# LuLu

Published January 1, 2026 · Updated August 10, 2026

Open-source firewall to block unknown outgoing connections

Category: Security & Privacy · Free · Replaces Little Snitch ($65) · [Official website](https://objective-see.org/products/lulu.html)

## Install with Homebrew

`brew install --cask lulu`

## Quick take

LuLu remains the best free outbound firewall for macOS in August 2026: maintained, profile-aware, and honest about Network Extension limits. Install it on every Mac that does not already run Little Snitch. Upgrade only when DNS encryption and deeper monitoring justify a paid licence.

Best for: Budget privacy setups, Students and indie developers, Lab and malware triage Macs, Secondary machines beside a paid Little Snitch daily driver

## What is LuLu?

LuLu is the free open-source outbound firewall for macOS from Patrick Wardle and Objective-See. If you are asking whether LuLu is good enough in 2026, the short answer is yes for most people who want to see and block apps phoning home without paying for Little Snitch. Apple's built-in firewall is mainly inbound; LuLu watches new outgoing connections and lets you allow or block them. Current download on objective-see.org is v4.5.1 for macOS 10.15+, Apple Silicon and Intel, notarized, Network Extension based. Features in the 4.x line include profiles, allow and block lists, passive and global block modes, optional VirusTotal hash checks, rule export/import, and a packaged Netiquette monitor. LuLu vs Little Snitch is the real money question: start free with LuLu; buy Little Snitch (one-time license, commonly listed around $59 / about €59 for a single seat depending on store currency) when you want DNS encryption, maps, curated blocklists, and commercial polish.

## Features

- **Outbound connection alerts.** When an unknown process connects out, LuLu shows process name, destination and code-signing context so you can Allow or Block with optional duration and endpoint scoping.
- **Rules database with code signing IDs.** Rules prefer signing identifiers over brittle paths, surviving app moves/updates. Filter views for default, Apple, third-party baseline, user and recent rules.
- **Profiles.** v4+ profiles keep separate rule and setting sets, for example a locked-down travel profile versus a permissive development profile, switchable from the status item.
- **Allow lists & block lists.** Point LuLu at local or remote host/IP lists that supersede ordinary rules. Remote lists refresh daily; block lists win over allow lists when both match.
- **Passive, block and no-icon modes.** Run silently with automatic allow/deny for new connections, force-block most traffic or hide the menu bar icon for kiosk-style deployments.
- **Netiquette network monitor.** Launch Objective-See’s Netiquette from LuLu’s menu to inspect current sockets and process ownership, lighter than Little Snitch’s map but useful for triage.
- **Open source & free updates.** Source on GitHub, free DMG downloads, optional update checks to Objective-See. No premium SKU, upsell or licence key.

## How to Install LuLu on Mac

Download LuLu from objective-see.org, open the DMG, drag LuLu.app to /Applications, then launch it to approve System Extension and Network Extension prompts under System Settings (Login Items & Extensions on recent macOS). Quit any previous LuLu instance before replacing the app bundle. On macOS Tahoe 26.x the approval flow still depends on Apple's extension UI; if LuLu does not appear, open the Network Extensions detail row and toggle it there.

1. **Install via Homebrew.** Download LuLu v4.5.1 (or newer) from https://objective-see.org/products/lulu.html and verify the published SHA-256 if desired.
2. **Launch LuLu and Grant Permissions.** Open LuLu from Applications. You'll need to grant System Extension permissions in System Settings > Privacy & Security > Extensions. Click 'Allow' when prompted for network extension approval.
3. **Complete Setup.** Follow the onboarding wizard to configure your initial preferences. LuLu will begin monitoring connections immediately after setup. You may see initial alerts as it learns your normal application behavior.

