Linux SSH and web attack protection

Scantide Guard for Linux

Protect Linux servers with lightweight log-based detection, configurable thresholds and local nftables enforcement for SSH, web servers and application logs.

SSH failed-authentication monitoring

Supported as part of the Guard monitoring, policy or enforcement workflow.

Apache and Nginx access-log monitoring

Supported as part of the Guard monitoring, policy or enforcement workflow.

Tomcat and WildFly web evidence

Supported as part of the Guard monitoring, policy or enforcement workflow.

nftables firewall enforcement

Supported as part of the Guard monitoring, policy or enforcement workflow.

Temporary and permanent IP blocks

Supported as part of the Guard monitoring, policy or enforcement workflow.

Tor, country and reputation-assisted policy

Supported as part of the Guard monitoring, policy or enforcement workflow.

Capabilities

What this Guard workflow covers

Designed around observable server evidence

Scantide Guard does not need to attack, exploit or brute-force a service to decide that repeated hostile activity deserves action. Collectors observe evidence already generated by the server, normalize it into a common event model, then apply explicit thresholds, allowlists, exceptions and enforcement policy.

The result is intended to be understandable by an administrator: which source IP was seen, which collector reported it, which rule or threshold was reached, what action Guard took, and when a temporary block is due to expire.

Standalone when you need it. Centralized when you grow.

A single Guard can protect its own server with local policy and local firewall enforcement. Organizations with multiple systems can add Scantide Guard Datacenter for shared policy, fleet visibility, licensing and coordinated reputation services.

Frequently asked questions

Does Scantide Guard use nftables?

Yes. On supported Linux installations, Guard uses the local Linux firewall backend for enforcement rather than requiring a network appliance.

Can it protect SSH without Fail2ban?

Guard can monitor SSH authentication failures and enforce its own configured blocking policy. It can be used where administrators want Guard's shared management and evidence model.

Does Linux Guard require Datacenter?

No. It can run standalone or enroll into Guard Datacenter for centralized management.

See Scantide Guard in context

Read the current Guard documentation, deployment notes and product status, then choose the Windows, Linux or Datacenter path that fits your environment.