Mail authentication is an attractive target
Email addresses often reveal the username format, and webmail or SMTP authentication must be reachable by legitimate users. That makes Exchange-related authentication surfaces attractive to password guessing and spraying.
Bad passwords can become a denial-of-service technique
If directory policy locks an account after a small number of failures, an attacker who knows valid usernames may intentionally trigger the threshold against many users. The attack does not need to authenticate successfully to cause disruption.
Use source-based response where evidence allows it
When Guard can associate repeated Exchange, SMTP or relevant web authentication failures with a source IP, per-monitor policy can block the source in the local firewall. This reduces reliance on manually blocking addresses after the directory account is already affected.
Different protocols need different policy
SMTP authentication, OWA-style web login and other Exchange paths do not necessarily have the same normal failure patterns. Guard therefore supports independent policy per monitor instead of requiring one universal threshold.
Practical depth: examples, failure modes and what to verify
Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.
Current Scantide detail
Current Scantide source: Brute Force Protection for Windows & Linux ServersA brute-force or password-guessing attack repeatedly attempts authentication, often across common usernames or passwords. Guard focuses on observable failed-authentication evidence and source behavior.
Current Scantide source: RdpGuard Alternative for Windows & Linux Server ProtectionNo. This page explains Scantide Guard capabilities for administrators evaluating the same category of server brute-force protection. Product capabilities and licensing should be checked with each vendor.
Current Scantide source: RdpGuard Alternative for Windows & Linux Server ProtectionScantide Guard does not need to attack, exploit or brute-force a service to decide that repeated hostile activity deserves action. Collectors observe evidence already generated by the server, normalize it into a common event model, then apply explicit thresholds, allowlists, exceptions and enforcement policy.
Current Scantide source: Brute Force Protection for Windows & Linux ServersNo. Guard does not perform brute-force testing. It observes authentication evidence generated by the protected server and responds according to policy.
Current Scantide source: Brute Force Protection for Windows & Linux ServersScantide Guard can use successful authentication evidence from supported built-in collectors and Custom Monitors to recognize trusted administration sources, reset or contextualize active failure history where appropriate, and reduce unnecessary blocking without weakening the deterministic protection model.
Field experience from the archive
Historical source · JufCorp: Securing your servers, users and customers onlineYou simply need this to get rid of the attacks where username/password is hammered onto you servers (brute force attacks/dictionary attacks) . (I've written an earlier entry on why firewalls, VPN, account lockout polices and so on aren't enough here :
Enforce an Account Lockout Policy and enforce complex password. Yes, people will hate you but they will hate you even more if someone actually succeeds in hacking your users data. Have a look at the link above about Account Lockout Policies though. Do not have local users more than necessary on the Exchange Server itself.
Brute force attacks Another method of rendering you server useless is to use a brute force attack on the usernames (sometimes also known as a "dictionary attack" ) .
Historical source · JufCorp: Automatisk skydd av Windows servrarAccount lockout is ineffective if the attacker is using a username/password combo list and guesses correctly on the first couple of attempts.
An attacker can continuously lock out the same account, even seconds after an administrator unlocks it, effectively disabling the account.
Historical source · JufCorp: Brute force protection on Windows ServerThere's a not that many tools to use natively in a Windows Server environment apart from Account Lockout Policies (which in some cases can do more harm than good to be honest). Imagine having 100 000 deliberately using all of your usernames but faulty passwords. This will simply render all of your user accounts locked out from your systems and nobody except Administrator is allowed to login (since that account can't be locked out)
Practical review checklist
- A brute-force or password-guessing attack repeatedly attempts authentication, often across common usernames or passwords.
- Scantide Guard does not need to attack, exploit or brute-force a service to decide that repeated hostile activity deserves action.
- Scantide Guard can use successful authentication evidence from supported built-in collectors and Custom Monitors to recognize trusted administration sources, reset or contextualize active failure history where appropriate, and reduce unnecessary blocking without weakening the deterministic protection model.
- You simply need this to get rid of the attacks where username/password is hammered onto you servers (brute force attacks/dictionary attacks) .
- Enforce an Account Lockout Policy and enforce complex password.
- Brute force attacks Another method of rendering you server useless is to use a brute force attack on the usernames (sometimes also known as a "dictionary attack" ) .
- Account lockout is ineffective if the attacker is using a username/password combo list and guesses correctly on the first couple of attempts.