TCPCLI
DETECT → DECIDE → ACT

Don’t just tell the customer they’re under attack.STOP IT.

TCPCLI is an AI-powered active server defense agent for your Linux fleet. It detects brute-force attacks, config and port drift, and file tampering in real time — then takes response action, with humans firmly in control of what goes live.

500+

Organizations protected

1000+

Servers monitored

5M+

Incidents detected

4M+

Response actions executed

The loop

A closed-loop defense cycle, not a dashboard full of alerts you have to act on yourself.

01
DETECT

The agent streams SSH, web server, firewall, config, and file-integrity signals in real time.

02
CORRELATE

Signals are grouped against baselines and attack patterns to separate noise from real incidents.

03
DECIDE

Confidence-scored findings are matched against your org's policy — dry-run, or auto-execute.

04
ACT

Response actions are queued to the agent: block an IP, lock an account, quarantine a file, restrict a port.

05
VERIFY

The agent reports back what actually happened, closing the loop with proof, not assumptions.

Built for real servers, real risk

Brute-force detection

Correlates SSH and auth log failures across IPs and time windows to catch credential attacks as they happen, not after the breach report.

Config & port drift

Every server has a known-good baseline. The moment a port opens or a config changes outside it, you know — before an attacker finds it first.

File integrity monitoring

Hashes and watches sensitive paths (sshd_config, sudoers, passwd, shadow, crontab) and flags unauthorized changes the instant they occur.

AI security copilot

Ask plain-language questions about what's happening on your fleet — why an IP was blocked, what changed today, where your top risks are.

Compliance evidence

Generate CIS, ISO 27001, PCI DSS, and SOC 2-aligned evidence reports straight from real detection and response activity on your servers.

Dry-run by default

Every response action is simulated and reported first. Nothing executes on a live server until your policy allows it or a human approves it.

Safe by default. Live when you say so.

Every response action starts as a dry-run — the agent determines and reports exactly what it would do, with zero risk to production. It only executes for real when your org explicitly enables auto-execute per action type, or a dashboard user reviews and approves a specific finding. No silent surprises on a customer’s server, ever.

Frequently asked questions

What is TCPCLI?

TCPCLI is an active server defense and compliance platform for Linux servers. A lightweight agent installs on your server and streams SSH, web server, firewall, config, and file-integrity signals to a portal that detects attacks, tracks known vulnerabilities, monitors uptime, and — with your explicit approval — takes response action like blocking an IP or locking a compromised account.

How does TCPCLI detect SSH brute-force attacks?

The agent tails your server's auth logs in real time and correlates failed SSH login attempts by source IP, username, and time window. A burst of failed logins from one or more IPs triggers a scored incident and, per your policy, a temporary IP block.

Does TCPCLI do vulnerability scanning?

Yes. The agent fingerprints your OS and installed packages and checks them against OSV.dev's public vulnerability database for known CVEs, so you know about exploitable software before an attacker does.

Can TCPCLI monitor website uptime?

Yes. Independent of the agent, TCPCLI can check any URL on a schedule and alert your team by email, Slack, or webhook the moment it goes down or comes back up — catching outages even when the server itself can't report in.

Will TCPCLI automatically take action on my server?

Not unless you tell it to. Every response action starts as a dry-run: the agent determines and reports exactly what it would do, with zero risk to production. It only executes for real when you explicitly enable auto-execute for that action type, or a team member reviews and approves a specific finding.

What compliance frameworks does TCPCLI support?

TCPCLI maps real detection, response, and audit activity from your servers into technical evidence reports aligned to CIS benchmarks, ISO 27001, PCI DSS, and SOC 2 control families. This is technical evidence to support an audit, not a certification itself.