## Pros

- Completely free outbound firewall with transparent source
- Profiles and block/allow lists cover many power-user needs
- Code-signing-aware rules survive updates better than path-only tools
- Trusted Objective-See pedigree in the Mac security community
- Works alongside, not against, learning toward Little Snitch later
- Light footprint relative to full commercial suites

## Cons

- No integrated DNS encryption or geographic traffic map like Little Snitch
- Alert UX and monitoring are less polished than paid alternatives
- Some traffic never hits Network Extensions and cannot be blocked
- Enterprise MDM packaging is community-driven, not a commercial support SKU
- False sense of safety if users blindly allow every prompt

## Analysis: LuLu Architecture and Security Philosophy

People searching for LuLu usually want three answers fast: is it free, does it replace Little Snitch, and will it work on Apple Silicon with current macOS. Free: yes. Replace Little Snitch: no for power users who want DNS encryption, maps, and polished history; yes as a starting outbound firewall for everyone else. Apple Silicon and Tahoe: yes, with Network Extension approval.

LuLu filters outbound connections using Apple's Network Extension framework rather than legacy kernel extensions. That is why you approve a system extension and why some privileged traffic never appears in alerts. When an unknown process opens a new outbound socket, LuLu shows process name, destination, and code-signing context so you can allow or block once, until quit, or permanently. Rules prefer signing identifiers over brittle paths, which is why updates are less noisy than older path-only blockers.

Profiles (v4+) keep separate rule and setting sets. A locked-down travel profile and a permissive build profile are the common pattern. Allow and block lists point at local files or remote URLs, refresh on a schedule for remote sources, and let block lists win when both match. Passive mode applies existing rules quietly and auto-allows or auto-denies new connections based on your choice. Global block is the panic switch with the documented caveat that traffic outside Network Extension visibility cannot be stopped.

Netiquette ships packaged for quick socket triage. VirusTotal is opt-in per click, not a silent cloud mirror of your traffic. Update checks hit Objective-See version metadata; you can disable them. Enterprise MDM packaging is community-driven, so pilot before fleet rollout.

LuLu vs Little Snitch is the comparison that decides upgrades. Little Snitch adds a full network monitor with maps and long history, DNS encryption to trusted resolvers, curated blocklist topics, automatic profile switching, and commercial support. LuLu wins price and openness. Many Macs run LuLu for years without needing more. When you outgrow it, you usually know: you want DNS policy, richer forensics, or less DIY list management.

Dealbreakers: if you need guaranteed interception of every packet, neither userspace Network Extension tool is a magical total firewall; some system paths bypass them. If you need a vendor SLA, buy commercial software. If you need free and good enough with honest limits, LuLu remains the standard Objective-See answer in August 2026.

## FAQ

### Is LuLu free?

Yes. LuLu is free and open source with no paid upgrade path.

### What version should I install in 2026?

Download the current release from objective-see.org, v4.5.1 at research time and verify the published SHA-256 when possible.

### Do I still need LuLu if macOS Firewall is on?

Yes if you care about outbound connections. Apple’s firewall is primarily inbound; LuLu targets apps phoning home.

### Does LuLu work on Apple Silicon and macOS Tahoe?

Yes on modern Apple Silicon Macs via Network Extensions. Keep LuLu and macOS updated; re-approve extensions after major OS upgrades including Tahoe.

### LuLu vs Little Snitch?

Start with LuLu for free alerts/rules. Buy Little Snitch when you need DNS encryption, rich monitoring, curated blocklist UX or commercial support.

### Can LuLu block browser trackers?

Partially via block lists and endpoint-scoped rules, with platform limits (hostname blocking depends on APIs the browser uses). Dedicated content blockers still help inside the browser.

### Is Objective-See still maintaining LuLu?

Yes. The product page and GitHub releases continue to ship 4.x updates; it has not been discontinued.

### Does LuLu send my data to the cloud?

Update checks hit Objective-See version metadata; VirusTotal lookups only occur if you click through (hash in URL). Connection decisions stay local.

### Is LuLu safe to install?

LuLu is a long-running open-source project from Objective-See with notarized downloads and a public GitHub history. As with any system extension, download only from objective-see.org or the GitHub releases you trust, verify checksums when provided, and approve the extension yourself in System Settings.

### Is LuLu better than Little Snitch?

Better on price and openness: LuLu is free. Little Snitch is better on monitor depth, DNS encryption, curated blocklists, and commercial polish. Most people should try LuLu first and upgrade only if those paid features become daily needs.

