ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    TS_Block

    IT Discussion
    5
    15
    1.6k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      Jason Banned
      last edited by

      A Nice script we started using in addtional to our firewalls nice thing is we scripted it to be able to add to our palto alto and not just the windows box and even email us when it blocks it and what IP. : https://github.com/EvanAnderson/ts_block

      1 Reply Last reply Reply Quote 3
      • syko24S
        syko24
        last edited by

        For a while we were using the free version of Cyberarms. They recently changed their model and now offer their full product for free. It covers more than RDP which is nice. Great for OWA and other exposed Windows services.

        www.cyberarms.net

        J 1 Reply Last reply Reply Quote 0
        • JaredBuschJ
          JaredBusch
          last edited by

          There was some other tool mentioned a year or so ago that is basically fail2ban for windows. I meant to set it up and something made me forget.. back to looking at this stuff.

          J scottalanmillerS 2 Replies Last reply Reply Quote 0
          • J
            Jason Banned @syko24
            last edited by

            @syko24 said in TS_Block:

            For a while we were using the free version of Cyberarms. They recently changed their model and now offer their full product for free. It covers more than RDP which is nice. Great for OWA and other exposed Windows services.

            www.cyberarms.net

            It doesn't seem to do as much as the VB script. with that you can set it so with certian accounts are used they are instantly ban. for us we modified the script to make it so any user not a member of certain groups results in an instant ban.

            1 Reply Last reply Reply Quote 0
            • J
              Jason Banned @JaredBusch
              last edited by

              @JaredBusch said in TS_Block:

              There was some other tool mentioned a year or so ago that is basically fail2ban for windows. I meant to set it up and something made me forget.. back to looking at this stuff.

              RDPGuard is the one a lot of people use, but a non-admin can even modify that one.. and I like scripts.

              JaredBuschJ 1 Reply Last reply Reply Quote 1
              • JaredBuschJ
                JaredBusch @Jason
                last edited by

                @Jason said in TS_Block:

                @JaredBusch said in TS_Block:

                There was some other tool mentioned a year or so ago that is basically fail2ban for windows. I meant to set it up and something made me forget.. back to looking at this stuff.

                RDPGuard is the one a lot of people use, but a non-admin can even modify that one.. and I like scripts.

                Can the script monitor a webpage such as OWA or RDWEB?

                1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @JaredBusch
                  last edited by

                  @JaredBusch said in TS_Block:

                  There was some other tool mentioned a year or so ago that is basically fail2ban for windows. I meant to set it up and something made me forget.. back to looking at this stuff.

                  @Mike-Davis set it up for some RDS servers.

                  JaredBuschJ 1 Reply Last reply Reply Quote 0
                  • JaredBuschJ
                    JaredBusch @scottalanmiller
                    last edited by

                    @scottalanmiller said in TS_Block:

                    @JaredBusch said in TS_Block:

                    There was some other tool mentioned a year or so ago that is basically fail2ban for windows. I meant to set it up and something made me forget.. back to looking at this stuff.

                    @Mike-Davis set it up for some RDS servers.

                    Right, but I want to protect OWA also.

                    scottalanmillerS 1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @JaredBusch
                      last edited by

                      @JaredBusch said in TS_Block:

                      @scottalanmiller said in TS_Block:

                      @JaredBusch said in TS_Block:

                      There was some other tool mentioned a year or so ago that is basically fail2ban for windows. I meant to set it up and something made me forget.. back to looking at this stuff.

                      @Mike-Davis set it up for some RDS servers.

                      Right, but I want to protect OWA also.

                      Not sure which tool does that.

                      JaredBuschJ 1 Reply Last reply Reply Quote 0
                      • JaredBuschJ
                        JaredBusch @scottalanmiller
                        last edited by

                        @scottalanmiller said in TS_Block:

                        @JaredBusch said in TS_Block:

                        @scottalanmiller said in TS_Block:

                        @JaredBusch said in TS_Block:

                        There was some other tool mentioned a year or so ago that is basically fail2ban for windows. I meant to set it up and something made me forget.. back to looking at this stuff.

                        @Mike-Davis set it up for some RDS servers.

                        Right, but I want to protect OWA also.

                        Not sure which tool does that.

                        RDPGuard says it does. But I do not want to buy it if a scripted solution works.

                        0_1475603919681_upload-252ff996-3aea-4516-97f8-952157f13313

                        1 Reply Last reply Reply Quote 0
                        • JaredBuschJ
                          JaredBusch
                          last edited by JaredBusch

                          RDPGuard Pricing.

                          0_1475604211228_upload-73c93fb5-df9a-44b9-bd67-6e14556c619c

                          Price is per computer.

                          So for me to protect RDS and OWA I will need two.

                          1 Reply Last reply Reply Quote 0
                          • J
                            Jason Banned
                            last edited by

                            The script uses logon auditing. I'm not sure if owa makes an event log for failed audits but if it does it will work. There is another script that is suppose to work for other stuff. I'll have to find it again.

                            1 Reply Last reply Reply Quote 1
                            • Mike DavisM
                              Mike Davis
                              last edited by

                              RDPGuard has as free 30 day trial. As easy as it is to install, I would test it to see if it works.

                              I guess it depends what your time is worth if you want to try to script something.

                              J 1 Reply Last reply Reply Quote 0
                              • J
                                Jason Banned @Mike Davis
                                last edited by

                                @Mike-Davis said in TS_Block:

                                I guess it depends what your time is worth if you want to try to script something.

                                Scripting isn't about trying to save money. Doing the script cost way more in time than what that thing costs. Scripts are way more flexible than a program. You can add more variables and even pass off arguments to other systems.

                                JaredBuschJ 1 Reply Last reply Reply Quote 3
                                • JaredBuschJ
                                  JaredBusch @Jason
                                  last edited by

                                  @Jason said in TS_Block:

                                  @Mike-Davis said in TS_Block:

                                  I guess it depends what your time is worth if you want to try to script something.

                                  Scripting isn't about trying to save money. Doing the script cost way more in time than what that thing costs. Scripts are way more flexible than a program. You can add more variables and even pass off arguments to other systems.

                                  Also a script, once completed, can be replicated for no additional outlay of time beyond deployment. So it can scale to every Windows device needed in this case.

                                  1 Reply Last reply Reply Quote 2
                                  • 1 / 1
                                  • First post
                                    Last post