Skip to content
← All courses

Intermediate · Lessons: 8

AI-driven desktop defense: host-based firewalls on macOS

Why the laptop is the new perimeter, how a modern Mac firewall hooks into the system without a kernel extension, and how behavioural signals, a learned baseline, context and plain-language rules work together, with FireAI as the worked example.

Start the course

  1. 1 The endpoint is the perimeter: why the laptop needs its own firewall

    Zero trust stops assuming that anything inside the office network is safe. Learn why that moves a large part of the defence onto the laptop itself, and what a host-based firewall adds when the device leaves the building.

    7 min
  2. 2 macOS Network Extensions: how a modern Mac firewall sees every connection

    Mac firewalls no longer need kernel extensions. Learn how Apple’s Network Extension content filters work, why they are safer, what the user must approve, and how FireAI uses them.

    8 min
  3. 3 Behavioural signals vs static rules: what a firewall can actually observe

    Static rules say what is allowed; behavioural signals notice when something changes. Learn which behaviours a network firewall can see, which it cannot, and how FireAI combines weak signals into one risk score.

    8 min
  4. 4 Learning a baseline: AI-driven anomaly detection on one Mac

    An on-device model can learn what is normal for one person’s Mac and act on the everyday cases. Learn how baselines work, why they drift and can be poisoned, and the safeguards FireAI’s Autopilot uses.

    8 min
  5. 5 Application-layer filtering: why port 443 proves nothing

    Almost everything travels over HTTPS on port 443, including attackers’ traffic. Learn why filtering by app identity beats filtering by port, what a firewall can learn from an encrypted connection without decrypting it, and where that stops.

    8 min
  6. 6 Context-aware security: one laptop, many networks

    The same connection can be fine at home and risky in a café. Learn why good policy depends on context, which signals a laptop can trust, and how FireAI’s security modes, Coffee Shop Armor and Wi-Fi places change the rules as you move.

    8 min
  7. 7 Seeing the network: threat visualisation and its limits

    A map of live connections turns thousands of log lines into something a person can read at a glance. Learn what visualisation is good for, why IP geolocation is only approximate, and how to read FireAI’s world map without over-reading it.

    7 min
  8. 8 Natural-language firewall rules, with a human in the loop

    Typing “block Teams after 6pm” is easier than filling in a rule form, but a security tool that acts on language must never guess silently. Learn how natural-language rule generation should be built, what can go wrong, and how Ask FireAI keeps you in control.

    8 min

Free, no account, nothing tracked. Your progress stays in this browser.