[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"package:cask:lulu:en":3,"releases:stats:cask:lulu:en":486,"related:cask:lulu:en":487,"markdown:3:4291:4m8ata":538},{"accentColor":4,"artifacts":5,"autoUpdates":30,"categories":31,"conflictsWith":37,"dependsOn":40,"deprecated":30,"description":48,"descriptionEn":49,"developer":50,"disabled":30,"displayName":51,"downloadSha256":52,"downloadSize":53,"downloadUrl":54,"editorChoice":30,"formulaeUrl":55,"homepage":56,"iconUrl":57,"installCommand":58,"installs":59,"installs30d":60,"isFont":30,"isLibrary":30,"kegOnly":30,"kind":63,"latestRelease":64,"machineTranslated":30,"name":51,"names":83,"platforms":85,"primaryCategory":457,"rank30d":458,"releaseCount":459,"releaseStats":460,"repoUrl":466,"screenshots":467,"sourceLocale":77,"sourceUrl":475,"summary":476,"summaryTranslation":477,"supports":478,"tags":480,"tap":485,"token":84,"version":82,"versionChangedAt":69},"#C7E779",{"apps":6,"binaries":8,"entries":9,"pkgs":29},[7],"LuLu.app",[],[10,17],{"declaration":11,"phase":14,"sources":15,"target":13,"type":16},{"app":12,"target":13},[7],"\u002FApplications\u002FLuLu.app","install",[7],"app",{"declaration":18,"phase":26,"sources":27,"type":28},{"zap":19},[20],{"trash":21},[22,23,24,25],"~\u002FLibrary\u002FCaches\u002Fcom.objective-see.lulu","~\u002FLibrary\u002FCaches\u002Fcom.objective-see.lulu.helper","~\u002FLibrary\u002FPreferences\u002Fcom.objective-see.lulu.helper.plist","~\u002FLibrary\u002FPreferences\u002Fcom.objective-see.lulu.plist","cleanup",[],"zap",[],false,[32],{"icon":33,"machineTranslated":30,"name":34,"slug":35,"sourceLocale":36},"lucide:shield","Security & Privacy","security","zh-CN",{"casks":38,"formulae":39},[],[],{"arch":41,"casks":44,"formulae":45,"requirements":46},[42,43],"arm64","x86_64",[],[],{"macos":47},{},"LuLu is Objective-See's free, open-source outbound firewall for macOS. It alerts you when a program attempts a new, unauthorized outgoing network connection and lets you allow or block it using rules. Alerts show the responsible process and destination, with additional signing and process-origin information to help you decide. It complements the built-in macOS inbound firewall; it is not an antivirus scanner, a VPN or a guarantee that every possible network connection will be blocked.\n\n## Installation and system approval\nLuLu4.5.1 requires macOS10.15 Catalina or later and is universal for Intel x86-64 and Apple Silicon ARM64. Its DMG is7,251,712 bytes before installed storage. Copy LuLu.app into Applications, quit an existing LuLu copy before replacing it, then open the copy in Applications to complete setup.\n\nLuLu uses Apple's Network Extension framework. Setup requires manually approving its System Extension and Network Filter through macOS prompts and settings. Copying the app alone does not complete firewall activation. Follow the developer's version-specific approval guide; it does not require a legacy kernel-extension installation or bypassing system security. The developer recommends current macOS updates and specifically recommends at least15.3 for Sequoia because the initial15.0 release had networking problems.\n\n## Default rules and decisions\nThe recommended initial configuration allows Apple programs and programs already installed on the Mac to keep connecting without alerts. The Apple allowance applies to software signed by Apple itself, not every third-party code-signed app. Already-installed software can therefore be allowed automatically; installing LuLu does not mean every existing application will immediately ask for approval. Review these options during setup and change them in Settings if they do not suit your needs.