Scantide Guard for Linux
Protect Linux servers with lightweight log-based detection, configurable thresholds and local nftables enforcement for SSH, web servers and application logs.
SSH failed-authentication monitoring
Supported as part of the Guard monitoring, policy or enforcement workflow.
Apache and Nginx access-log monitoring
Supported as part of the Guard monitoring, policy or enforcement workflow.
Tomcat and WildFly web evidence
Supported as part of the Guard monitoring, policy or enforcement workflow.
nftables firewall enforcement
Supported as part of the Guard monitoring, policy or enforcement workflow.
Temporary and permanent IP blocks
Supported as part of the Guard monitoring, policy or enforcement workflow.
Tor, country and reputation-assisted policy
Supported as part of the Guard monitoring, policy or enforcement workflow.
What this Guard workflow covers
- SSH failed-authentication monitoring
- Apache and Nginx access-log monitoring
- Tomcat and WildFly web evidence
- nftables firewall enforcement
- Temporary and permanent IP blocks
- Tor, country and reputation-assisted policy
- Custom application log monitors
- Central Datacenter enrollment when required
- Local standalone operation
Designed around observable server evidence
Scantide Guard does not need to attack, exploit or brute-force a service to decide that repeated hostile activity deserves action. Collectors observe evidence already generated by the server, normalize it into a common event model, then apply explicit thresholds, allowlists, exceptions and enforcement policy.
The result is intended to be understandable by an administrator: which source IP was seen, which collector reported it, which rule or threshold was reached, what action Guard took, and when a temporary block is due to expire.
Standalone when you need it. Centralized when you grow.
A single Guard can protect its own server with local policy and local firewall enforcement. Organizations with multiple systems can add Scantide Guard Datacenter for shared policy, fleet visibility, licensing and coordinated reputation services.
Frequently asked questions
Does Scantide Guard use nftables?
Yes. On supported Linux installations, Guard uses the local Linux firewall backend for enforcement rather than requiring a network appliance.
Can it protect SSH without Fail2ban?
Guard can monitor SSH authentication failures and enforce its own configured blocking policy. It can be used where administrators want Guard's shared management and evidence model.
Does Linux Guard require Datacenter?
No. It can run standalone or enroll into Guard Datacenter for centralized management.
See Scantide Guard in context
Read the current Guard documentation, deployment notes and product status, then choose the Windows, Linux or Datacenter path that fits your environment.