Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: Configuration Language Lock 1.0.2 Minor update available for module config_language_lock (1.0.2). Release: Canvas Override 1.0.1 Minor update available for module canvas_override (1.0.1). Release: Media Remote Image 8.x-1.2 Minor update available for module media_entity_remote_image (8.x-1.2). Release: IDNA Convert Service (punycode) 2.0.4 Minor update available for module idna (2.0.4). Release: Bootstrap Cloud 7.1.3 Minor update available for theme bootstrap_cloud (7.1.3). Release: Token Browser 1.0.2 Minor update available for module token_browser (1.0.2). Release: Varbase Project 11.0.8 Minor update available for module varbase_project (11.0.8). Release: Media Remote Image 2.0.0-beta1 First beta version released for module media_entity_remote_image (2.0.0-beta1). Usage Milestone: Term CSV Export Import Module term_csv_export_import crossed 1,000 active installs. Security Coverage: Module Scout Module module_scout now has official Drupal security advisory coverage.

Suspect Blocker

6 sites No security coverage
View on drupal.org

The Suspect Blocker module helps protect your Drupal site from attacks like brute force or denial-of-service by monitoring for suspicious requests, such as those resulting in 403 or 404 errors. It can automatically ban IP addresses that exhibit excessive suspicious activity, with customizable thresholds and settings.

The Suspect Blocker module is a security tool for Drupal that detects and blocks suspicious behavior, such as brute force or flood attacks, by monitoring requests resulting in errors like 403 or 404.

Features

This module identifies bursts of rapid access attempts to multiple pages, monitors requests triggering status codes like 403 and 404, and automatically bans IPs that exceed a configurable threshold of suspicious activity. Use cases include mitigating brute force attacks, preventing flood attacks, and enabling customizable security rules.

  • Burst Detection: Tracks rapid access attempts ("bursts") to multiple pages within a time window.
  • IP Banning: Automatically bans IPs with high levels of suspicious activity.
  • Customizable Settings: Adjust thresholds and time windows for monitoring via the settings page.
  • Real-Time Logging: Logs suspicious attempts for analysis, including IP, path, and HTTP status.
  • Efficient Resource Usage: Uses in-memory logging for low performance impact.

Post-Installation

After installing the Suspect Blocker module, navigate to its configuration page at /admin/config/security/suspect-blocker. Customize settings such as the ban threshold (default: 5 suspicious requests) and the monitoring time window (default: 60 seconds). Once saved, the module starts monitoring your site for suspicious activity.

Additional Requirements

The Suspect Blocker module requires Drupal 10 or 11. For IP banning functionality, the Ban module is required.

Similar Modules

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
5
Tracked since
Dec 2024
Latest release
5 months ago
Releases (12 mo)
4 ▲ from 1
Maintenance
Active

Release Timeline

Releases

Version Type Core Release date
1.0.0-alpha3 Pre-release 10–11 Mar 13, 2026
1.0.0-alpha2 Pre-release 10–11 Mar 13, 2026
1.x-dev Dev 10 Mar 13, 2026
1.0.0-alpha1 Pre-release 10–11 Mar 13, 2026
1.0.x-dev Dev 10–11 Dec 19, 2024