- DNS Security Endpoint Reimagined.
- Application Control for macOS.
- Scheduled Scan capabilities for Home users.
- Fix for Administrator rights persisting after PEDM elevation expiry.
- Fix for macOS device visibility (online status and hostname uniqueness handling).
Heimdal DNS Security Network and Endpoint
● DNS Security Endpoint reimagined for macOS
This release introduces a major architectural evolution of DNS Security Endpoint on macOS. Following extensive operational experience with Apple's Network Extension framework, Heimdal has fully redesigned the DNS enforcement engine to address deployment complexity, operating system dependencies, and lifecycle limitations associated with extension-based DNS filtering.
At the core of this enhancement is the introduction of a dedicated local DNS server architecture, replacing the previous NEDNSProxyProvider implementation. DNS traffic is now processed through the HeimdalDNSProxy service, a privileged LaunchDaemon capable of operating independently of Network Extension activation and approval workflows.
This approach simplifies deployment, reduces administrative overhead, improves service resilience, and ensures DNS protection remains active throughout the device lifecycle, including before user sign-in.
From an IT Administrator's perspective, policy management remains unchanged and continues to be performed through the familiar DNS Security interface within the Heimdal Dashboard.
Administrators already managing DNS Security across Windows environments will benefit from the same policy workflows, reporting experience, and configuration model, ensuring a consistent cross-platform administration experience.
The architectural improvements are delivered transparently while preserving existing DNS Security capabilities, including threat intelligence validation, category-based filtering, allowlists and blocklists.
In addition, this release introduces support for custom block pages on macOS, further aligning the platform with the DNS Security experience available on Windows.
Together, these changes simplify deployment, reduce operational overhead, and provide a more resilient foundation for DNS protection on macOS.
When DarkLayer Guard™ protection is enabled, the new DNS Security Endpoint architecture automatically deploys and starts the HeimdalDNSProxy service, preserves the endpoint's existing DNS configuration, and transparently redirects DNS traffic through a dedicated local DNS server operating on 127.1.1.6:53 (UDP and TCP).
Existing DNS resolvers are retained as upstream providers, allowing the solution to integrate seamlessly into the endpoint's existing network configuration without requiring administrator intervention.
Once traffic reaches the local DNS server, every request is evaluated against the configured DNS Security policy, including Heimdal threat intelligence, allowlists, blocklists, category-based filtering rules and other protection controls.
Allowed requests are forwarded to the configured upstream resolver, while blocked requests are redirected to the configured Heimdal block page. Should protection be disabled or the Agent removed, the original DNS configuration is automatically restored.
The evaluation process applies a layered decision model designed to balance protection and operational flexibility. DNS requests are assessed against configured allowlists, blocklists, locally cached validation results, and Heimdal threat intelligence before a final decision is reached. Domains that do not match any blocking criteria are allowed and forwarded to the configured upstream resolver.
To assist troubleshooting and operational monitoring, the Agent status tooltip provides visibility into the active local DNS route through 127.1.1.6, the currently configured upstream resolvers and the health state of the local DNS service.
Unlike the previous implementation, the new DarkLayer Guard™ architecture no longer depends on DNS Network Extension approval workflows. As a result, Starting or Degraded states should be investigated as local service, DNS routing, upstream resolver, policy synchronization, XPC communication, or custom block-page certificate issues rather than Network Extension configuration problems.
ENDPOINT SETTINGS/ GROUP POLICY
Consistent with the DNS Security experience already available on Windows, macOS policies continue to be configured through the familiar DNS Security interface within the Heimdal Dashboard.
DNS Security Endpoint settings can be configured from: Dashboard -> Endpoint Settings -> macOS -> Select or Edit a Group Policy -> DNS Security.
DLG™ policies are configured through the existing DNS Security interface and expose all controls required to manage DNS filtering, threat protection, custom block pages and domain-based exceptions.
Administrators can enable or disable DarkLayer Guard™, configure Domains Allowlist and Domains Blocklist entries, activate VectorN behavioral detection capabilities and customize the end-user experience through branded block pages.
Domains Allowlist and Domains Blocklist entries are centrally configured through Group Policies and automatically synchronized to assigned endpoints.
During policy evaluation, Allowlist entries take precedence over all other DNS Security controls, ensuring explicitly approved domains remain accessible even when they would otherwise match blocklists or threat intelligence indicators.
