Blocks malicious IP addresses by detecting failed login attempts from event viewers and log files.

IPBan is an open-source web app and server that protects servers by blocking malicious IP addresses. It monitors system logs and event viewers to detect failed login attempts, automatically updating firewall rules to ban intruders. The software is available for Windows and various Linux distributions, including Ubuntu, Debian, CentOS, and RedHat, making it a versatile choice for managing network security across different operating systems.
Users install the application as a background service to ensure continuous monitoring. On Windows, it is deployed via a PowerShell script, while Linux installations are handled through a bash script. The software supports both IPv4 and IPv6 across all compatible platforms and requires administrative or root privileges to manage firewall rules. It is designed to run on Windows 10 or newer and Windows Server 2016 or newer, as well as x64 and ARM architectures on supported Linux distributions.
Built using .NET, the application is designed for server administrators who need to mitigate botnets and brute-force attacks. It allows for the addition of custom application recipes via a configuration file to extend monitoring beyond the default services, such as Exchange, SmarterMail, and MailEnable. The architecture focuses on speed to ensure that the firewall implementation remains the only primary bottleneck in the banning process. Users can build a self-contained executable to eliminate the need for the .NET runtime on the server machine.
IPBan serves as a security layer for dedicated or cloud servers requiring automated intrusion prevention and threat detection.
A network-wide DNS sinkhole that blocks unwanted content for all devices on a local network.
Automate security workflows and playbooks using a low code builder with integrated AI agents and case management.
Join our newsletter to get shiny new open source software delivered to your inbox. Unsubscribe anytime.