Bring your own authentication evidence

Custom Security Log Monitoring

Not every application deserves a hard-coded collector. Guard Custom Monitors let administrators teach Guard how a trusted event channel or log file represents authentication failures, successful logins and source IP evidence.

Windows Event channel monitors

Supported as part of the Guard monitoring, policy or enforcement workflow.

Single log file or rolling-directory patterns

Supported as part of the Guard monitoring, policy or enforcement workflow.

Recognition and IP extraction expressions

Supported as part of the Guard monitoring, policy or enforcement workflow.

Username extraction where available

Supported as part of the Guard monitoring, policy or enforcement workflow.

Failed and successful authentication classification

Supported as part of the Guard monitoring, policy or enforcement workflow.

Successful-login evidence for trusted-host learning

Supported as part of the Guard monitoring, policy or enforcement workflow.

Capabilities

What this Guard workflow covers

Designed around observable server evidence

Scantide Guard does not need to attack, exploit or brute-force a service to decide that repeated hostile activity deserves action. Collectors observe evidence already generated by the server, normalize it into a common event model, then apply explicit thresholds, allowlists, exceptions and enforcement policy.

The result is intended to be understandable by an administrator: which source IP was seen, which collector reported it, which rule or threshold was reached, what action Guard took, and when a temporary block is due to expire.

Standalone when you need it. Centralized when you grow.

A single Guard can protect its own server with local policy and local firewall enforcement. Organizations with multiple systems can add Scantide Guard Datacenter for shared policy, fleet visibility, licensing and coordinated reputation services.

Frequently asked questions

Can Guard watch rotating logs?

Yes. Custom monitors can target a directory and filename pattern, with optional recursive handling where appropriate.

Can successful logins be used?

Yes. A custom monitor can classify successful authentication evidence so Guard can use it for trusted-host or safe-list learning rather than blocking.

Can each application have different thresholds?

Yes. The design supports per-monitor overrides so applications with different authentication behavior do not have to share one global threshold.

See Scantide Guard in context

Read the current Guard documentation, deployment notes and product status, then choose the Windows, Linux or Datacenter path that fits your environment.