Ark Backup & ProtectionComing soon

SentinelGuard Brute-force protection for your whole fleet

We're building protection that detects password-guessing attacks on RDP, SSH, SQL, FTP, mail, and VPN, blocks attackers at the firewall, and shares the blocklist across every Windows and Linux server you manage.

SentinelGuard is in active development and not yet available. Join the preview list to hear about progress and help shape the first release.

How SentinelGuard Will Work

Detection and blocking are designed to happen on each server. The cloud will only coordinate, and agents pull updates, so nothing pushes commands into your network.

01

Detect

The agent will watch authentication logs on each server for repeated failures across RDP, SSH, SQL Server, MySQL, PostgreSQL, mail, FTP, VPN and more, plus custom log patterns.

02

Block locally

Offending IPs will be blocked on the host firewall, Windows Filtering Platform on Windows and iptables or nftables on Linux, with no round trip to the cloud.

03

Share the blocklist

Each block will be reported to the central service. Agents are designed to pull signed, versioned blocklist updates so an attacker blocked on one server is blocked everywhere.

04

Manage from one place

Whitelists, GeoIP rules, escalation policies, and per-location overrides will be managed in a single dashboard across your entire fleet.

What We're Building

Planned capabilities: central control with local enforcement, plus the fleet view and policies that per-server tools don't offer. Details may change as development continues.

Windows and Linux

One agent planned for Windows Server, Windows 10/11, and Ubuntu, Debian, RHEL, and Rocky Linux. Many single-server tools cover only one.

Broad protocol coverage

Planned detectors for RDP, SSH, SQL Server, MySQL, PostgreSQL, mail (SMTP, IMAP, POP3), FTP, VPN (OpenVPN, WireGuard), SIP, and HTTP auth, plus custom log patterns.

Fleet-wide shared blocklist

Blocks will propagate to every server in your organization as agents poll for updates. Signed updates are designed so agents only apply what the service actually issued.

Per-location rules

You will be able to group servers by site, customer, or role. Block a country on production but not dev, or auto-block everywhere after three servers see the same attacker.

GeoIP blocking

Planned country-level block and allow rules, globally or per server group, with exceptions for the offices and partners that need access.

Protected whitelists

Designed so whitelisted addresses are never blocked by any rule, with multi-factor authentication required to change them.

Works offline

If the central service is unreachable, agents are designed to keep detecting and blocking locally and catch up when the connection returns.

Alerts where you work

Planned alerts via email, Slack, Microsoft Teams, Discord, PagerDuty, and webhooks for new attackers, escalations, and agent health.

Evidence for auditors

Each block will record the protocol, timestamp, server, and evidence hash, with weekly and monthly reports planned for compliance reviews.

Designed for Fleets, Not Single Servers

You'll be able to group servers by location, customer, or role and apply different policies to each group from one dashboard. Who it's for:

  • MSPs protecting 5 to 50 client environments from one console
  • SMBs with exposed RDP, SQL, or mail servers
  • Teams replacing per-server tools that have no central view
  • Regulated businesses that need proof of brute-force controls

Want Early Access to SentinelGuard?

Join the preview list and we'll keep you posted as SentinelGuard takes shape and let you know when the first release is ready.