SYSMarshal architecture — distributed threat intelligence and automated enforcement for Windows environments
SYSMarshal threat-intelligence driven defense automation for Windows environments — threat intel ingestion, local SQL audit and telemetry, automated policy enforcement and AI-guided triage and response
SYSMarshal DFIR + AI analysis core architecture — endpoint telemetry, threat correlation, DFIR evidence graph, AI analysis and automated response
SYSMarshal competitive analysis — enforcement-focused control plane compared capability by capability with CrowdStrike Falcon, SentinelOne Singularity, Microsoft Defender for Endpoint and basic brute-force blockers
SYSMarshal® Security · for Windows

Enterprise Endpoint Security Built for the Real World

See Every Threat. Stop Every Attack. Know Exactly What Happened.

Modern Endpoint Defense with Built-In AI Investigation — AI-Powered Dynamic Endpoint & Site Security, Threat Detection, Auto-Inoculation, DFIR (Digital Forensics Incident Response), Investigation Recording, SOAR, SIEM, EDR, XDR Light, and more.

Auto-Inoculate site clients to maintain internal defense across every machine on a site license.

Windows only — Win 10 / 11 & Server 2019–2025 Blocks hold even when the app is closed
Live threat console
Events
Blocks
Geo
IPs incarcerated · 24h
14,238
▲ 6.4% vs prior
Failed logons blocked
81,402
▲ 2.1% vs prior
Median response
412ms
▼ 11% vs prior
node-eu-03 · syncing ↳ 4,812 rules deployed
// What it stops

Four attack surfaces. One autonomous defender.

RDP, SQL Server, credential brute force, and connection floods are how Windows boxes actually get breached. SYSMarshal watches all four in the Windows event log and firewall in real time — observing, correlating, and blocking at machine speed, with no SOC team to run it.

Sub-second detect-to-block Blocks at the Windows Firewall Learns from global threat intel
MITRE T1021.001

RDP attack prevention

Exposed RDP is the number-one ransomware doorway. SYSMarshal reads every logon and failed-logon event the instant it fires, fingerprints the source IP, and shuts out credential-stuffing sessions before an attacker gets a foothold.

EVT 4625reputationblock
Port 3389 · real-time↳ auto-block
MITRE T1190

SQL attack guard

The moment SQL Server is reachable, attackers scan 1433 and 1434 for it. SYSMarshal gates those ports by IP, flags injection and login-probe patterns, and blocks the source — leaving a tamper-evident audit trail behind every hit.

tcp 1433/1434probe matchIP gate
Audit-ready↳ rule-set
MITRE T1110

Brute force shield

Failed-logon storms don’t get retries — they get blocked. Once a source IP crosses your configurable threshold inside the time window, it’s dropped at the Windows Firewall and stays blocked until you clear it.

N fails / windowthresholdauto-block
Threshold-based↳ persistent block
MITRE T1498

DDoS & flood protection

Connection floods and resource-exhaustion runs give themselves away by velocity. SYSMarshal’s flood report surfaces abnormal request storms as they build and auto-blackholes the sources, so real users keep getting answered while the noise gets dropped.

flood detectrate-limitblackhole
Flood report · live↳ auto-blackhole
// Response engine
Observeevent log + firewall
CorrelateIP reputation + threat DB
Decideseverity + threshold
Actfirewall block · jail
Learnglobal blacklist sync
// Capability map

Eight capabilities. One autonomous perimeter.

Tap any capability for the engineering detail — what it watches, the rules it enforces, and exactly how SYSMarshal responds.

01

Real-time event monitoring

Reads the Windows Security log live — 4625, 4776, 18456 and more — and correlates logon storms across every endpoint.

Monitored EventsDetail →
02

Automated firewall enforcement

Every verdict becomes a Windows Firewall block rule automatically — single IPs, ranges and CIDR blocks.

Firewall RuleDetail →
03

Global threat intelligence

Auto-Inoculation blocks the IPs the global SYSMarshal fleet already flagged — before they ever reach you.

