Scantide Guard Guide

Slow Brute-Force Attacks: Why Short Trigger Windows Are Not Enough

Low-and-slow attacks deliberately stay below burst thresholds. Longer observation windows, repeat-offender handling and reputation context help reveal persistent sources.

Technical guideUpdated 25 September 2026Scantide Guard
Short answer: Low-and-slow attacks deliberately stay below burst thresholds. Longer observation windows, repeat-offender handling and reputation context help reveal persistent sources.

Short windows detect bursts

A five-minute trigger window is useful for noisy sources. It is intentionally less effective when attempts are spread over hours or days.

Longer windows detect persistence

Guard policies can use longer observation periods where the application's normal behavior allows it. The goal is to catch sources that deliberately wait between attempts to remain below short thresholds.

Repeat offenders deserve different treatment

A source that returns repeatedly after temporary blocks is not equivalent to a user mistyping a password once. Repeat-offender policy can escalate the response when the same origin keeps reappearing.

Distributed campaigns need more context

Password spraying may spread attempts across many IPs or across many usernames. Reputation context and Datacenter-wide visibility can reveal patterns that are not obvious on one host.

Practical depth: examples, failure modes and what to verify

Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.

Current Scantide detail

Current Scantide source: Scantide Guard for Windows Server

Scantide Guard is intended for Windows Server estates ranging from Windows Server 2008 R2 SP1 through current Windows Server releases. The product family includes Windows Server 2008 R2, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022 and Windows Server 2025. Server 2008 R2 uses the Legacy Guard implementation; later Windows Server versions use the modern Guard implementation.

Current Scantide source: Scantide Guard for Windows Server

Combined with Datacenter, successful-login intelligence can help reduce friction for known management sources while keeping attack blocking and repeat-offender handling active across the fleet.

Current Scantide source: Scantide Guard Product & Server Security Guides

Protect Windows Server from repeated RDP, IIS/RDWeb, Kerberos and SQL Server authentication attacks with deterministic monitoring and Windows Firewall blocking.

Current Scantide source: Scantide Guard Supported Operating Systems

Windows Server coverage: Windows Server 2008 R2 SP1, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022 and Windows Server 2025. The unified Windows installer automatically selects Legacy Guard on Server 2008 R2 SP1 and uses the modern Guard implementation on later Windows Server versions.

Current Scantide source: Scantide Guard Datacenter

Scantide Guard Datacenter is not limited to modern Windows Server releases. It can also run on Windows Server 2008 R2 SP1, as well as later Windows Server generations including 2012 R2, 2016, 2019, 2022 and 2025. The same unified Windows installer is used; there is no separate Windows Datacenter installer.

Field experience from the archive

Historical source · JufCorp: Brute force protection on Windows Server

Anyhoo.. just a short post on the matter of brute force prevention on Windows and what it can do for yu.

Brute force attacks are a constantly ongoing thing. Basically they're all automated and they (usually) try usernames such as administrator, root, backup etc .

Historical source · JufCorp: Securing your servers, users and customers online

Brute force attacks Another method of rendering you server useless is to use a brute force attack on the usernames (sometimes also known as a "dictionary attack" ) .

Use an automatic brute force prevention software ( I can recommend you some that can block attacks on RDWeb, RDP, Exchange Webmail, FTP, Citrix., basically anything that uses Windows Authentication or help you set it up if you like)

You simply need this to get rid of the attacks where username/password is hammered onto you servers (brute force attacks/dictionary attacks) . (I've written an earlier entry on why firewalls, VPN, account lockout polices and so on aren't enough here :

Historical source · JufCorp: Protect your Windows servers from brute force attacks

Low cost, easy to configure, automatic brute force prevention for Windows servers. Includes global blacklist, reporting, support for Exchange OWA, SMTP AUTH , Terminal Server, RDWEB and more

Practical review checklist

Frequently asked questions

What is a low-and-slow brute-force attack?

It is a password-guessing strategy that deliberately spaces attempts out to avoid short detection windows.

Should I just make every trigger window very long?

No. Windows should match the service and normal behavior. Very long windows without context can increase false positives.

Use the same principles with Scantide Guard

Scantide Guard combines preconfigured collectors, Custom Monitors, per-monitor policy, successful-login learning, explainable firewall enforcement and optional Datacenter management across Windows and Linux.

Explore Scantide Guard Custom Monitors Datacenter