Skip to content

Attacks and blocks in the panel

Everything Shield sees and does is visible under Audit → Attacks.

Each row is one attacking source IP against one resource:

Column Meaning
Source IP + location The attacker, with country/ISP where resolvable
Resource The targeted machine
Attempts Cumulative failed attempts
Service RDP / SSH / network — conservative labels; RDP only when proven
Usernames Which account names were tried (raw, as attempted)
First / last seen The attack’s time span
Block status Blocked (auto / persistent / manual), block pending (old agent), or ineffective — firewall off

From an attack row you can Block an IP yourself — a manual block has no expiry until you release it. Unblock releases any block early. Both actions require the security-management permission and are recorded in the admin audit log (who, when).

Manual blocks are listed alongside automatic ones but never counted in the automatic-blocks metric — the headline number stays comparable and honest.

The blocks view lists every block including released and expired ones, with:

  • origin — automatic (threshold), persistent (low-and-slow), or manual,
  • strike count — how many times this IP has re-offended (drives the escalating duration),
  • blocked-at / expires timestamps, and a release action.

Audit → Map plots sign-in sources and attack sources geographically for the last 1 / 7 / 30 days, with an attacks toggle. Location comes from Dynacop’s self-hosted GeoIP resolution — no third party sees your IPs. Sources without resolvable coordinates still appear in the attack feed — the map is a view, not the source of truth.

  • the Overview dashboard’s attack-protection card (daily blocks, most-targeted resources),
  • the weekly digest email,
  • and the Threat Feed API for your firewall or SIEM.