Scantide Guard Guide

Background Internet Noise vs a Targeted Authentication Attack

Not every failed login means someone selected your organization specifically. Usernames, timing, recurrence and cross-server patterns help distinguish generic scanning from more targeted behavior.

Technical guideUpdated 25 September 2026Scantide Guard
Short answer: Not every failed login means someone selected your organization specifically. Usernames, timing, recurrence and cross-server patterns help distinguish generic scanning from more targeted behavior.

Most exposed services attract generic noise

Internet-facing RDP, SSH and web authentication endpoints are continuously discovered by automated scanners. Many attacks cycle through generic usernames and password lists without knowing anything about the organization.

Targeted usernames change the picture

When attempts use a real employee name, a distinctive service account or a username convention specific to the organization, the activity deserves more attention. That does not prove a sophisticated targeted campaign, but it indicates the attacker has more context than a generic scanner.

Look at persistence and distribution

A source that returns over days, multiple geographic origins trying the same username, or the same account being attacked across several servers can indicate a more deliberate campaign.

Use Datacenter to compare servers

One Guard server sees its own evidence. Datacenter can make it easier to see whether the same source, username or pattern appears across the estate.

Respond proportionally

Generic noise may justify normal automated blocking. Targeted patterns may justify password reset review, MFA verification, account exposure review and wider incident investigation.

Practical depth: examples, failure modes and what to verify

Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.

Current Scantide detail

Current Scantide source: Brute Force Protection for Windows & Linux Servers

A brute-force or password-guessing attack repeatedly attempts authentication, often across common usernames or passwords. Guard focuses on observable failed-authentication evidence and source behavior.

Current Scantide source: Scantide Guard Datacenter

See the current Windows Server, Windows client, Legacy Windows and Linux compatibility overview, including which platforms are tested, targeted or still awaiting explicit validation.

Current Scantide source: RDP Brute Force Protection for Windows Server

A successful login can reset or contextualize the active failure counter for the same source where the monitor supports it, helping distinguish mistyped credentials from a sustained brute-force attack.

Current Scantide source: Scantide Guard for Windows Server

Scantide Guard is intended for Windows Server estates ranging from Windows Server 2008 R2 SP1 through current Windows Server releases. The product family includes Windows Server 2008 R2, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022 and Windows Server 2025. Server 2008 R2 uses the Legacy Guard implementation; later Windows Server versions use the modern Guard implementation.

Current Scantide source: Scantide Guard Datacenter

Datacenter adds centralized fleet visibility, policy distribution, shared services and coordinated administration. Individual Guard servers still perform local monitoring and enforcement.

Field experience from the archive

Historical source · JufCorp: Brute force protection on Windows Server

Brute force attacks are a constantly ongoing thing. Basically they're all automated and they (usually) try usernames such as administrator, root, backup etc .

The second interesting fact is that someone is clearly targeting me since they do use my username when trying to get in. This tells me that I am being targeted somehow. I do know my emailddress is here and there online so finding out metadata about me isn't very hard and I've also written a few ... tips .. on how to think when it comes to guessing usernames

Anyhoo.. just a short post on the matter of brute force prevention on Windows and what it can do for yu.

Historical source · JufCorp: Securing your servers, users and customers online

Brute force attacks Another method of rendering you server useless is to use a brute force attack on the usernames (sometimes also known as a "dictionary attack" ) .

This means that the OWA interface is reachable for the entire world to try and login into and thus leaving you open for DOS, DDOS, brute force attacks and so on .

Use an automatic brute force prevention software ( I can recommend you some that can block attacks on RDWeb, RDP, Exchange Webmail, FTP, Citrix., basically anything that uses Windows Authentication or help you set it up if you like)

Practical review checklist

Frequently asked questions

Does a real username prove a targeted attack?

No, but it is stronger context than a generic username list and should be reviewed.

Can distributed attacks look less obvious locally?

Yes. Cross-server and longer-term context can reveal patterns that one host may not show clearly.

Use the same principles with Scantide Guard

Scantide Guard combines preconfigured collectors, Custom Monitors, per-monitor policy, successful-login learning, explainable firewall enforcement and optional Datacenter management across Windows and Linux.

Explore Scantide Guard Custom Monitors Datacenter