Scantide
Public beta · 0.7.7

Turn hostile logons into controlled server protection.

Scantide Guard is a Windows and Linux server protection system that observes authentication and service events, correlates repeated hostile activity, enriches the source with useful intelligence and applies explainable firewall blocks. It is being built for real mixed-generation server estates—not only one protocol or one current operating system.

Public beta downloads

Install Scantide Guard 0.7.7.

Windows builds can be downloaded directly. On Linux, the recommended bootstrap installer reads the current beta release from the Scantide update manifest, downloads the package over HTTPS, verifies its published SHA-256 and then runs the packaged installer.

Linux — quick install

Run this as a user with sudo access:

curl -fsSL https://www.scantide.com/guard/install.sh | sudo bash

The bootstrap script uses /guard/update.json, verifies the package SHA-256 and then starts the packaged install.sh.

Prefer to review it first?

curl -fLO https://www.scantide.com/guard/install.sh
less install.sh
sudo bash install.sh
View install.sh

Linux — package

Current beta: 0.7.7

Download Linux package

SHA-256

ec46dd6138ed0ce16e8cdd42cd7a5c3ca7c2da8f7b7c984f869c26cdc6d98ab8
What Scantide Guard does

Evidence first. Response second.

A single failed logon is context. A repeated, correlated pattern may justify action. Guard keeps collection separate from policy and enforcement so an incomplete event does not become a guessed identity or an unsafe firewall decision.

Collects local evidence

Reads supported Windows Event Log, IIS/RD Web, SQL Server and Linux journal evidence using small, independent collectors.

Correlates repeated activity

Groups observations by source and time window before policy decides whether to observe, warn or block.

Applies controlled blocks

Creates Guard-owned Windows Firewall, nftables or iptables rules without replacing the server's existing firewall policy.

Investigates aggressors

Adds reverse DNS, country, city, ASN, network and abuse context asynchronously without delaying enforcement.

Tracks repeat offenders

Escalates sources across separate block occurrences and can turn repeated temporary blocks into permanent ones.

Preserves an audit trail

Keeps searchable security events, block history and append-only audit records for investigation and review.

Decision path

How an observation becomes a block

ObserveA collector extracts a real source address and normalized evidence from a supported local event.
Protect trusted sourcesLoopback, private networks and administrator-defined IP/CIDR allow lists take precedence.
CorrelateGuard measures related activity against the configured threshold, window and repeat-offender policy.
Respond and explainA Guard-owned rule is created, recorded with its reason and released automatically unless permanent.
Supported development targets

One Guard model across mixed server estates.

These are current development-preview targets, not a general-availability compatibility promise. Final support will follow validation on real systems.

Windows Server

Preview
  • Windows failed logons, including RDP/network events
  • Kerberos pre-authentication failures
  • SQL Server failed logons
  • IIS, classic RD Web and HTML5 RD Web correlation
  • Windows Firewall enforcement

Legacy Windows

Legacy preview
  • Windows Server 2008 R2 SP1 target
  • .NET Framework 4.8 compatibility
  • Windows Event Log collectors
  • Windows Firewall blocking via legacy-safe tooling
  • Explicit unsupported-OS risk indication

Linux

First preview
  • Systemd-based Ubuntu/Debian and RHEL-family target
  • OpenSSH authentication failures
  • Journal cursor checkpointing
  • Isolated nftables address sets
  • Isolated iptables/ip6tables fallback chain
Development scope

What exists now—and what comes next.

Implemented in current previews

  • Local browser-based management interface
  • Automatic and user-driven IP blocking
  • Exact IP and CIDR allow lists with automatic block release
  • Temporary and permanent repeat-offender blocks
  • Durable event, block and offender state
  • Daily append-only audit history
  • Reverse DNS, geographic, ASN/ISP and abuse enrichment
  • Email alerts with per-source cooldown
  • Outbound Datacenter enrollment and managed policies

Planned and expanding

  • Additional Cyberarms-derived collectors
  • User-selected Windows Event Viewer triggers
  • User-defined text and application log collectors
  • Broader Linux PAM, sudo, web, mail and database collectors
  • Scheduled local area network discovery and security checks
  • Scheduled local server security-posture assessments
  • Installed software inventory with CVE and lifecycle analysis
  • Certificate discovery, expiry and renewal visibility
  • Searchable centralized fleet history
  • Automatic allow-list assistance
  • Independent Tor exit-node intelligence
  • Deeper aggressor reconnaissance
  • Backend-delivered collector and rule catalog
Coming development

Scheduled protection and posture visibility from the same lightweight client.

Planned Guard scheduling will let administrators run periodic local area network checks to identify reachable devices, exposed services and unexpected changes, alongside local server security-posture checks covering installed software, missing or relevant CVEs, product lifecycle, listening services, hardening signals and certificate health.

The local Guard client will collect and normalize evidence. Product matching, vulnerability intelligence, lifecycle interpretation, enrichment and confidence decisions will remain centralized in the Scantide backend so clients stay lightweight and the intelligence can improve without repeatedly rebuilding every installation.

Development notice

Scantide Guard is available as a beta for testing.

Guard is under active development and validation. Beta builds are published for testing and may change before general availability. Test in controlled environments, keep trusted management addresses allow-listed, and verify the published SHA-256 before deployment.

Guard complements patching, supported operating systems, firewalls and endpoint protection. Supporting a legacy server does not make that operating system supported or remove its underlying security risk.

Frequently asked questions

Scantide Guard FAQ

What is Scantide Guard?

Scantide Guard is a cross-platform server attack-protection project. It converts normalized local security evidence into transparent observe, warn or block decisions and manages only the firewall objects it creates.

Is Guard only an RDP brute-force blocker?

No. RDP and Windows authentication are important starting points, but Guard's collector model also covers Kerberos, SQL Server, IIS/RD Web and Linux SSH. The roadmap includes administrator-defined Event Viewer and application-log collectors.

Does it support Windows Server 2008 R2?

A separate .NET Framework 4.8 legacy preview is being developed for Windows Server 2008 R2 SP1. This is intended for organizations that still have unavoidable legacy systems, while clearly identifying the operating system as unsupported and high risk.

How does Linux blocking work?

The first Linux preview observes OpenSSH failures in the systemd journal. It manages an isolated Scantide Guard nftables table or, when necessary, a dedicated iptables/ip6tables chain. It does not flush the existing ruleset or change its default policy.

Can multiple Guard servers be managed centrally?

Centralized Datacenter management is under development. Agents connect outbound, enroll using one-use codes, report status and retrieve revisioned global or per-server policies while retaining their last known policy if disconnected.

Is Scantide Guard available now?

Yes. Current builds are available as a public beta for testing. Beta does not imply general-availability production support; packaging and behavior may still change as Windows, Legacy Windows, Linux and Datacenter validation continues.

Interested in Scantide Guard?

Guard is being shaped around the mixed Windows, legacy and Linux environments that organizations actually operate. Contact Scantide if you are interested in the project or future testing.

Contact Scantide