SSHepherd®
Be Invisible.
Be Invincible.
SSHepherd® completely removes the open, listening ports for SSH, RDP, and applications — while still maintaining the full access and functionality of those services for authorised users.
Traditional Security Leaves You Exposed
VPNs and Firewalls are a necessary piece of your perimeter security — but this is not enough. Protecting your resources inside the perimeter is a vital piece of your defence.
Open ports will always be the primary attack vector for threat actors. Even with firewalls, ports often remain open for operational needs, increasing the attack surface and making them prime targets for ransomware, DDoS attacks, and unauthorised remote access.
Preventing unauthorised access to your critical systems, auditing activity during remote access sessions, mitigating the risk of data loss, and good cyber hygiene are key to most security compliance guidelines like NIST, CIS, CERT, and all others.
-
Persistent Open Ports
Even with firewalls, ports often remain open for operational needs, increasing your attack surface.
-
Inefficient Access Controls
Existing solutions struggle to dynamically manage access without causing disruptions to operations.
-
Compliance Auditing Complexity
Organisations must adhere to strict compliance regulations — NIST, ISO 27001, GDPR — while ensuring smooth IT operations.
-
Lateral Movement Risk
Once inside, attackers move laterally across your network. Traditional tools have no built-in mechanism to stop this.
Inverse Coupling Architecture
SSHepherd utilises a proprietary WebSocket tunnel between the Client and Agent in the absence of open ports. The tunnel is TLS-encrypted and appears as standard outbound web traffic from the Agent machine.
Deploy the Agent
Install the lightweight Shepherd Agent on any protected server, VM, or IoT device. Extremely lightweight — CPU under 1%, RAM 128–512 MB — with no changes to your existing network or security stack.
Ports Close. Assets Go Dark.
SSH (port 22) and RDP (port 3389) are instantly closed and cloaked. Your servers become a “dead box” — invisible to port scans, brute-force attempts, and reconnaissance. The attack surface no longer exists.
Authorised Access via Secure Tunnel
The C3 Server acts as the central policy engine and identity broker. Authorised users connect via the Shepherd Client through an encrypted outbound-only TLS tunnel — full SSH and RDP functionality, zero open inbound ports.
Everything You Need to Secure Privileged Access
SSHepherd consolidates Zero Trust Network Access, Privileged Access Management, and session monitoring into a single, lightweight platform.
Control Access
Only authorised users and applications can see SSH, RDP, or application services. Enforces zero-trust posture for on-premise and cloud assets.
Real-Time Live View
Gives security staff live oversight of all active SSH and RDP sessions — who is connected, from where, and what they are doing in real time.
Terminate Sessions
Built-in kill switches allow immediate manual or automated session termination via SIEM — removing ingress/egress points for lateral movement instantly.
Archive for Audit
Full video playback of RDP sessions and text replay of SSH sessions. Logs stored centrally on the C3 database — tamper-proof, not on the local agent.
Full Auditing
Comprehensive logs — who, when, from where, what they did — streamed to your SIEM for real-time threat identification and forensic investigations.
Prevents Lateral Movement
By removing the exposed attack surface and enforcing just-in-time connections, SSHepherd eliminates the pathways attackers use to move inside your network.
On-Premise & Cloud
Works uniformly across on-premise data centres, AWS, Azure, GCP, and hybrid environments. Consistent control without changing your existing infrastructure.
Easy Deployment
Lightweight agent. Supports Windows, Linux, Kubernetes. Compatible with Ansible, Chef, and Puppet. No changes to existing network or security stack required.
SSHepherd® vs. Other Solutions
Most ZTNA and security tools reduce exposure — SSHepherd eliminates it entirely. Servers appear as a “dead box” to every attacker.
| Capability | SSHepherd® | Firewalls / VPN | EDR / NDR | Zscaler ZPA | Teleport |
|---|---|---|---|---|---|
| Removes open / listening ports | ✓ Yes | ✗ No | ✗ No | ✗ No | ✗ No |
| Zero Trust Access Control | ✓ Yes | Limited | Limited | ✓ Yes | ✓ Yes |
| Real-time session monitoring | ✓ Yes | Limited | ✓ Yes | ✗ No | Partial |
| Session recording (video / text replay) | ✓ Yes | ✗ No | Limited | ✗ No | Partial |
| Real-time kill switch | ✓ Yes | ✗ No | Limited | ✗ No | ✗ No |
| Outbound-only connectivity | ✓ Yes | ✗ No | ✗ No | ✓ Yes | ✓ Yes |
| Seamless user experience | ✓ Yes | ✗ No | Moderate | Moderate | Moderate |
| Compliance & forensics audit trail | ✓ Yes | Limited | Limited | Limited | Partial |
Built for Regulated Industries
SSHepherd directly addresses control objectives across major cybersecurity frameworks and Malaysian regulatory mandates.
