is kept, for how long and with which rights: the same register, connector by connector, in the data inventory.
Verification
This connector has been run end to end against a real instance of the tool, not merely tested against a mock.
The trademarks and logos mentioned belong to their respective owners and identify the tools Vigicap is compatible with — see the legal notice.