The autonomous defender for Windows servers.
SYSMarshal reads the Windows event log in real time, scores every threat, blocks hostile IPs at the Windows Firewall in seconds, and learns from a global threat-intelligence feed — so attacks that hit one protected machine are stopped before they ever reach yours.
Why we exist
Most successful attacks on Windows servers aren’t sophisticated. RDP brute force, SQL Server credential stuffing, port scans and web probes succeed for one simple reason: nobody is watching the event log at 3 a.m., and nobody responds fast enough when something does show up.
Most Windows servers aren’t defended by a security operations centre — they’re defended by a busy administrator with fifty other responsibilities. We built SYSMarshal for exactly that person: enterprise-grade detection and automated response that runs itself, explains itself, and never needs someone staring at a screen.
How the defender works
The background service runs one tight loop, continuously — whether or not the console is open. The desktop console is just a window onto it.
What we build
Real-Time Detection
Watches the Windows event IDs that matter out of the box — failed logons, NTLM and SQL Server failures, network probes — and lets you monitor any event that carries a source IP.
One Clean Firewall Rule
Every block lives in a single inbound rule. Nothing else is modified, outbound traffic is unaffected, and the whole list is exportable and editable in a purpose-built range editor.
Community Threat Intelligence
Baseline Protection surfaces attackers seen across every reporting installation, and Auto-Inoculation blocks the worst of them on a schedule — before their first packet reaches you.
Investigation-Grade Evidence
Every monitoring session becomes a case file with an evidence timeline you can filter, review and export straight into a ticket.
An AI Analyst On Call
Ten one-click DefCon forensic scans — from live incident response to credential audit — plus chat, AI database analysis and a script-aware PowerShell terminal.
Protection That Survives
An independent Watchdog service alerts you if protection stops and restores the Windows audit policy daily — because blinding the logs is an attacker’s first move.
How we think about security
Licensing, kept simple
SYSMarshal has exactly two licence types. The free Trial gives you the full local defender — real-time monitoring, auto-blocking, dashboards and your site’s threat data — so you can prove it on your own servers first. Professional covers every machine at your site under one account and adds the global threat-intelligence feed, the AI Assistant with all ten DefCon scans, and cross-site visibility. And if our licence server is ever briefly unreachable, a 12-hour grace period keeps you protected — your security never blinks.
See what your servers have been going through.
Install the free trial and SYSMarshal will show you the attacks you never knew were happening.