Strong Guard candidates
Internet-reachable RDP/RDWeb, SSH, application login surfaces, Exchange/SMTP authentication, SQL authentication, web servers under scanner pressure and internal servers with meaningful authentication evidence are strong candidates.
Not every endpoint needs the same thing
A workstation with no inbound service exposure may gain little from host-based brute-force blocking. Security tooling should solve an observed risk rather than be installed simply because it exists.
Custom Monitors extend the useful scope
If an important application records source addresses and authentication outcomes in a usable Event Log or log file, a Custom Monitor can make Guard relevant even when the product has no dedicated built-in collector.
Monitor-only can be the right first step
Where normal application behavior is not yet understood, run the monitor without enforcement first. Build a baseline, verify parsing and source attribution, then enable blocking.
Practical depth: examples, failure modes and what to verify
Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.
Current Scantide detail
Current Scantide source: Scantide Guard for LinuxThe bundled SSH, Apache, Nginx, Tomcat, WildFly and related collectors are intended to give Linux Guard useful coverage immediately. Custom Monitors extend the same detection, alerting and blocking model to other applications that write meaningful authentication or security evidence to files or supported logs.
Current Scantide source: Custom Security Log Monitoring & Automatic IP BlockingYes. A custom monitor can classify successful authentication evidence so Guard can use it for trusted-host or safe-list learning rather than blocking.
Current Scantide source: Scantide Guard for Windows ServerScantide Guard can use successful authentication evidence from supported built-in collectors and Custom Monitors to recognize trusted administration sources, reset or contextualize active failure history where appropriate, and reduce unnecessary blocking without weakening the deterministic protection model.
Current Scantide source: Scantide Guard for Windows ServerGuard does more than count failures. Supported built-in collectors and Custom Monitors can also classify successful authentication . That lets Guard learn which source addresses are repeatedly associated with legitimate administration and use that evidence to reduce unnecessary blocking.
Current Scantide source: Scantide Guard Product & Server Security GuidesExtend Guard beyond its preinstalled collectors. Turn Windows Event channels and application log files into Guard security evidence with custom parsers, failed/successful authentication classification, per-monitor policies and Datacenter-managed distribution.
Field experience from the archive
Historical source · JufCorp: Using HTTP redirects for mitigating vulnerability scans and bruteforce attacksThis would imitate brute force protection such as Fail2Ban on SSH etc The sky's the limit, right? I'm sure one could do a lot of fun things if one's up for it but , as stated earlier, I'm lazy :-)
I started thinking about how it actually works. If a vulnerability scan is performed (if you have the WAF, Wordfence Application Firewall, enabled that is) or a brute force attempt is made against your /wp-login-page, there are rules that determine things such as "how many invalid login attempts during how long". Based on those rules, the IP address is presented with a 503 error or 403 error. The client isn't allowed to access for instance the /wp-admin page for a specified period of time. All of this works fine from out of the box with Wordfence so they've done the hard work i.e writing the engine to detect the stuff. And while at it , you might also want to have a look at using Wordfence for blocking XMLRPC traffic ( here's an article about why you should btw) It's simply done by adding the line /xmlrcp.php into the blocking part of Wordfence)
Historical source · JufCorp: Securing your servers, users and customers onlineJust remember , the same thing goes for antivirus as for 0day attacks, if you antivirus provider hasn't released any protection against that virus you just got into your system , there's not that much you can do about it, more than start cleaning your server once you the antivirus updated or even restore your server to a state prior to the virus. These days there are also a few other approaches to finding viruses such as Sentinel One that's not signature based.. Very cool actually. Still, an antivirus is not the single point of protection.
Brute force attacks Another method of rendering you server useless is to use a brute force attack on the usernames (sometimes also known as a "dictionary attack" ) .
Historical source · JufCorp: Securing Windows Server with a baseline security15. You need to have an automatic intrusion protection against brute force and dictionary attacks with Syspeace since the “classic” methods do not get the job done. Here’s an older blog post on why . I you don’t have the time to read the article then simply download the free Syspeace trial or contact me for licenses and consulting regarding Brute force prevention
Practical review checklist
- The bundled SSH, Apache, Nginx, Tomcat, WildFly and related collectors are intended to give Linux Guard useful coverage immediately.
- Scantide Guard can use successful authentication evidence from supported built-in collectors and Custom Monitors to recognize trusted administration sources, reset or contextualize active failure history where appropriate, and reduce unnecessary blocking without weakening the deterministic protection model.
- This would imitate brute force protection such as Fail2Ban on SSH etc The sky's the limit, right?
- Brute force attacks Another method of rendering you server useless is to use a brute force attack on the usernames (sometimes also known as a "dictionary attack" ) .
- Implementation: Configure these DNS servers in your router/firewall for network-wide protection, or set them on individual devices.