Government Technology  •  Microsoft Licensing  •  Cybersecurity  •  Software  •  Custom Solutions and Software
Endpoint DNS & Web Filtering Platform

Control outbound access before the connection begins.

AtlasEWF is a centrally managed Windows endpoint filtering platform designed to enforce outbound DNS, web, IP, port, protocol, and application policy before TCP connection establishment or UDP transmission. It provides local resilience, forensic-quality logging, and centralized administration without forcing all traffic through a traditional proxy appliance.

Endpoint web filtering built for secure operations.

AtlasEWF combines signed policy, managed DNS attribution, Windows Defender Firewall and Windows Filtering Platform enforcement, offline continuity, protected local administration, and centralized reporting. It is designed for organizations that need stronger endpoint-level outbound control without the complexity and blind spots of browser-extension-only filtering.

Pre-Connect Enforcement

  • Blocks denied TCP traffic before session establishment
  • Blocks denied UDP traffic before application transmission
  • Direct-IP enforcement independent of DNS observation
  • IPv4 and IPv6 destination controls
  • Port and protocol restrictions, including UDP 443 / QUIC
  • Windows Defender Firewall / WFP enforcement backend

DNS Attribution & Policy

  • Managed DNS policy and approved resolver controls
  • Domain-to-IP correlation for outbound decisions
  • Destination rules committed before approved DNS answers are returned
  • Domain, suffix, IP, network, port, protocol, and application rules
  • Explicit handling for encrypted DNS and reduced-attribution conditions
  • Deterministic policy precedence with visible decision explanations

Central Management

AtlasEWF provides centralized policy management for Windows endpoints while allowing tightly controlled local administration where secure or disconnected environments require it.

  • Base templates and endpoint-specific overrides
  • Disabled, Logging Only, and Web Filter + Logging modes
  • Endpoint health, mode, queue, policy, update, and clock status
  • Remote re-enable, update, quarantine, and removal workflows
  • Role-based administration and append-only audit logging

Offline Resilience

Protection continues when the central manager is unavailable. Endpoints retain the last valid signed policy, preserve installed enforcement rules, and queue events locally until connectivity returns.

  • Signed and versioned cached policy
  • Continued enforcement during manager outages
  • Protected local event queue with retry and synchronization
  • Policy replay, tamper, corruption, and rollback protection
  • Safe restoration of product-owned DNS and firewall changes

AtlasEWF operating profiles

AtlasEWF supports flexible monitoring for ordinary endpoints and strict default-deny enforcement for high-sensitivity systems. Because one security profile for every workstation is how organizations eventually learn painful lessons.

Capability Logging Profile Managed Filter Profile High-Security Profile
Primary useVisibility, baselining, and policy developmentCentralized endpoint web and outbound filteringCJIS-style and tightly controlled sensitive workstations
Enforcement modeLogging OnlyWeb Filter + LoggingDefault-block Web Filter + Logging
Unknown destinationsAllow and logAllow, block, or review according to policyBlock and log unless explicitly approved
DNS controlsObserve and report DNS activityManaged DNS with approved resolver enforcementRestricted resolvers with encrypted-DNS bypass controls
Direct-IP trafficObserved and logged where availableAllowed or denied by compiled destination policyDenied unless specifically permitted
QUIC / HTTP/3Observed where availableConfigurable UDP 443 restrictionBlocked by default where required
Local overrideConfigurableDisabled, emergency-only, or permitted by policyDisabled or strictly time-bound with secondary authorization
Manager outageLocal event queue continuesLast valid policy and firewall rules remain enforcedProtection remains active with no silent fail-open behavior
Audit requirementsAdministrative and endpoint events recordedAppend-only audit trail with actor and before/after valuesImmutable administrative evidence and strict bypass reporting
Best fitPolicy discovery, pilots, and operational baseliningBusiness, government, education, and managed endpoint fleetsPublic safety, criminal justice, critical infrastructure, and regulated systems

Product packaging, licensing, and final edition names remain subject to the AtlasEWF commercial roadmap. The current requirements baseline defines the operational and security capabilities rather than final commercial tiers.

Built for visibility, evidence, and control.

AtlasEWF does more than block destinations. It explains why a decision occurred, preserves evidence through outages, and gives administrators the tools to test legitimate site dependencies before changing production policy.

Forensic-Quality Logging

Record DNS activity, destination addresses, ports, protocols, users, processes, policy sources, outcomes, attribution confidence, and local queue status where observable without TLS decryption.

URL Dependency Testing

Test an allowed site to identify redirects, domains, CDNs, certificate endpoints, destination IPs, and blocked dependencies. Recommendations remain subject to human review instead of automatically broadening production access.

SIEM-Ready Reporting

Export normalized, versioned event data through secure JSON delivery, local files, and planned mappings for common SIEM and observability models.

Protected Administration

Require authorized administrators, reason, duration, and scope for temporary disablement, with automatic expiry and complete auditing of policy changes, overrides, updates, and removal.

Low Endpoint Overhead

Designed as a lightweight Windows service with bounded local storage, unattended deployment, predictable health status, and operational targets suitable for ordinary workstations and sensitive terminals.

No TLS Interception Required

Enforce outbound policy using DNS intelligence, destination controls, and Windows networking controls without deploying certificate substitution or transparent man-in-the-middle inspection.

Current prototype scope

AtlasEWF prototype v0.2 establishes the architecture for centralized policy, endpoint enforcement, offline operation, protected administration, and normalized reporting.

Implemented in Prototype

  • Central FastAPI manager
  • Windows service agent architecture
  • Signed cached policy and local event queue
  • DNS policy component
  • Windows Defender Firewall / WFP rule compilation
  • Direct-IP, IPv4, IPv6, UDP 443, and external-DNS controls
  • Normalized JSON / SIEM output
  • Safe state restoration model for uninstall and rollback

Validation Status

  • Policy compilation validated
  • Cryptographic signing paths validated
  • DNS handling validated
  • Firewall rule compilation validated
  • Windows 11 integration testing remains pending
  • Production-scale, code-signing, and high-availability work remains roadmap-aligned
  • Custom WFP callout driver remains a future architecture decision

AtlasEWF is under active development. Prototype features and architecture may evolve as Windows integration, scale, security testing, and production packaging are completed.

Interested in AtlasEWF?

Discuss endpoint filtering, government use cases, pilot deployments, or early access.

Contact McCartney Systems