gvalkov's Intrusion Prevention System

Description

☂︎ Monitors the Security Event Log for authentication failures
☂︎ Blocks attackers using a blacklist filter in IP Security Policies

Command line options

The command line options can also be triggered manually while the application is running: press ~ to enable the debug console or F1 for help.

CMDgips [WAiIanh?EDsfbc][…]CMDDescription
WWrite initial IPsec policyEErase gIPS IPsec policy
AActivate gIPS IPsec policyDDeactivate gIPS IPsec policy
iService installUDeactivate gIPS IPsec policy
IService install interactivesService start
uService uninstallqService stop
aShow whitelisted addressesrService resume
nShow whitelisted user namespService pause
aAutopause enablefLog to file
dAutopause disablebShow blocked hosts
hShow helpcOpen config path in regedit
?Show help F1~Debug console

Sample use: Install as a service, create and activate IPsec policy for blocked hosts

"C:\Windows\gvalkov\gips.exe" WAis

Configuration path

These two registry locations are searched for configuration, the first found is used:

SYSTEM\CurrentControlSet\Services\gvalkov.IPS\Parameters
SYSTEM\CurrentControlSet\services\eventlog\Application\gvalkov.IPS

Supported Platforms

☂︎ Windows

Prerequisites and build instructions

© 2011-2023 Georgi Valkov

https://httpstorm.com/download/windows/gips/