Backup and Server Hardening Tools: A Practical Guide

Backup and server hardening tools guide for sysadmins: Windows imaging, Linux backups, SSH hardening and malware scanning

This guide is for sysadmins, MSP technicians and IT generalists who look after Windows PCs, Windows servers and Linux boxes, on premises or in the cloud, and need every machine to be restorable and none of them to be an easy target.

The short answer: image Windows machines with AOMEI Backupper Standard or Veeam Agent, back up Linux servers with Restic or BorgBackup, copy file shares with FreeFileSync, and treat Syncthing as replication, not backup. Harden every Linux server with key-only SSH, automatic updates, a firewall, fail2ban and a Lynis audit; add OSArmor on Windows endpoints, ClamAV for server-side scanning and Maltrail on the network.

The short list

ToolBest forLicencePlatformsStatus
AOMEI Backupper StandardSystem images and bare-metal restore of Windows PCsFree edition for non-commercial use; paid editions existWindows 7–11Active (8.4.0, June 2026)
FreeFileSyncPreviewed mirror and versioned copies to NAS or SFTPFree for private individuals, open source (GPL-3.0); organisations need the Business EditionWindows, macOS, LinuxActive (14.12, Sept 2026)
SyncthingContinuous peer-to-peer folder replicationFree, open source (MPL-2.0)Windows, macOS, Linux, BSD, DockerActive (2.1.5, Sept 2026)
Cobian Backup (Cobian Reflector)Keeping existing scheduled file backups runningFree (freeware)WindowsDiscontinued: 2.7.20 (July 2024) was the last update
Areca BackupRestoring old Areca archivesFree, open source (GPL-2.0)Windows, LinuxDormant since 7.5 (2015); one-person community fork
WinSCPScripted SFTP uploads of backup files from WindowsFree, open source (GPL-3.0 or later)WindowsActive (6.5.7, Sept 2026)
OSArmorBlocking malicious process behaviour on WindowsShareware (conditionally free)Windows 7 SP1–11, Server 2016–2022Active (2.0.7.0, Aug 2026)
ClamAVScanning mail, uploads and file serversFree, open source (GPL-2.0)Linux, Windows, macOS, FreeBSDActive (1.5.4; 1.4 LTS)
MaltrailDetecting malware callbacks and scanners on the networkFree, open source (MIT); Trails dataset has its own termsLinux, BSD, macOS, Windows 10+Active (3.4, Sept 2026)
Veeam Agent for Microsoft WindowsImage backups of Windows machines, one job in the FREE editionShareware (conditionally free)WindowsActive
ResticEncrypted, deduplicated backups to SFTP or object storageFree, open source (BSD 2-Clause)Linux, BSD, macOS, WindowsActive (0.19.1, July 2026)
BorgBackupDeduplicated, encrypted backups of Linux servers over SSHFree, open source (BSD)Linux, macOS, BSDActive (1.4.5, July 2026); 2.0 still in beta
LynisSecurity audit and hardening suggestionsFree, open source (GPL-3.0)Linux, macOS, BSD and other UnixActive
fail2banBanning IPs after repeated failed loginsFree, open source (GPL-2.0 or later)Linux, BSD, macOS, SolarisActive (1.1.1, Aug 2026)

Decide what a backup must survive

For each system, write down how much data you can afford to lose, how long a restore may take and what the backup must survive. A USB disk next to the server survives a failed drive, not ransomware running as domain admin or a fire. Keep three copies on two kinds of media, one off site, and at least one that production credentials cannot delete.

Then split the estate by restore type. Workstations and small Windows servers need a system image. File servers need file-level versions. Linux servers are usually rebuilt from configuration management and need only /etc, application data and database dumps.

Image Windows PCs and servers for bare-metal restore

AOMEI Backupper Standard creates system, disk, partition and file images, runs scheduled incremental backups to a USB disk or NAS share and restores from WinPE rescue media. It is free for use without commercial gain; differential backups, automatic cleanup of old images, encryption, the command line, system clone and Windows Server support are paid features. Without automatic cleanup, start a new full chain every month or so and delete old chains yourself.

Veeam Agent for Microsoft Windows has a FREE edition that needs no licence and covers entire-computer, volume and file backup with bootable recovery media. Its key limit is one backup job to a local drive, network share or Veeam repository, with no object storage target and no GFS retention; the paid Workstation and Server editions lift these.

Either way, store images on a NAS share with its own credentials, verify each image, and boot the rescue USB once on the real hardware to confirm it sees the disk and network.

