beane.meOperations briefing
Updated
This briefing has not refreshed recently, so what you see may be out of date.
Healthy

Everything is operating normally.

6 of 6 services are healthy and mirrored; 7 of 7 fleet nodes are reporting; the last backup finished 6.8 hours ago.

A self-hosted, multi-node platform: every public service runs on a primary and a mirror behind automatic DNS failover, FluxCD keeps configuration in line with its Git repository, each node repairs any drift between its nftables firewall and CrowdSec's ban decisions, and a decision engine escalates repeat offenders from the shared threat feed to 24-hour and then 14-day bans across the whole fleet. This page is generated from the platform's own APIs and explains, in one place, what is running and what changed.

Services healthy
6/6
all with a live mirror and DNS failover
Fleet nodes reporting
7/7
263 active bans, ban lists in sync
Since last backup
6.8 h
Triton · 5.27 GB · 35.28 s · 12/12 recent runs ok
Bans yesterday
252
a typical day (median 169)
Firewall self-heal, 24h
100%
200 drifts detected, 0 unresolved

What changed last 7 days

Tracking began . Nothing has changed since.

Needs attention

Nothing needs attention.

Services

ServicePrimaryMirrorServing
Threatsthreats.beane.meUpUpPrimary
Intelintel.beane.meUpUpPrimary
Backupsbackups.beane.meUpUpPrimary
Observeobserve.beane.meUpUpPrimary
Vulnvuln.beane.meUpUpPrimary
Portfoliobeane.meUpUpPrimary

Each service runs on a primary and a mirror; DNS moves to the mirror automatically if the primary fails.

Threat picture

The 25 most recent distinct threats from CrowdSec, reaching back 7.7 h, seen by 6 nodes. Severity reflects the techniques a source attempted.

By severity

Critical7
High8
Low10

By technique (MITRE ATT&CK)

Exploit public-facing application T119015
Active scanning T159511
Ingress tool transfer T11053
Command & scripting interpreter T10593

1 group of sources share a network block, which usually means one actor.

Bans per day, last 30 days

0250500Sep 7: 171 bansSep 8: 64 bansSep 9: 107 bansSep 10: 73 bansSep 11: 158 bansSep 12: 146 bansSep 13: 136 bansSep 14: 67 bansSep 15: 49,564 bans (suspected botnet)Sep 16: 189 bansSep 17: 234 bansSep 18: 200 bansSep 19: 112 bansSep 20: 339 bansSep 21: 306 bansSep 22: 334 bansSep 23: 345 bansSep 24: 107 bansSep 25: 159 bansSep 26: 128 bansSep 27: 156 bansSep 28: 104 bansSep 29: 179 bansSep 30: 205 bansOct 1: 269 bansOct 2: 238 bansOct 3: 113 bansOct 4: 246 bansOct 5: 252 bansOct 6: 146 bans so far49,564 · suspected botnetSep 7Sep 14Sep 21Sep 28today

The tallest bar is clipped so normal days stay readable. The line marks the median day (169). The pale bar is today, still in progress.

View as table
DateBans
Oct 6146 (so far)
Oct 5252
Oct 4246
Oct 3113
Oct 2238
Oct 1269
Sep 30205
Sep 29179
Sep 28104
Sep 27156
Sep 26128
Sep 25159
Sep 24107
Sep 23345
Sep 22334
Sep 21306
Sep 20339
Sep 19112
Sep 18200
Sep 17234
Sep 16189
Sep 1549,564
Sep 1467
Sep 13136
Sep 12146
Sep 11158
Sep 1073
Sep 9107
Sep 864
Sep 7171

Decision engine, active now

14-day ban250
24-hour ban21
Watching189

New in the last 24 hours: 10 14-day bans, 21 24-hour bans, 20 watching.

Most common reasons, last 24 hours

Single node only30
Low scenario volume19
High severity single node17

Fleet

Ares Healthy · seen 15 min ago
Argus Healthy · seen 20 min ago
Hermes Healthy · seen 15 min ago
Iris Healthy · seen 19 min ago
Triton Healthy · seen 23 min ago
Vault Healthy · seen 16 min ago
Zephyrus Healthy · seen 16 min ago

Each node continuously compares its nftables firewall with CrowdSec's ban decisions and repairs any mismatch: 200 mismatches were detected and 200 repaired in the last 24 hours.

Inspect the evidence