SCANTIDE GUARD / LIVE LOCAL PROTECTION

Overview

ManualCHECKINGChecking managementHOST
ACTIVE BLOCKS0Linux firewall rules managed by Guard
OBSERVATIONS0Normalized security evidence retained locally
LIVE COLLECTORS0Enabled evidence sources
ENGINEACTIVECorrelation and response policy
RECENT ACTIVITY

Security timeline

EVIDENCE

Security events

TimeSourceCountryCollectorProtocolUserDecisionEnforcementScoreReason
RESPONSE

Blocks

IPCountryCreatedExpiresCollectorReasonStatus
TRUST

Learned safe list

Candidates are learned from successful authentication. Trusted entries are exempt from Guard blocking while fresh, and may be shared through Datacenter policy.

IPStateSuccessesDistinct daysProtocolsUsersFirst seenLast seen
CUSTOM MONITORS

Create your own Guard monitor

LOG FILE

Point Guard at a text log file or rolling log directory, paste an example of the evidence, and define how to recognize it. A matching source IP is normalized into the ordinary Guard correlation and blocking pipeline.

NameSourceLocationCategoryProtocolState
ASSESSMENTS

Server health and security posture

CHECKING

One unified Linux assessment covers CPU, memory, filesystems, enabled services, network, firewall, listening ports, shares, certificates and software/package intelligence where supported. Windows-only checks are identified explicitly.

StartedAssessmentStatusChecksReport
SCHEDULE

Assessment delivery

Catch window and immediate username blocking

Count related security events from an address within this period. Maximum: 30 days. A longer period detects slower attempts but retains more history in memory; counters restart with the service.

Exact, case-insensitive matches only. Use DOMAIN\\name when that is what the collector reports. Only trusted authentication failures can trigger this rule; successful logins and arbitrary web parameters never do. Trusted/private-address protections and the automatic-blocking switch still apply. Fleet propagation is optional and requires Datacenter. Leave the username list blank to disable.

LOCAL POLICY

Response settings

Use the catch-window controls below; managed servers receive their thresholds from Datacenter.

ESCALATION

Repeat offenders

Only separate automatic block episodes count. Attempts made while an address is already blocked do not add occurrences. A permanent block has no expiry and remains until manually released or allow-listed.

Trust a Datacenter

Option 1: import the enrollment package copied by your administrator. Option 2: enter its HTTPS hostname below, select its public CA certificate and enter a one-use enrollment code.

No new certificate selected.

Hostname alone cannot establish trust. Guard will not accept unknown certificates or fall back to HTTP. Changing trust removes the old enrollment. Use the existing Datacenter Save button to connect.

MANAGEMENT

Datacenter console

Not configured

Guard initiates trusted outbound HTTPS connections only. After enrollment, the one-use code is replaced by a unique agent credential. Unknown Datacenters and HTTP connections are never accepted.
SAFETY

Local allow-list / whitelist

Allow a trusted source IP or an entire CIDR network. Allow-listed sources are observed but never automatically blocked. Adding an entry also releases any matching active Guard block.

Loopback addresses are permanently protected and cannot be removed.

Local block-list / blacklist

Manual blocks are permanent until unblocked. Enter a single IP address; trusted and allow-listed addresses cannot be blocked. Changes below are saved immediately.

AddressSourceReasonExpiryAction