# How FireAI watches your Mac’s connections

> This is how a Mac firewall can work without a kernel extension: FireAI sits on your Mac as an Apple Network Extension content filter, so it can see and judge every app’s connection without a separate helper daemon.

FireAI Docs (HisnLabs) · Recurso · Disponível desde o FireAI 0.1.0
Canonical: https://hisnlabs.com/fireai/en/docs/how-the-network-filter-works

**Onde no FireAI:** Setup, and every page that shows live connections

Know which app is talking to the internet, in plain terms, without installing anything that runs as a hidden background service.

A firewall that needs a kernel extension, or a helper running quietly with root access, is a lot to trust. FireAI is built on Apple’s own Network Extension content filter framework instead, the same mechanism apps like a corporate VPN client use, running as an ordinary system extension you approve once in Setup.

## What it does for you

Every outbound connection your Mac makes, from Zoom joining a call to a game launcher checking for updates, passes through FireAI first. FireAI identifies the exact app by its code signature, not just its name, so a fake copy of a real app doesn’t inherit that app’s rules.

## How it works

- FireAI registers a system extension that macOS asks about every new connection, before it opens: app identity, remote host or IP, port and protocol.
- For apps that resolve names themselves (many browsers and Electron apps), FireAI reads the DNS answer to attach the real hostname to the connection — so a rule for `*.microsoft.com` still matches even when the app only ever shows an IP.
- Turning off `Protect this Mac` on the Protection page does not stop FireAI from watching: it keeps reporting every connection, it just stops blocking or asking about them (FireAI Pilot, prompts and rules pause too).
- FireAI also enforces rules on incoming connections to your Mac, not only outgoing ones — but it never prompts you about an incoming connection, and it does not (yet) show a list of which apps are currently listening for them.

## Good to know

> **Note:** FireAI only sees flows the filter is asked about, and only while the filter is running. It does not read the contents of an encrypted connection — see [how connections are inspected without decryption](https://hisnlabs.com/fireai/en/docs/protocol-inspection-without-decryption) for what it can and can’t tell.

> **Warning:** If the filter ever fails to load your rules, FireAI allows traffic and shows an alert rather than cutting your Mac off the network. The kill switch is the only deliberate “block everything” switch, and you have to turn it on yourself.

## Leia em seguida

- [Install the FireAI Mac firewall and finish Setup](https://hisnlabs.com/fireai/pt-br/docs/install-and-finish-setup.md)
- [Answer your first connection prompt, and what each lifetime means](https://hisnlabs.com/fireai/pt-br/docs/answer-your-first-connection-prompt.md)
- [Mac firewall rules: by app, website, domain, IP or range](https://hisnlabs.com/fireai/pt-br/docs/per-app-rules.md)
- [Deep inspection, without decrypting anything](https://hisnlabs.com/fireai/pt-br/docs/protocol-inspection-without-decryption.md)

---

Teste todos os recursos grátis por 17 dias, sem cartão. Garantia de reembolso de 30 dias. [Baixar para Mac](https://hisnlabs.com/fireai/pt-br/download)
