RDP, FTP and MS SQL brute-force protection for Windows servers

Stop RDP brute-force attacks on your Windows servers

RDP Protector is server brute-force protection in a small Windows agent paired with a cloud panel. The agent watches failed RDP, FTP and MS SQL logons and permanently bans the attacking network with a single firewall rule — RDP brute-force protection that keeps working even without an internet connection. Setup takes a couple of minutes and needs no configuration.

Free forever for one server — plus 14 days of Pro, no card required.

One brute-force protection agent for every Windows version

Server 2012R2–2025Windows 8.1 / 10 / 11x64 · x86 · ARM64near-zero CPU usage

Install the RDP brute-force protection agent

One file for everyone, no account needed to download it. Install now and connect the server whenever you like — the agent asks for an enrollment token from your panel, and protects nothing until you paste one.

Download installer (.exe)

Windows Server 2016 and newer. The PowerShell script installs the same service and is the practical choice for a fleet.

An open RDP port is under brute-force attack around the clock

Bots scan the entire internet address space and try passwords on every reachable server. It does not matter whether it is a corporate machine or a single VPS.

Thousands of login attempts per day

Within hours of going online a server starts receiving login attempts from all over the world. A typical machine with an exposed RDP port logs thousands of failed logons every day.

Server resources burned for nothing

Every attempt costs CPU time, memory, an event-log write and network traffic. A constant stream of brute-force requests creates permanent background load, slows the server down and bloats the logs.

One guessed password from a breach

A single successful guess gives full access to the machine: ransomware, data theft, spam sent from your address. Weak and reused passwords fall to dictionaries within days.

Attackers can lock out your admin account

Windows locks an account after too many failed logons. By guessing a valid username an attacker trips that limit and locks out the real administrator — a denial of service, even without ever guessing the password.

RDP Protector cuts attacks off at the firewall

The agent notices a series of failed logons and blocks the attacker's whole subnet with one Windows Firewall rule. Blocked packets are dropped before the system spends anything on them — CPU load and log noise go down, the server runs faster, and bots never get enough tries to guess a password.

Set up RDP brute-force protection in minutes

No config files and no command line: download the installer, run it, confirm the UAC prompt.

  1. 01

    Create an account

    Sign up with email or through Google/GitHub. No credit card needed.

  2. 02

    Download the installer

    You get a personal signed installer with your access token already embedded.

  3. 03

    Run it on the server

    The agent detects the RDP port on its own and adds your current IP to the whitelist so you cannot lock yourself out.

  4. 04

    Done — RDP brute-force protection is live

    The server shows up online in the panel within seconds and starts blocking attackers with sensible default settings.

Everything you need for Windows Server brute-force protection

Brute-force protection at the core, extended with shared attacker intelligence, geo rules, temporary access and central management.

01RDP, FTP and MS SQL brute-force protection

The agent reads failed logons from the Windows security log, the IIS FTP log and SQL Server's own log, and blocks the attacker locally — instantly, even with no cloud connection.

02Bans whole subnets, not single addresses

Attackers rotate addresses within their network. RDP Protector bans the whole subnet, using ASN data, with one consolidated firewall rule.

03Shared attacker database

An attack on one customer protects everyone: subnet reputation is aggregated across the platform and the worst networks are blocked before they reach you.

04Geo rules

Allow RDP only from the countries you actually work from. Everything is evaluated locally on the agent, so it stays fast and works offline.

05Temporary access

Keep the port closed by default and open it for a specific address after an MFA-confirmed request, with a timer and automatic close.

06Whitelist and strict mode

Trusted addresses and dynamic DNS names are never blocked. In strict mode only whitelisted sources may reach the port at all.

07Notifications and audit

Ban spikes, a server going offline, configuration drift — delivered by email, Telegram, Slack or webhook. Every action is recorded in an audit log.

08One lightweight agent

A single small executable running as a service. A few megabytes of memory, near-zero CPU, every Windows version and architecture.

09Central management

Server list, policies, version rollback, groups and bulk actions — all from the panel, with no inbound ports opened on your servers.

10Always-On lockout protection

Guarantees your account is never locked by Windows under brute force: the agent bans attackers before the lockout threshold and auto-unlocks protected accounts (admins + your list). On by default, on every plan.

11MSP console and white-label reports

Agencies manage every client organization from one console and send PDF security reports and invoices under their own brand, not ours.

Flat plans, no per-server surprises

Free stays free forever, no card required. Every account also gets 14 days of Pro — no card, nothing to cancel.

Free

$0/mo
1 server

Basic protection for one server. Free forever, no card.

