Services fail differently
An administrator may mistype an RDP password once or twice. A mail client with a stale password may retry automatically for hours. An application might perform several backend authentication steps for one user action. Those patterns should not share one simplistic threshold.
Global defaults are useful starting points
A consistent default policy makes deployment manageable, especially across many servers. But defaults should be overridable where the application behavior is known to differ.
Per-monitor policy reduces false positives
Guard monitors can inherit global settings or override alert threshold, block threshold, observation window, block duration and related behavior. This lets a noisy but legitimate service remain protected without applying the same loosened rule to RDP or another high-confidence source.
Some patterns justify faster response, but only where the source event and input are trustworthy. Attacker-controlled web parameters should not automatically have the same authority as a Windows authentication event.
Practical depth: examples, failure modes and what to verify
Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.
Current Scantide detail
Current Scantide source: Custom Security Log Monitoring & Automatic IP BlockingYes. The design supports per-monitor overrides so applications with different authentication behavior do not have to share one global threshold.
Current Scantide source: Scantide Guard for Windows ServerEach monitor can inherit the global Guard policy or use its own alert threshold, block threshold, time window, block duration, immediate-block behavior and notification settings.
Current Scantide source: Brute Force Protection for Windows & Linux ServersYes. Guard supports monitor-specific policy concepts so an administrator can tune alert and block behavior to the application rather than forcing every service into one threshold.
Current Scantide source: Scantide Guard for LinuxA custom Linux monitor can inherit the normal Guard thresholds or use an explicit override for alerts, blocking, windows, durations and other monitor-specific behavior.
Current Scantide source: Scantide Guard for Windows ServerRDP, Kerberos, SQL Server, IIS/RDWeb, Exchange SMTP and other bundled collectors are best understood as preinstalled and preconfigured monitors . They give Guard useful coverage immediately, but the deeper capability is the same Guard event-and-policy model applied to your own applications.
Field experience from the archive
Historical source · JufCorp: Securing your server environment - Part III - Operating systemsHave a look at file permissions. NTFS and other file systems can give you a granular control of what is accessed and by whom. A lot of these permission are set a bit loosely by default to make it fairly easy for systems administrators to install applications etc and grant access to users. Usually they can be tightened to avoid users from starting applications or snooping around where they're not supposed to.
Make sure to keep track of your disk space. When you install your server , you're good to go but over time applications etc may fill your system drive. A way to try and minimize this is to install applications on other drives than the System drive. Sadly that's not foolproof since they may use %TEMP% or other hard coded paths pointing to for instance C:\ProgramData etc so you need to keep track of that before it's too late. Nobody wants to have a full System drive.
Historical source · JufCorp: Securing your servers, users and customers onlineUse an automatic brute force prevention software ( I can recommend you some that can block attacks on RDWeb, RDP, Exchange Webmail, FTP, Citrix., basically anything that uses Windows Authentication or help you set it up if you like)
Practical review checklist
- Each monitor can inherit the global Guard policy or use its own alert threshold, block threshold, time window, block duration, immediate-block behavior and notification settings.
- A custom Linux monitor can inherit the normal Guard thresholds or use an explicit override for alerts, blocking, windows, durations and other monitor-specific behavior.
- RDP, Kerberos, SQL Server, IIS/RDWeb, Exchange SMTP and other bundled collectors are best understood as preinstalled and preconfigured monitors .
- Printer Security: Printers store documents, have web interfaces, and can be entry points.
- Make sure to keep track of your disk space.
- Use an automatic brute force prevention software ( I can recommend you some that can block attacks on RDWeb, RDP, Exchange Webmail, FTP, Citrix., basically anything that uses Windows Authentication or help you set it up if you like)