Connections and files

Connections and files

What AFKSecurity connects to, what it writes, and why.

This page lists every connection AFKSecurity makes and every place it writes on your computer, as of version 1.0.5. If you see something on your computer that is not listed here, please write to support@afksecurity.online and we will correct the page or the software.

There is no telemetry, no usage statistics, no analytics and no cloud scanning. Files, file names, program names and the contents of the log never leave your computer.

Connections

Three kinds of connection.

1. The licence check. Once a day, while the AFKSecurity window is running, it contacts https://afksecurity.online/api/licence/ over HTTPS, using Windows' own HTTPS stack and certificate validation. It sends a fingerprint of the computer (a SHA-256 hash of the hardware identifiers, from which they cannot be read back) and, only when you activate or release a licence, your licence key. It receives a token signed by our server, which the protection service checks itself. The licence screen shows what this token says. Offline, protection keeps working for up to 35 days.

2. The update check, when you ask for it. Only when you click Check for an update in the Updates tab, the window reads https://afksecurity.online/maj/afksecurity.json. If you then choose to install, it downloads the installer from the same site and checks it twice before running it: against the signed list of versions, and its Authenticode signature, which must be in the same publisher's name as the software already installed.

3. Microsoft WebView2. The window is drawn by Microsoft Edge WebView2, a Windows component. Since version 1.0.4, AFKSecurity starts it with its background network services turned off: component updates, crash reports, translation and the other services a browser runs on its own. The WebView2 runtime itself is updated by Microsoft's own updater, as on any Windows computer. If it is missing, the installer installs it from Microsoft.

No more certificate revocation checks on the network. To know who published a program running on your computer, the protection service asks Windows to verify that program's digital signature. Up to version 1.0.4, Windows then asked the certificate authority (DigiCert, Sectigo, Microsoft and others) whether the certificate had been revoked, usually over port 80, and a firewall showed that traffic under the service's name. Since version 1.0.5, the service only reads the answers Windows already keeps in its own cache and never makes Windows fetch new ones. A certificate the cache knows to be revoked is refused; an unknown status leaves the signature valid.

There are no other connections. The protection service opens no network connection at all, to our servers or to any other. When it isolates the computer during an attack, it blocks connections and opens none.

Files and settings

Where it writes on your computer.

The program. C:\Program Files\AFKSecurity: the protection service, the window, the legal texts and the list of files in the package with their SHA-256 hashes. The service is registered in Windows as AFKSecurityCore. Uninstalling removes both.

The log. C:\ProgramData\AFKSecurity\journal: what the product observed, each line sealed by the one before it. It contains no file paths, no window titles and no command lines, so it can be sent as is. When you uninstall, you are asked whether to keep it. Next to it, coffre.temoin records which vault the service last used and the number of its last save, so that a vault erased, replaced or put back from an older copy is noticed at the next start. It contains nothing about you.

Its memory. In the profile of the account the service runs under (C:\Windows\System32\config\systemprofile\AppData\Roaming\AFKSecurity), encrypted by Windows for that account: salted fingerprints of the programs it has met (never their names), your settings, the licence token, the fingerprint of the exception password if you set one (never the password itself), and the list of decoy files with their hashes, so that uninstalling can remove them.

The window's data. %LOCALAPPDATA%\com.afksecurity.console, written by WebView2 for the window's display.

Decoy files. A few hidden files that nobody has a reason to open. If ransomware encrypts, renames or deletes one of them, it is caught early. Others imitate a crypto wallet, a password database or saved browser logins, to catch programs that look for secrets. They contain none of your data. They are placed only at the root of your Documents, your Pictures and your user folder, never in another application's folder. Settings > Decoy files lists each one with its location and lets you remove them. They are removed when you uninstall.

Exports. The report, the log export, the MITRE table and the incident file are written only when you ask, in the folder you choose.

Start with Windows. The protection service starts with Windows. The window opens at sign-in only if you turn that on in Settings; it is then a single entry named AFKSecurity under your account's Run key, removed when you turn it off or uninstall.

Firewall rules, only during an isolation. When AFKSecurity cuts the network to stop an attack, it adds two Windows Firewall rules named AFKSecurity - isolement (sortant) and AFKSecurity - isolement (entrant) (the names are in French in every language). They are removed when the isolation ends, after two minutes unless it is renewed, and you can restore the network at any time from the window.

What it does not do

Nothing beyond what is listed above.

AFKSecurity does not inject code into other programs, does not install a kernel driver, does not add browser extensions, scheduled tasks or other services, and does not change your Windows settings, apart from the temporary firewall rules above. It watches through interfaces Windows provides to any program with the right permissions, such as the system's event tracing.

Share: Facebook · X · Reddit · LinkedIn