Random Forest 本機 AI
在主機本機分析目的連接埠、封包長度與 TCP 視窗等特徵, 協助辨識 SYN Flood、掃描機器人與異常連線.
核心能力
在主機本機分析目的連接埠、封包長度與 TCP 視窗等特徵, 協助辨識 SYN Flood、掃描機器人與異常連線.
偵測到攻擊來源後建立專屬 Windows 防火牆規則, 並在介面顯示封鎖狀態與剩餘時間.
彙整 Abuse.ch、Cisco Talos、Emerging Threats 等公開情報來源; 已知惡意 IP 命中時立即進入防禦流程.
可排除可信任的單一 IP、CIDR 網段及服務連接埠, 降低重要服務遭誤判的風險.
選用 Cloudflare API, 將經可信 Nginx 日誌確認的真實攻擊者封鎖在雲端邊緣.
每天 02:30 自動向雲端取得最新 AI 模型, 並同步更新威脅情報.
首次成功啟用時將授權綁定至該裝置, 降低序號遭未授權分享與濫用的風險.
為 Minecraft 伺服器、Web API、NAS 與小型 Windows 主機設計, 並持續針對背景運行與資源使用進行最佳化.
購買內容
完整的 Windows 安全應用程式, 內含核心 AI 防禦引擎及必要安裝資源.
授權期間可同步經整理、去重與驗證格式的 30,000+ 惡意 IP 情報.
可選 30 天或 365 天; 有效天數從第一次成功啟用後才開始計算.
取得技術協助、版本消息與即時威脅更新.加入 Discord
部署方式
支援 Windows 10、Windows 11 與 Windows Server 2016 以上版本. 只需安裝 CyberSentinel 與 Npcap, 即可監控直接到達主機的流量, 並透過 Windows 防火牆封鎖可疑來源.
網站位於 Cloudflare 代理後方時, 封包來源會是共用的 Cloudflare 節點. CyberSentinel 可從受信任的 Nginx Access Log 取得真實訪客 IP, 再透過 Cloudflare API 精準封鎖攻擊者.
常見問題
是. Npcap 是 CyberSentinel 擷取與分析網路封包的必要驅動. 程式偵測不到 Npcap 時會引導安裝, 沒有它便無法啟動完整防禦引擎.
不需要. 一般 Windows 主機或直接對外的服務只需要 Npcap. 只有網站已使用 Cloudflare 代理, 並希望針對真實訪客進行抗 DDoS/惡意請求聯動時, 才需要設定 Nginx 與 Cloudflare.
Cloudflare 會讓主機在網路層看到共用邊緣節點 IP, 而不是真實訪客. 受信任的 Nginx 日誌能提供經 Cloudflare 驗證的訪客 IP, 避免把共用節點當成攻擊者.
程式會識別 Cloudflare 官方網段並拒絕將共用節點當作訪客封鎖. Cloudflare 模式只會處理從受信任 Nginx 日誌取得的真實 IP.
可以. 設定頁支援白名單連接埠、單一 IP 及 CIDR 網段; 符合白名單的流量不會進入自動封鎖流程.
不是. CyberSentinel 專注於網路流量偵測、威脅情報與自動封鎖, 不能取代防毒、端點偵測回應 (EDR) 、備份或系統更新.
需要. 管理員權限用於封包監控與 Windows 防火牆規則; 網路連線則用於授權驗證、模型與威脅情報同步, 以及選用的 Cloudflare API.
不會. 30 天或 365 天的有效期限會在授權碼第一次成功啟用時開始計算, 購買後尚未啟用的時間不會被扣除.
任何單一主機端工具都無法保證阻擋所有 DDoS. CyberSentinel 可縮短偵測與封鎖時間; 若攻擊已塞滿上游頻寬, 仍需要上游清洗或 CDN 防護.
官方商城提供 30 天及 365 天授權方案, 付款完成後自動發送授權碼與下載連結.
查看授權方案Stop threats before they hit your server.
Powered by machine learning and global threat intelligence. Built for solo developers, home-server enthusiasts, and small businesses, CyberSentinel combines local AI inference, cloud-based collective intelligence, and Windows Firewall automation.
Core capabilities
Analyzes destination port, packet length, and TCP window size locally to help identify SYN floods, scanning bots, and abnormal connections.
Creates dedicated Windows Firewall rules for detected sources and shows each active block with its remaining time.
Combines public intelligence from Abuse.ch, Cisco Talos, Emerging Threats, and other feeds so known malicious IPs enter the defense flow immediately.
Exclude trusted IP addresses, CIDR networks, and service ports to reduce the risk of blocking important traffic.
Optionally use the Cloudflare API to block the verified real attacker obtained from trusted Nginx logs at the edge.
Downloads the latest AI model from the cloud every day at 02:30 and keeps threat intelligence refreshed.
Binds the license to the device on its first successful activation to reduce unauthorized key sharing and abuse.
Designed for Minecraft servers, Web APIs, NAS environments, and small Windows hosts, with ongoing optimization for background operation.
What is included
A complete Windows security application containing the core AI defense engine and required installation resources.
Synchronize more than 30,000 curated, deduplicated malicious IP indicators while your license is active.
Choose 30 or 365 days. Subscription time begins only after the first successful activation.
Get technical support, release news, and live threat updates.Join Discord
Deployment
Supports Windows 10, Windows 11, and Windows Server 2016 or later. Install CyberSentinel and Npcap to monitor traffic reaching the host directly and block suspicious sources through Windows Firewall.
When a site is proxied by Cloudflare, packet-level traffic comes from shared Cloudflare edges. CyberSentinel can read the verified visitor IP from a trusted Nginx access log and use the Cloudflare API to block the actual attacker.
Frequently asked questions
Yes. Npcap is the packet-capture driver required by CyberSentinel. The application guides you through installation when it is missing; the complete defense engine cannot run without it.
No. A standard Windows host or directly exposed service only needs Npcap. Nginx and Cloudflare are needed only when your website is already behind the Cloudflare proxy and you want DDoS or malicious-request integration using the real visitor IP.
At the network layer, the host sees a shared Cloudflare edge address instead of the visitor. A trusted Nginx log supplies the Cloudflare-verified visitor IP so the shared edge is not mistaken for the attacker.
CyberSentinel recognizes official Cloudflare networks and refuses to treat shared edge addresses as visitors. Cloudflare mode acts only on real IPs obtained from the trusted Nginx log format.
Yes. Settings support allowlisted ports, individual IP addresses, and CIDR networks. Matching traffic is excluded from automatic blocking.
No. CyberSentinel focuses on network traffic detection, threat intelligence, and automated blocking. It does not replace antivirus, EDR, backups, or operating-system updates.
Yes. Administrator privileges are required for packet monitoring and Windows Firewall rules. Internet access is used for license validation, model and threat-intelligence updates, and optional Cloudflare API access.
No. The 30-day or 365-day term begins when the license key is successfully activated for the first time. Time spent unactivated after purchase is not deducted.
No single host-level tool can guarantee that. CyberSentinel can reduce detection and blocking time, but an attack that saturates upstream bandwidth still requires provider-side scrubbing or CDN protection.
The official store offers 30-day and 365-day licenses. Your license key and download link are delivered automatically after payment.
View license plans