Blocklist entries can be used to explicitly deny access to specific domains and their associated subdomains, providing administrators with granular control over permitted and restricted destinations.
The redesigned architecture continues to support both the standard Heimdal-hosted block page and fully customized block pages.
Organizations can personalize the blocked-page experience by configuring their own branding, custom messaging, and company logo directly from the Heimdal Dashboard.
When custom block pages are enabled, the Agent securely retrieves and caches the configured content locally, ensuring a consistent user experience even during temporary connectivity interruptions. Support for HTTPS block pages is also available through automated certificate deployment and trust management.
All policy changes are applied through the existing Group Policy workflow, allowing Heimdal Dashboard users to configure, preview, duplicate and distribute DNS Security settings while maintaining a familiar cross-platform administration experience across both Windows and macOS environments.
HEIMDAL DASHBOARD/ PRODUCT VIEWS
DNS Security Endpoint activity is centrally reported within the Heimdal Dashboard under Products -> DNS Security -> Endpoint. The reporting experience follows the same investigation and visibility principles already familiar from Heimdal's Windows platform.
The interface provides both operational visibility and detailed investigation capabilities, allowing administrators to monitor DNS activity, review policy enforcement results, identify blocked requests and analyze endpoint risk exposure across managed macOS devices.
The Heimdal Dashboard includes high-level counters for Analyzed Traffic Requests, Prevented Attacks, Manual Blocklists and Category Blocks, helping security teams quickly assess the effectiveness of deployed DNS Security policies.
Reporting data can be filtered by timeframe, hostname, Group Policy assignment and additional event criteria, while CSV export capabilities support offline analysis and compliance workflows.
The Standard view presents aggregated endpoint-level statistics, including Hostname, Username, IP Address, Analyzed Requests, Prevented Attacks, Manual Blocklists, and Risk Level indicators.
Additional reporting tabs provide dedicated visibility into category-based filtering actions, manually blocked domains, allowlisting activity, full DNS logging data, investigation workflows, and CASB-related events where applicable.
Selecting (clicking) a hostname opens the corresponding Client Specifics page for the selected endpoint, where administrators can review device information, policy assignment, operational status and detailed DNS Security Endpoint activity.
Information is organized into dedicated product and feature views, providing both high-level endpoint context and detailed event analysis for DarkLayer Guard™ Endpoint and VectorN Endpoint.
Within the DarkLayer Guard™ Endpoint view, administrators can review DNS Security events across multiple categories, including Prevented Attacks, Manual Blocklists, Allowed, Analyzed, Category Blocks and Full Logging data.
Consistent with the DNS Security Endpoint product views, the same investigation-centric structure is preserved while presenting activity for the selected endpoint rather than aggregated data across multiple devices.
Event records include key investigation details such as Active Username, Domain, Threat Type, TTPC (Threat-to-Process Correlation), Protocol, Timestamp, and Status, enabling rapid identification and analysis of malicious, suspicious, or policy-controlled DNS activity. Integrated actions provide direct access to Heimdal investigation and forensic data, external reputation lookups where available, and process-correlation information, helping security teams accelerate threat hunting and incident response activities.
HEIMDAL AGENT
DarkLayer Guard™ is also available directly within the Heimdal Agent through Agent -> DNS Security, providing end users and administrators with local visibility into the current protection status, DNS filtering activity and endpoint-specific security events.
The interface displays the operational state of the DNS Security Endpoint engine together with relevant protection metrics, including analyzed traffic, prevented attacks, blocked traffic statistics, VectorN detections and TTPC (Threat-to-Process Correlation) activity.
The See details view enables direct investigation of DNS Security events recorded on the endpoint, including blocked domains, threat classifications, TTPC (Threat-to-Process Correlation) data, timestamps, and enforcement actions. The view includes built-in search and navigation capabilities to facilitate event analysis.
While Home users can locally allowlist blocked domains directly from the Agent, centrally managed environments continue to enforce allowlisting exclusively through Group Policies. This approach provides users with immediate visibility into DNS protection activity while ensuring that security policy enforcement remains aligned with organizational requirements.
Heimdal Privileges & App. Control
● Application Control arrives on macOS
This release introduces Application Control for macOS, bringing Heimdal's application allowlisting and execution-control capabilities to Apple endpoints for the first time.
