A failure without a source is incomplete evidence
Event ID 4625 is useful, but automatic blocking needs more than “authentication failed.” If the relevant connection path does not provide a reliable client address, a protection engine must not invent one or block an intermediary blindly.
Authentication paths change the log evidence
RDP, RemoteApp, RDWeb, gateways, TLS termination and web front ends can change which component records the failure and which address appears. This is why Guard collectors are application-aware rather than a single generic parser for every 4625 event.
Trusted forwarding requires explicit trust
For web-facing applications behind a reverse proxy or load balancer, forwarded client-address headers are useful only when the intermediary is explicitly trusted. An attacker-controlled header is not equivalent to an observed network source.
Test the real path
After changing authentication settings, certificates, gateways or proxy behavior, generate controlled failures and verify the source IP in the actual deployment. Documentation for a different topology is not proof that your path records the same evidence.
Practical depth: examples, failure modes and what to verify
Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.
Current Scantide detail
Current Scantide source: RDP Brute Force Protection for Windows ServerWindows Security Event ID 4625 is a common failed-logon source. Guard also supports other trusted authentication evidence depending on the configured collector.
Current Scantide source: Scantide Guard for Windows ServerScantide Guard is intended for Windows Server estates ranging from Windows Server 2008 R2 SP1 through current Windows Server releases. The product family includes Windows Server 2008 R2, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022 and Windows Server 2025. Server 2008 R2 uses the Legacy Guard implementation; later Windows Server versions use the modern Guard implementation.
Current Scantide source: Scantide Guard Product & Server Security GuidesProtect Windows Server from repeated RDP, IIS/RDWeb, Kerberos and SQL Server authentication attacks with deterministic monitoring and Windows Firewall blocking.
Current Scantide source: Scantide Guard Product & Server Security GuidesSee the current Windows Server, Windows client, Legacy Windows and Linux compatibility overview, including which platforms are tested, targeted or still awaiting explicit validation.
Current Scantide source: Scantide Guard Product & Server Security GuidesWhen a trusted authentication source reports a successful login, Guard can use that evidence to learn or reinforce the source as a known administrative origin instead of treating every future failure from that address as hostile.
Field experience from the archive
Historical source · JufCorp: Securing your servers, users and customers onlineUse an automatic brute force prevention software ( I can recommend you some that can block attacks on RDWeb, RDP, Exchange Webmail, FTP, Citrix., basically anything that uses Windows Authentication or help you set it up if you like)
It's absolutely no guarantee even if you do use a valid certificate since also the "Trusted Authorities" can be hacked and therefore all of their certificates can be compromised (yes, it's already happened a few time in the past year, GoDaddy, Verisign and even Microsoft themselves realized they had a bug in how Windows Update actually validates that it is connecting to the Windows Update site and nowhere else.)
Historical source · JufCorp: Closing in on 1 Million blocked brute force and dictionary attacks on Windows Servers world wideOther news regarding Syspeace is that we're beta testing the new release now that will support Windows Server 2012, SQL Server and also have a completely new reporting, sorting and exporting feature called Access Reports. The new Access Reports feature lets you create reports on failed and succesful logins on your Windows Servers and export them to .CSV reports. The information is saved in the local database so even if the Windows Security Log is cleared, the information is still available for use in for instance forensics and other tasks.
Historical source · JufCorp: Brute force protection on Windows ServerAnyhoo.. just a short post on the matter of brute force prevention on Windows and what it can do for yu.
Now, there are other ways of taking care of this problem and one is to use a brute force prevention software (which I do )
Practical review checklist
- Windows Security Event ID 4625 is a common failed-logon source.
- Scantide Guard is intended for Windows Server estates ranging from Windows Server 2008 R2 SP1 through current Windows Server releases.
- Protect Windows Server from repeated RDP, IIS/RDWeb, Kerberos and SQL Server authentication attacks with deterministic monitoring and Windows Firewall blocking.
- See the current Windows Server, Windows client, Legacy Windows and Linux compatibility overview, including which platforms are tested, targeted or still awaiting explicit validation.
- When a trusted authentication source reports a successful login, Guard can use that evidence to learn or reinforce the source as a known administrative origin instead of treating every future failure from that address as hostile.
- Use an automatic brute force prevention software ( I can recommend you some that can block attacks on RDWeb, RDP, Exchange Webmail, FTP, Citrix., basically anything that uses Windows Authentication or help you set it up if you like)
- Other news regarding Syspeace is that we're beta testing the new release now that will support Windows Server 2012, SQL Server and also have a completely new reporting, sorting and exporting feature called Access Reports.