Automate file backups of Windows file shares

For file shares, FreeFileSync is the practical choice. Build a Mirror job from \fs01data to \nas01mirrordata with deletion handling set to Versioning, save it as a .ffs_batch file and run it from Task Scheduler with UNC paths, never mapped drives. Alert on the exit code (0 success, 1 warnings, 2 errors). Companies need the Business Edition.

Cobian Backup still runs encrypted Zip backups as a service and is free even in companies, but it is discontinued: Cobian Reflector 2.7.20 (July 2024) was the final update. Areca Backup is dormant since 7.5 (2015), with a one-person Windows-only fork. Keep both only until the old archives expire, then migrate.

For an off-site copy from a Windows server, WinSCP scripting is reliable. A script with a pinned host key and a private key, run by Task Scheduler under a service account:

open sftp://backup@offsite.example.com/ -hostkey="ssh-ed25519 255 ..." -privatekey="C:Keysbackup.ppk"
put -neweronly D:Backups*.zip /data/incoming/
exit

Run it with WinSCP.com /ini=nul /log=C:Logsoffsite.log /script=C:Scriptsoffsite.txt and alert on any non-zero exit code. On a Mac admin workstation, Cyberduck and its duck CLI cover the same SFTP and S3 transfers.

Back up Linux servers with Restic or BorgBackup

Both tools deduplicate, encrypt and let you restore any snapshot. The difference is storage: Restic writes to local paths, SFTP, its REST server, S3 and S3-compatible storage, Backblaze B2, Azure, Google Cloud Storage and anything rclone reaches. Borg works with a local disk or a machine reachable over SSH that has Borg installed.

A nightly Restic job to a NAS over SFTP:

export RESTIC_REPOSITORY=sftp:backup@nas01:/srv/restic/web01
export RESTIC_PASSWORD_FILE=/root/.restic-pass
restic init                      # once
restic backup /etc /var/www /var/backups/db --exclude-caches
restic forget --keep-daily 7 --keep-weekly 4 --keep-monthly 6 --prune
restic check --read-data-subset=5%

The last line reads a random 5% of the stored data each night, so over time you verify real restorability rather than just the index. The Borg equivalent follows its quickstart: borg init --encryption=repokey, then borg create with an archive name such as '{hostname}-{now}', borg prune --keep-daily 7 --keep-weekly 4 --keep-monthly 6 and borg compact to free space. Stay on Borg 1.4 for production; the project itself says Borg 2.0 is not ready for it yet.

Assume the server itself can be compromised: on the repository host, force borg serve --append-only --restrict-to-path /srv/borg/web01 for the client’s key in authorized_keys, so it can add archives but not delete old ones. Keep the repository password in your password manager; without it the backup is unreadable. Dump databases first (pg_dump, mysqldump) rather than copying live data files. VMs on Proxmox VE have built-in scheduled backups; see the virtualization and container tools hub.

Replicate folders between sites, and why sync is not backup

Syncthing keeps folders identical between machines over TLS, with no cloud or account. For branch-office replication, set the branch folder to Send Only and the head-office copy to Receive Only with Staggered File Versioning. It is not a backup: deletions and ransomware-encrypted files replicate everywhere, so point a real backup tool at the replica.

Make sure backup jobs actually run

Most failed restores trace back to a job that silently stopped weeks earlier. Check exit codes in a wrapper script and send a success ping to a dead-man’s-switch monitor so silence raises an alert; our server monitoring and log management hub covers this. Once a quarter, restore one server and one share to a spare machine and time it: that is your real recovery time.

Harden a new Linux server: a baseline

Apply the same baseline to every Linux server, preferably from an Ansible playbook so it is repeatable and auditable:

  1. SSH keys only. Create /etc/ssh/sshd_config.d/10-hardening.conf with PermitRootLogin no, PasswordAuthentication no and KbdInteractiveAuthentication no. sshd uses the first value it reads, so a low file number beats cloud-image files that re-enable passwords. Test with sudo sshd -t and keep a second session open before you reload.
  2. Automatic security updates. On Debian and Ubuntu, sudo apt install unattended-upgrades and sudo dpkg-reconfigure -plow unattended-upgrades. On RHEL-family systems, install dnf-automatic and enable its timer.
  3. Firewall with default deny. sudo ufw allow OpenSSH, open only the service ports, then sudo ufw enable; on RHEL use firewalld zones.
  4. fail2ban. Never edit jail.conf; put overrides in jail.local so package upgrades do not overwrite them:
    [DEFAULT]
    bantime  = 1h
    findtime = 10m
    maxretry = 5
    
    [sshd]
    enabled = true

    Apply with sudo fail2ban-client reload and check with sudo fail2ban-client status sshd.

