Dear Team,
Thank you for your response and for taking the time to review my suggestion. I appreciate your candor, and I’d like to respectfully address the concerns you raised while providing additional context that may help reconsider this feature’s value.
1. Regarding the “minimal audience/impact” concern
With respect, the data suggests otherwise. RDP brute-force attacks have become one of the most critical threats facing Windows servers today:
-
RDP accounts for 90.3% of all brute-force traffic according to the Zscaler ThreatLabz 2025 Protocol Attack Surface Report.
-
Attacks on RDP servers have tripled since 2020, increasing by 325%.
-
GreyNoise recently reported a single-week surge of 340.7% in RDP brute-force attempts, reaching nearly one million sessions.
-
A single malicious host generated over 4.18 million RDP sessions in a 48-hour burst.
These aren’t theoretical threats. They are happening right now, at scale, against real servers. Every system administrator running a Windows server with RDP enabled—whether for a small business, a development environment, or an enterprise—faces this risk daily. That audience is not minimal; it is substantial and growing.
2. Regarding the “alternative solutions already exist” argument
You’re absolutely correct that alternatives exist. Administrators can implement Group Policy lockouts, deploy third-party tools like RdpGuard, or use VPNs and 2FA. However, this argument misses the opportunity:
-
GlassWire already detects RDP connections. You are halfway there. The natural, logical extension is to act on those detections—to move from notification to protection.
-
Server administrators choose GlassWire because they value simplicity and integration. Requiring them to deploy, configure, and maintain separate brute-force protection tools fragments their security stack. A unified solution is more manageable, more reliable, and less error-prone.
-
The market has already spoken: competitors like Bitdefender, TSplus, and RdpGuard offer RDP brute-force protection as a standard feature. GlassWire currently lacks this capability, putting it at a competitive disadvantage.
3. Regarding the “this sounds like it was written by AI” comment
I assure you this suggestion comes from genuine operational experience. I run Windows servers. I have watched failed login attempts accumulate in event logs. I have installed third-party tools to fill this gap because GlassWire couldn’t. My suggestion reflects a real pain point, not a theoretical exercise.
4. A practical, low-impact implementation path
I’m not asking GlassWire to become a full-fledged IPS. Here’s a modest, achievable scope:
-
Leverage what you already have: GlassWire already monitors Windows Security Event Log for RDP connections. Extend this to count Event ID 4625 (failed logon attempts) per source IP.
-
Add configurable thresholds: Allow administrators to set a failure limit (e.g., 10 attempts) and a reset timer (e.g., 2 hours).
-
Integrate with your existing firewall: GlassWire already has bidirectional firewall control. Use it to temporarily block offending IPs.
-
Leverage your existing alerting system: Send a notification when an attack is detected—just as you already do for RDP connections.
This isn’t a massive architectural overhaul. It’s an incremental enhancement that builds on existing capabilities. The development effort is modest; the security benefit is significant.
5. The strategic opportunity
Adding RDP brute-force protection would:
-
Fill a critical gap in GlassWire’s server protection story.
-
Differentiate GlassWire from competitors that lack integrated protection.
-
Address a real, growing threat—brute-force attacks remain one of the top vectors for server compromise and ransomware propagation.
-
Deliver immediate value to your existing server-administrator user base.
In closing
I believe in GlassWire’s vision. Your zero-trust approach to endpoint protection is excellent. But zero-trust isn’t complete without addressing the network-layer threat of credential brute-forcing. This feature would make GlassWire a truly comprehensive security solution for Windows servers—not just a network monitor with a firewall, but a complete protection platform.
I would be happy to provide more detailed technical specifications, assist with testing, or help in any way. This isn’t just a feature request—it’s an opportunity to make GlassWire stronger, more competitive, and more valuable to the administrators who rely on it every day.
Thank you for reconsidering. I look forward to your thoughts.