Building on capabilities already available for Windows, the new module brings powerful application allowlisting and execution control to macOS endpoints.
Using Apple's native Endpoint Security framework, it evaluates application, process and script execution in real time, enabling administrators to enforce granular policies through Allow, Block or Reporting Only actions based on trusted indicators such as file attributes, hashes, digital signatures, certificates, Team IDs, software names and command-line arguments.
Combined with script-aware enforcement, unified PEDM integration, local notifications, audit history, and centralized Dashboard reporting, Application Control helps organizations maintain tighter control over software execution, improve security posture, and achieve consistent governance across their macOS environment.
ENDPOINT SETTINGS/ GROUP POLICY
Application Control is centrally managed from the Heimdal Dashboard through Endpoint Settings -> macOS GPs -> Privileges & App Control -> Application Control tab, providing a consistent, intuitive and streamlined administration experience across the Heimdal platform.
The Application Control policy provides administrators with a comprehensive set of controls for managing software execution across macOS endpoints. From the main configuration panel, administrators can enable or disable the module, define enforcement behavior, configure default actions for unmatched applications and scripts, manage Team ID allowlists, and create or maintain execution rules.
Additional options support enhanced visibility through Full Logging Mode and allow integration with Privileged Elevation and Delegation Management (PEDM) for approved elevation scenarios.
Ruleset Mode defines how the product module evaluates and responds to application, process and script execution events. In Disable mode, the module does not enforce any policies, allowing all executions to proceed normally.
When set to Enable, the solution actively enforces the configured ruleset, evaluating each execution request in real time and applying the corresponding Allow or Block action when a matching rule exists. If no rule is matched, the execution outcome is determined by the configured Default File Action.
For organizations looking to assess policy impact before enforcement, Reporting Only mode provides full visibility into execution activity without interrupting users, allowing all processes to run while logging rule matches and intercepted events for auditing, analysis and policy fine tuning purposes.
Default File Action determines how App C handles applications, processes and scripts that do not match any explicitly configured rule.
This setting provides administrators with a final decision path for previously unknown or unclassified software, allowing them to adopt either a permissive or restrictive execution model. When configured to Allow, unmatched executions are permitted to run, reducing the likelihood of operational disruption while still enforcing existing rules.
When configured to Block, any execution that does not match an approved rule is denied, enabling a default-deny security posture. This behavior is applied only when Ruleset Mode is set to Enable, helping organizations balance security requirements with operational flexibility.
The Rule Editor is used to create and manage Application Control rules that determine how applications, executables, scripts, and processes are handled across managed endpoints.
Administrators can define Allow or Block actions based on a variety of matching criteria, including application names, file paths, wildcard paths, MD5 hashes, Apple Team IDs, code-signing signatures, certificate subjects, and command-line arguments. Each rule includes a matching value, rule type, priority, and action, enabling the creation of granular policies tailored to specific operational and security requirements.
Rules are evaluated according to their assigned priority, ensuring that more specific or critical policies take precedence over broader ones.
This flexible approach supports everything from simple allowlists and blocklists to advanced execution-control strategies based on software publishers, digital signatures, and execution context. Once configured, rules are added to the policy and become active after the updated Group Policy is saved and distributed to managed endpoints.
To create a new rule, select Add New Rule.
Application Control extends enforcement beyond traditional executables to cover a wide range of script and package formats commonly used on macOS environments. When Apply Default Action to Scripts is enabled, administrators can control the execution of AppleScript, shell and interpreted-language scripts, as well as application and installer packages.
Supported types include AppleScript formats (.osa, .applescript, .scpt, .scptd), shell scripts (.sh, .csh, .zsh, .command), interpreted languages such as Python, JavaScript, PHP, Ruby, Perl, Swift, PowerShell, and Tcl, together with application and installer formats including .app, .pkg, and .dmg.
When a script is launched, the Heimdal Agent identifies the associated interpreter, resolves the underlying script target, including /usr/bin/env redirections and evaluates the file against the configured Allowlist Script Extensions policy.
Allowlisted script types are permitted to execute, while managed script types that are not explicitly approved are handled according to the effective policy configuration. Dedicated handling of inline interpreter commands helps minimize false positives and reduce impact on legitimate administrative workflows.