  5. Audit with Lynis. sudo lynis audit system runs agentless checks and only reports; it changes nothing. Work through the warnings first, then the suggestions. Results go to /var/log/lynis.log and /var/log/lynis-report.dat, and --cronjob runs it unattended so you can compare reports over time. Lynis Enterprise is a separate commercial product that adds central management.

Manage Linux servers day to day

From a Windows workstation, mRemoteNG keeps SSH and RDP sessions in one tree, and WinSCP edits config files over SFTP; for root-owned files, set its SFTP server to sudo /usr/lib/openssh/sftp-server instead of logging in as root. Verify host key fingerprints on first connection. Anything you do on more than two servers belongs in an Ansible task; the DevOps automation tools hub covers configuration management.

Harden Windows endpoints and servers

OSArmor blocks the process chains most Windows intrusions use: Office spawning cmd.exe or PowerShell, scripts running from Downloads, vssadmin deleting shadow copies. It runs next to Defender, not instead of it. Pilot it on one machine first, because behaviour rules catch RMM agents and admin scripts, then write exclusions that match signer and path. It is shareware (conditionally free); Windows Server needs the Business or Enterprise licence. Microsoft’s Attack Surface Reduction rules and AppLocker or WDAC cover similar ground if you already manage Group Policy or Intune.

Scan files and watch network traffic

ClamAV belongs on Linux mail gateways, upload handlers and file servers, not as a desktop antivirus. A nightly scan that quarantines instead of deleting:

30 2 * * * root clamscan -r -i --move=/var/quarantine --log=/var/log/clamav/nightly.log /srv/www /home

For uploads, stream each file to clamd before accepting it. Budget over 1 GB of RAM for signatures and let freshclam handle updates; scripted downloads get rate-limited.

Maltrail watches a SPAN port or gateway and flags traffic to known-bad domains and IPs, scanning and DNS tunnelling. It detects rather than blocks; its /fail2ban endpoint can feed a firewall blocklist. Change the default dashboard login (port 8338) immediately.

Cloud servers: security basics that also protect backups

A cloud VM has a public IP from minute one, so apply the baseline above first. Then allow SSH and RDP only from office or VPN addresses in the provider’s security group, put the management console behind MFA, and give each server storage credentials with the minimum rights it needs, ideally unable to delete old snapshots. Keep at least one backup copy with a different provider or on premises, so one compromised account cannot erase production and backups together.

How to choose

  1. Sort machines by restore type: image (workstations, small Windows servers), file versions (shares), or rebuild plus data (Linux servers).
  2. Windows images: AOMEI Backupper Standard for non-commercial use; Veeam Agent FREE when one job is enough; paid editions for encryption, retention or servers.
  3. File shares: FreeFileSync with versioning; migrate off Cobian and Areca.
  4. Linux: Restic for object storage or one binary everywhere; Borg for SSH targets you control and append-only repositories.
  5. Hardening: the Linux baseline everywhere, OSArmor or ASR rules on Windows endpoints, ClamAV where files arrive from outside, Maltrail at the network edge.
  6. Prove it: monitor every job and run a timed test restore each quarter.

FAQ

What is the best free backup software for Windows Server?

AOMEI Backupper Standard does not support Windows Server; that needs its paid Server edition. Veeam presents Agent FREE for desktops and laptops, and its paid Server edition adds unlimited jobs, application-aware guest processing and backup windows. For file-level server jobs, FreeFileSync (Business Edition) or Restic on Windows both run from Task Scheduler.

Restic or BorgBackup: which should I use?

Restic supports many storage back ends directly, including S3, B2, Azure and Google Cloud Storage, and runs on Windows. Borg is built around SSH repositories and offers an append-only mode. Both deduplicate and encrypt; pick by where the data will live.

Is Cobian Backup still safe to use?

It still runs and is free, but development has ended with Cobian Reflector 2.7.20, so it will get no security fixes or support for new Windows releases. Keep existing jobs only until you move to a maintained tool.

What are the first steps to harden a Linux server?

Disable root and password logins over SSH, turn on automatic security updates, enable a default-deny firewall, add fail2ban for SSH, then run lynis audit system and work through its warnings.

Does ClamAV replace antivirus on Windows servers?

No. ClamAV has no real-time protection or GUI on Windows. Keep Microsoft Defender and use ClamAV for scripted scans, mail filtering and Linux servers.

Last updated: 30 September 2026 · ITForgePro editorial team. Licence, version and platform details are checked against each developer's official documentation.

Other articles

Submit your application