SystemVPN

Systemchip — Support & Documentation

SystemVPN Documentation

1. Overview

SystemVPN is an all‑in‑one tool that combines a secure TLS tunnel with a set of active security sensors to protect your Windows server or pc against unauthorized access, data exfiltration, and automated attacks. It runs as a lightweight agent 24/7, with or without an active tunnel.

2. System Requirements

  • Operating System: Windows 10/11 (64‑bit) or Windows Server 2019/2022.
  • Privileges: Local Administrator for installation and firewall/honeypot configuration.
  • Network: Port 443 (for the TLS tunnel) and port 55000 (optional, for consuming the Wazuh API).
  • Hardware: 2 GB RAM, 1 GB disk space (logs and rules).

3. Quick Installation

  1. Download the SystemVPN installer from the official website.
  2. Run SystemVPN-Setup.exe as Administrator.
  3. Choose the installation directory (default: C:\Program Files\SystemChip\SystemVPN).
  4. The installer creates the Start Menu and Desktop shortcuts and installs the virtual network driver (Wintun) with the app.
  5. Complete the installation and restart the server ou pc if prompted.

3.1 License activation

  1. Without a license, SystemVPN opens in the Free plan (Monitor mode only).
  2. For the tunnel (Server/Client), buy a plan on the website and receive an activation code by e-mail.
  3. In the app, tap Plano on the status bar (or About > Activate license), enter the code and choose Server or Client.
  4. The app validates the payment and saves the license.key automatically.

4. First Configuration

After installation, access the SystemVPN control panel (via desktop shortcut or localhost:8080).

  • Set a strong password for the administrator (minimum 12 characters, with uppercase, lowercase, numbers, and symbols).
  • Enable 2FA (TOTP) — scan the QR code with your authenticator app (Google Authenticator, Authy).
  • Configure the tunnel: choose the port (default 443) and define which internal services (folders, databases) will be exposed.
  • Enable security modules: Honeypot, Active Firewall, Egress Blocking, and Behavioral Monitoring.

5. Security Modules (Native Monitoring)

SystemVPN already includes a set of native sensors — no external tools required:
  • Honeypot: Listens on fake ports to identify scanners. Upon detection, it blocks the IP automatically via firewall.
  • Active Firewall: Manages blocking rules via netsh advfirewall, isolating malicious IPs in real time.
  • Log Monitoring: Reads Windows Event Logs (Security, System, Application) and triggers alerts for login failures (ID 4625), suspicious process creation, and policy changes.
  • File Integrity Monitoring (FIM): Watches critical folders (e.g., C:\Windows\System32, C:\Program Files) and alerts on unauthorized changes.
  • Egress Blocking: Controls outbound connections. You can define a whitelist of allowed IPs/domains — any outbound attempt outside that list is blocked and logged.
  • Behavioral Monitoring: Analyzes process execution patterns (e.g., PowerShell with download arguments, scripts running from temp folders) and generates alerts for "Living Off the Land" (LOTL) techniques.

6. Wazuh Integration (Pro Plan – Optional)

SystemVPN Pro has a native engine that consumes the Wazuh REST API to display advanced alerts in the unified dashboard.

  • What SystemVPN does: It authenticates with the Wazuh Manager (via JWT), makes GET requests to the /alerts, /agents, and /manager/info endpoints, and displays these alerts alongside native events.
  • What SystemVPN does NOT do: It does not send logs to Wazuh. Data ingestion into Wazuh is done exclusively by the Wazuh Agent installed on the operating system (communication via ports 1514/55000).
  • To enable the integration, set the environment variables: WAZUH_API_URL, WAZUH_API_USER, WAZUH_API_PASSWORD (or token) and set WAZUH_ENABLED=true.
  • The Wazuh infrastructure (Manager server) is not included in the Pro price. See the Add‑on Services section to contract the managed SIEM.

7. Maintenance and Logs

  • SystemVPN logs are stored in %PROGRAMDATA%\SystemVPN\Logs\ (rotated daily).
  • To check the service status: services.msc → look for "SystemVPN Service".
  • To update SystemVPN, download the new version and run the installer again — it will preserve your settings.

8. Support

If you have questions, check the FAQ or contact us at suporte@systemchip.com.br.

Frequently Asked Questions

Yes, we offer a Free version with basic features (tunnel with 30 min/day limit, basic monitoring, 1 concurrent client). For unlimited professional use, we have Essential (R$ 200) and Pro (R$ 300) plans — both with a lifetime license.

Yes. Essential and Pro plans are paid once and the license is lifetime for the purchased version. Upgrades to future versions have a differentiated cost (only for Pro, upgrades are free for 2 years). The license is per endpoint (server) and can be transferred to another machine, as long as the previous one is deactivated.