NIST Zero Trust Architecture
Implements stringent access control policies aligned with NIST SP 800-53 and the Zero Trust Architecture standard NIST SP 800-207.
Information Security Management
Supports risk assessment, access control documentation, and compliance reporting required under ISO 27001 Annex A controls.
Data Privacy Regulations
Ensures secure handling of personally identifiable information through encrypted access channels and immutable audit trails.
Cryptographic Standards
All data in transit encrypted using TLS 1.2/1.3 tunnels. Cryptographic modules capable of FIPS 140-2 compliance. Supports MFA, SAML 2.0, and OIDC.
Bank Negara Malaysia RMiT
Directly addresses BNM’s revised Risk Management in Technology policy (effective November 2025) — attack surface reduction, privileged access control, and continuous monitoring.
Cloud Technology Risk Assessment
Aligns with CTRAG (BNM Appendix 10) requirements for zero-trust principles, secure configuration, and audit log enablement in cloud and hybrid environments.
Defence Through Attack Surface Elimination
Nation-state actors are currently using a “Harvest Now, Decrypt Later” (HNDL) strategy — scanning for open management ports (TCP 22, TCP 3389) and siphoning encrypted data today to decrypt retroactively when quantum computers mature.
Step 1: Invisibility — Immediate Action
Before spending on Post-Quantum Cryptography (PQC), stop the bleeding. Deploying SSHepherd immediately eliminates the attack surface — adversaries cannot scan, find, or harvest from ports that do not exist.
Step 2: Transition — Medium Term
Because SSHepherd protects legacy infrastructure by hiding it, your organisation buys crucial time. No need to panic-upgrade every legacy server, because those servers are no longer exposed.
Step 3: PQC Integration — Long Term
As NIST finalises PQC standards, SSHepherd’s TLS tunnels can be upgraded to quantum-resistant algorithms — securing the entire brokered connection without touching the underlying cloaked servers.
“A quantum computer cannot crack a connection it cannot find.”
SSHepherd removes the door entirely. It does not matter how powerful the adversary’s quantum computer is if there is no network port to aim it at. SSHepherd secures your infrastructure today, satisfies BNM RMiT mandates, and buys the time needed to execute your long-term quantum strategy.
Built for Every Sector
Enterprise IT Security
Protects internal corporate networks from port-based attacks and provides centralised, auditable privileged access management.
Financial Services & Banking
Ensures secure remote access for banking infrastructure. Directly supports BNM RMiT 2025 and CTRAG compliance for Malaysian financial institutions.
Healthcare & Medical Devices
Prevents unauthorised access to IoT medical equipment and healthcare servers — protecting sensitive patient data at the network level.
Government & Defence
Secures classified networks and critical infrastructure. The “dead box” architecture ensures assets are invisible even to adversaries inside the perimeter.
Cloud & Data Centres
Enables a “Secure by Default” posture for cloud-hosted workloads across AWS, Azure, GCP, and on-premise data centres.
Three Components. One Unified Platform.
The SSHepherd ecosystem is composed of three discrete components working together to deliver complete privileged access control.
C3 Server — Command & Control
- Central policy engine and identity broker
- On-premise, private cloud (AWS/Azure/GCP), or hybrid
- Supports 10,000+ Shepherd Agents per cluster
- 500+ concurrent active sessions per standard node
- Active-Active clustering behind standard load balancers
- Recommended: 8 vCPU, 32 GB RAM, 1 TB SSD, 10 Gbps NIC
Shepherd Agent — Protected Endpoint
- Installed on any protected server, VM, or IoT device
- Windows Server 2012 R2 through 2025, Windows 10/11 Enterprise
- RHEL 7/8/9, CentOS 7, Ubuntu 18.04–24.04, Debian 10, Amazon Linux
- Kubernetes (GKE, EKS, AKS, OpenShift) — DaemonSet deployment
- CPU: <1% idle · RAM: 128–512 MB · Disk: 200–500 MB
- No open inbound ports required — all inbound blocked
Shepherd Client — User Interface
- Application used by authorised administrators to connect
- Supports Windows 10/11, macOS 11+, Linux (Ubuntu/Fedora)
- Minimal hardware — runs on standard corporate laptops
- MFA, SAML 2.0 (Microsoft Entra ID / Azure AD), OIDC (Okta, Ping)
- All traffic outbound only — TCP 443 TLS to C3 Server
Ready to Make Your Infrastructure Invisible?
Our team can arrange a Proof of Concept (PoC) to demonstrate how SSHepherd can make your critical infrastructure invisible to attackers and showcase its superior auditing capabilities in your environment.
