ACTIVE BLOCKS0Linux firewall rules managed by GuardOBSERVATIONS0Normalized security evidence retained locallyLIVE COLLECTORS0Enabled evidence sourcesENGINEACTIVECorrelation and response policy
RECENT ACTIVITY
Security timeline
DEVELOPMENT
Simulation collector
EVIDENCE
Security events
Time
Source
Country
Collector
Protocol
User
Decision
Enforcement
Score
Reason
RESPONSE
Blocks
IP
Country
Created
Expires
Collector
Reason
Status
TRUST
Learned safe list
Candidates are learned from successful authentication. Trusted entries are exempt from Guard blocking while fresh, and may be shared through Datacenter policy.
IP
State
Successes
Distinct days
Protocols
Users
First seen
Last seen
CUSTOM MONITORS
Create your own Guard monitor
LOG FILE
Point Guard at a text log file or rolling log directory, paste an example of the evidence, and define how to recognize it. A matching source IP is normalized into the ordinary Guard correlation and blocking pipeline.
Name
Source
Location
Category
Protocol
State
New custom monitorCreate a separate monitor. Existing monitors are not changed.
LOG SOURCE
Single file or rolling log directory
File
Modified
Size
SAMPLE
Evidence to analyze
PASTED / SELECTED
EXTRACTION
Recognition and fields
Use Analyze & test sample for the easiest setup: Guard proposes the matching phrase, source IP, username and authentication type, then validates it immediately. Successful authentication can contribute to trusted-host statistics. Rolling-folder monitors continuously discover new matching filenames. Regexes may use named groups ?<ip> and ?<user>.
ASSESSMENTS
Server health and security posture
CHECKING
One unified Linux assessment covers CPU, memory, filesystems, enabled services, network, firewall, listening ports, shares, certificates and software/package intelligence where supported. Windows-only checks are identified explicitly.
Started
Assessment
Status
Checks
Report
SCHEDULE
Assessment delivery
Catch window and immediate username blocking
Count related security events from an address within this period. Maximum: 30 days. A longer period detects slower attempts but retains more history in memory; counters restart with the service.
Exact, case-insensitive matches only. Use DOMAIN\\name when that is what the collector reports. Only trusted authentication failures can trigger this rule; successful logins and arbitrary web parameters never do. Trusted/private-address protections and the automatic-blocking switch still apply. Fleet propagation is optional and requires Datacenter. Leave the username list blank to disable.
LOCAL POLICY
Response settings
Use the catch-window controls below; managed servers receive their thresholds from Datacenter.
Local allow-list and block-list
Manage local trusted addresses and manual blocks in Local lists. Datacenter-managed entries are labelled separately.
ESCALATION
Repeat offenders
Only separate automatic block episodes count. Attempts made while an address is already blocked do not add occurrences. A permanent block has no expiry and remains until manually released or allow-listed.
SHARED RESPONSE
Datacenter shared blacklist
Only public IP addresses are propagated. Shared blocks are permanent desired state; removing an address from the shared list releases only blocks that were created from that shared policy, never an independent local permanent block.
TRUST LEARNING
Automatic safe list
Successful Windows/RDP and SSH authentications become candidates first. Once the configured confidence threshold is reached, the source is trusted and exempt from normal blocking and future panic-room/global blocking. Static whitelist entries still have highest priority.
SCANTIDE API
Scantide account
NOT CONFIGURED
Adds Scantide vulnerability/lifecycle intelligence and central enrichment to assessments. This account is separate from the Guard license.
Source: checking…
SERVICENOW / CMDB
LAN discovery → CMDB awareness
NOT CONFIGURED
Adds CMDB context to LAN scans by matching each discovered IP against ServiceNow. Guard is read-only against ServiceNow in this release.
Source: checking…
NETWORK LOCATION
Country and Tor blocking
The local allowlist always wins. Country decisions remain event-driven and fail open when lookup is unavailable. Tor blocking is independent of AbuseIPDB and preemptive: the complete Tor exit list is synchronized into dedicated nftables sets and input-chain rules.
COLLECTORS
Authentication and application collectors
Collectors can be enabled locally or by a Datacenter server policy. Unsupported collectors remain harmless on platforms where their source is unavailable. CrushFTP auto-discovers common installations and can also follow explicit local log roots.
WEB PROTECTION
Apache, Nginx, Tomcat, WildFly and HAProxy
Effective profile contents — inspect exactly what this profile will detect and block
Standard immediately blocks high-confidence secret, credential, traversal and web-shell probes while ordinary reconnaissance contributes to the normal Guard threshold. Monitor only records these requests without single-request immediate blocking.
Guard auto-discovers local web access logs, including HAProxy configuration and common rsyslog/journald sources. HAProxy frontends/backends are preserved in events, and forwarded client headers are trusted only from explicitly configured upstream IP/CIDR entries. Dangerous path matches enter the normal Guard policy immediately. Generic scanner activity is detected when the same source produces many 4xx responses across many distinct paths in a short window.
STARTUP & ENRICHMENT
Event processing
Scantide API credentials: checking source…
Startup history is evaluated only when Guard starts. Saving a change requires restarting Guard. Imported events can trigger normal policy decisions, so use a limited lookback. Geo-IP uses a cached HTTPS lookup; AbuseIPDB is optional and requires an API key. Intelligence is informational and never changes a block decision.
SCANTIDE GUARD LICENSE
Guard licensing
NOT CHECKED
No license check has completed yet.
Guard licensing is separate from Scantide API credentials. Datacenter-managed Guard can also receive these credentials centrally.
LIFECYCLE
Updates and retention
NOT CHECKED
Linux Guard downloads only HTTPS packages, verifies the Scantide-published SHA-256, then launches the packaged install.sh through a transient systemd update unit so the Guard service can safely replace and restart itself.
NOTIFICATIONS
Email alerts
Emails when a safe/allow-listed IP reaches a blocking threshold. The exemption stays in place; no block is applied. Repeated warnings use the per-IP cooldown below.
Save before testing. The test uses the same layout as a real block alert but does not create a firewall rule.
Trust a Datacenter
Option 1: import the enrollment package copied by your administrator. Option 2: enter its HTTPS hostname below, select its public CA certificate and enter a one-use enrollment code.
No new certificate selected.
Hostname alone cannot establish trust. Guard will not accept unknown certificates or fall back to HTTP. Changing trust removes the old enrollment. Use the existing Datacenter Save button to connect.
MANAGEMENT
Datacenter console
Not configured
Guard initiates trusted outbound HTTPS connections only. After enrollment, the one-use code is replaced by a unique agent credential. Unknown Datacenters and HTTP connections are never accepted.
SAFETY
Local allow-list / whitelist
Allow a trusted source IP or an entire CIDR network. Allow-listed sources are observed but never automatically blocked. Adding an entry also releases any matching active Guard block.
Loopback addresses are permanently protected and cannot be removed.
Local block-list / blacklist
Manual blocks are permanent until unblocked. Enter a single IP address; trusted and allow-listed addresses cannot be blocked. Changes below are saved immediately.