Heimdal DNS Security Endpoint

Filters endpoint DNS and web traffic to block harmful destinations.

For endpoint environments needing DNS and web traffic filtering across local and remote connections.

Filter harmful web destinations at the endpoint

Endpoint web requests can reach harmful domains through DNS, HTTP or HTTPS traffic, including encrypted DNS over HTTPS connections. IT teams may also need to understand which cloud applications endpoints are accessing and apply restrictions to specific applications.

Heimdal DNS Security Endpoint processes web requests through a local DNS service, using threat intelligence and machine learning to identify and block malicious or potentially malicious destinations. It also supports allow and block lists, associates threats with processes, and discovers cloud applications for access control.

Where Heimdal DNS Security Endpoint is used

The product is suited to filtering endpoint DNS and web traffic for on-site and remote users, including VPN connections and DNS over HTTPS traffic. Process correlation and forensic information provide context for investigating identified threats.

It is also useful where organisations need an endpoint-derived record of cloud application use, including application vendors, endpoints and risk levels, with the option to control access or add applications to block lists.

Fits within these solutions

DNS Security
Endpoint Protection
Endpoint Detection & Response
Browser Security

Suitable environments

Heimdal DNS Security Endpoint is intended for endpoint environments using on-site or remote connections, including VPN use and IPv4 or IPv6 traffic. It filters endpoint DNS, HTTP and HTTPS traffic rather than providing broader endpoint security on its own.

Benefits

Fewer harmful connections

Reduces endpoint connections to malicious or potentially malicious web destinations.

Encrypted DNS coverage

Extends filtering to DNS over HTTPS traffic rather than relying on unencrypted DNS alone.

Investigation context

Links identified threats to associated processes and forensic information.

Cloud app visibility

Provides a record of cloud applications accessed from endpoints and their risk levels.

Capabilities

DNS and web filtering

Filters endpoint DNS, HTTP and HTTPS traffic according to DNS requests.

Local DNS service

Creates a local DNS service to process web requests and block malicious content.

DNS over HTTPS

Filters DNS over HTTPS traffic from endpoints.

Threat identification

Uses threat intelligence and machine learning to identify malicious or potentially malicious domains.

Custom access lists

Supports custom allow and block lists for web destinations.

Cloud app discovery

Records cloud application names, vendors, endpoints and risk levels across endpoints.

Common Use Cases

Endpoint destination filtering

Apply DNS-based filtering to endpoint requests for web destinations.

Remote user filtering

Filter endpoint traffic for users working remotely or through VPN connections.

Threat process review

Review identified threats alongside their associated endpoint processes.

Cloud app access control

Discover cloud applications and add selected applications to access block lists.

How we help

Armstrong can discuss endpoint DNS filtering requirements, including the need to filter DNS over HTTPS traffic and manage access to discovered cloud applications. Discovery meetings help establish whether the product's endpoint-focused controls fit the organisation's existing security arrangements.

Part of (depending on licence)

Resources

How would you like to proceed?