Fast, and light
Detection runs in memory and bans land in nftables the instant a threshold is crossed. The agent uses a fraction of one core even on a busy host, and a flood makes it more selective — never slower.
Shieldlist reads your servers' logs, bans brute-forcers, scanners and request floods at the firewall the moment a rule fires, and shows you the exact log lines behind every decision. One agent per server, one console for the fleet.
Open source (AGPL-3.0) Free to run Made in France
Detection runs in memory and bans land in nftables the instant a threshold is crossed. The agent uses a fraction of one core even on a busy host, and a flood makes it more selective — never slower.
The scrapers and request floods that eat your CPU are the same addresses that probe your logins. Banning them gives the processor back to real visitors: faster sites, fewer incidents.
Each ban carries the lines that convicted it, and the console shows who is approaching a threshold before they cross it. You tune a rule on evidence, not on guesswork.
Live feed, world map, one search box for an address, a rule, a server or a network; ban, lift or exempt in one click; a public unblock page where a blocked visitor checks their address and asks to be let back in.
Choose which servers offer their bans to the others and which enforce what the fleet shares. An enrolled machine receives its rules and their updates — and keeps defending itself when the controller is unreachable.
Native reporting of offenders to AbuseIPDB, with an allow-list of what may leave: usernames and log lines never do. Our own base is next.
Everything the console does is one call an API token can make — from a script, a hosting panel, or the shield command on your desk.
Agent and controller are AGPL-3.0: read the source, build it, run it without paying anyone. The company, the servers and the data are in France.
Configuration is a handful of readable files, commands explain themselves, nothing is hidden. An AI coding agent — Claude Code, for one — operates and extends it with ease.
Keep all your servers' logs in one place. Publish your bans and your lists of bad addresses — with a tool to build them and submit them.
The free packs below can be read here and downloaded. Copy the files into /etc/shieldlist, validate with the agent, done.
A machine enrolled to a controller receives its rules and their updates from it — this is the only way a server gets rules, free or premium, without anyone copying files. Premium packs need an account.
SSH brute force, key-only hosts included — two rules, one ladder.
2 rules · 8 parsers PremiumWeb sites behind nginx or Apache: scanners, probes, crawlers, WordPress and shop floods.
26 rules · 1 of 26 free · 1 parsers PremiumShared hosting on Plesk: the panel, webmail, mail, database and FTP.
13 rules · 3 parsers
Shieldlist is built and operated by LRob SARL, a French web hosting company, out of what it takes to keep shared hosting servers clean. The engine is free software; the company sells the curated rules, the lists and the reporting. About →