SYSMarshal architecture — distributed threat intelligence and automated enforcement for Windows environments
SYSMarshal Threat Origin Map — live global view of blacklisted attack sources, attack paths into the protected network, severity mix and the top threat origin countries
SYSMarshal threat-intelligence driven defense automation for Windows environments — threat intel ingestion, local SQL audit and telemetry, automated policy enforcement and AI-guided triage and response
SYSMarshal DFIR + AI analysis core architecture — endpoint telemetry, threat correlation, DFIR evidence graph, AI analysis and automated response
SYSMarshal competitive analysis — enforcement-focused control plane compared capability by capability with CrowdStrike Falcon, SentinelOne Singularity, Microsoft Defender for Endpoint and basic brute-force blockers
SYSMarshal® Security · for Windows

AI-Powered Windows Endpoint Security & DFIR

Enterprise endpoint security built for the real world. See every threat. Stop every attack. Know exactly what happened.

Modern Endpoint Defense with Built-In AI Investigation — AI-Powered Dynamic Endpoint & Site Security, Threat Detection, Auto-Inoculation, DFIR (Digital Forensics Incident Response), Investigation Recording, SOAR, SIEM, EDR, XDR Light, and more.

Auto-Inoculate site clients to maintain internal defense across every machine on a site license.

Windows only — Win 10 / 11 & Server 2019–2025 Blocks hold even when the app is closed
Global threat intelligence
IPs on the global blacklist
–––
community-sourced, all sites
Newly blocked · 7 days
–––
first seen this week
Countries of origin
–––
observed attack sources
Loading latest detections… ↳ View full dashboard
// What it stops

Four attack surfaces. One autonomous defender.

RDP, SQL Server, credential brute force, and connection floods are how Windows boxes actually get breached. SYSMarshal watches all four in the Windows event log and firewall in real time — observing, correlating, and blocking at machine speed, with no SOC team to run it.

Sub-second detect-to-block Blocks at the Windows Firewall Learns from global threat intel
MITRE T1021.001

RDP attack prevention

Exposed RDP is the number-one ransomware doorway. SYSMarshal reads every logon and failed-logon event the instant it fires, fingerprints the source IP, and shuts out credential-stuffing sessions before an attacker gets a foothold.

EVT 4625reputationblock
Port 3389 · real-time↳ auto-block
MITRE T1190

SQL attack guard

The moment SQL Server is reachable, attackers scan 1433 and 1434 for it. SYSMarshal gates those ports by IP, flags injection and login-probe patterns, and blocks the source — leaving a tamper-evident audit trail behind every hit.

tcp 1433/1434probe matchIP gate
Audit-ready↳ rule-set
MITRE T1110

Brute force shield

Failed-logon storms don’t get retries — they get blocked. Once a source IP crosses your configurable threshold inside the time window, it’s dropped at the Windows Firewall and stays blocked until you clear it.

N fails / windowthresholdauto-block
Threshold-based↳ persistent block
MITRE T1498

DDoS & flood protection

Connection floods and resource-exhaustion runs give themselves away by velocity. SYSMarshal’s flood report surfaces abnormal request storms as they build and auto-blackholes the sources, so real users keep getting answered while the noise gets dropped.

flood detectrate-limitblackhole
Flood report · live↳ auto-blackhole
// Response engine
Observeevent log + firewall
CorrelateIP reputation + threat DB
Decideseverity + threshold
Actfirewall block · jail
Learnglobal blacklist sync
// Capability map

Eight capabilities. One autonomous perimeter.

Tap any capability for the engineering detail — what it watches, the rules it enforces, and exactly how SYSMarshal responds.

01

Real-time event monitoring

Reads the Windows Security log live — 4625, 4776, 18456 and more — and correlates logon storms across every endpoint.

Monitored EventsDetail →
02

Automated firewall enforcement

Every verdict becomes a Windows Firewall block rule automatically — single IPs, ranges and CIDR blocks.

Firewall RuleDetail →
03

Global threat intelligence

Auto-Inoculation blocks the IPs the global SYSMarshal fleet already flagged — before they ever reach you.

Auto-InoculationDetail →
04

Threat enrichment & attribution

Every hostile IP scored and mapped — AbuseIPDB reputation, RDAP/WHOIS ownership and GeoIP location.

WHOIS IntelDetail →
05

SOC dashboard & threat map

A live posture score, attack-spike alerts and a world map of exactly where your hits originate.

DashboardDetail →
06

Diagnostics & IIS analytics

IP diagnostics, connection-flood reports, ping watch and W3C IIS-log parsing with suspicious-pattern detection.

DiagnosticDetail →
07

Incident investigation & audit

Every session becomes a case — evidence timeline, captured artifacts and an audit-ready TXT / CSV export.

InvestigationDetail →
08

AI security copilot

Ask your data anything — plus ten one-click DefCon scans that turn live forensics into PDF reports.

AI AssistantDetail →
// Product tour

Seven frames. The whole perimeter.

The highlight reel — real-time detection and response, global threat intelligence, the SOC dashboard, incident investigation, the AI copilot and the built-in toolbench.

SYSMarshal — stop RDP, SQL, brute-force and DDoS attacks automatically Real-time detection and response — from failed logon to firewall block in under a second Global threat intelligence — Auto-Inoculation blocks known attackers before they reach you AI security copilot — ask your own threat data anything SOC dashboard — a live posture score, spike alerts and a world map of every attack origin Incident investigation — case files, evidence timelines, captured artifacts and audit-ready reports Built-in security toolbench — PowerShell terminal with AI, IIS log analyser and network diagnostics