Scantide Guard Guide

What to Do After Guard Blocks an Attack

A firewall block stops immediate traffic, but the event can also support incident review, abuse reporting, threat correlation and longer-term hardening.

Technical guideUpdated 25 September 2026Scantide Guard
Short answer: A firewall block stops immediate traffic, but the event can also support incident review, abuse reporting, threat correlation and longer-term hardening.

Preserve the evidence

Keep the source IP, timestamp, target server, monitor, username where available, trigger count, rule and block duration. If the event is part of a broader incident, preserve the relevant Windows, Linux or application logs before normal retention removes them.

Check whether it is isolated or part of a pattern

Look for the same source against other servers, repeated usernames, neighboring IP ranges, reputation history and recurrence after previous blocks. Datacenter is particularly useful here because one event can be compared across multiple managed servers.

Enrich before reporting

Reverse DNS, country, ASN/provider and abuse reputation can help identify the network responsible for the source address. Treat these as context, not proof of who operated the system.

Report abuse with useful facts

If you contact an ISP, hosting provider or organization, provide concise evidence: UTC timestamp, attacking source IP, target service, type of activity and relevant log lines. Avoid speculative accusations. A provider can act more effectively on a precise technical report than on a generic “your customer hacked us” message.

Review the control that was targeted

The useful question after the block is whether the service needed to be exposed at all, whether MFA or gateway restrictions are possible, whether the username pattern reveals unnecessary information, and whether the same class of attempt is reaching other systems.

Practical depth: examples, failure modes and what to verify

Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.

Current Scantide detail

Current Scantide source: Scantide Guard Product & Server Security Guides

Use Scantide Guard assessment reporting to review system health, security posture, software, CVEs, lifecycle, services, disks, firewall and other server evidence.

Current Scantide source: Web Attack & Scanner Protection for IIS, Apache and Nginx

A single Guard can protect its own server with local policy and local firewall enforcement. Organizations with multiple systems can add Scantide Guard Datacenter for shared policy, fleet visibility, licensing and coordinated reputation services.

Current Scantide source: Scantide Guard Product & Server Security Guides

Host-level intrusion and abuse prevention for Windows and Linux using authentication logs, web evidence, reputation context and local firewall response.

Current Scantide source: Scantide Guard for Windows Server

No. Guard uses the local Windows firewall as the enforcement layer and adds correlation, policy, evidence and automated block management.

Current Scantide source: Lightweight Server Intrusion Prevention for Windows & Linux

Scantide Guard is designed for administrators who want focused host-level attack response without deploying a large endpoint or SIEM stack simply to stop repeated login abuse and obvious hostile probes.

Field experience from the archive

Historical source · JufCorp: Security Reality Check: Why a Perfect Score Doesn't Mean You're Safe

Implementation: Configure these DNS servers in your router/firewall for network-wide protection, or set them on individual devices. Many services offer deployment guides for various platforms.

Historical source · JufCorp: Securing your servers, users and customers online

Minimize the attack surface behind a good firewall that can deal with the SYN Floods and port scans and stuff. Be cautious not to open up anything more than what's absolutely necessary to and from the outside world. Use local firewalls also!

Historical source · JufCorp: Protect your Windows servers from brute force attacks

Low cost, easy to configure, automatic brute force prevention for Windows servers. Includes global blacklist, reporting, support for Exchange OWA, SMTP AUTH , Terminal Server, RDWEB and more

Practical review checklist

Frequently asked questions

Should I report every blocked IP to an ISP?

Usually no. Reporting is most useful for persistent, targeted or clearly abusive activity where you have good evidence.

What should an abuse report contain?

Source IP, accurate timestamp, target/service, concise description and relevant log evidence.

Use the same principles with Scantide Guard

Scantide Guard combines preconfigured collectors, Custom Monitors, per-monitor policy, successful-login learning, explainable firewall enforcement and optional Datacenter management across Windows and Linux.

Explore Scantide Guard Custom Monitors Datacenter