\n\nFor an alert, inspect the process, its origin and destination before choosing Block or Allow. By default, a decision applies to the entire program and future destinations; use the detailed rule options when you need a narrower destination, temporary decision or other scope. Rules can identify signed programs by bundle-signing identity so they continue to apply after moves or updates. The4.5.0 Process+Kids option extends a rule to a process and its child processes. Rule order, wildcard\u002FCIDR and regular-expression matching affect the result.\n\nManage rules in the Rules window and review automatically created allowances as well as manual decisions. Passive or no-client behavior can create allowances instead of interrupting with an alert; absence of a popup does not establish that traffic was blocked. Blocking a legitimate connection can disrupt synchronization, software updates or other network-dependent features.\n\n## Limits and privacy\nCode-signing information helps identify a program and integrity of its signed code; it is not a malware verdict or a promise that a signed program is trustworthy. LuLu is not advertised as a tamper-proof security boundary against a privileged attacker. The developer's compatibility testing with other firewalls and security products is limited. No blanket compatibility guarantee is provided for every VPN, network filter or security-tool combination; investigate connection problems using the supported tools' guidance.\n\nLuLu checks Objective-See for updates unless update checking is disabled. The developer states that this check transmits no user or product information. Clicking the optional VirusTotal button opens an online lookup containing the item's file hash; it is not a built-in offline antivirus scan. An allowed connection can still transmit private data, and firewall rules do not replace safe software choices or other security controls.\n\n## Cost and license\nLuLu is free under GPLv3, with optional donations and sponsorship supporting the Objective-See Foundation. There is no required subscription, activation purchase or account for the firewall. Online services such as VirusTotal have their own terms and network behavior.\n\nOfficial sources: [User guide and permissions](https:\u002F\u002Fobjective-see.org\u002Fproducts\u002Flulu.html), [Source and GPLv3 license](https:\u002F\u002Fgithub.com\u002Fobjective-see\u002FLuLu), [Official releases](https:\u002F\u002Fgithub.com\u002Fobjective-see\u002FLuLu\u002Freleases).","Open-source firewall to block unknown outgoing connections","Objective-See Foundation \u002F Patrick Wardle","LuLu","98f4d3427f4c6fccf9680fed22879be90a5ae81e80eb8616c1d758755b6bb624",7251712,"https:\u002F\u002Fgithub.com\u002Fobjective-see\u002FLuLu\u002Freleases\u002Fdownload\u002Fv4.5.1\u002FLuLu_4.5.1.dmg","https:\u002F\u002Fformulae.brew.sh\u002Fcask\u002Flulu","https:\u002F\u002Fobjective-see.org\u002Fproducts\u002Flulu.html","https:\u002F\u002Fcdn.opennavo.com\u002Ficons\u002Fuploads\u002F315ee9fe5093\u002F99087a02af33-256.png","brew install --cask lulu",{"d30":60,"d365":61,"d90":62},880,16883,4235,"cask",{"bodyMarkdown":65,"brewCommittedAt":66,"hasNotes":67,"id":68,"isLatest":67,"isPrerelease":30,"machineTranslated":30,"publishedAt":69,"sections":70,"source":76,"sourceLocale":77,"summary":78,"title":79,"translation":80,"version":82},"## LuLu 4.5.1\n\nImproves rule validation and startup during upgrades.\n\n- Improves Add Rules handling of deleted or invalid rules.