  • RDP brute-force protection
  • Blocks the attacking address
  • 24 hours of attack history
  • Whitelist up to 3 addresses
  • Subnet bans
  • Telegram alerts
Start for free

Solo

$9/mo
1 server

Full protection for one production server.

  • Everything in Free
  • FTP and MS SQL Server protection
  • Bans the whole attacking subnet
  • Telegram, Slack and webhook alerts
  • 90 days of history
  • Shared threat database
Choose Solo
Popular

Pro

$15/mo
Up to 5 servers

For teams and small server fleets.

  • Everything in Solo
  • GeoIP rules and strict whitelist
  • Server groups
  • Full audit log with export
  • 365 days of history
  • Extra servers at $3/mo each
Choose Pro

Enterprise

$99/mo
Up to 50 servers

For agencies and companies managing many servers.

  • Everything in Pro
  • MSP console for all your clients
  • White-label PDF reports
  • Invoices for bank transfer
  • Admin and moderator roles
  • Priority support
Choose Enterprise

Need one more server than your plan includes? Add servers individually for $3 per server per month instead of jumping a tier.

14 days of Pro, free — no card

Sign up and try subnet bans, Telegram alerts, GeoIP and the shared threat database on your own server. When the trial ends your account returns to Free on its own and protection keeps running. Nothing is charged, and there is nothing to cancel.

Start the free trial

RDP brute-force protection: frequently asked questions

What exactly is free, and for how long?

Free is permanent and needs no card: RDP brute-force protection on one server, blocking of the attacking address, 24 hours of attack history and a whitelist of up to three addresses. It does not expire and it is not a trial. What the paid plans add is the ability to ban the attacker's whole subnet instead of one address at a time, FTP and MS SQL protection, Telegram alerts, GeoIP rules, longer history and the shared threat database.

How does the 14-day trial work?

Every account gets one, with no card and nothing to cancel. It unlocks the full Pro feature set on your own servers. When the 14 days are up the account returns to Free by itself and protection keeps running — subnet bans fall back to blocking single addresses, Telegram alerts switch off and history shortens to 24 hours. Nothing is ever charged automatically.

What if I need one more server than my plan includes?

Add servers individually for $3 per server per month instead of moving up a tier. Extra servers renew on the same cycle as the plan they extend.

Is it safe to install on a production server?

Yes. The agent only reads the security log of its own operating system and blocks inbound connections to the protected ports on that same machine. It makes outbound HTTPS requests only and opens no inbound ports.

Does protection work without an internet connection?

Yes. The decision to block an attacker is made locally on the agent, so protection keeps working with the last applied policy even when the cloud is unreachable.

What if I changed the RDP port?

The agent detects the actual RDP port automatically from the registry and listening sockets, and rebuilds its rules when the port changes. The FTP port is detected the same way.

Can I lock myself out?

No. During installation your current IP address is added to the whitelist, and whitelisted sources always take priority over any block.

Which Windows versions are supported?

Windows Server 2012 R2 through 2025 and Windows 8.1 / 10 / 11, on x64, x86 and ARM64. One binary with no additional runtimes to install.

How does payment work?

International payments go through PayPro Global, payments in Russia through YooKassa, with cryptocurrency available as a fallback. The Free plan is permanent and requires no card.

Protect your first Windows server today

The Free plan stays free forever. Upgrade in one click whenever you need more.

Recovery Toolbox / File Master LLC

Contact Recovery Toolbox

Contact details for Recovery Toolbox and File Master LLC, plus the profile of Victor G. Bobrov, the company's leading software development specialist and file recovery expert.

Company office

File Master LLC is the legal entity behind the Recovery Toolbox online services and software products.

File Master LLC
Serena app., office C13
Golden Sands, Varna, 9007
Bulgaria, European Union
Bulstat/VAT
180842207

About Recovery Toolbox

File Master LLC develops and supports Recovery Toolbox online services and software products for repairing damaged files, databases and mail storage formats. The company focuses on practical recovery tools for users, IT specialists and businesses that need to restore access to corrupted data.

Comments and suggestions are welcome. Please send website feedback by email: webmaster@recoverytoolbox.com

Victor G. Bobrov
Company specialist

Victor G. Bobrov

Leading Software Development Specialist and File Recovery Expert

Victor G. Bobrov works with Recovery Toolbox / File Master LLC on file structure analysis, damaged file recovery, database recovery and online repair services.

  • File recovery
  • Data recovery
  • Online repair services
  • MCSD
  • MCDBA
About the author →

Microsoft certifications

Microsoft Certified Solutions Developer — MCSD. Microsoft Certified Database Administrator — MCDBA.

MCSD MCDBA