Windows MFA and attack blocking.
One agent, no extra cost.
Most MFA products never see attack traffic; IP-blocking tools don't verify the Windows sign-in. Dynacop combines both in one lightweight Windows agent: it verifies the authorized user with MFA and blocks the attacker IP right on the target machine.
Today you'd install two separate products. Why?
The Windows sign-in security market is split into two camps — and customers end up installing and managing two separate tools.
In our segment — no AD requirement, a multi-customer cloud console, one install — we couldn't find another product that does this. Shield isn't a separate SKU or an add-on fee: it ships with every Dynacop install.
The threshold isn't one number; you're in control.
Per-resource policy plus safety layers designed so it never locks you out by mistake.
The attempt threshold, watch window, and block duration are tuned per machine — an internet-facing RDP server and an internal accounting PC don't have to live under the same rule.
IPs on your safe list, the IPs of real users who signed in successfully in the last 7 days, and private network addresses are never blocked at any threshold.
Burst intensity within a short window AND cumulative persistence are evaluated together — fast bots and low-and-slow bots both get caught.
The blocked-IP list lives in the panel, and you can block a suspicious address by hand without waiting for the threshold.
- Source IP
- Protected machine
- Targeted account
- Sign-in service
- Attempt count
- Short-window rate
- Cumulative persistence
- Prior block history
- Safe-list status
These signals are evaluated together; an IP that crosses the threshold is blocked right in the machine's Windows Firewall.
The lifecycle of a block
The first block is short and reversible; persistence gets punished exponentially.
First block — a time-limited Windows Firewall rule
If the same IP tries again, the duration doubles each time
The escalation cap — a stubborn attacker stays out all day
IPs that cross the persistence threshold get a long-term block
Every event appears in the panel with its resource, service, and person context — the same data feeds the map and the weekly report.
Beyond RDP: Windows SSH and other network sign-ins.
Shield tells you which door is being probed with evidence, not guesses — and it protects a door most Windows tools never look at.
Failed sign-ins are cross-checked against RDP service logs — an "RDP attack" is proof, not inference.
Password attempts against OpenSSH on Windows show up without an IP in standard security events; that's why most tools never see them. Shield reads the SSH logs directly and blocks SSH brute-force too.
Attempts arriving over the network (such as SMB) count toward the same meters; unattributable traffic is honestly labeled a "network sign-in".
Shield detected the attempts, attributed them to SSH, and automatically blocked the IPs that crossed the threshold in Windows Firewall. The threat isn't theoretical.
Try Shield for freeTake what Shield sees beyond Dynacop
Feed blocked-IP intelligence to your firewall or SIEM as JSON or plain text.
{
"ip": "91.240.118.7",
"service": "ssh",
"attempts": 412,
"blocked": true
}Threat Feed →An attack and block summary in your inbox every week — with per-customer breakdowns for MSPs.
Shield FAQ
Where are blocks enforced — in the cloud or on the machine?
On the machine. Shield decides locally and blocks the IP with a time-limited rule in the machine's own Windows Firewall. Your traffic is never routed through our cloud, and protection continues even if the internet goes down.
Can I accidentally block myself?
Three safety layers prevent this: IPs on your safe list, the IPs of real users who signed in successfully in the last 7 days, and private network addresses are never blocked at any threshold. Mistyping your password a few times doesn't make you an attacker — thresholds are tuned for real brute-force intensity.
My team is behind a VPN or a shared office IP — is that a risk?
Add your shared egress IP to the safe list and it will never be blocked. And since IPs with a successful sign-in in the last 7 days are automatically exempt, a regularly used office IP protects itself anyway.
What if the attacker keeps changing IP addresses?
Every new IP is tracked with its own counter and hits the same thresholds — switching addresses doesn't reset the game, it just gets each address blocked in turn. And since the door itself is locked with MFA, even a correct password doesn't complete the sign-in.
Do I need to install anything separate for Shield?
No. Shield lives inside the Dynacop agent — the moment you set up MFA, attack visibility and automatic blocking start working too. No separate license, no separate agent, no extra fee.
Does Shield still work if I don't use MFA?
Yes. Attack monitoring and automatic blocking work independently of your MFA policy — but together, an attacker is both stopped at the door by the code and locked out by IP. The MFA side in depth: Windows Login MFA.
Your first 10 users are free.
Protect your first Windows sign-in in about 4 minutes.
No credit card required · No minimum purchase