Before a process is allowed to start, Application Control performs a series of policy validation steps. The solution first protects Heimdal components and essential operating system processes from accidental self-blocking, resolves the actual execution target when intermediary launch mechanisms are used and collects relevant metadata, including file path, version information, MD5 hash, code-signing details, process attributes and command-line parameters.
Configured rules are then evaluated according to their assigned priority, followed by any applicable script-control policies.
Where the Privilege Elevation and Delegation Management (PEDM) to bypass the ruleset option is enabled, an approved PEDM elevation can temporarily override an Application Control block, allowing the requested process to execute during the active elevation session. Following policy evaluation, the final Allow or Block decision is returned before process execution begins.
Policy decisions are evaluated in real time and are not permanently cached by the macOS Endpoint Security authorization layer, ensuring newly synchronized policies and rule updates take effect on subsequent execution attempts without requiring endpoint restarts or policy resets.
HEIMDAL DASHBOARD/ PRODUCT VIEWS
Application Control events and policy decisions are centrally reported within the Heimdal Dashboard under Products -> Privileges & App Control -> Application Control -> macOS tab. To support both operational monitoring and detailed investigation workflows, the reporting interface provides Standard and Raw views.
The Standard view presents processed and user-friendly event information for day-to-day administration, while the Raw view exposes the complete event details collected by the Agent, enabling deeper analysis, troubleshooting and validation of Application Control policy behavior across managed macOS endpoints.
Note:
- Standard view: Historical data is limited to a maximum of one calendar month ending on the selected To date.
- Raw view: Data is limited to the last 24 hours of the selected timeframe.
Within the dashboard grids, IT Administrators can review both Executions Allowed by Rules and Executions Blocked by Rules, helping assess policy effectiveness and identify security or operational risks.
Reporting data can be filtered by operating system, Group Policy, process attributes and additional event criteria, while CSV export capabilities support offline analysis and compliance reporting.
For macOS endpoints, reported events include key metadata such as Hostname, Process Name, Software Name, Version, MD5 Hash, Apple Team ID, Execution Status, Deny File Permissions indicators, and Timestamp information.
Together, these details provide comprehensive visibility into application execution activity, helping administrators investigate blocked processes, validate policy behavior, and refine Application Control configurations as needed.
HEIMDAL AGENT
Application Control activity is also available locally on macOS endpoints through Agent -> Privileges & App Control -> Application Control. The view provides end users with visibility into recent execution events, including the intercepted process name, final execution status (Allow or Block) and event timestamp.
The interface displays locally retained Application Control events and automatically refreshes when new execution decisions are received, policies are synchronized, or the view is reopened.
To provide immediate user feedback, Application Control generates local notifications whenever an application execution is explicitly allowed or blocked by policy.
Notifications are automatically dismissed after a short period, while the corresponding execution events are preserved locally and queued for Dashboard reporting.
To ensure reporting reliability, events are stored before being delivered from the dedicated App Control service to the Agent and are retained locally until successful synchronization with the Heimdal Dashboard.
When connectivity is temporarily unavailable, events are automatically retried upon recovery. Reporting mechanisms also include batching and deduplication logic to minimize duplicate records while maintaining reporting accuracy and consistency.
By bringing Application Control to macOS, Heimdal extends a key endpoint governance capability beyond the Windows platform, enabling organizations to adopt a more consistent application execution strategy across heterogeneous environments while reducing application-related risk and providing greater control over software execution across their macOS estate.
Other improvements & fixes
● Endpoint Detection -> Next-Gen Antivirus - Scheduled Scan capabilities for Home users
In addition to the enterprise-focused enhancements delivered in this release, macOS Agent 3.5.9 introduces Scheduled Scans for Heimdal Home users.
The new functionality enables security scans to run automatically at predefined intervals, helping ensure endpoints are regularly assessed without requiring user intervention.
End users can create recurring scan schedules tailored to their needs, such as running a Quick Scan every weekday before work starts, a Full System Scan every Sunday evening, or a Deep Scan on specific days each month. Flexible scheduling options support daily, weekly and monthly recurrence patterns, configurable execution times and multiple weekday or month-day selections within a single schedule.
By combining proactive scan scheduling with the existing Next-Gen Antivirus capabilities, users can maintain continuous visibility into their device's security posture while reducing the risk of threats remaining undetected between manual scans.
