About SYSMarshal

The autonomous defender for Windows servers.

SYSMarshal reads the Windows event log in real time, scores every threat, blocks hostile IPs at the Windows Firewall in seconds, and learns from a global threat-intelligence feed — so attacks that hit one protected machine are stopped before they ever reach yours.

Windows Server 2016–2022 & Win 10 / 11
IPv4 & IPv6, end to end
Blocks at the Windows Firewall
Global threat intelligence
AI DefCon forensics

Why we exist

Most successful attacks on Windows servers aren’t sophisticated. RDP brute force, SQL Server credential stuffing, port scans and web probes succeed for one simple reason: nobody is watching the event log at 3 a.m., and nobody responds fast enough when something does show up.

Most Windows servers aren’t defended by a security operations centre — they’re defended by a busy administrator with fifty other responsibilities. We built SYSMarshal for exactly that person: enterprise-grade detection and automated response that runs itself, explains itself, and never needs someone staring at a screen.

How the defender works

The background service runs one tight loop, continuously — whether or not the console is open. The desktop console is just a window onto it.

01 · Observe
Read the logsSecurity & Application events are read in real time and the source IP is extracted from every hit — RDP, NTLM, SQL Server, network probes.
02 · Correlate
Count & enrichFailures are counted per IP, then enriched with reputation, geolocation and abuse-confidence — a decision is never made on a raw address alone.
03 · Decide
Check the rulesYour thresholds, whitelist and private-IP policy are applied before anything is blocked — you stay in command.
04 · Act
Block in secondsThe IP lands in one dedicated firewall rule — the SYSMarshal IP Jailhouse. Your other firewall rules are never touched.
05 · Learn
Share the signalConfirmed threats feed the global blacklist, and Auto-Inoculation pulls the worldwide feed back down — herd immunity for your fleet.

What we build

Real-Time Detection

Watches the Windows event IDs that matter out of the box — failed logons, NTLM and SQL Server failures, network probes — and lets you monitor any event that carries a source IP.

🛡

One Clean Firewall Rule

Every block lives in a single inbound rule. Nothing else is modified, outbound traffic is unaffected, and the whole list is exportable and editable in a purpose-built range editor.

🌐

Community Threat Intelligence

Baseline Protection surfaces attackers seen across every reporting installation, and Auto-Inoculation blocks the worst of them on a schedule — before their first packet reaches you.

🔍

Investigation-Grade Evidence

Every monitoring session becomes a case file with an evidence timeline you can filter, review and export straight into a ticket.

An AI Analyst On Call

Ten one-click DefCon forensic scans — from live incident response to credential audit — plus chat, AI database analysis and a script-aware PowerShell terminal.

🐕

Protection That Survives

An independent Watchdog service alerts you if protection stops and restores the Windows audit policy daily — because blinding the logs is an attacker’s first move.

How we think about security

Never lock the owner out.Whitelisting your own IPs is step one of our quick start, the whitelist is checked before every block, and a reputation lookup can mark noisy-but-legitimate sources as trusted.
Automate the response, keep the human in command.Thresholds, windows and policies are yours to set; every action the defender takes is visible, logged and reversible.
Evidence first.A block without a record is a mystery six months later. Every detection and action lands in an auditable case timeline.
Community defense.Every attack one installation sees can make every other installation safer. Shared intelligence multiplies defense.

Licensing, kept simple

SYSMarshal has exactly two licence types. The free Trial gives you the full local defender — real-time monitoring, auto-blocking, dashboards and your site’s threat data — so you can prove it on your own servers first. Professional covers every machine at your site under one account and adds the global threat-intelligence feed, the AI Assistant with all ten DefCon scans, and cross-site visibility. And if our licence server is ever briefly unreachable, a 12-hour grace period keeps you protected — your security never blinks.

See what your servers have been going through.

Install the free trial and SYSMarshal will show you the attacks you never knew were happening.