
What Is Included in Aegis
- ThoseYearsBrian
- Concepts
- 07 Jan, 2026
Aegis is a personal digital firewall ruleset based on Surge.
It helps users accurately identify and classify traffic locally on iOS and macOS, then define traffic policies according to their own needs.
Aegis is not traditional protection software, and it does not automatically make security decisions for you.
It is a ruleset for identifying and presenting network communication behavior.
In real use, Aegis identifies and classifies network communication.
It helps you understand more clearly how different applications and services communicate.
A rule match only means that a communication has been identified. It describes the type and behavior characteristics of the communication, but it does not itself make a risk judgment.
Based on this visible information, users can define corresponding traffic policies according to their own usage scenarios and needs.
This process is not complicated and does not depend on frequent adjustment. Instead, through long-term use, it gradually establishes a stable and sustainable way of judgment.
On this basis, the Aegis ruleset can also be used as a basis for traffic routing.
By identifying and classifying different communication behaviors, users can route traffic to different policies, nodes, or handling methods instead of being limited to simple allow or block decisions.
What Aegis Includes
Aegis is not a single-purpose rule collection. It is a rule system built around network communication visibility, understandability, and controllability. Its content is mainly reflected in the following areas.
Uses Encrypted DNS Throughout and Rejects Plaintext Requests
In network communication, DNS queries are often one of the easiest parts to overlook, yet they are highly sensitive.
The default assumption in Aegis rule design is that plaintext DNS requests should not be the norm.
Therefore, related rules prioritize guiding or constraining communication behavior toward encrypted DNS, preventing domain resolution from being exposed in plaintext or tampered with by intermediate nodes. This design is not about “forced blocking”; it provides users with a safer default communication premise that better matches modern network environments.
Focuses on Identifying Potential Communication Risks at the Application and Transport Layers
Aegis does not limit identification to a single protocol or scenario. It focuses on real communication behavior occurring at the application and transport layers.
Through rule matching, Aegis attempts to identify behavior characteristics of different applications, services, or components during communication, such as whether third-party services are involved, whether abnormal request patterns exist, or whether the communication is related to known tracking, analytics, or distribution mechanisms.
These identification results are not direct risk judgments. They provide foundational information for users to understand communication behavior.
10+ Preset Rule Modules for Network Traffic Identification and Classification
To better organize and maintain rules, Aegis divides the ruleset into multiple modules:
| Module | Name | File | Description | Criteria |
|---|---|---|---|---|
| ① | Untrusted Certificate Authorities | CA_Block.list | Marks CA root certificates, OCSP endpoints, and certificate revocation list (CRL) domains with records of mis-issuance or revocation. Suitable for strengthening digital trust-chain scenarios. Advanced module, disabled by default. | Records of certificate mis-issuance, forged issuance, or revocation |
| ② | Advertising Domain Identification | AdDomain.list | Covers domain identification for commercial advertising delivery, social pixel tracking, behavioral analytics, and third-party statistics SDKs. Identification module, disabled by default. | Identified based on delivery behavior characteristics and data collection patterns, distinct from telemetry or monitoring communication |
| ③ | Adult Content Identification | AdultDomain.list | Covers domain identification for major global adult-content platforms. Identification module, disabled by default. | Domains directly associated with adult-content distribution |
| ④ | PCDN Communication Identification | PCDNDomain.list | Identifies communication behavior suspected of using shared-bandwidth architecture, involving device forwarding, cache relay, and distributed delivery nodes. Identification module, disabled by default. | Identified by communication paths and node distribution patterns involving multi-hop relay, cache, and forwarding characteristics |
| ⑤ | Inspection and Node Identification | InspectionDomain.list | Identifies active intervention behavior at the link or egress level, including DPI probing, DNS pollution, HTTP injection, and man-in-the-middle monitoring. Identification module, disabled by default. | Identifies traffic tampering, redirection, and injection behavior by abnormal communication characteristics, common in link-intervention environments |
| ⑥ | Behavioral Analytics / Telemetry Node Identification | BehaviorDomain.list | Identifies cloud service nodes with behavioral fingerprint characteristics, including telemetry SDKs, analytics platforms, and behavior modeling services, based on DNS patterns, TLS handshakes, CDN requests, and related characteristics. Identification module, disabled by default. | Focuses on communication characteristics of behavioral analytics SDKs, using DNS/TLS packets and behavior patterns for identification while excluding advertising and background upload SDKs |
| ⑦ | Background Callback and Silent Communication Node Blocking | Background_Block.list | Identifies domains in IoT, NAS, or SDK scenarios with configuration upload, device callback, and similar characteristics, assisting in identifying monitoring-style silent communication. Blocking module, enabled by default. | Focuses on background connection behavior of monitoring-style SDKs, identified by communication frequency, callback paths, and data upload characteristics while excluding advertising and behavior modeling SDKs |
