ProductShieldMSPPricingCompareBlogDocsStart for FreeSign InTR
Dynacop Shield

Windows MFA and attack blocking.
One agent, no extra cost.

Most MFA products never see attack traffic; IP-blocking tools don't verify the Windows sign-in. Dynacop combines both in one lightweight Windows agent: it verifies the authorized user with MFA and blocks the attacker IP right on the target machine.

How it works
Detect
Correlate
Decide
Block in Windows Firewall
Escalate on repeat

Today you'd install two separate products. Why?

The Windows sign-in security market is split into two camps — and customers end up installing and managing two separate tools.

Camp A — IP blockers
Tools like IPBan, RdpGuard, and CrowdSec
✓ Watch failed attempts and block IPs in the firewall
✕ No MFA — a stolen password still walks through the door
Camp B — Windows MFA products
Products like Duo, Rublon, and LoginTC
✓ Add a second verification step to the sign-in
✕ They don't see attacks and don't block IPs — the door can be probed forever
Dynacop combines both in a single Windows agent.
One agent · One panel · One policy engine

In our segment — no AD requirement, a multi-customer cloud console, one install — we couldn't find another product that does this. Shield isn't a separate SKU or an add-on fee: it ships with every Dynacop install.

The threshold isn't one number; you're in control.

Per-resource policy plus safety layers designed so it never locks you out by mistake.

Per-resource policy

The attempt threshold, watch window, and block duration are tuned per machine — an internet-facing RDP server and an internal accounting PC don't have to live under the same rule.

Safe list and exceptions

IPs on your safe list, the IPs of real users who signed in successfully in the last 7 days, and private network addresses are never blocked at any threshold.

Two-layer decision

Burst intensity within a short window AND cumulative persistence are evaluated together — fast bots and low-and-slow bots both get caught.

Instant manual control

The blocked-IP list lives in the panel, and you can block a suspicious address by hand without waiting for the threshold.

Policy — SRV-WEB
Attempt threshold20
Watch window10 min
First block duration15 min
Longest block24 hrs
Safe list3 IPs
What does Shield see on every failed sign-in?
  • Source IP
  • Protected machine
  • Targeted account
  • Sign-in service
  • Attempt count
  • Short-window rate
  • Cumulative persistence
  • Prior block history
  • Safe-list status

These signals are evaluated together; an IP that crosses the threshold is blocked right in the machine's Windows Firewall.

The lifecycle of a block

The first block is short and reversible; persistence gets punished exponentially.

15 min

First block — a time-limited Windows Firewall rule

Doubles each repeat

If the same IP tries again, the duration doubles each time

24 hrs

The escalation cap — a stubborn attacker stays out all day

30 days

IPs that cross the persistence threshold get a long-term block

Dynacop Panel — Attacks
185.220.101.4RDP13,633 attemptsBlocked · 30 days
91.240.118.7SSH412 attemptsBlocked · 15 min
104.28.227.11RDP9 attemptsWatching · below threshold

Every event appears in the panel with its resource, service, and person context — the same data feeds the map and the weekly report.

Beyond RDP: Windows SSH and other network sign-ins.

Shield tells you which door is being probed with evidence, not guesses — and it protects a door most Windows tools never look at.

RDP — verified with evidence

Failed sign-ins are cross-checked against RDP service logs — an "RDP attack" is proof, not inference.

Windows SSH — closing the blind spot

Password attempts against OpenSSH on Windows show up without an IP in standard security events; that's why most tools never see them. Shield reads the SSH logs directly and blocks SSH brute-force too.

Other network sign-ins

Attempts arriving over the network (such as SMB) count toward the same meters; unattributable traffic is honestly labeled a "network sign-in".

From the field
One internet-facing Windows server, 2 hours, 535 SSH attempts.
2 hrsduration
535password attempts
1Windows server

Shield detected the attempts, attributed them to SSH, and automatically blocked the IPs that crossed the threshold in Windows Firewall. The threat isn't theoretical.

Try Shield for free

Take what Shield sees beyond Dynacop

Threat Feed API

Feed blocked-IP intelligence to your firewall or SIEM as JSON or plain text.

{
  "ip": "91.240.118.7",
  "service": "ssh",
  "attempts": 412,
  "blocked": true
}
Threat Feed →
Weekly security summary

An attack and block summary in your inbox every week — with per-customer breakdowns for MSPs.

Weekly summary — sample
Failed attempts: 12,406
Automatic blocks: 214
Targeted services: RDP 78% · SSH 14%
See the product tour →

Shield FAQ

Where are blocks enforced — in the cloud or on the machine?

On the machine. Shield decides locally and blocks the IP with a time-limited rule in the machine's own Windows Firewall. Your traffic is never routed through our cloud, and protection continues even if the internet goes down.

Can I accidentally block myself?

Three safety layers prevent this: IPs on your safe list, the IPs of real users who signed in successfully in the last 7 days, and private network addresses are never blocked at any threshold. Mistyping your password a few times doesn't make you an attacker — thresholds are tuned for real brute-force intensity.

My team is behind a VPN or a shared office IP — is that a risk?

Add your shared egress IP to the safe list and it will never be blocked. And since IPs with a successful sign-in in the last 7 days are automatically exempt, a regularly used office IP protects itself anyway.

What if the attacker keeps changing IP addresses?

Every new IP is tracked with its own counter and hits the same thresholds — switching addresses doesn't reset the game, it just gets each address blocked in turn. And since the door itself is locked with MFA, even a correct password doesn't complete the sign-in.

Do I need to install anything separate for Shield?

No. Shield lives inside the Dynacop agent — the moment you set up MFA, attack visibility and automatic blocking start working too. No separate license, no separate agent, no extra fee.

Does Shield still work if I don't use MFA?

Yes. Attack monitoring and automatic blocking work independently of your MFA policy — but together, an attacker is both stopped at the door by the code and locked out by IP. The MFA side in depth: Windows Login MFA.

Your first 10 users are free.
Protect your first Windows sign-in in about 4 minutes.

No credit card required · No minimum purchase