Observed arrival · 2026-10-09
LogonShield: Windows server login-failure blocking
A Windows utility that watches server login failures and adds repeat-offending IP addresses to Windows Firewall block rules.
○Open
⊠Login
$Paid
†Ads
✦Pretty
●Pro
◎Niche
◉Human
⚑Risk
ƒJS
- For
- Administrators of Windows servers facing repeated login attempts
- Worth noticing
- Its default rule blocks an IP after five failures in ten minutes, then removes the firewall rule after 24 hours.
Field notes
LogonShield is described as a Windows service that keeps monitoring when no user is logged in. Its service list names the log source and failed-login marker for each supported service, including RDP event 4625 and MS-SQL event 18456. The page also describes whitelist handling, manual release, and CSV export; the displayed requirements are 64-bit Windows 10 or Server 2016 and later.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
○OpenPublic substance visible
$PaidCommerce or pricing visible
◎NicheUnusually specific use
One card from the complete issue