ShdGuard is a passive defensive monitor for detecting suspicious activity on a PC and attributing incidents to attacker IPs. It monitors botnet C2 connections, open ports, inbound connections, Temp-folder programs and failed logons, with evidence sealing, reputation enrichment and optional phone alerts.
cybersecurity threatintelligence cyberdefense incidentresponse endpointsecurity networksecurity threatdetection malwaredetection digitalforensics securitytools threatmonitoring securitymonitoring defensivesecurity c2detection botnetdetection ipattribution passivedefence
-
Updated
Oct 8, 2026 - Python