Windows Filtering Platform (WFP)
Integration & Setup Manual
Windows Filtering Platform (WFP) Integration Guide
Overview
Cup’n’String integrates with the Windows Filtering Platform (WFP) to govern outbound traffic on Windows workstations. This native kernel-level driver integration enforces policy boundaries dynamically without installing unmanaged network overlays.
Support level
Kernel-Level Enforcement
What Cup’n’String detects
- Active WFP layers and network filters
- Windows Defender firewall configurations
- Process path signatures initiating socket connections
What it governs
- Process-specific socket connection requests
- Outbound blocks to unauthorized LLM endpoints
- Safe relay connection limits
Recommended policies
- Block all direct outbound LLM API connections, forcing traffic through the local proxy
- Monitor changes to Windows Defender rulesets to detect manual tampering
- Apply strict network isolation for untrusted terminal agents
Setup outline
- Deploy the Cup’n’String Windows agent using the MSI package.
- The agent installs a background Windows Service that registers WFP callout drivers.
- Policy intents are translated into WFP filter rules at the transport layer.
Verification
Open a PowerShell terminal and attempt to query an unapproved API endpoint directly. The connection should be immediately dropped at the network layer by WFP.
Troubleshooting
Verify the Cup’n’String helper service is running via Get-Service cns-agent. Check Windows Event logs under Application for any driver initialization errors.
Known limitations
Requires administrator credentials to install the WFP kernel callouts.
Integration Info
Links
Verify what categories and runtimes this stack fits inside in the global compatibility dashboard.
Supported Environments Matrix