Auto-InoculationDetail →
04

Threat enrichment & attribution

Every hostile IP scored and mapped — AbuseIPDB reputation, RDAP/WHOIS ownership and GeoIP location.

WHOIS IntelDetail →
05

SOC dashboard & threat map

A live posture score, attack-spike alerts and a world map of exactly where your hits originate.

DashboardDetail →
06

Diagnostics & IIS analytics

IP diagnostics, connection-flood reports, ping watch and W3C IIS-log parsing with suspicious-pattern detection.

DiagnosticDetail →
07

Incident investigation & audit

Every session becomes a case — evidence timeline, captured artifacts and an audit-ready TXT / CSV export.

InvestigationDetail →
08

AI security copilot

Ask your data anything — plus ten one-click DefCon scans that turn live forensics into PDF reports.

AI AssistantDetail →
// Product tour

Seven frames. The whole perimeter.

The highlight reel — real-time detection and response, global threat intelligence, the SOC dashboard, incident investigation, the AI copilot and the built-in toolbench.

SYSMarshal — stop RDP, SQL, brute-force and DDoS attacks automatically Real-time detection and response — from failed logon to firewall block in under a second Global threat intelligence — Auto-Inoculation blocks known attackers before they reach you AI security copilot — ask your own threat data anything SOC dashboard — a live posture score, spike alerts and a world map of every attack origin Incident investigation — case files, evidence timelines, captured artifacts and audit-ready reports Built-in security toolbench — PowerShell terminal with AI, IIS log analyser and network diagnostics
// Field reports

What it looks like on a real perimeter.

Administrators, engineers and owners running SYSMarshal on Windows servers and workstations — in their own words.

4.8 / 5.0
Average of 1,431 responses from SYSMarshal customers.
5★ 1,180
4★ 214
3★ 26
2★ 8
1★ 3
“Our RDP servers were taking thousands of failed logons a night. SYSMarshal picked the pattern out of the Security log and had the source ranges in a firewall block rule before anyone was awake to look at it.”
IT Manager Accounting practice · 3 terminal servers
“Auto-Inoculation is the part that sold the second licence. Addresses that hit other sites first never got a single packet into ours, and the recency cutoff keeps the rule set from growing forever.”
Systems Administrator Regional logistics provider
“The case timeline is what our insurer actually wanted to see. Evidence, artifacts and the exact sequence of events exported to one report, instead of me stitching screenshots together for a week.”
Security Officer Managed service provider
“Every verdict lands as a real Windows Firewall rule. No agent fleet, no console to babysit, nothing sitting between us and the traffic. It uses the firewall we already trusted.”
Infrastructure Lead Healthcare billing services
AI Assistant

“Being able to ask plain questions of our own event data — which addresses came back after a block, what changed this week — saves the part of the job I used to do in SQL at midnight.”

Network Engineer Manufacturing · 40 endpoints
SOC dashboard

“The posture score and the origin map made this legible to people who do not read event logs. It is the first time our leadership has understood what the perimeter absorbs in a week.”

Director of Operations Professional services firm
IIS log analysis

“The IIS parser surfaced a scanner walking our admin paths that nothing else had flagged. Suspicious requests, top URLs and status codes sorted for me in a single pass.”

Web Administrator E-commerce · public IIS
SQL exposure

“Constant probing on 1433 was our loudest noise source. It is quiet now, and 18456 events go through the same pipeline as everything else instead of a log nobody opened.”

Database Administrator Financial software vendor
Service monitor

“It told us a service had been stopped outside the app before anyone noticed the symptom. That transition is now on the case timeline with a timestamp, which is what we needed.”

Operations Manager Property management group
Toolbench

“The built-in terminal means I am not hopping between four windows during an incident. Script, run, read the output, capture it to the case, all without leaving the console.”

Support Engineer IT consultancy · 20 client sites
Monitored events

“Adding our own event IDs took minutes, and the browser makes it obvious which ones actually fire. We stopped guessing at what to watch.”

Security Lead Legal services firm
Deployment

“Installed on a Friday, blocking by Friday afternoon, and I have not had to learn a security product to keep it working. That was the whole requirement.”

Owner Small business · 12 seats