Essential already includes unlimited tunnel, honeypot, firewall, Windows logs, and file integrity. Pro adds: Custom IP (real routing), Egress Blocking, Behavioral Monitoring, 2FA for critical actions, native Wazuh integration (consumes API), unified dashboard, and free upgrades for 2 years. Pro also gets priority support.

No. SystemVPN Pro has its own native sensors (honeypot, firewall, logs, egress, behavior). Wazuh integration is optional and is only for customers who need a full SIEM (log retention, dashboards, correlation). If you don't contract the Wazuh service, SystemVPN Pro works perfectly with its native monitoring.

It is a mechanism that controls outbound connections from the server or pc. You define a list of allowed IPs or domains (e.g., your database IP, Windows update domain). Any attempt by the server to connect to a destination outside that list is immediately blocked and logged. This prevents an attacker, even if they gain access, from exfiltrating data to external servers.

Yes. SystemVPN is compatible with most commercial antivirus and firewalls (Windows Defender, Kaspersky, etc.). During installation, it adds exception rules for its own traffic. We recommend adding the C:\SystemVPN folder to your antivirus exclusion list to avoid false positives.

Support is provided via email (suporte@systemchip.com.br). For Pro customers, support is priority, with an SLA response time of up to 4 business hours. Essential and Free customers receive a response within 24 business hours.

No. Each license is valid for one endpoint (one server). If you have multiple servers, purchase a license for each one. We offer volume discounts: 5–10 points → R$ 250/point; 10+ points → R$ 200/point.

License Terms of Use

Last updated: August 24, 2026

This End‑User License Agreement ("EULA") is a legal agreement between you (individual or legal entity) and Systemchip Ltda., the developer of SystemVPN software. By installing, copying, or using the software, you agree to all terms below.

1. Grant of License

Systemchip grants you a perpetual, non‑exclusive, non‑transferable license to use SystemVPN on the number of servers (endpoints) for which the license was purchased. The license is valid for the purchased version and for all bug‑fix updates (patches) of that same version.

  • Free Version: Personal or evaluation use, with the limitations described on the website (tunnel time, number of clients, etc.).
  • Essential and Pro Versions: Commercial or professional use, without time or feature limitations, according to the plan characteristics.

2. Restrictions

You MAY NOT:

  • Sell, rent, sublicense, or distribute SystemVPN without express authorization from Systemchip.
  • Reverse engineer, decompile, or disassemble the software, or attempt to extract its source code.
  • Remove or alter any copyright, trademark, or other proprietary notices.
  • Use the software for illegal activities, cyberattacks, or any purpose that violates Brazilian or international laws.
  • Use the software in mission‑critical environments (e.g., life‑support systems, air traffic control) without separately contracted warranties.

3. Updates and Upgrades

  • Updates (fixes and patches): Free for all licensed versions throughout the software's lifetime.
  • Upgrades (new major versions, e.g., v2.x → v3.0): Free for Pro customers during the first 2 years after purchase. After that, or for Essential customers, upgrades are offered at a discount on the new license price.

4. Intellectual Property

All content, code, design, and trademarks related to SystemVPN are the exclusive property of Systemchip Ltda. This license does not transfer any ownership rights to you. The software is protected by copyright laws and international treaties.

5. Disclaimer of Warranties

The software is provided "AS IS", without any warranties of any kind, express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, or non‑infringement. Systemchip does not warrant that the software is error‑free, secure against all types of attacks, or that it will meet all your operational requirements.

Your use of the software is at your sole risk, and you assume all risks associated with its installation and operation.

6. Limitation of Liability

In no event shall Systemchip Ltda. be liable for direct, indirect, incidental, special, consequential, or punitive damages, including without limitation loss of profits, data, use, or business interruption, arising out of the use or inability to use the software, even if Systemchip has been advised of the possibility of such damages.

In any case, Systemchip's total liability under this EULA shall be limited to the amount actually paid by you for the SystemVPN license.

7. Governing Law and Jurisdiction

This EULA shall be governed by and construed in accordance with the laws of the Federative Republic of Brazil, without regard to its conflict of laws provisions. The courts of the district of Santos, São Paulo shall have exclusive jurisdiction over any disputes arising out of this agreement, with waiver of any other venue, however privileged.

8. Termination

This EULA will be effective until terminated. Systemchip may terminate this agreement immediately, without prior notice, if you violate any of its terms. Upon termination, you must cease using the software and destroy all copies in your possession.

9. General Provisions

  • If any provision of this EULA is found to be invalid or unenforceable, the remaining provisions shall remain in full force.
  • Systemchip reserves the right to update these terms periodically. The latest version will always be available on our website.
  • This EULA constitutes the entire agreement between the parties and supersedes any prior understandings or agreements, written or oral.
Questions about the terms? Contact us: suporte@systemchip.com.br