SSH Protector is a small Linux agent paired with a cloud panel. The agent watches failed SSH and FTP logons, blocks the attacking network with a single firewall rule and keeps working even without an internet connection. Setup takes a couple of minutes and needs no configuration.
The free version includes full protection for one server.
One agent for every Linux distribution
One binary for everyone, no account needed to download it. Install now and connect the server whenever you like — the agent asks for an enrollment token from your panel, and protects nothing until you paste one.
Any modern systemd-based Linux — Debian, Ubuntu, RHEL/CentOS/Alma/Rocky, Fedora — on x86-64 or ARM64. The script installs the same service and is the practical choice for a fleet.
Bots scan the entire internet address space and try passwords on every reachable server. It does not matter whether it is a corporate machine or a single VPS.
The agent notices a series of failed logons and blocks the attacker's whole subnet with one nftables rule. Blocked packets are dropped before the system spends anything on them — CPU load and log noise go down, the server runs faster, and bots never get enough tries to guess a password.
No config files and no command line: download the installer, run it, confirm the sudo prompt.
Sign up with email or through Google/GitHub. No credit card needed.
You get a personal signed installer with your access token already embedded.
The agent detects the SSH port on its own and adds your current IP to the whitelist so you cannot lock yourself out.
The server shows up online in the panel within seconds and starts blocking attackers with sensible default settings.
Brute-force protection at the core, extended with shared attacker intelligence, geo rules, temporary access and central management.
The agent reads failed logons from the systemd journal (journald) and the FTP server logs and blocks the attacker locally — instantly, even with no cloud connection.
Attackers rotate addresses within their network. SSH Protector bans the whole subnet, using ASN data, with one consolidated firewall rule.
An attack on one customer protects everyone: subnet reputation is aggregated across the platform and the worst networks are blocked before they reach you.
Allow SSH only from the countries you actually work from. Everything is evaluated locally on the agent, so it stays fast and works offline.
Keep the port closed by default and open it for a specific address after an MFA-confirmed request, with a timer and automatic close.
Trusted addresses and dynamic DNS names are never blocked. In strict mode only whitelisted sources may reach the port at all.
Ban spikes, a server going offline, configuration drift — delivered by email, Telegram, Slack or webhook. Every action is recorded in an audit log.
A single small executable running as a service. A few megabytes of memory, near-zero CPU, every major Linux distribution and architecture.
Server list, policies, version rollback, groups and bulk actions — all from the panel, with no inbound ports opened on your servers.
Guarantees your account is never locked out under brute force: the agent bans attackers before the PAM faillock threshold and auto-unlocks protected accounts (admins + your list). On by default, on every plan.
Free stays free forever, no card required. Paid plans have a fixed price with a set number of servers included.
Basic SSH protection for a single server.
Full protection for one production server.
For teams and small server fleets.
For companies with a large server fleet.
Need one more server than your plan includes? Add servers individually for $3 per server per month instead of jumping a tier.
Sign up and try subnet bans, Telegram alerts, GeoIP and the shared threat database on your own server. When the trial ends your account returns to Free on its own and protection keeps running. Nothing is charged, and there is nothing to cancel.
Yes. The agent only reads the auth log of its own operating system and blocks inbound connections to the protected ports on that same machine. It makes outbound HTTPS requests only and opens no inbound ports.
Yes. The decision to block an attacker is made locally on the agent, so protection keeps working with the last applied policy even when the cloud is unreachable.
The agent detects the actual SSH port automatically from sshd_config and listening sockets, and rebuilds its rules when the port changes. The FTP port is detected the same way.
No. During installation your current IP address is added to the whitelist, and whitelisted sources always take priority over any block.
Any modern systemd-based distribution — Debian, Ubuntu, RHEL/CentOS/Alma/Rocky, Fedora — on x86-64 and ARM64. One static binary with no additional runtimes to install.
International payments go through PayPro Global, payments in Russia through YooKassa, with cryptocurrency available as a fallback. The Free plan is permanent and requires no card.
The Free plan stays free forever. Upgrade in one click whenever you need more.
Contact details for Recovery Toolbox and File Master LLC, plus the profile of Victor G. Bobrov, the company's leading software development specialist and file recovery expert.
File Master LLC is the legal entity behind the Recovery Toolbox online services and software products.
File Master LLC develops and supports Recovery Toolbox online services and software products for repairing damaged files, databases and mail storage formats. The company focuses on practical recovery tools for users, IT specialists and businesses that need to restore access to corrupted data.
Comments and suggestions are welcome. Please send website feedback by email: webmaster@recoverytoolbox.com

Leading Software Development Specialist and File Recovery Expert
Victor G. Bobrov works with Recovery Toolbox / File Master LLC on file structure analysis, damaged file recovery, database recovery and online repair services.
About the author →Microsoft Certified Solutions Developer — MCSD. Microsoft Certified Database Administrator — MCDBA.