From attack attempt to block
WF SecurityCloud rests on a simple observation: whoever attacks you has almost always attacked someone else first. If we see the first attempt, we can stop the second.
Four steps
The chain runs one way only. Threat data comes in to us from the sensors, protection goes out to your devices.
The sensors pick it up
Sensors receive real attack attempts. Each attempt gives an address, a method and a point in time.
Threat data is processed
Hits are weighed together, duplicates removed, and addresses that have stopped being dangerous drop out of the lists again.
Devices fetch the protection
Clients and websites fetch updated block lists continuously. Nothing about your operations travels the other way.
Block and log
Traffic is stopped locally on the device. The event is logged and becomes visible in the panel.
The four parts, one at a time
Threat intelligence and the sensor network
Where the threat data comes from, what a sensor actually records and how many independent hits are required.
The kernel driver
Why blocking happens in the operating system kernel, and what Microsoft's signature means.
Privacy and data handling
Exactly which details leave your device, why they are needed and what we never touch.
Methodology and sources
How an address ends up in the lists, how it is weighted and how it is removed again.
Why not scan the files instead
An antivirus program looks at what is on your computer and decides whether any of it is malicious. That is a reasonable method, and you should keep your antivirus. But it requires the program to read your files.
WF SecurityCloud works from the other direction. We do not look at your files. We look at which addresses and domains are demonstrably used for attacking, and make sure your device does not talk to them.
That has two consequences. One is that the protection works without anyone having to read your material. The other is that it does not cover everything — a file already on the machine is not stopped by an address being blocked. That is why WF SecurityCloud is one more layer, not a layer instead.
See it in practice
The product pages show what each part does on the device it sits on.