Scantide Guard Guide

Why Manual IP Blocking Does Not Scale

Manual firewall blocks can stop one source, but distributed and recurring authentication attacks require automation, provenance, expiry and policy.

Technical guideUpdated 25 September 2026Scantide Guard
Short answer: Manual firewall blocks can stop one source, but distributed and recurring authentication attacks require automation, provenance, expiry and policy.

One attacker is easy to block manually

If a single source is hammering one server, an administrator can add a firewall rule in seconds. That is useful during an emergency, but it does not become a scalable operating model.

Distributed attacks create administrative overload

Hundreds of sources, repeated attacks and multiple servers turn manual blocking into continuous work. Administrators also need to remember which rules were temporary, why they were created and when they should be removed.

Automation needs policy, not just scripts

A useful automated block includes the reason, source event, threshold, duration and unblock behavior. Guard turns observed events into policy-controlled firewall actions rather than simply adding permanent rules whenever a script sees a failure.

Expiration is part of the control

Temporary blocks should expire automatically. Permanent blocks should be deliberate and auditable. Otherwise the firewall becomes a historical dumping ground of addresses that may no longer represent the same systems.

Central visibility prevents hidden local state

Datacenter makes local Guard enforcement visible across the environment so administrators can understand which servers are blocking what and why.

Practical depth: examples, failure modes and what to verify

Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.

Current Scantide detail

Current Scantide source: Scantide Guard Product & Server Security Guides

Protect Windows Server from repeated RDP, IIS/RDWeb, Kerberos and SQL Server authentication attacks with deterministic monitoring and Windows Firewall blocking.

Current Scantide source: Windows & Linux Server Security Assessment

A single Guard can protect its own server with local policy and local firewall enforcement. Organizations with multiple systems can add Scantide Guard Datacenter for shared policy, fleet visibility, licensing and coordinated reputation services.

Current Scantide source: RdpGuard Alternative for Windows & Linux Server Protection

If you are evaluating tools to stop repeated RDP and server authentication attacks, Scantide Guard covers the RDP use case while extending the same operational model to Linux SSH, web servers, SQL Server, Exchange and custom application logs.

Current Scantide source: Scantide Guard for Windows Server

Scantide Guard is intended for Windows Server estates ranging from Windows Server 2008 R2 SP1 through current Windows Server releases. The product family includes Windows Server 2008 R2, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022 and Windows Server 2025. Server 2008 R2 uses the Legacy Guard implementation; later Windows Server versions use the modern Guard implementation.

Current Scantide source: Windows & Linux Server Security Assessment

Blocking attacks is only one part of server security. Guard assessment reporting brings operational posture, software inventory and vulnerability/lifecycle context into the same product family so administrators can see what needs attention beyond the current attacker.

Field experience from the archive

Historical source · JufCorp: Increased hacking and bruteforce attacks .. And it will get worse

Easy to use, cheap and it's helped protect against 185 000 live brute force attacks around the world so far. Since July 15th!

Historical source · JufCorp: Securing your servers, users and customers online

Brute force attacks Another method of rendering you server useless is to use a brute force attack on the usernames (sometimes also known as a "dictionary attack" ) .

DOS and DDOS Attacks A DDOS (Distributed Denial of Service) attack is kind of the same thing , the main difference being that its spread out over an extremely large number of computers around the world doing the same thing , making it very difficult to manually block each and every one of them in the firewall manually.

You simply need this to get rid of the attacks where username/password is hammered onto you servers (brute force attacks/dictionary attacks) . (I've written an earlier entry on why firewalls, VPN, account lockout polices and so on aren't enough here :

Historical source · JufCorp: Brute force protection on Windows Server

Brute force attacks are a constantly ongoing thing. Basically they're all automated and they (usually) try usernames such as administrator, root, backup etc .

Anyhoo.. just a short post on the matter of brute force prevention on Windows and what it can do for yu.

Practical review checklist

Frequently asked questions

Why not just script Windows Firewall rules?

You can, but you then need to build event parsing, thresholds, retention, expiry, provenance, reporting, trust and central management yourself.

Should blocks always be temporary?

Not always, but permanent blocks should be explicit and based on stronger evidence or policy than an ordinary transient failure burst.

Use the same principles with Scantide Guard

Scantide Guard combines preconfigured collectors, Custom Monitors, per-monitor policy, successful-login learning, explainable firewall enforcement and optional Datacenter management across Windows and Linux.

Explore Scantide Guard Custom Monitors Datacenter