### Does LuLu replace the macOS firewall?

No. Keep Apple's firewall for inbound control if you use it. LuLu focuses on outbound connection approval. They solve different sides of the problem.

### Will LuLu slow down my Mac?

For normal desktop use the overhead is small compared with full security suites. The bigger cost is human: alert fatigue if you install dozens of noisy apps at once. Use passive mode only after you trust your rule baseline.

### Can I use LuLu for free on a work Mac?

The software is free for commercial use under its open-source licence, but your employer may restrict system extensions. Get IT approval before installing on managed devices.

## Sources

- [Objective-See: LuLu](https://objective-see.org/products/lulu.html)
- [objective-see/LuLu on GitHub](https://github.com/objective-see/LuLu)
- [LuLu GitHub Releases](https://github.com/objective-see/LuLu/releases)
- [LuLu on MacUpdate](https://lulu.macupdate.com/)
- [Objective-See tools index](https://objective-see.org/products/lulu.html)
- [Little Snitch product page (comparison context)](https://www.obdev.at/products/littlesnitch/index.html)
- [Little Snitch order page](https://www.obdev.at/products/littlesnitch/order.html)

## Related

- [1Password](https://bundl.run/apps/1password)
- [Tailscale](https://bundl.run/apps/tailscale-app)
- [ZeroTier](https://bundl.run/apps/zerotier-one)
- [Bitwarden](https://bundl.run/apps/bitwarden)
- [KeePassXC](https://bundl.run/apps/keepassxc)
- [ExpressVPN](https://bundl.run/apps/expressvpn)
- [LuLu vs Little Snitch](https://bundl.run/compare/little-snitch-vs-lulu)
- [Free alternative to Little Snitch](https://objective-see.org/products)

```json
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@type": "Organization",
      "@id": "https://bundl.run/#organization",
      "name": "Bundl.run",
      "url": "https://bundl.run",
      "logo": {
        "@type": "ImageObject",
        "url": "https://bundl.run/og-image.png",
        "width": 1200,
        "height": 630
      },
      "description": "The Ninite for Mac. Install all your essential Mac apps with one terminal command.",
      "sameAs": [
        "https://github.com/abhiofficial/bundl-mac-setup",
        "https://x.com/bundlrun",
        "https://www.producthunt.com/products/bundl-run"
      ],
      "foundingDate": "2024",
      "contactPoint": {
        "@type": "ContactPoint",
        "contactType": "customer support",
        "url": "https://bundl.run/faq"
      }
    },
    {
      "@type": "WebSite",
      "@id": "https://bundl.run/#website",
      "name": "Bundl.run",
      "url": "https://bundl.run",
      "description": "The Ninite for Mac. Install all your essential Mac apps with one terminal command.",
      "publisher": {
        "@id": "https://bundl.run/#organization"
      },
      "inLanguage": "en-US"
    },
    {
      "@type": "Person",
      "@id": "https://bundl.run/authors/sam-patel#person",
      "name": "Sam Patel",
      "jobTitle": "Security & Privacy Researcher",
      "url": "https://bundl.run/authors/sam-patel",
      "worksFor": {
        "@id": "https://bundl.run/#organization"
      },
      "description": "Sam Patel is a cybersecurity professional specializing in application security, privacy tools, and secure software practices. With over 9 years in information security—including roles at security firms and as an independent consultant—Sam evaluates applications for security vulnerabilities, data handling practices, and privacy implications. Sam holds multiple security certifications and regularly presents at security conferences. Each review includes assessment of encryption methods, data collection policies, and potential privacy concerns that users should understand.",
      "knowsAbout": [
        "Security Software",
        "Privacy Tools",
        "Network Security",
        "Password Managers",
        "VPNs & Encryption",
        "macOS Security Hardening"
      ],
      "image": "https://bundl.run/authors/sam-patel.svg"
    },
    {
      "@type": "BreadcrumbList",
      "@id": "https://bundl.run/apps/lulu#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://bundl.run"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Apps",
          "item": "https://bundl.run/apps"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "LuLu",
          "item": "https://bundl.run/apps/lulu"
        }
      ]
    },
    {
      "@type": "WebPage",
      "@id": "https://bundl.run/apps/lulu",
      "url": "https://bundl.run/apps/lulu",
