Detect
Syspeace Service follows the Windows Security event log for repeated failed sign-in attempts and other suspicious authentication activity, then evaluates it against configurable rules.
Syspeace watches for repeated failed sign-in attempts and other suspicious authentication behavior on Windows Server, then blocks the offending IP addresses automatically.
response.completedautomaticSyspeace blocks attacks on your own servers, blocks known bad actors pre-emptively through the Global Blocklist, and lets you define exactly how blocking works — down to specific countries and conditions.
Syspeace Service follows the Windows Security event log for repeated failed sign-in attempts and other suspicious authentication activity, then evaluates it against configurable rules.
Syspeace v4 blocks offending IP addresses directly through the Windows Filtering Platform, so enforcement keeps working even when Windows Firewall is disabled or managed by other software.
Syspeace Console connects to every protected server through the Syspeace relay, so administrators can review and configure services remotely without direct line-of-sight to the server.
Access Log and Access Report give administrators a searchable history of sign-in activity, exportable to CSV — plus daily and weekly email reports that summarize what happened without needing to open Console.
Blocks reported across the Syspeace customer community are analyzed for repeat offenders and shared back to every Syspeace installation — so an address flagged on someone else's server can be blocked on yours before it ever attacks it.
Set your own blocking policy beyond Syspeace's defaults — block an entire country outright with Geo IP override lists, or build detection rules with nested and negative conditions (time of day, IP range, sign-in user, and more) in Syspeace v4.
Syspeace Service handles detection and blocking on each protected server. Syspeace Console connects to every service through the Syspeace relay, so administrators can review activity and change configuration without needing direct network line-of-sight to the server.
Syspeace runs the same detection and blocking model everywhere — these pages cover how it applies to specific Windows Server environments.
Why internet-exposed Windows Server sign-ins attract automated attacks, and how Syspeace responds.
Repeated failed sign-in attempts against Remote Desktop and RDS environments, and how Syspeace responds.
Where Windows-hosted web and application services expose authentication surfaces Syspeace can respond to.
Central visibility and consistent operations across servers you manage for multiple customers.
Not a general endpoint agent — Syspeace Service is designed specifically for Windows Server sign-in surfaces.
Blocking goes through the Windows Filtering Platform directly, not by delegating to Windows Firewall.
Syspeace Console reaches every paired server through the Syspeace relay, without needing direct network line-of-sight.
Syspeace complements MFA, patching, network segmentation, and firewall policy — it does not replace them.
Start with the full Syspeace Service and Console package. New accounts receive a 30-day trial with no credit card required.