Brute Force Protection for Windows and Linux Servers
Repeated password guessing should not be allowed to hammer a server indefinitely. Scantide Guard correlates authentication failures, applies thresholds and allowlists, and can block the attacking source at the local firewall.
Threshold and time-window based blocking
Supported as part of the Guard monitoring, policy or enforcement workflow.
Per-monitor rule overrides
Supported as part of the Guard monitoring, policy or enforcement workflow.
Temporary or permanent block policy
Supported as part of the Guard monitoring, policy or enforcement workflow.
Allowlist and trusted-host controls
Supported as part of the Guard monitoring, policy or enforcement workflow.
Windows and Linux support
Supported as part of the Guard monitoring, policy or enforcement workflow.
Authentication-source aware evidence
Supported as part of the Guard monitoring, policy or enforcement workflow.
What this Guard workflow covers
- Threshold and time-window based blocking
- Per-monitor rule overrides
- Temporary or permanent block policy
- Allowlist and trusted-host controls
- Windows and Linux support
- Authentication-source aware evidence
- Optional centralized policy via Datacenter
- Clear block reason and event history
- Reputation enrichment without depending on it for every decision
Designed around observable server evidence
Scantide Guard does not need to attack, exploit or brute-force a service to decide that repeated hostile activity deserves action. Collectors observe evidence already generated by the server, normalize it into a common event model, then apply explicit thresholds, allowlists, exceptions and enforcement policy.
The result is intended to be understandable by an administrator: which source IP was seen, which collector reported it, which rule or threshold was reached, what action Guard took, and when a temporary block is due to expire.
Standalone when you need it. Centralized when you grow.
A single Guard can protect its own server with local policy and local firewall enforcement. Organizations with multiple systems can add Scantide Guard Datacenter for shared policy, fleet visibility, licensing and coordinated reputation services.
Frequently asked questions
What is a brute-force attack?
A brute-force or password-guessing attack repeatedly attempts authentication, often across common usernames or passwords. Guard focuses on observable failed-authentication evidence and source behavior.
Does Guard try passwords itself?
No. Guard does not perform brute-force testing. It observes authentication evidence generated by the protected server and responds according to policy.
Can different applications use different thresholds?
Yes. Guard supports monitor-specific policy concepts so an administrator can tune alert and block behavior to the application rather than forcing every service into one threshold.
See Scantide Guard in context
Read the current Guard documentation, deployment notes and product status, then choose the Windows, Linux or Datacenter path that fits your environment.