SvrGuard reads your Apache logs, detects attacks in real time with 14 built-in rules, and writes blocks straight into your system firewall. Free for a single server, installed in five minutes — then you stop thinking about it.
Open your access log and it's full of /wp-login.php, /.env, /phpMyAdmin — things you never installed. That's not traffic; it's probing. Someone is methodically testing every possible way into your server.
You can look up IPs and add firewall rules by hand. Tomorrow there's a fresh batch, and the day after that. You can't win this fight manually — a machine should be watching the logs.
SvrGuard's approach is direct: read the logs every minute, match them against 14 attack-signature rules, and when it's an attack, write the block into the firewall and keep the evidence. All you get is one notification email: "Blocked."
Continuously tails your Apache access and error logs, analyzing incrementally with no impact on your site. Logs never leave your machine.
14 built-in rules catch vulnerability probing, sensitive-path access, error bursts, brute-force attempts and more. Every verdict comes with the log evidence that triggered it.
Writes directly into the system firewall (Linux nftables / Windows Firewall) — no extra tools to install. Blocks expire on a TTL and clean themselves up.
This is the attack map from the author's own server: 9 days online, 721 IPs from 48 countries blocked automatically. Your server faces the same crowd.
Clear boundaries are what make it safe to hand your firewall to a tool.
Core protection — detection, blocking, the local console, email alerts — is free forever, not a trial. When you manage multiple servers and want rule packs and threat intel delivered automatically, Pro is US$10 per seat per year, three seats minimum.