Cup'n'String
Join Waitlist

© 2026 Cup'n'String

All Guides/Windows Filtering Platform (WFP) Guide
WI

Windows Filtering Platform (WFP)

Integration & Setup Manual

Windows Filtering Platform (WFP) Integration Guide

Overview

Cup’n’String integrates with the Windows Filtering Platform (WFP) to govern outbound traffic on Windows workstations. This native kernel-level driver integration enforces policy boundaries dynamically without installing unmanaged network overlays.

Support level

Kernel-Level Enforcement

What Cup’n’String detects

  • Active WFP layers and network filters
  • Windows Defender firewall configurations
  • Process path signatures initiating socket connections

What it governs

  • Process-specific socket connection requests
  • Outbound blocks to unauthorized LLM endpoints
  • Safe relay connection limits
  • Block all direct outbound LLM API connections, forcing traffic through the local proxy
  • Monitor changes to Windows Defender rulesets to detect manual tampering
  • Apply strict network isolation for untrusted terminal agents

Setup outline

  1. Deploy the Cup’n’String Windows agent using the MSI package.
  2. The agent installs a background Windows Service that registers WFP callout drivers.
  3. Policy intents are translated into WFP filter rules at the transport layer.

Verification

Open a PowerShell terminal and attempt to query an unapproved API endpoint directly. The connection should be immediately dropped at the network layer by WFP.

Troubleshooting

Verify the Cup’n’String helper service is running via Get-Service cns-agent. Check Windows Event logs under Application for any driver initialization errors.

Known limitations

Requires administrator credentials to install the WFP kernel callouts.

Integration Info

Support LevelKernel-Level Enforcement
CategoryFirewalls
Setup ComplexityMedium
Governed Safeguards
Network

Links

Verify what categories and runtimes this stack fits inside in the global compatibility dashboard.

Supported Environments Matrix