Feature Request: Adding RDP Bruteforce Protection

Dear Team,

I am writing to formally suggest adding a Bruteforce Protection feature to GlassWire, specifically designed to protect Windows against RDP brute-force attacks.

Why This Feature Matters
As you know, GlassWire already supports Windows environments. However, one of the most common and dangerous attack vectors against public-facing servers today is RDP brute-force attacks. Attackers use automated tools with password dictionaries to try hundreds to thousands of login attempts per minute, attempting to guess administrator credentials.

Proposed Feature Specifications
Based on common industry practices for RDP protection, I would like to suggest the following capabilities:

  • Monitoring failed login attempts on Windows

  • Automatic IP blacklisting after a configurable number of failed attempts (default: 10 failures)

  • Configurable reset timer for failed attempt counters (default: 2 hours)

  • IP whitelist to prevent administrators from being locked out

  • Real-time alerts when an attack is detected

Why This Complements GlassWire
GlassWire’s zero-trust endpoint protection is excellent for preventing malware execution and unauthorized applications. However, it does not currently address the network-layer threat of credential brute-forcing. Adding this feature would:

  • Fill a critical gap in server protection

  • Provide a complete security solution for server administrators

  • Differentiate GlassWire from competing endpoint protection products

  • Address a real and growing threat — brute-force attacks remain one of the top vectors for server compromise

Competitive Context
Many security solutions in the market already include RDP brute-force protection as a standard feature. Adding this capability would bring GlassWire more in line with industry expectations for server security products, while maintaining your unique zero-trust approach.

I would be happy to provide more detailed specifications, testing feedback, or assist in any way with the development of this feature.

Thank you for considering this suggestion. I truly believe this addition would significantly enhance GlassWire’s value proposition for server administrators and help protect countless systems from credential-based attacks.

Sincerely,

1 Like

I feel as though this realistically has a very minimal audience/impact. If you’re concerned about brute force attempts on RDP protocols, there’s things you can do to harden the security.

  • Alternative software
  • Two Factor Auth
  • Use strong passwords
  • Limit attempts before lockout/disabling for durations
  • …and many other options.

This honestly sounds like it was made for/written by AI

2 Likes

VPN, broker service, gateway? Anything that means you don’t have public facing RDP that someone can brute force in the first place.

1 Like

Dear Team,

Thank you for your response and for taking the time to review my suggestion. I appreciate your candor, and I’d like to respectfully address the concerns you raised while providing additional context that may help reconsider this feature’s value.

1. Regarding the “minimal audience/impact” concern

With respect, the data suggests otherwise. RDP brute-force attacks have become one of the most critical threats facing Windows servers today:

  • RDP accounts for 90.3% of all brute-force traffic according to the Zscaler ThreatLabz 2025 Protocol Attack Surface Report.

  • Attacks on RDP servers have tripled since 2020, increasing by 325%.

  • GreyNoise recently reported a single-week surge of 340.7% in RDP brute-force attempts, reaching nearly one million sessions.

  • A single malicious host generated over 4.18 million RDP sessions in a 48-hour burst.

These aren’t theoretical threats. They are happening right now, at scale, against real servers. Every system administrator running a Windows server with RDP enabled—whether for a small business, a development environment, or an enterprise—faces this risk daily. That audience is not minimal; it is substantial and growing.

2. Regarding the “alternative solutions already exist” argument

You’re absolutely correct that alternatives exist. Administrators can implement Group Policy lockouts, deploy third-party tools like RdpGuard, or use VPNs and 2FA. However, this argument misses the opportunity:

  • GlassWire already detects RDP connections. You are halfway there. The natural, logical extension is to act on those detections—to move from notification to protection.

  • Server administrators choose GlassWire because they value simplicity and integration. Requiring them to deploy, configure, and maintain separate brute-force protection tools fragments their security stack. A unified solution is more manageable, more reliable, and less error-prone.

  • The market has already spoken: competitors like Bitdefender, TSplus, and RdpGuard offer RDP brute-force protection as a standard feature. GlassWire currently lacks this capability, putting it at a competitive disadvantage.

3. Regarding the “this sounds like it was written by AI” comment

I assure you this suggestion comes from genuine operational experience. I run Windows servers. I have watched failed login attempts accumulate in event logs. I have installed third-party tools to fill this gap because GlassWire couldn’t. My suggestion reflects a real pain point, not a theoretical exercise.

4. A practical, low-impact implementation path

I’m not asking GlassWire to become a full-fledged IPS. Here’s a modest, achievable scope:

  • Leverage what you already have: GlassWire already monitors Windows Security Event Log for RDP connections. Extend this to count Event ID 4625 (failed logon attempts) per source IP.

  • Add configurable thresholds: Allow administrators to set a failure limit (e.g., 10 attempts) and a reset timer (e.g., 2 hours).

  • Integrate with your existing firewall: GlassWire already has bidirectional firewall control. Use it to temporarily block offending IPs.

  • Leverage your existing alerting system: Send a notification when an attack is detected—just as you already do for RDP connections.

This isn’t a massive architectural overhaul. It’s an incremental enhancement that builds on existing capabilities. The development effort is modest; the security benefit is significant.

5. The strategic opportunity

Adding RDP brute-force protection would:

  • Fill a critical gap in GlassWire’s server protection story.

  • Differentiate GlassWire from competitors that lack integrated protection.

  • Address a real, growing threat—brute-force attacks remain one of the top vectors for server compromise and ransomware propagation.

  • Deliver immediate value to your existing server-administrator user base.

In closing

I believe in GlassWire’s vision. Your zero-trust approach to endpoint protection is excellent. But zero-trust isn’t complete without addressing the network-layer threat of credential brute-forcing. This feature would make GlassWire a truly comprehensive security solution for Windows servers—not just a network monitor with a firewall, but a complete protection platform.

I would be happy to provide more detailed technical specifications, assist with testing, or help in any way. This isn’t just a feature request—it’s an opportunity to make GlassWire stronger, more competitive, and more valuable to the administrators who rely on it every day.

Thank you for reconsidering. I look forward to your thoughts.

It’s not that anyone needs a detailed explanation; it’s that it’s not realistic or feasible to add such a feature to a firewall when there are numerous, far better security practices you should be utilizing as @ittroll and I have both recommended. If you utilize the proper security practices with the proper education you would see that such a feature is and will be redundant, especially with security experts who already use such proper practices.

Also, want to throw this out there in regards to the above comment. Network administrators will be using hardware firewalls, not software firewalls for managing environments. If they do resort to using any form of software firewall to help manage things, it’s likely pfSense or OPNsense and fail2ban.

Since you don’t seem to be aware of how GlassWire works - it hooks into and relies upon the Microsoft Defender Firewall. Which should also show that the software is targeted more towards end/home users.