Install it and it starts blocking —
it finds whoever is attacking your site and locks them out at the firewall

SvrGuard reads your Apache logs, detects attacks in real time with 14 built-in rules, and writes blocks straight into your system firewall. Free for a single server, installed in five minutes — then you stop thinking about it.

9 days
In production
721
Attacking IPs auto-blocked
48
Source countries
0
Manual interventions
Real numbers from the author's own production server (2026-07-16 – 2026-07-25). Not a simulation.

At 3 a.m., your site is being scanned

Open your access log and it's full of /wp-login.php, /.env, /phpMyAdmin — things you never installed. That's not traffic; it's probing. Someone is methodically testing every possible way into your server.

You can look up IPs and add firewall rules by hand. Tomorrow there's a fresh batch, and the day after that. You can't win this fight manually — a machine should be watching the logs.

SvrGuard's approach is direct: read the logs every minute, match them against 14 attack-signature rules, and when it's an attack, write the block into the firewall and keep the evidence. All you get is one notification email: "Blocked."

How it works

1

Read the logs

Continuously tails your Apache access and error logs, analyzing incrementally with no impact on your site. Logs never leave your machine.

2

Match the rules

14 built-in rules catch vulnerability probing, sensitive-path access, error bursts, brute-force attempts and more. Every verdict comes with the log evidence that triggered it.

3

Block at the firewall

Writes directly into the system firewall (Linux nftables / Windows Firewall) — no extra tools to install. Blocks expire on a TTL and clean themselves up.

Attacks aren't hypothetical — they're happening now

This is the attack map from the author's own server: 9 days online, 721 IPs from 48 countries blocked automatically. Your server faces the same crowd.

SvrGuard attack map: source country distribution
Attack map: every dot is a real attack source (GeoIP located)
SvrGuard dashboard
Local dashboard: block status, event list, and firewall backend at a glance

What we don't do

Clear boundaries are what make it safe to hand your firewall to a tool.

Free on one server, subscription for fleets

Core protection — detection, blocking, the local console, email alerts — is free forever, not a trial. When you manage multiple servers and want rule packs and threat intel delivered automatically, Pro is US$10 per seat per year, three seats minimum.

Full feature comparison and pricing →

Five minutes from now, your server defends itself