Real-time event monitoring
Reads the Windows Security log live — 4625, 4776, 18456 and more — and correlates logon storms across every endpoint.
Automated firewall enforcement
Every verdict becomes a Windows Firewall block rule automatically — single IPs, ranges and CIDR blocks.
Global threat intelligence
Auto-Inoculation blocks the IPs the global SYSMarshal fleet already flagged — before they ever reach you.
Threat enrichment & attribution
Every hostile IP scored and mapped — AbuseIPDB reputation, RDAP/WHOIS ownership and GeoIP location.
SOC dashboard & threat map
A live posture score, attack-spike alerts and a world map of exactly where your hits originate.
Diagnostics & IIS analytics
IP diagnostics, connection-flood reports, ping watch and W3C IIS-log parsing with suspicious-pattern detection.
Incident investigation & audit
Every session becomes a case — evidence timeline, captured artifacts and an audit-ready TXT / CSV export.
AI security copilot
Ask your data anything — plus ten one-click DefCon scans that turn live forensics into PDF reports.
Every Windows breach leaves its first trace in the event log. SYSMarshal tails the Windows Security log in real time, so hostile activity is scored the instant it happens — not on the next scheduled scan.
ConsoleMonitored Events
SourceSecurity log
LatencyReal-time
What it watches
- Failed logons (
4625) — the classic brute-force and password-spray fingerprint. - Credential attacks (
4776, 4777, 18456) — NTLM validation failures and SQL Server login failures. - Network probes (
5152, 5157, 5140) — packets and connections blocked by the Windows Filtering Platform, plus network-share access. - Any event ID you choose — eight events ship pre-configured and enabled; add your own from a simple list.
How it works
For every hit, SYSMarshal extracts the source IP, counts repeat offenders across all of your endpoints, and passes the verdict straight to the firewall and intelligence engines. Failed-logon storms that would bury a human analyst arrive as one ranked, de-duplicated signal.
Supported on Windows only — Windows 10, Windows 11 and Windows Server 2019, 2022 and 2025. No other operating systems are supported, and there is no external SIEM to license or babysit.
Detection is only half the job. The moment an IP crosses your threshold, SYSMarshal writes a Windows Firewall block rule itself — no console, no ticket, no waiting for a human to act.
ConsoleFirewall Rule
Enforced atWindows Firewall
ScopeIP / range / CIDR
What it enforces
- Single IPs, address ranges and CIDR blocks, applied natively at the OS.
- One named, auditable rule — the
SYSMarshal IP Jailhouse — plus AutoInoculation #N chunks you can inspect at any time. - Bulk IP lists you can paste, sort, de-duplicate and import in seconds.
How SYSMarshal responds
Because blocks live in the Windows Firewall, they hold even when the app is closed. Rules are chunked and self-pruning — when a block list empties, the rule is removed rather than left as a wildcard that could accidentally block all inbound traffic. Every change is written to the Recent Activity log for a clean audit trail.
Why wait to be attacked before you block an attacker? Auto-Inoculation immunises your server against IPs already caught attacking other SYSMarshal-protected machines — anywhere in the world.
ConsoleBaseline
EngineAuto-Inoculation
ReachGlobal fleet
Two intelligence tiers
- Site data — every machine on your own licence, sharing a single threat picture.
- Global data — the entire SYSMarshal fleet’s live blacklist (Professional licence).
How it works
Set a confidence threshold, a sync interval and an optional recency window, then let it run. On each sync SYSMarshal pulls fresh known-bad IPs, blocks the ones that clear your bar, and prunes stale entries whose latest sighting has aged out — so your firewall stays sharp instead of bloating over time. It’s herd immunity for your infrastructure.
A blocked IP raises a question: who is this, and how dangerous are they? SYSMarshal answers it on demand, fusing live intelligence from three independent sources into one report.
ConsoleWHOIS Intel
Sources3 live feeds
OutputEvidence record
What it pulls
- AbuseIPDB — abuse-confidence score and reported attack categories.
- RDAP / WHOIS — the network owner and the organisation responsible for the address.
- GeoIP — country, city, postal code and map coordinates.
Why it matters
Every hostile address is tagged with a severity, an attack vector and a confidence rating, so you can tell a misconfigured partner apart from a hostile botnet node in seconds. Attribution turns a raw IP into an evidence-grade record you can act on — or attach directly to an incident case.
One screen answers the only question that matters at a glance: am I under attack right now? The dashboard is a native SOC console built on fast SQL aggregations — no bolt-on BI engine to slow it down.
ConsoleDashboard
Posture0–100 score
Windows1d / 7d / 30d
What you see
- Security Posture score blending severity mix, block rate and attack spikes into one number — labelled Good, Guarded, Elevated or Critical.
- Attack-spike banner the moment the last hour runs 3× hotter than the trailing day.
- New Attackers and Repeat Offenders, first-seen across the global fleet.
- A 7×24 weekly heatmap plus protocol and direction breakdowns.
Threat Origin Map
A live world map plots exactly where your hits come from, complete with a day/night terminator, a scrolling origin ticker and a time-lapse replay of first-seen attackers. Re-scope every card to Today, 7 days, 30 days or all time with a single click.
When something looks off, SYSMarshal gives you the tools to prove it — four focused diagnostic surfaces plus a full IIS log analyser.
ConsoleDiagnostic
Surfaces4 + IIS logs
IIS parsingW3C format
Diagnostic toolkit
- IP Diagnostics — traceroute, firewall-rule match and blacklist lookup for any address.
- Event Flood Report — surfaces abnormal event bursts as they build.
- Ping Monitor — continuous reachability watch on the hosts you care about.
IIS log intelligence
Point it at your W3C logs and SYSMarshal parses them for suspicious request patterns, then ranks the top offending IPs, most-hit URLs and status-code anomalies. Pair it with the Diagnostic Report’s threat scan — six security event IDs aggregated by IP and port against your ban threshold — for a full picture before you pull the trigger.
Blocking the attack is step one. Proving what happened — for your own records, an auditor or an insurer — is step two. The Investigation workspace turns raw events into a structured case file.
ConsoleInvestigation
UnitCase · evidence · artifacts
ExportTXT / CSV
How it works
- Every monitoring session becomes a case, tracked through Open, Escalated and Closed.
- A severity-ranked evidence timeline that also records the actions you take in the app — a user-action audit trail for free.
- Artifacts preserve the complete raw content behind an event — AI reports, DEFCON telemetry, PowerShell output — in a full-screen viewer.
- Filter fast by case number, status, date range or username.
Audit-ready by design
Stale cases auto-close and empty ones are purged, so the record stays clean without manual housekeeping. When you’re done, export the whole case as a TXT or CSV report — a trail that stands up long after the incident is over.
Not every admin is a threat analyst — so SYSMarshal ships with one built in. The AI copilot reads your own live threat data and answers in plain language.
ConsoleAI Assistant
ContextYour live data
AccessProfessional
What you can ask
- “Why did this IP get blocked?” — it walks you through the event chain.
- “What should I do about this attacker?” — it recommends the next action.
- “Summarise today’s activity” — it writes the report for you.
Ten DefCon quick scans
One click runs an elevated forensic collector on the machine — crisis response, compromise investigation, persistence & privilege, endpoint triage, vulnerabilities, registry audit, AD security, patch assessment, exfil detection and credential audit — and streams back a structured report you can download as a PDF.
Grounded in your data
Because it works from the same events, blocks and intelligence the rest of the console uses, its answers are specific to your server — not generic web advice. It’s the fastest way to turn a wall of security noise into a clear next step.