Windows Server attack protection

Scantide Guard for Windows Server

Monitor failed authentication and hostile web activity, correlate repeated sources, and apply controlled Windows Firewall blocks without turning the server into a heavy endpoint-security platform.

Windows Security Event 4625 failed-logon monitoring

Supported as part of the Guard monitoring, policy or enforcement workflow.

Kerberos 4771 pre-authentication failure monitoring

Supported as part of the Guard monitoring, policy or enforcement workflow.

RDP and RDWeb attack correlation

Supported as part of the Guard monitoring, policy or enforcement workflow.

IIS web request and hostile-probe monitoring

Supported as part of the Guard monitoring, policy or enforcement workflow.

SQL Server 18456 failed-login detection

Supported as part of the Guard monitoring, policy or enforcement workflow.

Exchange SMTP authentication monitoring

Supported as part of the Guard monitoring, policy or enforcement workflow.

Capabilities

What this Guard workflow covers

Designed around observable server evidence

Scantide Guard does not need to attack, exploit or brute-force a service to decide that repeated hostile activity deserves action. Collectors observe evidence already generated by the server, normalize it into a common event model, then apply explicit thresholds, allowlists, exceptions and enforcement policy.

The result is intended to be understandable by an administrator: which source IP was seen, which collector reported it, which rule or threshold was reached, what action Guard took, and when a temporary block is due to expire.

Standalone when you need it. Centralized when you grow.

A single Guard can protect its own server with local policy and local firewall enforcement. Organizations with multiple systems can add Scantide Guard Datacenter for shared policy, fleet visibility, licensing and coordinated reputation services.

Frequently asked questions

Does Guard replace Windows Firewall?

No. Guard uses the local Windows firewall as the enforcement layer and adds correlation, policy, evidence and automated block management.

Can it protect RDP?

Yes. Guard can correlate failed Windows/RDP authentication evidence and block hostile source IPs according to configured thresholds and allowlists.

Is a Datacenter server required?

No. Guard can run standalone. Datacenter adds centralized policy, visibility and fleet management.

See Scantide Guard in context

Read the current Guard documentation, deployment notes and product status, then choose the Windows, Linux or Datacenter path that fits your environment.