Control outbound access before the connection begins.
AtlasEWF is a centrally managed Windows endpoint filtering platform designed to enforce outbound DNS, web, IP, port, protocol, and application policy before TCP connection establishment or UDP transmission. It provides local resilience, forensic-quality logging, and centralized administration without forcing all traffic through a traditional proxy appliance.
Endpoint web filtering built for secure operations.
AtlasEWF combines signed policy, managed DNS attribution, Windows Defender Firewall and Windows Filtering Platform enforcement, offline continuity, protected local administration, and centralized reporting. It is designed for organizations that need stronger endpoint-level outbound control without the complexity and blind spots of browser-extension-only filtering.
Pre-Connect Enforcement
- Blocks denied TCP traffic before session establishment
- Blocks denied UDP traffic before application transmission
- Direct-IP enforcement independent of DNS observation
- IPv4 and IPv6 destination controls
- Port and protocol restrictions, including UDP 443 / QUIC
- Windows Defender Firewall / WFP enforcement backend
DNS Attribution & Policy
- Managed DNS policy and approved resolver controls
- Domain-to-IP correlation for outbound decisions
- Destination rules committed before approved DNS answers are returned
- Domain, suffix, IP, network, port, protocol, and application rules
- Explicit handling for encrypted DNS and reduced-attribution conditions
- Deterministic policy precedence with visible decision explanations
Central Management
AtlasEWF provides centralized policy management for Windows endpoints while allowing tightly controlled local administration where secure or disconnected environments require it.
- Base templates and endpoint-specific overrides
- Disabled, Logging Only, and Web Filter + Logging modes
- Endpoint health, mode, queue, policy, update, and clock status
- Remote re-enable, update, quarantine, and removal workflows
- Role-based administration and append-only audit logging
Offline Resilience
Protection continues when the central manager is unavailable. Endpoints retain the last valid signed policy, preserve installed enforcement rules, and queue events locally until connectivity returns.
- Signed and versioned cached policy
- Continued enforcement during manager outages
- Protected local event queue with retry and synchronization
- Policy replay, tamper, corruption, and rollback protection
- Safe restoration of product-owned DNS and firewall changes
AtlasEWF operating profiles
AtlasEWF supports flexible monitoring for ordinary endpoints and strict default-deny enforcement for high-sensitivity systems. Because one security profile for every workstation is how organizations eventually learn painful lessons.
| Capability | Logging Profile | Managed Filter Profile | High-Security Profile |
|---|---|---|---|
| Primary use | Visibility, baselining, and policy development | Centralized endpoint web and outbound filtering | CJIS-style and tightly controlled sensitive workstations |
| Enforcement mode | Logging Only | Web Filter + Logging | Default-block Web Filter + Logging |
| Unknown destinations | Allow and log | Allow, block, or review according to policy | Block and log unless explicitly approved |
| DNS controls | Observe and report DNS activity | Managed DNS with approved resolver enforcement | Restricted resolvers with encrypted-DNS bypass controls |
| Direct-IP traffic | Observed and logged where available | Allowed or denied by compiled destination policy | Denied unless specifically permitted |
| QUIC / HTTP/3 | Observed where available | Configurable UDP 443 restriction | Blocked by default where required |
| Local override | Configurable | Disabled, emergency-only, or permitted by policy | Disabled or strictly time-bound with secondary authorization |
| Manager outage | Local event queue continues | Last valid policy and firewall rules remain enforced | Protection remains active with no silent fail-open behavior |
| Audit requirements | Administrative and endpoint events recorded | Append-only audit trail with actor and before/after values | Immutable administrative evidence and strict bypass reporting |
| Best fit | Policy discovery, pilots, and operational baselining | Business, government, education, and managed endpoint fleets | Public safety, criminal justice, critical infrastructure, and regulated systems |
Product packaging, licensing, and final edition names remain subject to the AtlasEWF commercial roadmap. The current requirements baseline defines the operational and security capabilities rather than final commercial tiers.
Built for visibility, evidence, and control.
AtlasEWF does more than block destinations. It explains why a decision occurred, preserves evidence through outages, and gives administrators the tools to test legitimate site dependencies before changing production policy.
Forensic-Quality Logging
Record DNS activity, destination addresses, ports, protocols, users, processes, policy sources, outcomes, attribution confidence, and local queue status where observable without TLS decryption.
URL Dependency Testing
Test an allowed site to identify redirects, domains, CDNs, certificate endpoints, destination IPs, and blocked dependencies. Recommendations remain subject to human review instead of automatically broadening production access.
SIEM-Ready Reporting
Export normalized, versioned event data through secure JSON delivery, local files, and planned mappings for common SIEM and observability models.
Protected Administration
Require authorized administrators, reason, duration, and scope for temporary disablement, with automatic expiry and complete auditing of policy changes, overrides, updates, and removal.
Low Endpoint Overhead
Designed as a lightweight Windows service with bounded local storage, unattended deployment, predictable health status, and operational targets suitable for ordinary workstations and sensitive terminals.
No TLS Interception Required
Enforce outbound policy using DNS intelligence, destination controls, and Windows networking controls without deploying certificate substitution or transparent man-in-the-middle inspection.
Current prototype scope
AtlasEWF prototype v0.2 establishes the architecture for centralized policy, endpoint enforcement, offline operation, protected administration, and normalized reporting.
Implemented in Prototype
- Central FastAPI manager
- Windows service agent architecture
- Signed cached policy and local event queue
- DNS policy component
- Windows Defender Firewall / WFP rule compilation
- Direct-IP, IPv4, IPv6, UDP 443, and external-DNS controls
- Normalized JSON / SIEM output
- Safe state restoration model for uninstall and rollback
Validation Status
- Policy compilation validated
- Cryptographic signing paths validated
- DNS handling validated
- Firewall rule compilation validated
- Windows 11 integration testing remains pending
- Production-scale, code-signing, and high-availability work remains roadmap-aligned
- Custom WFP callout driver remains a future architecture decision
AtlasEWF is under active development. Prototype features and architecture may evolve as Windows integration, scale, security testing, and production packaging are completed.
Interested in AtlasEWF?
Discuss endpoint filtering, government use cases, pilot deployments, or early access.