Type something to search...
What Is Included in Aegis

What Is Included in Aegis

Aegis is a personal digital firewall ruleset based on Surge.

It helps users accurately identify and classify traffic locally on iOS and macOS, then define traffic policies according to their own needs.

Aegis is not traditional protection software, and it does not automatically make security decisions for you.

It is a ruleset for identifying and presenting network communication behavior.

In real use, Aegis identifies and classifies network communication.

It helps you understand more clearly how different applications and services communicate.

A rule match only means that a communication has been identified. It describes the type and behavior characteristics of the communication, but it does not itself make a risk judgment.

Based on this visible information, users can define corresponding traffic policies according to their own usage scenarios and needs.

This process is not complicated and does not depend on frequent adjustment. Instead, through long-term use, it gradually establishes a stable and sustainable way of judgment.

On this basis, the Aegis ruleset can also be used as a basis for traffic routing.

By identifying and classifying different communication behaviors, users can route traffic to different policies, nodes, or handling methods instead of being limited to simple allow or block decisions.

What Aegis Includes

Aegis is not a single-purpose rule collection. It is a rule system built around network communication visibility, understandability, and controllability. Its content is mainly reflected in the following areas.

Uses Encrypted DNS Throughout and Rejects Plaintext Requests

In network communication, DNS queries are often one of the easiest parts to overlook, yet they are highly sensitive.

The default assumption in Aegis rule design is that plaintext DNS requests should not be the norm.

Therefore, related rules prioritize guiding or constraining communication behavior toward encrypted DNS, preventing domain resolution from being exposed in plaintext or tampered with by intermediate nodes. This design is not about “forced blocking”; it provides users with a safer default communication premise that better matches modern network environments.

Focuses on Identifying Potential Communication Risks at the Application and Transport Layers

Aegis does not limit identification to a single protocol or scenario. It focuses on real communication behavior occurring at the application and transport layers.

Through rule matching, Aegis attempts to identify behavior characteristics of different applications, services, or components during communication, such as whether third-party services are involved, whether abnormal request patterns exist, or whether the communication is related to known tracking, analytics, or distribution mechanisms.

These identification results are not direct risk judgments. They provide foundational information for users to understand communication behavior.

10+ Preset Rule Modules for Network Traffic Identification and Classification

To better organize and maintain rules, Aegis divides the ruleset into multiple modules:

ModuleNameFileDescriptionCriteria
Untrusted Certificate AuthoritiesCA_Block.listMarks CA root certificates, OCSP endpoints, and certificate revocation list (CRL) domains with records of mis-issuance or revocation. Suitable for strengthening digital trust-chain scenarios. Advanced module, disabled by default.Records of certificate mis-issuance, forged issuance, or revocation
Advertising Domain IdentificationAdDomain.listCovers domain identification for commercial advertising delivery, social pixel tracking, behavioral analytics, and third-party statistics SDKs. Identification module, disabled by default.Identified based on delivery behavior characteristics and data collection patterns, distinct from telemetry or monitoring communication
Adult Content IdentificationAdultDomain.listCovers domain identification for major global adult-content platforms. Identification module, disabled by default.Domains directly associated with adult-content distribution
PCDN Communication IdentificationPCDNDomain.listIdentifies communication behavior suspected of using shared-bandwidth architecture, involving device forwarding, cache relay, and distributed delivery nodes. Identification module, disabled by default.Identified by communication paths and node distribution patterns involving multi-hop relay, cache, and forwarding characteristics
Inspection and Node IdentificationInspectionDomain.listIdentifies active intervention behavior at the link or egress level, including DPI probing, DNS pollution, HTTP injection, and man-in-the-middle monitoring. Identification module, disabled by default.Identifies traffic tampering, redirection, and injection behavior by abnormal communication characteristics, common in link-intervention environments
Behavioral Analytics / Telemetry Node IdentificationBehaviorDomain.listIdentifies cloud service nodes with behavioral fingerprint characteristics, including telemetry SDKs, analytics platforms, and behavior modeling services, based on DNS patterns, TLS handshakes, CDN requests, and related characteristics. Identification module, disabled by default.Focuses on communication characteristics of behavioral analytics SDKs, using DNS/TLS packets and behavior patterns for identification while excluding advertising and background upload SDKs
Background Callback and Silent Communication Node BlockingBackground_Block.listIdentifies domains in IoT, NAS, or SDK scenarios with configuration upload, device callback, and similar characteristics, assisting in identifying monitoring-style silent communication. Blocking module, enabled by default.Focuses on background connection behavior of monitoring-style SDKs, identified by communication frequency, callback paths, and data upload characteristics while excluding advertising and behavior modeling SDKs
Backdoor Control and Implant Communication Node BlockingBackdoor_Block.listBlocks communication behavior with malicious characteristics such as remote control, reverse connection, and heartbeat behavior by default, including RAT, Sliver, Metasploit, and similar infrastructure. Blocking module, enabled by default.Clearly malicious communication patterns or direct association with implant attack behavior
Botnet and Control Node BlockingBotnet_Block.listBlocks known Botnet control sources, DDoS nodes, mass-control infrastructure, and related communication paths by default. Blocking module, enabled by default.Based on public reports with clear attribution and verifiable intelligence chains
APT Attack Source BlockingAPT_Block.listBlocks known C2 infrastructure of APT groups by default, including attributed country codes and IOC sources. Blocking module, enabled by default.Based on public reports with clear attribution and verifiable intelligence chains
Pegasus Spyware Communication Node BlockingPegasus_Block.listIncludes Pegasus controllers and command nodes published by Amnesty for identifying extremely high-risk monitoring communication. Blocking module, enabled by default.Based on publicly disclosed Pegasus control nodes from Amnesty, with monitoring risk
Phishing BlockingPhishing_Block.listBlocks phishing-related domains by default, covering fake login pages, impersonated official sites, phishing email links, and other typical social engineering attack behavior. Blocking module, enabled by default.Based on public reports with clear attribution and verifiable intelligence chains
Scam BlockingScam_Block.listBlocks suspicious website domains with very low reputation, fraud, fake services, or user reports by default. Blocking module, enabled by default.Based on public reports with clear attribution and verifiable intelligence chains
Risk Communication Observation ListQuarantine_Block.listIncludes domains and IPs that are not yet confirmed malicious but show abnormal communication characteristics, such as opaque purposes, non-public protocols, or unusual ports. It applies defensive blocking to reduce potential risk. Observation module, enabled by default.Based on abnormal communication behavior characteristics. Risk is not fully confirmed, so isolation and observation are used for later analysis and verification

Through multiple preset rule modules, Aegis separates different communication identification needs so each group of rules has a relatively clear focus. Users can enable or disable specific modules according to their own usage scenarios without accepting all rule content at once.

This structure keeps the rule system consistent as a whole while preserving choice and extensibility.

Extends Domain Identification for Major Global Advertising, Behavior Tracking, and Adult-content Platforms

In real network environments, many communications do not come directly from the application itself, but from advertising platforms, analytics services, behavior tracking systems, or specific content platforms.

The Aegis ruleset covers many common domains of this type worldwide, identifying their occurrence frequency and behavior characteristics in the network. This identification is not the same as default blocking. It provides users with a basis for judgment so they can clearly understand the source and purpose of a communication.

Whether to further restrict, route, or observe these communications is always decided by the user.

Uses Modular Design Such as Optional Regional Routing, Supporting User-defined Traffic Policies

After communication is identified and classified, Aegis does not prescribe a unified handling method. Instead, it provides the basic conditions for users to define traffic policies.

Based on rule matches, users can design different routing logic according to communication source, category, or purpose. For example, different types of traffic can be handled by different policies, or routing methods can be defined for specific regions or service types to better match the user’s network environment.

This routing capability is not mandatory. It exists as an optional tool. Users can gradually introduce optional regional routing policies after fully understanding communication behavior, without needing to make complex configurations for all traffic at once.