All scheduling, execution, persistence, and activity history management are performed locally by the Heimdal Agent, providing a seamless and self-contained protection experience for Home users.
The Scheduled Scans view is accessed through Agent -> Endpoint Detection -> Go To Scans -> Scheduled Scans and serves as the central location for managing recurring antivirus scans.
From here, Home users can create, modify, and remove scan schedules, configure recurrence settings and review scan activity history, providing a simplified and centralized experience for automated endpoint protection.
The Scheduled Scans view provides a consolidated overview of all configured recurring antivirus scans, including the schedule name, selected scan type, execution time and recurrence pattern.
Users can quickly review existing schedules, navigate between on-demand and scheduled scan workflows, and access the scan activity report to review execution history and results.
New schedules can be created directly from this view, while existing schedules can be modified either by opening the schedule entry or through the contextual actions menu.
Home users can update scan settings, adjust recurrence patterns, or remove schedules that are no longer required, providing a centralized and streamlined experience for managing automated Next-Gen Antivirus scans.
Selecting Add Scheduled Scan opens a guided two-step workflow used to configure a new recurring antivirus scan.
During the first step, users define the scan itself by selecting one of the available antivirus scan profiles and specifying a user-friendly scan name.
Supported scan types include Quick Scan, Active Processes Scan, Full Scan, Hard Drive Scan, Local Drive Scan, Removable Drive Scan, System Scan, and Network Drive Scan, allowing users to tailor automated protection to their specific requirements.
After selecting the desired scan profile, users proceed to the scheduling step, where the recurrence pattern and execution time are configured.
Scheduled scans can be configured to run daily, weekly, or monthly, with support for selecting multiple weekdays or multiple calendar dates within a single schedule. A real-time schedule summary provides a human-readable overview of the configured recurrence pattern before the schedule is saved and activated.
Once created, the schedule becomes immediately available in the Scheduled Scans view and will execute automatically according to the configuration.
Weekly and monthly schedules support multiple selections, which are displayed in chronological calendar order within the schedule list, ensuring consistent and predictable presentation regardless of the order in which values were originally selected.
Existing schedules can be modified by selecting Edit Schedule from the schedule actions menu or by opening the schedule directly from the list view.
The edit workflow uses the same two-step configuration process as schedule creation, with all existing settings automatically prepopulated, including the scan type, scan name, recurrence pattern, selected weekdays or calendar dates, and execution time.
Any changes are applied immediately after saving and the local scheduler is automatically refreshed to reflect the updated configuration.
To prevent duplicate entries, the Agent validates the modified schedule before saving. If another schedule already exists with the same configuration, the Agent displays a validation message and requires the user to adjust the scan name, recurrence settings, or execution time before the changes can be saved.
Existing schedules can be removed directly from the Scheduled Scans view by selecting Delete Schedule from the schedule actions menu. Before the removal is completed, the Agent displays a confirmation dialog to prevent accidental deletion of active recurring scan tasks.
Once confirmed, the schedule is permanently removed from local storage and immediately deregistered from the active scheduler. Any future automatic executions associated with the schedule are cancelled, while previously completed scan results remain available through the scan activity history for auditing and review purposes.
Scheduled Scans improve operational flexibility and help ensure regular malware inspections occur automatically, without requiring manual intervention from users.
By combining configurable recurrence schedules with Heimdal's Next-Gen Antivirus capabilities, Home users can maintain a more consistent security posture and reduce the likelihood of threats remaining undetected between manual scans.
● Fix for Administrator rights persisting after PEDM elevation expiry
Resolved an issue affecting Privilege Elevation and Delegation Management (PEDM), where administrator privileges could persist after an elevation session had ended under specific circumstances.
The elevation cleanup process has been improved to ensure temporary administrative access is correctly revoked once the approved elevation window expires, maintaining the intended least privilege security model.
● Fix for macOS device visibility (online status and hostname uniqueness handling)
Addressed an issue affecting macOS endpoint identification and hostname uniqueness handling, which could under specific circumstances lead to duplicate device representations, incorrect online/offline status reporting, or outdated Last Seen information within the Heimdal Dashboard.
Improvements to the device registration and synchronization process ensure more reliable endpoint visibility, accurate status reporting and consistent inventory representation across managed environments.