Observe. Decide. Enforce.

Lightweight Server Intrusion Prevention

Scantide Guard is designed for administrators who want focused host-level attack response without deploying a large endpoint or SIEM stack simply to stop repeated login abuse and obvious hostile probes.

Deterministic rules and explainable evidence

Supported as part of the Guard monitoring, policy or enforcement workflow.

No exploit attempts or active attack simulation

Supported as part of the Guard monitoring, policy or enforcement workflow.

Windows and Linux local firewall response

Supported as part of the Guard monitoring, policy or enforcement workflow.

Authentication, web and custom-log collectors

Supported as part of the Guard monitoring, policy or enforcement workflow.

Temporary, permanent and repeat-offender policy

Supported as part of the Guard monitoring, policy or enforcement workflow.

Country, Tor and reputation context

Supported as part of the Guard monitoring, policy or enforcement workflow.

Capabilities

What this Guard workflow covers

Designed around observable server evidence

Scantide Guard does not need to attack, exploit or brute-force a service to decide that repeated hostile activity deserves action. Collectors observe evidence already generated by the server, normalize it into a common event model, then apply explicit thresholds, allowlists, exceptions and enforcement policy.

The result is intended to be understandable by an administrator: which source IP was seen, which collector reported it, which rule or threshold was reached, what action Guard took, and when a temporary block is due to expire.

Standalone when you need it. Centralized when you grow.

A single Guard can protect its own server with local policy and local firewall enforcement. Organizations with multiple systems can add Scantide Guard Datacenter for shared policy, fleet visibility, licensing and coordinated reputation services.

Frequently asked questions

Does Guard use AI to decide who to block?

Guard is designed around deterministic evidence, explicit rules, thresholds and administrator policy rather than opaque AI decisions.

Is it an EDR replacement?

No. Guard addresses a narrower server abuse and intrusion-prevention problem. EDR products cover broader endpoint telemetry, process behavior and incident response.

Can it be used on a single server?

Yes. Guard is useful as a standalone host protector and can later be enrolled into Datacenter if centralized management is needed.

See Scantide Guard in context

Read the current Guard documentation, deployment notes and product status, then choose the Windows, Linux or Datacenter path that fits your environment.