The problem
Every VPS with a public SSH port gets hammered around the clock by bots guessing passwords. Most attempts fail — but the noise hides targeted attacks, and a single weak password anywhere on the server is enough. Reading /var/log/secure by hand is nobody’s idea of monitoring.
The solution
VpsMonitor.Pro’s SSH brute-force check counts failed logins per day and grades the result, so a sudden surge turns the Security tile red and fires an email alert. The Security view goes further: it scans web-attack logs (ModSecurity) too, groups attackers by IP with country lookup and attack counts, and lets you block any of them via the CSF firewall with one click.
Turn on auto-block and the app does it for you on an interval you choose: foreign attackers above your threshold are blocked automatically, while IPs from your own protected country are held for manual review so you never lock out a real customer. Your own IP and a whitelist are always protected from blocking — the app even auto-detects the address you are connecting from.
Every action lands in an audit log (who was blocked, when and why), with a blocked-IPs list you can review or undo at any time.
Frequently asked questions
Will auto-block lock me out of my own server?
No. The scanner always skips the current SSH client IP, private addresses and everything on your whitelist — protection against self-lockout is built in.
What is a normal number of failed SSH logins?
Hundreds per day is background noise on any public server. The check alerts on unusual surges, which usually mean a coordinated or targeted attack.
Does blocking use iptables directly?
It uses CSF (ConfigServer Security & Firewall), the firewall manager standard on SPanel/cPanel servers, so blocks survive reboots and are easy to list and remove.
Get a license · Download free — 7-day trial