\n- Adds check-in logic to improve startup during upgrades.\n\nSource: [Official release](https:\u002F\u002Fgithub.com\u002Fobjective-see\u002FLuLu\u002Freleases\u002Ftag\u002Fv4.5.1).","2026-08-05T13:41:55Z",true,1447,"2026-10-07T09:38:38.931734Z",[71],{"area":72,"items":73},"Changes",[74,75],"Improves Add Rules handling of deleted or invalid rules.","Adds check-in logic to improve startup during upgrades.","editorial","en-US","Improves rule validation and startup during upgrades.","LuLu 4.5.1",{"locale":77,"machineTranslated":30,"sourceLocale":77,"status":81},"source","4.5.1",[51,84],"lulu",[86,113,139,166,192,219,245,272,298,325,351,378,404,431],{"arch":43,"artifacts":87,"conflictsWith":102,"dependsOn":105,"downloadSha256":52,"downloadUrl":54,"macos":111,"requiresRosetta":30,"tag":112,"version":82},{"apps":88,"binaries":89,"entries":90,"pkgs":101},[7],[],[91,95],{"declaration":92,"phase":14,"sources":94,"target":13,"type":16},{"app":93,"target":13},[7],[7],{"declaration":96,"phase":26,"sources":100,"type":28},{"zap":97},[98],{"trash":99},[22,23,24,25],[],[],{"casks":103,"formulae":104},[],[],{"arch":106,"casks":107,"formulae":108,"requirements":109},[43],[],[],{"macos":110},{},"27","golden_gate",{"arch":42,"artifacts":114,"conflictsWith":129,"dependsOn":132,"downloadSha256":52,"downloadUrl":54,"macos":111,"requiresRosetta":30,"tag":138,"version":82},{"apps":115,"binaries":116,"entries":117,"pkgs":128},[7],[],[118,122],{"declaration":119,"phase":14,"sources":121,"target":13,"type":16},{"app":120,"target":13},[7],[7],{"declaration":123,"phase":26,"sources":127,"type":28},{"zap":124},[125],{"trash":126},[22,23,24,25],[],[],{"casks":130,"formulae":131},[],[],{"arch":133,"casks":134,"formulae":135,"requirements":136},[42],[],[],{"macos":137},{},"arm64_golden_gate",{"arch":43,"artifacts":140,"conflictsWith":155,"dependsOn":158,"downloadSha256":52,"downloadUrl":54,"macos":164,"requiresRosetta":30,"tag":165,"version":82},{"apps":141,"binaries":142,"entries":143,"pkgs":154},[7],[],[144,148],{"declaration":145,"phase":14,"sources":147,"target":13,"type":16},{"app":146,"target":13},[7],[7],{"declaration":149,"phase":26,"sources":153,"type":28},{"zap":150},[151],{"trash":152},[22,23,24,25],[],[],{"casks":156,"formulae":157},[],[],{"arch":159,"casks":160,"formulae":161,"requirements":162},[43],[],[],{"macos":163},{},"26","tahoe",{"arch":42,"artifacts":167,"conflictsWith":182,"dependsOn":185,"downloadSha256":52,"downloadUrl":54,"macos":164,"requiresRosetta":30,"tag":191,"version":82},{"apps":168,"binaries":169,"entries":170,"pkgs":181},[7],[],[171,175],{"declaration":172,"phase":14,"sources":174,"target":13,"type":16},{"app":173,"target":13},[7],[7],{"declaration":176,"phase":26,"sources":180,"type":28},{"zap":177},[178],{"trash":179},[22,23,24,25],[],[],{"casks":183,"formulae":184},[],[],{"arch":186,"casks":187,"formulae":188,"requirements":189},[42],[],[],{"macos":190},{},"arm64_tahoe",{"arch":43,"artifacts":193,"conflictsWith":208,"dependsOn":211,"downloadSha256":52,"downloadUrl":54,"macos":217,"requiresRosetta":30,"tag":218,"version":82},{"apps":194,"binaries":195,"entries":196,"pkgs":207},[7],[],[197,201],{"declaration":198,"phase":14,"sources":200,"target":13,"type":16},{"app":199,"target":13},[7],[7],{"declaration":202,"phase":26,"sources":206,"type":28},{"zap":203},[204],{"trash":205},[22,23,24,25],[],[],{"casks":209,"formulae":210},[],[],{"arch":212,"casks":213,"formulae":214,"requirements":215},[43],[],[],{"macos":216},{},"15","sequoia",{"arch":42,"artifacts":220,"conflictsWith":235,"dependsOn":238,"downloadSha256":52,"downloadUrl":54,"macos":217,"requiresRosetta":30,"tag":244,"version":82},{"apps":221,"binaries":222,"entries":223,"pkgs":234},[7],[],[224,228],{"declaration":225,"phase":14,"sources":227,"target":13,"type":16},{"app":226,"target":13},[7],[7],{"declaration":229,"phase":26,"sources":233,"type":28},{"zap":230},[231],{"trash":232},[22,23,24,25],[],[],{"casks":236,"formulae":237},[],[],{"arch":239,"casks":240,"formulae":241,"requirements":242},[42],[],[],{"macos":243},{},"arm64_sequoia",{"arch":43,"artifacts":246,"conflictsWith":261,"dependsOn":264,"downloadSha256":52,"downloadUrl":54,"macos":270,"requiresRosetta":30,"tag":271,"version":82},{"apps":247,"binaries":248,"entries":249,"pkgs":260},[7],[],[250,254],{"declaration":251,"phase":14,"sources":253,"target":13,"type":16},{"app":252,"target":13},[7],[7],{"declaration":255,"phase":26,"sources":259,"type":28},{"zap":256},[257],{"trash":258},[22,23,24,25],[],[],{"casks":262,"formulae":263},[],[],{"arch":265,"casks":266,"formulae":267,"requirements":268},[43],[],[],{"macos":269},{},"14","sonoma",{"arch":42,"artifacts":273,"conflictsWith":288,"dependsOn":291,"downloadSha256":52,"downloadUrl":54,"macos":270,"requiresRosetta":30,"tag":297,"version":82},{"apps":274,"binaries":275,"entries":276,"pkgs":287},[7],[],[277,281],{"declaration":278,"phase":14,"sources":280,"target":13,"type":16},{"app":279,"target":13},[7],[7],{"declaration":282,"phase":26,"sources":286,"type":28},{"zap":283},[284],{"trash":285},[22,23,24,25],[],[],{"casks":289,"formulae":290},[],[],{"arch":292,"casks":293,"formulae":294,"requirements":295},[42],[],[],{"macos":296},{},"arm64_sonoma",{"arch":43,"artifacts":299,"conflictsWith":314,"dependsOn":317,"downloadSha256":52,"downloadUrl":54,"macos":323,"requiresRosetta":30,"tag":324,"version":82},{"apps":300,"binaries":301,"entries":302,"pkgs":313},[7],[],[303,307],{"declaration":304,"phase":14,"sources":306,"target":13,"type":16},{"app":305,"target":13},[7],[7],{"declaration":308,"phase":26,"sources":312,"type":28},{"zap":309},[310],{"trash":311},[22,23,24,25],[],[],{"casks":315,"formulae":316},[],[],{"arch":318,"casks":319,"formulae":320,"requirements":321},[43],[],[],{"macos":322},{},"13","ventura",{"arch":42,"artifacts":326,"conflictsWith":341,"dependsOn":344,"downloadSha256":52,"downloadUrl":54,"macos":323,"requiresRosetta":30,"tag":350,"version":82},{"apps":327,"binaries":328,"entries":329,"pkgs":340},[7],[],[330,334],{"declaration":331,"phase":14,"sources":333,"target":13,"type":16},{"app":332,"target":13},[7],[7],{"declaration":335,"phase":26,"sources":339,"type":28},{"zap":336},[337],{"trash":338},[22,23,24,25],[],[],{"casks":342,"formulae":343},[],[],{"arch":345,"casks":346,"formulae":347,"requirements":348},[42],[],[],{"macos":349},{},"arm64_ventura",{"arch":43,"artifacts":352,"conflictsWith":367,"dependsOn":370,"downloadSha256":52,"downloadUrl":54,"macos":376,"requiresRosetta":30,"tag":377,"version":82},{"apps":353,"binaries":354,"entries":355,"pkgs":366},[7],[],[356,360],{"declaration":357,"phase":14,"sources":359,"target":13,"type":16},{"app":358,"target":13},[7],[7],{"declaration":361,"phase":26,"sources":365,"type":28},{"zap":362},[363],{"trash":364},[22,23,24,25],[],[],{"casks":368,"formulae":369},[],[],{"arch":371,"casks":372,"formulae":373,"requirements":374},[43],[],[],{"macos":375},{},"12","monterey",{"arch":42,"artifacts":379,"conflictsWith":394,"dependsOn":397,"downloadSha256":52,"downloadUrl":54,"macos":376,"requiresRosetta":30,"tag":403,"version":82},{"apps":380,"binaries":381,"entries":382,"pkgs":393},[7],[],[383,387],{"declaration":384,"phase":14,"sources":386,"target":13,"type":16},{"app":385,"target":13},[7],[7],{"declaration":388,"phase":26,"sources":392,"type":28},{"zap":389},[390],{"trash":391},[22,23,24,25],[],[],{"casks":395,"formulae":396},[],[],{"arch":398,"casks":399,"formulae":400,"requirements":401},[42],[],[],{"macos":402},{},"arm64_monterey",{"arch":43,"artifacts":405,"conflictsWith":420,"dependsOn":423,"downloadSha256":52,"downloadUrl":54,"macos":429,"requiresRosetta":30,"tag":430,"version":82},{"apps":406,"binaries":407,"entries":408,"pkgs":419},[7],[],[409,413],{"declaration":410,"phase":14,"sources":412,"target":13,"type":16},{"app":411,"target":13},[7],[7],{"declaration":414,"phase":26,"sources":418,"type":28},{"zap":415},[416],{"trash":417},[22,23,24,25],[],[],{"casks":421,"formulae":422},[],[],{"arch":424,"casks":425,"formulae":426,"requirements":427},[43],[],[],{"macos":428},{},"11","big_sur",{"arch":42,"artifacts":432,"conflictsWith":447,"dependsOn":450,"downloadSha256":52,"downloadUrl":54,"macos":429,"requiresRosetta":30,"tag":456,"version":82},{"apps":433,"binaries":434,"entries":435,"pkgs":446},[7],[],[436,440],{"declaration":437,"phase":14,"sources":439,"target":13,"type":16},{"app":438,"target":13},[7],[7],{"declaration":441,"phase":26,"sources":445,"type":28},{"zap":442},[443],{"trash":444},[22,23,24,25],[],[],{"casks":448,"formulae":449},[],[],{"arch":451,"casks":452,"formulae":453,"requirements":454},[42],[],[],{"macos":455},{},"arm64_big_sur",{"icon":33,"machineTranslated":30,"name":34,"slug":35,"sourceLocale":36},184,30,{"brewLag":461,"cadence":465,"count30d":463},{"compared":462,"earlierCount":463,"medianMinutes":464},3,1,153722867,"monthly","https:\u002F\u002Fgithub.com\u002Fobjective-see\u002FLuLu",[468],{"caption":469,"height":470,"machineTranslated":30,"sourceLocale":77,"theme":471,"thumbUrl":472,"url":473,"width":474},"Official Mac alert example showing Safari connecting to configuration.apple.com; app and macOS versions are unspecified.",468,"light","https:\u002F\u002Fcdn.opennavo.com\u002Fscreenshots\u002Fuploads\u002Fscreenshot\u002F56e24e6ce50f\u002F08626f4601a8-640.png","https:\u002F\u002Fcdn.opennavo.com\u002Fscreenshots\u002Fuploads\u002Fscreenshot\u002F56e24e6ce50f\u002F08626f4601a8-1280.png",1280,"https:\u002F\u002Fgithub.com\u002Fhomebrew\u002Fhomebrew-cask\u002Fblob\u002FHEAD\u002FCasks\u002Fl\u002Flulu.rb","Free open-source outbound firewall for macOS that prompts for unknown connections and manages allow or block rules.",{"locale":77,"machineTranslated":30,"sourceLocale":77,"status":81},{"arm64":67,"requiresRosetta":30,"status":479,"x86_64":67},"known",[481,482,483,484],"Firewall","Network Security","Privacy","Outbound Connections","homebrew\u002Fcask",null,[488,499,508,519,528],{"accentColor":489,"autoUpdates":30,"deprecated":30,"disabled":30,"displayName":490,"editorChoice":30,"iconUrl":491,"installs30d":492,"isFont":30,"isLibrary":30,"kind":63,"machineTranslated":30,"name":490,"primaryCategory":493,"rank30d":494,"sourceLocale":77,"summary":495,"token":496,"version":497,"versionChangedAt":498},"#48AE49","Cryptomator","https:\u002F\u002Fcdn.opennavo.com\u002Ficons\u002Fuploads\u002Ff70b31f92cf6\u002F5d8855faab49-256.png",742,{"icon":33,"machineTranslated":30,"name":34,"slug":35,"sourceLocale":36},216,"Encrypt files locally in password-protected vaults before synchronizing them through your chosen cloud storage provider.","cryptomator","1.19.3","2026-10-07T09:38:27.243348Z",{"autoUpdates":30,"deprecated":30,"disabled":30,"displayName":500,"editorChoice":30,"installs30d":501,"isFont":30,"isLibrary":30,"kind":63,"machineTranslated":30,"name":500,"primaryCategory":502,"rank30d":503,"sourceLocale":77,"summary":504,"token":505,"version":506,"versionChangedAt":507},"Burp