Scantide Guard Guide

Shared Reputation: From Local Attack Evidence to Preemptive Protection

Local attack evidence becomes more valuable when it can warn other servers, but shared reputation needs provenance, controlled publishing, caching and false-positive safeguards.

Technical guideUpdated 25 September 2026Scantide Guard
Short answer: Local attack evidence becomes more valuable when it can warn other servers, but shared reputation needs provenance, controlled publishing, caching and false-positive safeguards.

Local evidence comes first

A reputation entry should have provenance: which server saw the activity, which collector produced the evidence, when it occurred and why policy decided it was significant. Shared intelligence without origin context becomes difficult to trust.

Do not publish every temporary block

NAT, shared hosting, proxies and compromised legitimate systems make IP reputation imperfect. Guard distinguishes local enforcement from deliberately published permanent/public reputation observations.

Managed environments need one publisher

When a Guard server is enrolled in Datacenter, Datacenter is the natural central publisher. This prevents every managed server from independently reporting the same event and preserves a cleaner audit trail.

Cache external intelligence

Reputation lookup should not turn every authentication event into an external API call. Guard can cache locally, while Datacenter can provide shared caching/proxy behavior for managed servers.

Reputation is context, not proof

An address appearing in AbuseIPDB, Scantide Global Reputation or another provider is useful evidence. It should not erase local policy, trusted sources or administrator review.

Practical depth: examples, failure modes and what to verify

Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.

Current Scantide detail

Current Scantide source: Web Attack & Scanner Protection for IIS, Apache and Nginx

A single Guard can protect its own server with local policy and local firewall enforcement. Organizations with multiple systems can add Scantide Guard Datacenter for shared policy, fleet visibility, licensing and coordinated reputation services.

Current Scantide source: Scantide Guard Product & Server Security Guides

Host-level intrusion and abuse prevention for Windows and Linux using authentication logs, web evidence, reputation context and local firewall response.

Current Scantide source: Scantide Guard Datacenter

Manage multiple Guard servers from one control point: distribute policy, see attack activity across the fleet, coordinate shared blocking and reputation, and understand which systems are protected.

Current Scantide source: Scantide Guard Product & Server Security Guides

Linux server brute-force and hostile web request protection for SSH, Apache, Nginx, Tomcat and WildFly using local evidence and nftables enforcement.

Current Scantide source: Web Attack & Scanner Protection for IIS, Apache and Nginx

Guard is focused on log/evidence-driven host protection and controlled firewall response. It is not positioned as a full reverse-proxy WAF replacement.

Field experience from the archive

Historical source · JufCorp: Securing your server environment - Part III - Operating systems

In many environments, local firewalls are disabled out of pure laziness. "We can't be bothered troubleshooting why SQL traffic doesn't work .." Have local firewalls enabled , enable logging so you can easily find what's going on. If you're in a shared environment you'll also get alerted about noisy neighbors . Local firewalls also enables you to utilize a brute force prevention software and have those attacks mitigated, no matter where they come from. If you want, I'll happily help you out with getting a brute force prevention software in place.

Historical source · JufCorp: Securing your servers, users and customers online

Minimize the attack surface behind a good firewall that can deal with the SYN Floods and port scans and stuff. Be cautious not to open up anything more than what's absolutely necessary to and from the outside world. Use local firewalls also!

Historical source · JufCorp: Security Reality Check: Why a Perfect Score Doesn't Mean You're Safe

Implementation: Configure these DNS servers in your router/firewall for network-wide protection, or set them on individual devices. Many services offer deployment guides for various platforms.

Practical review checklist

Frequently asked questions

Does reputation alone justify permanent blocking?

Not necessarily. Reputation should be considered alongside local evidence and policy.

Why should Datacenter publish on behalf of managed Guards?

It avoids duplicate reporting and provides central provenance and control.

Use the same principles with Scantide Guard

Scantide Guard combines preconfigured collectors, Custom Monitors, per-monitor policy, successful-login learning, explainable firewall enforcement and optional Datacenter management across Windows and Linux.

Explore Scantide Guard Custom Monitors Datacenter