Attacks and blocks in the panel
Everything Shield sees and does is visible under Audit → Attacks.
The attack feed
Section titled “The attack feed”Each row is one attacking source IP against one resource:
| Column | Meaning |
|---|---|
| Source IP + location | The attacker, with country/ISP where resolvable |
| Resource | The targeted machine |
| Attempts | Cumulative failed attempts |
| Service | RDP / SSH / network — conservative labels; RDP only when proven |
| Usernames | Which account names were tried (raw, as attempted) |
| First / last seen | The attack’s time span |
| Block status | Blocked (auto / persistent / manual), block pending (old agent), or ineffective — firewall off |
Manual block and unblock
Section titled “Manual block and unblock”From an attack row you can Block an IP yourself — a manual block has no expiry until you release it. Unblock releases any block early. Both actions require the security-management permission and are recorded in the admin audit log (who, when).
Manual blocks are listed alongside automatic ones but never counted in the automatic-blocks metric — the headline number stays comparable and honest.
Block history
Section titled “Block history”The blocks view lists every block including released and expired ones, with:
- origin — automatic (threshold), persistent (low-and-slow), or manual,
- strike count — how many times this IP has re-offended (drives the escalating duration),
- blocked-at / expires timestamps, and a release action.
The map
Section titled “The map”Audit → Map plots sign-in sources and attack sources geographically for the last 1 / 7 / 30 days, with an attacks toggle. Location comes from Dynacop’s self-hosted GeoIP resolution — no third party sees your IPs. Sources without resolvable coordinates still appear in the attack feed — the map is a view, not the source of truth.
Attacks also feed…
Section titled “Attacks also feed…”- the Overview dashboard’s attack-protection card (daily blocks, most-targeted resources),
- the weekly digest email,
- and the Threat Feed API for your firewall or SIEM.