Suite Community Edition",549,{"icon":33,"machineTranslated":30,"name":34,"slug":35,"sourceLocale":36},262,"Web security testing toolkit","burp-suite","2026.9.1","2026-10-07T16:45:22.513765Z",{"accentColor":509,"autoUpdates":30,"deprecated":30,"disabled":30,"displayName":510,"editorChoice":30,"iconUrl":511,"installs30d":512,"isFont":30,"isLibrary":30,"kind":63,"machineTranslated":30,"name":510,"primaryCategory":513,"rank30d":514,"sourceLocale":77,"summary":515,"token":516,"version":517,"versionChangedAt":518},"#65AD36","KeePassXC","https:\u002F\u002Fcdn.opennavo.com\u002Ficons\u002Fuploads\u002F4388567d7af3\u002F836406846835-256.png",1375,{"icon":33,"machineTranslated":30,"name":34,"slug":35,"sourceLocale":36},135,"Free desktop password manager with local encrypted KDBX databases, password generation, browser integration, Auto-Type, TOTP and passkeys.","keepassxc","2.7.12","2026-10-07T09:38:37.849603Z",{"autoUpdates":30,"deprecated":30,"disabled":30,"displayName":520,"editorChoice":30,"installs30d":521,"isFont":30,"isLibrary":30,"kind":63,"machineTranslated":30,"name":520,"primaryCategory":522,"rank30d":523,"sourceLocale":77,"summary":524,"token":525,"version":526,"versionChangedAt":527},"Secretive",507,{"icon":33,"machineTranslated":30,"name":34,"slug":35,"sourceLocale":36},278,"Store SSH keys in the Secure Enclave","secretive","4.0.0","2026-10-07T09:38:42.722922Z",{"accentColor":529,"autoUpdates":30,"deprecated":30,"disabled":30,"displayName":530,"editorChoice":30,"iconUrl":531,"installs30d":532,"isFont":30,"isLibrary":30,"kind":63,"machineTranslated":30,"name":530,"primaryCategory":533,"rank30d":534,"sourceLocale":77,"summary":535,"token":536,"version":537,"versionChangedAt":69},"#0B0D2F","Mac Sai","https:\u002F\u002Fcdn.opennavo.com\u002Ficons\u002Fuploads\u002F5b3070609ea9\u002Fc21d1b0cce19-256.png",605,{"icon":33,"machineTranslated":30,"name":34,"slug":35,"sourceLocale":36},248,"Free open-source Mac utility for cleanup, disk analysis, app management, maintenance and curated malware scanning.","mac-sai","1.21.3","\u003Cp>LuLu is Objective-See's free, open-source outbound firewall for macOS. It alerts you when a program attempts a new, unauthorized outgoing network connection and lets you allow or block it using rules. Alerts show the responsible process and destination, with additional signing and process-origin information to help you decide. It complements the built-in macOS inbound firewall; it is not an antivirus scanner, a VPN or a guarantee that every possible network connection will be blocked.\u003C\u002Fp>\n\u003Ch3 class=\"on-md-heading-1\">Installation and system approval\u003C\u002Fh3>\n\u003Cp>LuLu4.5.1 requires macOS10.15 Catalina or later and is universal for Intel x86-64 and Apple Silicon ARM64. Its DMG is7,251,712 bytes before installed storage. Copy LuLu.app into Applications, quit an existing LuLu copy before replacing it, then open the copy in Applications to complete setup.\u003C\u002Fp>\n\u003Cp>LuLu uses Apple's Network Extension framework. Setup requires manually approving its System Extension and Network Filter through macOS prompts and settings. Copying the app alone does not complete firewall activation. Follow the developer's version-specific approval guide; it does not require a legacy kernel-extension installation or bypassing system security. The developer recommends current macOS updates and specifically recommends at least15.3 for Sequoia because the initial15.0 release had networking problems.