RDP security guides
Practical write-ups on how password-guessing attacks against Windows servers actually work, how to read what your own event log is telling you, and which defences are worth the effort.
All guides
What an RDP brute-force attack actually looks like
Anatomy of the attack that hits every Windows server exposed to the internet: who runs it, what it costs them, why the standard advice only half works, and what stops it.
Windows Event ID 4625: how to read a failed logon
Every field in a 4625 event, what the status codes mean, and how to tell a user who mistyped their password from a botnet working through a dictionary.
Fail2ban for Windows: what the real equivalents are
There is no fail2ban on Windows. Here is what the DIY PowerShell version looks like, where it breaks, and what the alternatives actually give you.
Changing the RDP port from 3389: what it fixes and what it doesn't
Moving RDP off its default port cuts attack volume dramatically and protects you from almost nothing. Both halves of that are worth understanding before you do it.
Port 3389 open to the internet: what actually happens
An hour-by-hour account of what reaches a Windows server the moment RDP becomes publicly reachable, how to check whether yours is, and what to do about it.
Windows Server hardening checklist for internet-facing hosts
An ordered checklist for a Windows server that has to be reachable from the internet — what to do first, what most lists get wrong, and what you can safely leave until later.
RDP vs VPN: which one your servers actually need
A VPN in front of RDP is the textbook answer and often the wrong one. What each approach actually changes, what it costs to run, and how to choose without pretending.
See it against your own attack stream
One server, free forever, no card. The agent installs in a minute and whitelists your current address before it blocks anything.
