SSHGuard protects hosts from brute-force attacks by monitoring system logs, detecting attacks, and blocking attackers using a firewall. It works by monitoring system log files and journal logs from various sources like cockpit, Common Log Format, macOS log, metalog, multilog, raw log files, syslog, syslog-ng, and systemd journal. SSHGuard's parser is fast, sandboxed, and secure, as it compiles attack signatures into a full lexical analyzer that does not slow down with more signatures, runs as a separate unprivileged process, and is not susceptible to regular expression denial of service attacks.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
DenyHosts is a script to block SSH server attacks by automatically preventing attackers after failed login attempts.
Zeek Remote desktop fingerprinting script for fingerprinting Remote Desktop clients.
Fail2ban is a daemon that automatically bans IP addresses showing malicious behavior by monitoring log files and updating firewall rules to prevent brute-force attacks.
Accurate detection of HTTPS interception and robust TLS fingerprinting tool.
A network detection and response solution that uses AI and machine learning to monitor network traffic, identify malicious behavior, and connect related security events to reveal attack patterns without requiring endpoint agents.
A website scanner that provides a sandbox for the web, allowing users to scan URLs and websites for potential threats and vulnerabilities.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.