\u003C\u002Fp>\n\u003Ch3 class=\"on-md-heading-1\">Default rules and decisions\u003C\u002Fh3>\n\u003Cp>The recommended initial configuration allows Apple programs and programs already installed on the Mac to keep connecting without alerts. The Apple allowance applies to software signed by Apple itself, not every third-party code-signed app. Already-installed software can therefore be allowed automatically; installing LuLu does not mean every existing application will immediately ask for approval. Review these options during setup and change them in Settings if they do not suit your needs.\u003C\u002Fp>\n\u003Cp>For an alert, inspect the process, its origin and destination before choosing Block or Allow. By default, a decision applies to the entire program and future destinations; use the detailed rule options when you need a narrower destination, temporary decision or other scope. Rules can identify signed programs by bundle-signing identity so they continue to apply after moves or updates. The4.5.0 Process+Kids option extends a rule to a process and its child processes. Rule order, wildcard\u002FCIDR and regular-expression matching affect the result.\u003C\u002Fp>\n\u003Cp>Manage rules in the Rules window and review automatically created allowances as well as manual decisions. Passive or no-client behavior can create allowances instead of interrupting with an alert; absence of a popup does not establish that traffic was blocked. Blocking a legitimate connection can disrupt synchronization, software updates or other network-dependent features.\u003C\u002Fp>\n\u003Ch3 class=\"on-md-heading-1\">Limits and privacy\u003C\u002Fh3>\n\u003Cp>Code-signing information helps identify a program and integrity of its signed code; it is not a malware verdict or a promise that a signed program is trustworthy. LuLu is not advertised as a tamper-proof security boundary against a privileged attacker. The developer's compatibility testing with other firewalls and security products is limited. No blanket compatibility guarantee is provided for every VPN, network filter or security-tool combination; investigate connection problems using the supported tools' guidance.\u003C\u002Fp>\n\u003Cp>LuLu checks Objective-See for updates unless update checking is disabled. The developer states that this check transmits no user or product information. Clicking the optional VirusTotal button opens an online lookup containing the item's file hash; it is not a built-in offline antivirus scan. An allowed connection can still transmit private data, and firewall rules do not replace safe software choices or other security controls.\u003C\u002Fp>\n\u003Ch3 class=\"on-md-heading-1\">Cost and license\u003C\u002Fh3>\n\u003Cp>LuLu is free under GPLv3, with optional donations and sponsorship supporting the Objective-See Foundation. There is no required subscription, activation purchase or account for the firewall. Online services such as VirusTotal have their own terms and network behavior.\u003C\u002Fp>\n\u003Cp>Official sources: \u003Ca href=\"https:\u002F\u002Fobjective-see.org\u002Fproducts\u002Flulu.html\" target=\"_blank\" rel=\"noopener noreferrer\">User guide and permissions\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fobjective-see\u002FLuLu\" target=\"_blank\" rel=\"noopener noreferrer\">Source and GPLv3 license\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fobjective-see\u002FLuLu\u002Freleases\" target=\"_blank\" rel=\"noopener noreferrer\">Official releases\u003C\u002Fa>.\u003C\u002Fp>\n"]