Protection in the kernel, not on top of it

Version 4.0 is built from the ground up around a kernel driver signed by Microsoft. It sees traffic where it passes through the operating system and can stop it before the connection is established.

How the client works, continuously

The client is active from the start and needs no daily attention. This is what it does while it runs.

Traffic in both directions

The client checks both what the machine tries to reach and what tries to reach the machine. If the address is in the threat data, the connection is cut while it is being established.

Login attempts as a pattern

One mistyped password means nothing. Many attempts in a row from the same source do. The client follows attempts against remote desktop and other exposed services, and blocks the address once the pattern is clear.

A log to go back to

Every block is recorded with address, event type and time, and sent on to the customer panel. You can see what happened on the machine without sitting at it.

Controlled from the panel

Protection is started and stopped per device in the customer panel. Useful when the server sits in a rack somewhere else, or when something needs troubleshooting without anyone travelling to it.

A few megabytes on disk

The block lists cover millions of addresses, networks and domains but occupy only a few megabytes. On a gigabit network there is no noticeable difference in speed.

Workstation or server

The same client and the same protection on Windows 10 in both 32-bit and 64-bit editions and on Windows 11. It makes no difference whether the machine sits on a desk or answers around the clock in a server room.

The client on the desktop

The interface is deliberately small. Most things are handled from the customer panel, and what needs to be on the machine is protection status, licence key and the log.

The WF SecurityCloud™ Windows client showing protection status, block statistics and licence key status.
The client's home view. Protection status, number of blocks and licence key, with menu entries for settings, log and information.

Why the level matters

A program running as an ordinary application sees traffic late, after the operating system has already handled it. A driver in the kernel sees it earlier, and can abort the connection before it gets going.

The driver being signed by Microsoft means it has passed Microsoft's review and certification for kernel code. Windows loads it without requiring you to turn off security features, and it works with Secure Boot enabled.

What that means in practice

  • Blocking happens before the connection is established, not after
  • Protection covers all traffic on the device, not just the browser
  • No Windows security features need to be turned off
  • The client complements antivirus rather than replacing it

What the client does and does not do

Knowing where the protection ends matters as much as knowing where it begins.

The client does

  • Stop traffic to known malicious addresses and domains
  • Recognise and block brute-force patterns
  • Log blocked events to the panel
  • Keep its block lists updated continuously

The client does not

  • Scan the contents of your files
  • Read your email
  • Replace an antivirus program
  • Send documents or file contents to us

Three steps to protection on one machine

  1. Create an account

    Register in the customer panel and add the licences you need.

  2. Get the installation file

    The file is downloaded from the panel while logged in, so that it is tied to your licence.

  3. Install and activate

    Run the installer on the machine and activate with your licence key. The device appears in the panel.

Downloads happen in the panel

The installation file for Windows client 4.0 is fetched from the customer panel after logging in. That ties the download to the right licence and ensures you always get the version that applies to your account.

Get started with the Windows client

Create an account, add a licence and get the installation file.