SYSMarshal (30 Days Trial)

Evaluate SYSMarshal free for 30 days on Windows 10, Windows 11 and Windows Server. SYSMarshal reads the Windows Security event log in real time, scores hostile IP addresses and blocks them automatically at the Windows Firewall, then records the whole incident for you. Includes dashboards, diagnostics, investigation cases and the global Baseline threat feed. No credit card required.
$0.00
Shares:

Run SYSMarshal free for 30 days

The trial is the full SYSMarshal desktop platform, time-limited to 30 days, on a single Windows machine. No credit card, no sales call, and no crippled feature set beyond the Professional-only items listed below. Install it on a server that is taking real traffic and you will usually see the first hostile IP addresses blocked within minutes.

What SYSMarshal actually does

  1. Watches. It reads the Windows Security event log continuously — failed logons, RDP sessions, SQL Server authentication failures, account lockouts, privilege use — and extracts the source IP address from every event.
  2. Correlates. Events are aggregated per IP address and per port, scored against a ban threshold you control, and checked against your whitelist and trusted IP ranges so your own offices and VPN egress are never touched.
  3. Blocks. When an IP crosses the threshold, SYSMarshal writes a block rule straight into the Windows Firewall. That is native Windows enforcement, so the block keeps holding after SYSMarshal is closed and across reboots.
  4. Records. Every detection, block and analyst action lands in an investigation case with a full evidence timeline you can export as TXT or CSV.

Included in the 30-day trial

  • Security Dashboard — a native SOC console: KPI trends against the previous window, a 0–100 security posture score, an attack-spike banner, new attackers and repeat offenders, a 7x24 weekly attack heatmap, and a live world Threat Origin Map.
  • Automatic firewall response — threshold-based blocking, an IP range editor, bulk import, whitelist and trusted-range protection.
  • Monitored Events — add any Windows event log and event ID you want watched, with your own thresholds.
  • Diagnostics — IP diagnostics with WHOIS, RDAP and geolocation; event flood reports; a ping monitor; and IIS log analysis that surfaces suspicious request patterns, top attacking IPs, top probed URLs and status-code anomalies.
  • Diagnostic Report — an on-demand security scan with threat-level, IP-type and port-risk breakdowns.
  • Investigations — DFIR case management with an evidence timeline, captured artifacts and exportable reports.
  • Data Explorer, Terminal and Service Monitor — query the local SQL database, run PowerShell against the endpoint, and watch Windows services for external start, stop and uninstall.
  • Global Baseline threat feed — anonymized attacker intelligence contributed by the SYSMarshal community, with Auto-Inoculation so IPs already attacking other members never reach you.
  • Light and dark themes, and a user interface in English, Spanish, French or Hindi.

What unlocks when you move to Professional

  • The AI Security Assistant — ask about your events and logs in plain English. Professional includes thousands of free AI queries.
  • Full hostnames in the Baseline blacklist instead of masked values.
  • The View Global Data toggle — worldwide attacker intelligence across every SYSMarshal customer, not only your own machines.
  • Priority updates and support.

System requirements

Operating systemWindows 10, Windows 11, Windows Server 2019 to 2025 (64-bit)
DatabaseSQL Server Express — installed automatically by SYSMarshal setup if it is not already present
PrivilegesLocal administrator (required to read the Security event log and write Windows Firewall rules)
Runtime.NET 9 desktop runtime and Microsoft Edge WebView2 — both installed by setup

Trial questions

Does the trial block real attacks, or only report them?

It blocks. The trial performs live Windows Firewall enforcement exactly like a paid license — nothing is simulated.

What happens to my firewall rules when the trial ends?

Rules already written to the Windows Firewall stay in place. SYSMarshal simply stops adding new ones until you activate a license.

Do I need to open anything on my perimeter?

No inbound ports. SYSMarshal only makes outbound HTTPS calls to fetch and contribute Baseline threat intelligence.

Is my data shared?

Only hostile IP addresses and attack metadata feed the community Baseline, and they are anonymized. Your event contents, hostnames and files never leave the machine.

Only registered users can write reviews