RDP intrusion prevention · Windows Server

Your servers are being brute-forced right now.

RDPShield blocks the attackers at the Windows kernel, pulls live threat intelligence, and lets you run your entire fleet from one console.

Free during beta. Founding-customer pricing locked in afterward.

RDPShield
The problem

Expose port 3389 and the internet finds you in minutes.

Every Windows Server reachable over RDP is under constant automated attack. Windows' own lockout policy locks out your admin account instead of the attacker. Built-in tools don't share what they learn, and they don't scale past one box.

~2,800
failed RDP logins per hour on a fresh, unadvertised VPS
Measured on our own test server
<10 min
from a new public IP to the first brute-force attempt
Typical time-to-first-attack
~35k
malicious networks blocked from curated threat feeds, before they ever reach you
Aggregated CIDRs, updated daily
What it does

Protection that works at the kernel — not a log-tailing script.

Kernel-level blocking

Bans are enforced through the Windows Filtering Platform — the same layer the OS firewall uses. Blocked traffic is dropped before it reaches RDP, not merely logged after the fact.

Real-time brute-force defense

Watches the Windows Security log for failed logons and bans the source IP the moment it crosses your threshold — with escalating durations and permanent bans for repeat offenders.

Live threat intelligence

Pulls curated blocklists — Spamhaus, FireHOL, CINS Army, blocklist.de and more — and pre-emptively blocks tens of thousands of known-hostile networks, refreshed automatically.

Fleet console

See every protected server in one dashboard. View any box's live ban list, lift a ban, or push settings — without RDP'ing into each machine one at a time.

Geo & network controls

Block whole countries you never do business with, keep an allowlist that always wins, and let RDPShield auto-protect your gateway, DNS and DHCP so protection never severs your own connectivity.

Runs quietly as a service

Installs as a Windows Service and stays out of the way. A local dashboard on each box shows exactly what's banned and why, with full audit history.

How it works

Install once. Protected in minutes.

Install the agent

Drop the Windows Service onto any server — 2008 R2 through 2025. No reboot, no RDP downtime.

It learns your network

Your IPs and infrastructure are allowlisted automatically so you can never lock yourself out.

Attacks get blocked

Failed logons and known-hostile networks are dropped at the kernel in real time.

Manage the fleet

Every box reports to one console where you watch bans and push changes remotely.

Built for more than one server

One console for every box you protect.

Most tools defend a single machine and forget it the moment you walk away. RDPShield reports every agent up to a central console, so you can see what's happening across your whole fleet — and act on it — without logging into each server. Purpose-built for MSPs and anyone running more than a couple of boxes.

● Private beta — now open

Help shape RDPShield. Get it free while we do.

We're onboarding a small group of design partners running real Windows Server workloads. You get the product free through the beta and founding-customer pricing locked in when we launch — in exchange for candid feedback.

  • Free for the full beta period
  • Founding-customer rate locked for 12 months after launch
  • Direct line to the developer — your feedback ships
  • Hands-on help getting your first servers protected
Questions

Good to know

Which Windows versions are supported?

Windows Server 2016 through 2025, and Windows 10/11. It runs as a native Windows Service and uses the built-in Windows Filtering Platform — no third-party drivers.

Will it lock me out of my own server?

That's the first thing it's designed to prevent. On install, RDPShield allowlists your own IPs plus the server's gateway, DNS and DHCP, and those infrastructure addresses can never be removed remotely. Your allowlist always wins over any block.

Does it change my RDP port or settings?

No. It watches for failed logons and blocks attackers at the network layer regardless of which port RDP listens on. It doesn't touch your RDP configuration.

What does the beta actually ask of me?

Install it on at least one real server, keep it running, and tell us what breaks or feels wrong. We're specifically hunting for edge cases across different hosting providers, so honest reports are the whole point.

What will it cost after beta?

Pricing is per-server with volume and MSP rates. Beta participants lock in a founding-customer discount for a year after launch. We'll share exact numbers with the beta group before anyone is ever charged.

Is my data sent anywhere?

The agent reports operational status — bans, version, health — to your fleet console so you can manage remotely. It doesn't read your files or your users' data. Self-hosted console options are on the roadmap for teams that need everything on-prem.