SentinelGuard Brute-force protection for your whole fleet
We're building protection that detects password-guessing attacks on RDP, SSH, SQL, FTP, mail, and VPN, blocks attackers at the firewall, and shares the blocklist across every Windows and Linux server you manage.
SentinelGuard is in active development and not yet available. Join the preview list to hear about progress and help shape the first release.
SentinelGuard fleet overview and attack map
Screenshot coming soon
How SentinelGuard Will Work
Detection and blocking are designed to happen on each server. The cloud will only coordinate, and agents pull updates, so nothing pushes commands into your network.
Detect
The agent will watch authentication logs on each server for repeated failures across RDP, SSH, SQL Server, MySQL, PostgreSQL, mail, FTP, VPN and more, plus custom log patterns.
Block locally
Offending IPs will be blocked on the host firewall, Windows Filtering Platform on Windows and iptables or nftables on Linux, with no round trip to the cloud.
Share the blocklist
Each block will be reported to the central service. Agents are designed to pull signed, versioned blocklist updates so an attacker blocked on one server is blocked everywhere.
Manage from one place
Whitelists, GeoIP rules, escalation policies, and per-location overrides will be managed in a single dashboard across your entire fleet.
What We're Building
Planned capabilities: central control with local enforcement, plus the fleet view and policies that per-server tools don't offer. Details may change as development continues.
Windows and Linux
One agent planned for Windows Server, Windows 10/11, and Ubuntu, Debian, RHEL, and Rocky Linux. Many single-server tools cover only one.
Broad protocol coverage
Planned detectors for RDP, SSH, SQL Server, MySQL, PostgreSQL, mail (SMTP, IMAP, POP3), FTP, VPN (OpenVPN, WireGuard), SIP, and HTTP auth, plus custom log patterns.
Fleet-wide shared blocklist
Blocks will propagate to every server in your organization as agents poll for updates. Signed updates are designed so agents only apply what the service actually issued.
Per-location rules
You will be able to group servers by site, customer, or role. Block a country on production but not dev, or auto-block everywhere after three servers see the same attacker.
GeoIP blocking
Planned country-level block and allow rules, globally or per server group, with exceptions for the offices and partners that need access.
Protected whitelists
Designed so whitelisted addresses are never blocked by any rule, with multi-factor authentication required to change them.
Works offline
If the central service is unreachable, agents are designed to keep detecting and blocking locally and catch up when the connection returns.
Alerts where you work
Planned alerts via email, Slack, Microsoft Teams, Discord, PagerDuty, and webhooks for new attackers, escalations, and agent health.
Evidence for auditors
Each block will record the protocol, timestamp, server, and evidence hash, with weekly and monthly reports planned for compliance reviews.
Designed for Fleets, Not Single Servers
You'll be able to group servers by location, customer, or role and apply different policies to each group from one dashboard. Who it's for:
- MSPs protecting 5 to 50 client environments from one console
- SMBs with exposed RDP, SQL, or mail servers
- Teams replacing per-server tools that have no central view
- Regulated businesses that need proof of brute-force controls
SentinelGuard per-location rules editor
Screenshot coming soon
Want Early Access to SentinelGuard?
Join the preview list and we'll keep you posted as SentinelGuard takes shape and let you know when the first release is ready.