In this way, network policy is no longer limited to simple allow or block decisions. It can be adjusted in a more detailed and controllable way according to real usage scenarios, while keeping the overall rule system clear and maintainable.

Who Aegis Is For

Aegis is not for everyone, but it has unique value for users who care about understanding network behavior and maintaining independent control. Aegis is likely suitable for you if you:

  • Want to understand the traffic structure and behavior types on your device instead of blindly allowing or blocking
  • Want to build more granular traffic policies that better fit your own scenarios
  • Value rule transparency, auditability, and sustainable maintenance
  • Want to avoid black-box judgments and make decisions based on rules and facts

For users who only want a smooth default internet experience, Aegis will not break normal network access. But using Aegis more deeply can help you better understand the details of network communication.

What You Can Do Next

After reading this article, you can continue exploring according to your own goals:

With these resources, you can move from theoretical understanding to practical use and define policies on your own devices that better fit your usage scenarios.

Share :

Related Posts

Explore the Core Capabilities of Aegis

Explore the Core Capabilities of Aegis

Aegis is a personal digital firewall ruleset based on Surge. It helps users accurately identify and classify traffic locally on iOS and macOS, then define traffic policies according to their own need

read more
Core Reasons to Choose Aegis

Core Reasons to Choose Aegis

Aegis is a personal digital firewall ruleset based on Surge. It helps users accurately identify and classify traffic locally on iOS and macOS, then define traffic policies according to their own need

read more
Aegis Adaptation for Apple Usage Scenarios

Aegis Adaptation for Apple Usage Scenarios

As digital services increasingly rely on cloud infrastructure, communication visibility is becoming an important prerequisite for evaluating network security maturity. Aegis was built in this context.

read more
Aegis Adaptation for Cloudflare Usage Scenarios

Aegis Adaptation for Cloudflare Usage Scenarios

In today's internet infrastructure, Cloudflare has become one of the most common network infrastructure platforms on the modern internet. Personal websites, open source projects, enterprise applicatio

read more
Aegis Adaptation for Crypto Asset Usage Scenarios

Aegis Adaptation for Crypto Asset Usage Scenarios

Aegis is a personal digital firewall ruleset built on Surge and designed for users who need a highly controllable network environment. In crypto asset usage scenarios, network communication is often

read more
Aegis Adaptation for GitHub Usage Scenarios

Aegis Adaptation for GitHub Usage Scenarios

Aegis is a personal digital firewall ruleset built on Surge, designed to help users accurately identify and classify network traffic locally on iOS and macOS, then independently define traffic policie

read more
Aegis Adaptation for Google Usage Scenarios

Aegis Adaptation for Google Usage Scenarios

In network environments that rely heavily on cloud infrastructure, whether communication is clearly visible is gradually becoming an important foundation for digital security. Aegis was built in this

read more
Aegis Adaptation for Microsoft Usage Scenarios

Aegis Adaptation for Microsoft Usage Scenarios

Microsoft has become an indispensable part of daily use for many users. Email, file synchronization, collaboration, communication, authentication, and related capabilities run steadily in the backgrou

read more
Aegis Adaptation for Telegram Usage Scenarios

Aegis Adaptation for Telegram Usage Scenarios

Aegis is a personal digital firewall ruleset based on Surge, designed for users with long-term needs for security, stability, and controllability. It is especially suitable for highly sensitive networ

read more
Aegis Adaptation for OpenAI Usage Scenarios

Aegis Adaptation for OpenAI Usage Scenarios

As artificial intelligence becomes rapidly widespread, OpenAI has become an important part of daily work and learning for many users. From conversation generation and text polishing to code assistance

read more
The Design Intent of Aegis

The Design Intent of Aegis

I began paying attention to device security not out of technical curiosity, but because of a persistent sense of security anxiety. In real-world use, I repeatedly encountered abnormal communication a

read more
How to Use the Aegis Ruleset

How to Use the Aegis Ruleset

Before using Aegis, it is necessary to briefly explain its position. Aegis is a personal digital firewall ruleset based on Surge. It helps users accurately identify and classify traffic locally on i

read more