Features

From reading logs to writing firewall rules, fully automated — every feature ran on the author's own production server (22 live sites) before it shipped.

14 detection rules, built in

Covers vulnerability scanning, sensitive-path probing (/.env, /wp-login.php…), 4xx error bursts, brute-force attempts and abnormal request patterns. Every verdict keeps the triggering log lines, so you can always verify why an IP was blocked.

Rules ship with every release and work out of the box; Pro subscribers get continuous online rule-pack updates without waiting for a new release.

SvrGuard event list with evidence
Event list: every block has a rule code, severity, and its evidence

Automatic blocking, straight into the system firewall

Linux — native nftables

Pure Go talking netlink directly to nftables — no ipset, iptables or any external tool required. Older kernels fall back to ipset compatibility mode automatically. Tested down to kernel 4.4.

Windows — built-in firewall

Manages Windows Firewall rules directly. Works out of the box on Windows 10 / Server 2016 and later.

TTL auto-expiry

Blocks expire and remove themselves — no graveyard of thousands of stale rules. A whitelist keeps your own IPs safe from false positives.

Attack map and dashboard

GeoIP pins every attack source to a country and city; the dashboard shows block counts, event trends and firewall backend status in real time. Everything exports to CSV.

SvrGuard attack map
Attack map: sources from 48 countries at a glance (real data from the author's server)

Notifications: when it blocks, you know

Email alerts are included in the Free tier — being able to tell you about a block is a protection tool's basic duty. Pro adds Telegram, webhooks, batching and daily digests, so a fleet of servers doesn't drown you in mail.

Fleet central management (Pro)

With multiple servers, clients run a lightweight agent (local console can be fully disabled), bind to your account with a pairing code, and report to a central dashboard:

Central dashboard

Status, events and the attack map for every server on one page — firewall backend and last heartbeat per host at a glance.

Pairing-code binding

Sign in, mint a one-time pairing code, paste it during install — bound. Reinstalling the same machine never burns an extra seat.

Shared threat intel

An IP caught attacking one server is pre-emptively blocked across your whole fleet — one hit, everyone immune.

SvrGuard fleet dashboard
Fleet dashboard: all servers monitored centrally

System resource monitoring (Pro)

CPU, memory, disk and service-liveness monitoring with threshold alerts — server trouble reaches you through the same channel as attack events, no separate monitoring stack needed.

SvrGuard resource monitoring
Resource monitoring: threshold alerts and trend charts

Install the free tier and watch it stop its first attack