Back to glossary

Egress filtering

1 min read

Egress filtering is the control of outbound traffic leaving a network, permitting only the destinations, ports and protocols a system actually needs. Most estates enforce inbound rules carefully and allow outbound traffic freely, which is why it is the control that most often breaks an intrusion in a real exercise.

July 29, 2026
Compartir:

Every stage after initial access depends on reaching the outside: retrieving a payload, establishing command and control, and moving data out. A default deny outbound policy, with an allow list per segment and a proxy that terminates and inspects what remains, attacks all three at once. It is unusual because it costs no licence and delivers more than most products in the same budget line.

The reason it is rare is operational rather than technical. Building the allow list means knowing what every system legitimately talks to, and estates that lack that knowledge are precisely the ones that need the control. The workable route in is to start with the segments where the answer is known and static, such as servers, before attempting user networks, and to begin by logging denials rather than enforcing them.

Two details decide whether it holds under test. Name resolution has to be restricted to the organisation’s own resolvers, or DNS tunnelling walks straight through a policy that blocks everything else. And an allow list of destination addresses is weak on its own, because so much of the internet is reachable through a small number of shared hosting and content platforms that appear on every allow list. What we report is the exact set of destinations and protocols that worked from each segment, which is the output of the red team work where we measure what the egress policy actually stops.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.