Thousands of login attempts per day
Within hours of going online a server starts receiving login attempts from all over the world. A typical machine with an exposed RDP port logs thousands of failed logons every day.
RDP Protector is server brute-force protection in a small Windows agent paired with a cloud panel. The agent watches failed RDP, FTP and MS SQL logons and permanently bans the attacking network with a single firewall rule — RDP brute-force protection that keeps working even without an internet connection. Setup takes a couple of minutes and needs no configuration.
Free forever for one server — plus 14 days of Pro, no card required.
One brute-force protection agent for every Windows version
One file for everyone, no account needed to download it. Install now and connect the server whenever you like — the agent asks for an enrollment token from your panel, and protects nothing until you paste one.
Windows Server 2016 and newer. The PowerShell script installs the same service and is the practical choice for a fleet.
Bots scan the entire internet address space and try passwords on every reachable server. It does not matter whether it is a corporate machine or a single VPS.
Within hours of going online a server starts receiving login attempts from all over the world. A typical machine with an exposed RDP port logs thousands of failed logons every day.
Every attempt costs CPU time, memory, an event-log write and network traffic. A constant stream of brute-force requests creates permanent background load, slows the server down and bloats the logs.
A single successful guess gives full access to the machine: ransomware, data theft, spam sent from your address. Weak and reused passwords fall to dictionaries within days.
Windows locks an account after too many failed logons. By guessing a valid username an attacker trips that limit and locks out the real administrator — a denial of service, even without ever guessing the password.
The agent notices a series of failed logons and blocks the attacker's whole subnet with one Windows Firewall rule. Blocked packets are dropped before the system spends anything on them — CPU load and log noise go down, the server runs faster, and bots never get enough tries to guess a password.
No config files and no command line: download the installer, run it, confirm the UAC prompt.
Sign up with email or through Google/GitHub. No credit card needed.
You get a personal signed installer with your access token already embedded.
The agent detects the RDP port on its own and adds your current IP to the whitelist so you cannot lock yourself out.
The server shows up online in the panel within seconds and starts blocking attackers with sensible default settings.
Brute-force protection at the core, extended with shared attacker intelligence, geo rules, temporary access and central management.
The agent reads failed logons from the Windows security log, the IIS FTP log and SQL Server's own log, and blocks the attacker locally — instantly, even with no cloud connection.
Attackers rotate addresses within their network. RDP Protector bans the whole subnet, using ASN data, with one consolidated firewall rule.
An attack on one customer protects everyone: subnet reputation is aggregated across the platform and the worst networks are blocked before they reach you.
Allow RDP only from the countries you actually work from. Everything is evaluated locally on the agent, so it stays fast and works offline.
Keep the port closed by default and open it for a specific address after an MFA-confirmed request, with a timer and automatic close.
Trusted addresses and dynamic DNS names are never blocked. In strict mode only whitelisted sources may reach the port at all.
Ban spikes, a server going offline, configuration drift — delivered by email, Telegram, Slack or webhook. Every action is recorded in an audit log.
A single small executable running as a service. A few megabytes of memory, near-zero CPU, every Windows version and architecture.
Server list, policies, version rollback, groups and bulk actions — all from the panel, with no inbound ports opened on your servers.
Guarantees your account is never locked by Windows under brute force: the agent bans attackers before the lockout threshold and auto-unlocks protected accounts (admins + your list). On by default, on every plan.
Agencies manage every client organization from one console and send PDF security reports and invoices under their own brand, not ours.
Free stays free forever, no card required. Every account also gets 14 days of Pro — no card, nothing to cancel.
Basic protection for one server. Free forever, no card.
Full protection for one production server.
For teams and small server fleets.
For agencies and companies managing many servers.
Need one more server than your plan includes? Add servers individually for $3 per server per month instead of jumping a tier.
Sign up and try subnet bans, Telegram alerts, GeoIP and the shared threat database on your own server. When the trial ends your account returns to Free on its own and protection keeps running. Nothing is charged, and there is nothing to cancel.
Free is permanent and needs no card: RDP brute-force protection on one server, blocking of the attacking address, 24 hours of attack history and a whitelist of up to three addresses. It does not expire and it is not a trial. What the paid plans add is the ability to ban the attacker's whole subnet instead of one address at a time, FTP and MS SQL protection, Telegram alerts, GeoIP rules, longer history and the shared threat database.
Every account gets one, with no card and nothing to cancel. It unlocks the full Pro feature set on your own servers. When the 14 days are up the account returns to Free by itself and protection keeps running — subnet bans fall back to blocking single addresses, Telegram alerts switch off and history shortens to 24 hours. Nothing is ever charged automatically.
Add servers individually for $3 per server per month instead of moving up a tier. Extra servers renew on the same cycle as the plan they extend.
Yes. The agent only reads the security log of its own operating system and blocks inbound connections to the protected ports on that same machine. It makes outbound HTTPS requests only and opens no inbound ports.
Yes. The decision to block an attacker is made locally on the agent, so protection keeps working with the last applied policy even when the cloud is unreachable.
The agent detects the actual RDP port automatically from the registry and listening sockets, and rebuilds its rules when the port changes. The FTP port is detected the same way.
No. During installation your current IP address is added to the whitelist, and whitelisted sources always take priority over any block.
Windows Server 2012 R2 through 2025 and Windows 8.1 / 10 / 11, on x64, x86 and ARM64. One binary with no additional runtimes to install.
International payments go through PayPro Global, payments in Russia through YooKassa, with cryptocurrency available as a fallback. The Free plan is permanent and requires no card.
The Free plan stays free forever. Upgrade in one click whenever you need more.
Contact details for Recovery Toolbox and File Master LLC, plus the profile of Victor G. Bobrov, the company's leading software development specialist and file recovery expert.
File Master LLC is the legal entity behind the Recovery Toolbox online services and software products.
File Master LLC develops and supports Recovery Toolbox online services and software products for repairing damaged files, databases and mail storage formats. The company focuses on practical recovery tools for users, IT specialists and businesses that need to restore access to corrupted data.
Comments and suggestions are welcome. Please send website feedback by email: webmaster@recoverytoolbox.com

Leading Software Development Specialist and File Recovery Expert
Victor G. Bobrov works with Recovery Toolbox / File Master LLC on file structure analysis, damaged file recovery, database recovery and online repair services.
About the author →Microsoft Certified Solutions Developer — MCSD. Microsoft Certified Database Administrator — MCDBA.