Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
BlockGuard — BlockGuard is a Windows Data Loss Prevention (DLP) agent that intercepts and controls file access at the process level. It ensures that only authorized processes — identified by executable path, cryptographic hash, Authenticode signature, and integrity level — can read protected files. | Kitploit
Tools/GitHubGitHub/m2l33k/blockguard
Authentication & AuthorizationDefensive ToolsEncryption/Decryption ToolsConfiguration AuditingData ExfiltrationIncident ResponseLog Analysis
GitHubm2l33k/blockguard

BlockGuard

View Repository
136 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

About

BlockGuard is a Windows Data Loss Prevention (DLP) agent that intercepts and controls file access at the process level. It ensures that only authorized processes — identified by executable path, cryptographic hash, Authenticode signature, and integrity level — can read protected files.

Share

BlockGuard — Trusty

.NET 9 Windows License DLP

🛡️ BlockGuard — Process-Based File Access Security Agent

BlockGuard is a Windows Data Loss Prevention (DLP) agent that intercepts and controls file access at the process level. It ensures that only authorized processes — identified by executable path, cryptographic hash, Authenticode signature, and integrity level — can read protected files. All other processes are denied by default at the OS kernel level via NTFS ACLs.


📑 Table of Contents

  • Features
  • Architecture
  • UI Management Interface
  • Prerequisites
  • Quick Start
  • Configuration
  • Running the Agent
  • Verifying It Works
  • Project Structure
  • How It Works
  • Troubleshooting
  • Security Considerations
  • Contributing

✨ Features

FeatureDescription
Deny-by-Default ACLsProtected files are locked down at agent startup — only SYSTEM and Administrators retain access
Real-Time ETW MonitoringKernel-level file I/O events captured via Event Tracing for Windows
6-Layer Process ValidationExecutable path, SHA-256 hash, Authenticode signature, owner SID, integrity level, parent process chain
DPAPI File EncryptionProtected files encrypted at rest using Windows Data Protection API
Auto-Revoking Temporary AccessAuthorized processes receive time-limited ACL grants that auto-expire
Tamper DetectionPeriodic integrity checks detect and auto-remediate ACL modifications
Structured Audit LoggingJSON audit trail of all access attempts (SIEM-ready)
Windows ServiceRuns as a background Windows Service under NT AUTHORITY\SYSTEM

🏗️ Architecture

BlockGuard uses a three-layer modular architecture:

┌─────────────────────────────────────────────────────────────────┐
│                    BlockGuard.Agent (Windows Service)            │
│                    Orchestrates all layers                       │
├───────────────────┬─────────────────────┬───────────────────────┤
│  Layer 1          │  Layer 2            │  Layer 3              │
│  MONITORING       │  POLICY & IDENTITY  │  PROTECTION           │
│                   │                     │                       │
│  • ETW Kernel     │  • Process Identity │  • DPAPI Encryption   │
│    File Trace     │    Validator (6     │  • Structured Audit   │
│  • ACL Enforcer   │    checks)          │    Logger (JSON)      │
│    (deny-by-      │  • Policy Evaluator │                       │
│    default)       │    (AND-logic       │                       │
│                   │    rules)           │                       │
│                   │  • Identity Cache   │                       │
│                   │    (LRU + TTL)      │                       │
└───────────────────┴─────────────────────┴───────────────────────┘

🖥️ UI Management Interface

BlockGuard includes a WPF desktop application for managing protected files and folders through a visual interface — no need to edit appsettings.json manually.

BlockGuard UI

Features

  • Dashboard — Overview of protection status (total files, folders, encryption state)
  • Protected Files — Add/remove files and folders to protect from AI access via file browser dialogs
  • Activity Log — Real-time log of all configuration changes
  • Settings — View configuration file path and agent information
  • Agent Status — Live indicator showing if the BlockGuard agent service is running

How to Launch the UI

# From the project root
dotnet run --project src/BlockGuard.UI

Note: The UI reads and writes appsettings.json from the Agent project. After saving changes, restart the BlockGuard Agent service for them to take effect.


📋 Prerequisites

Before running BlockGuard, ensure the following are installed on your Windows machine:

RequirementMinimum VersionCheck Command
Windows OSWindows 10 / Server 2019winver
.NET SDK9.0dotnet --version
Administrator PrivilegesRequiredRun terminal as Admin

Install .NET 9 SDK (if not installed)

# Download from https://dotnet.microsoft.com/download/dotnet/9.0
# Or use winget:
winget install Microsoft.DotNet.SDK.9

🚀 Quick Start

1. Clone the Repository

git clone [email protected]:m2l33k/BlockGuard.git
cd BlockGuard

2. Restore Dependencies

dotnet restore BlockGuard.sln

3. Build the Solution

dotnet build BlockGuard.sln --configuration Release

You should see:

Build succeeded.
    0 Warning(s)
    0 Error(s)

4. Configure Protected Paths and Rules

Edit src/BlockGuard.Agent/appsettings.json to define what files to protect and which processes are authorized:

{
  "BlockGuard": {
    "ProtectedPaths": [
      "C:\\Secrets\\ai-model-keys",
      "C:\\Secrets\\api-credentials.json"
    ],
    "AuthorizedProcesses": [
      {
        "RuleName": "AI-Model-Inference-Engine",
        "ExecutablePath": "C:\\Program Files\\MyAI\\inference.exe",
        "MinimumIntegrityLevel": "Medium",
        "RequireSignature": false
      }
    ]
  }
}

5. Run (Development Mode)

# Run as Administrator (required for ETW + ACL operations)
dotnet run --project src/BlockGuard.Agent

⚙️ Configuration

All configuration lives in src/BlockGuard.Agent/appsettings.json under the "BlockGuard" section.

Protected Paths

An array of files or directories to guard. Directories protect all files recursively.

"ProtectedPaths": [
  "C:\\Secrets\\ai-model-keys",
  "C:\\Secrets\\api-credentials.json",
  "D:\\Confidential\\reports"
]

Authorized Process Rules

Each rule defines the criteria a process must match to be granted access. All non-null fields must match (AND-logic):

FieldTypeDescription
RuleNamestringHuman-readable name for this rule (used in audit logs)
ExecutablePathstring?Full path to the authorized executable (case-insensitive)
ExpectedFileHashstring?SHA-256 hash of the executable (tamper detection)
ExpectedSignerSubjectstring?Authenticode certificate subject (e.g., "CN=Contoso")
MinimumIntegrityLevelstringMinimum Windows integrity level: Untrusted, Low, Medium, High, System
RequireSignatureboolIf true, the executable must have a valid Authenticode signature

Example: Path-based rule (for an AI model process)

{
  "RuleName": "AI-Model-Inference-Engine",
  "ExecutablePath": "C:\\Program Files\\MyAI\\inference.exe",
  "ExpectedFileHash": null,
  "ExpectedSignerSubject": null,
  "MinimumIntegrityLevel": "Medium",
  "RequireSignature": false
}
Download Tool