Automatic failed-login correlation

Brute Force Protection for Windows and Linux Servers

Repeated password guessing should not be allowed to hammer a server indefinitely. Scantide Guard correlates authentication failures, applies thresholds and allowlists, and can block the attacking source at the local firewall.

Threshold and time-window based blocking

Supported as part of the Guard monitoring, policy or enforcement workflow.

Per-monitor rule overrides

Supported as part of the Guard monitoring, policy or enforcement workflow.

Temporary or permanent block policy

Supported as part of the Guard monitoring, policy or enforcement workflow.

Allowlist and trusted-host controls

Supported as part of the Guard monitoring, policy or enforcement workflow.

Windows and Linux support

Supported as part of the Guard monitoring, policy or enforcement workflow.

Authentication-source aware evidence

Supported as part of the Guard monitoring, policy or enforcement workflow.

Capabilities

What this Guard workflow covers

Designed around observable server evidence

Scantide Guard does not need to attack, exploit or brute-force a service to decide that repeated hostile activity deserves action. Collectors observe evidence already generated by the server, normalize it into a common event model, then apply explicit thresholds, allowlists, exceptions and enforcement policy.

The result is intended to be understandable by an administrator: which source IP was seen, which collector reported it, which rule or threshold was reached, what action Guard took, and when a temporary block is due to expire.

Standalone when you need it. Centralized when you grow.

A single Guard can protect its own server with local policy and local firewall enforcement. Organizations with multiple systems can add Scantide Guard Datacenter for shared policy, fleet visibility, licensing and coordinated reputation services.

Frequently asked questions

What is a brute-force attack?

A brute-force or password-guessing attack repeatedly attempts authentication, often across common usernames or passwords. Guard focuses on observable failed-authentication evidence and source behavior.

Does Guard try passwords itself?

No. Guard does not perform brute-force testing. It observes authentication evidence generated by the protected server and responds according to policy.

Can different applications use different thresholds?

Yes. Guard supports monitor-specific policy concepts so an administrator can tune alert and block behavior to the application rather than forcing every service into one threshold.

See Scantide Guard in context

Read the current Guard documentation, deployment notes and product status, then choose the Windows, Linux or Datacenter path that fits your environment.