| ⑧ | Backdoor Control and Implant Communication Node Blocking | Backdoor_Block.list | Blocks communication behavior with malicious characteristics such as remote control, reverse connection, and heartbeat behavior by default, including RAT, Sliver, Metasploit, and similar infrastructure. Blocking module, enabled by default. | Clearly malicious communication patterns or direct association with implant attack behavior |
| ⑨ | Botnet and Control Node Blocking | Botnet_Block.list | Blocks known Botnet control sources, DDoS nodes, mass-control infrastructure, and related communication paths by default. Blocking module, enabled by default. | Based on public reports with clear attribution and verifiable intelligence chains |
| ⑩ | APT Attack Source Blocking | APT_Block.list | Blocks known C2 infrastructure of APT groups by default, including attributed country codes and IOC sources. Blocking module, enabled by default. | Based on public reports with clear attribution and verifiable intelligence chains |
| ⑪ | Pegasus Spyware Communication Node Blocking | Pegasus_Block.list | Includes Pegasus controllers and command nodes published by Amnesty for identifying extremely high-risk monitoring communication. Blocking module, enabled by default. | Based on publicly disclosed Pegasus control nodes from Amnesty, with monitoring risk |
| ⑫ | Phishing Blocking | Phishing_Block.list | Blocks phishing-related domains by default, covering fake login pages, impersonated official sites, phishing email links, and other typical social engineering attack behavior. Blocking module, enabled by default. | Based on public reports with clear attribution and verifiable intelligence chains |
| ⑬ | Scam Blocking | Scam_Block.list | Blocks suspicious website domains with very low reputation, fraud, fake services, or user reports by default. Blocking module, enabled by default. | Based on public reports with clear attribution and verifiable intelligence chains |
| ⑭ | Risk Communication Observation List | Quarantine_Block.list | Includes domains and IPs that are not yet confirmed malicious but show abnormal communication characteristics, such as opaque purposes, non-public protocols, or unusual ports. It applies defensive blocking to reduce potential risk. Observation module, enabled by default. | Based on abnormal communication behavior characteristics. Risk is not fully confirmed, so isolation and observation are used for later analysis and verification |
Through multiple preset rule modules, Aegis separates different communication identification needs so each group of rules has a relatively clear focus. Users can enable or disable specific modules according to their own usage scenarios without accepting all rule content at once.
This structure keeps the rule system consistent as a whole while preserving choice and extensibility.
Extends Domain Identification for Major Global Advertising, Behavior Tracking, and Adult-content Platforms
In real network environments, many communications do not come directly from the application itself, but from advertising platforms, analytics services, behavior tracking systems, or specific content platforms.
The Aegis ruleset covers many common domains of this type worldwide, identifying their occurrence frequency and behavior characteristics in the network. This identification is not the same as default blocking. It provides users with a basis for judgment so they can clearly understand the source and purpose of a communication.
Whether to further restrict, route, or observe these communications is always decided by the user.
Uses Modular Design Such as Optional Regional Routing, Supporting User-defined Traffic Policies
After communication is identified and classified, Aegis does not prescribe a unified handling method. Instead, it provides the basic conditions for users to define traffic policies.
Based on rule matches, users can design different routing logic according to communication source, category, or purpose. For example, different types of traffic can be handled by different policies, or routing methods can be defined for specific regions or service types to better match the user’s network environment.
This routing capability is not mandatory. It exists as an optional tool. Users can gradually introduce optional regional routing policies after fully understanding communication behavior, without needing to make complex configurations for all traffic at once.
In this way, network policy is no longer limited to simple allow or block decisions. It can be adjusted in a more detailed and controllable way according to real usage scenarios, while keeping the overall rule system clear and maintainable.
Who Aegis Is For
Aegis is not for everyone, but it has unique value for users who care about understanding network behavior and maintaining independent control. Aegis is likely suitable for you if you:
- Want to understand the traffic structure and behavior types on your device instead of blindly allowing or blocking
- Want to build more granular traffic policies that better fit your own scenarios
- Value rule transparency, auditability, and sustainable maintenance
- Want to avoid black-box judgments and make decisions based on rules and facts
For users who only want a smooth default internet experience, Aegis will not break normal network access. But using Aegis more deeply can help you better understand the details of network communication.
What You Can Do Next
After reading this article, you can continue exploring according to your own goals:
- Read How to Use the Aegis Ruleset to learn practical usage
- Watch the iOS video tutorials and macOS video tutorials for a deeper understanding
- Review the complete rules and module documentation on GitHub
With these resources, you can move from theoretical understanding to practical use and define policies on your own devices that better fit your usage scenarios.