      "name": "LuLu for Mac",
      "description": "Open-source firewall to block unknown outgoing connections",
      "isPartOf": {
        "@id": "https://bundl.run/#website"
      },
      "publisher": {
        "@id": "https://bundl.run/#organization"
      },
      "inLanguage": "en-US",
      "datePublished": "2026-01-01T00:00:00Z",
      "dateModified": "2026-08-10T21:30:10.000Z",
      "author": {
        "@id": "https://bundl.run/authors/sam-patel#person"
      },
      "mainEntity": {
        "@id": "https://bundl.run/apps/lulu#software"
      },
      "breadcrumb": {
        "@id": "https://bundl.run/apps/lulu#breadcrumb"
      }
    },
    {
      "@type": "SoftwareApplication",
      "@id": "https://bundl.run/apps/lulu#software",
      "name": "LuLu",
      "description": "Open-source firewall to block unknown outgoing connections",
      "applicationCategory": "SecurityApplication",
      "operatingSystem": "macOS",
      "url": "https://bundl.run/apps/lulu",
      "image": {
        "@type": "ImageObject",
        "url": "https://img.logo.dev/objective-see.org",
        "caption": "LuLu app icon for Mac"
      },
      "sameAs": [
        "https://objective-see.org/products/lulu.html",
        "https://formulae.brew.sh/cask/lulu"
      ],
      "review": {
        "@type": "Review",
        "author": {
          "@id": "https://bundl.run/authors/sam-patel#person"
        },
        "reviewBody": "LuLu remains the best free outbound firewall for macOS in August 2026: maintained, profile-aware, and honest about Network Extension limits. Install it on every Mac that does not already run Little Snitch. Upgrade only when DNS encryption and deeper monitoring justify a paid licence."
      },
      "about": {
        "@type": "Thing",
        "name": "LuLu",
        "description": "Open-source firewall to block unknown outgoing connections"
      },
      "isPartOf": {
        "@id": "https://bundl.run/#website"
      }
    },
    {
      "@type": "Article",
      "@id": "https://bundl.run/apps/lulu#article",
      "headline": "LuLu for Mac — Full Review & Installation Guide 2026",
      "description": "LuLu remains the best free outbound firewall for macOS in August 2026: maintained, profile-aware, and honest about Network Extension limits. Install it on every Mac that does not already run Little Snitch. Upgrade only when DNS encryption and deeper monitoring justify a paid licence.",
      "image": "https://img.logo.dev/objective-see.org",
      "author": {
        "@id": "https://bundl.run/authors/sam-patel#person"
      },
      "publisher": {
        "@id": "https://bundl.run/#organization"
      },
      "datePublished": "2026-01-01T00:00:00Z",
      "dateModified": "2026-08-10T21:30:10.000Z",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://bundl.run/apps/lulu"
      },
      "articleSection": "SecurityApplication",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".key-facts"
        ]
      },
      "about": {
        "@type": "SoftwareApplication",
        "name": "LuLu",
        "url": "https://bundl.run/apps/lulu"
      },
      "mentions": [
        {
          "@type": "SoftwareApplication",
          "name": "Little Snitch",
          "url": "https://objective-see.org/products"
        }
      ]
    },
    {
      "@type": "FAQPage",
      "@id": "https://bundl.run/apps/lulu#faq",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is LuLu free?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. LuLu is free and open source with no paid upgrade path."
          }
        },
        {
          "@type": "Question",
          "name": "What version should I install in 2026?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Download the current release from objective-see.org, v4.5.1 at research time and verify the published SHA-256 when possible."
          }
        },
        {
          "@type": "Question",
          "name": "Do I still need LuLu if macOS Firewall is on?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes if you care about outbound connections. Apple’s firewall is primarily inbound; LuLu targets apps phoning home."
          }
        },
        {
          "@type": "Question",
          "name": "Does LuLu work on Apple Silicon and macOS Tahoe?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes on modern Apple Silicon Macs via Network Extensions. Keep LuLu and macOS updated; re-approve extensions after major OS upgrades including Tahoe."
          }
        },
        {
          "@type": "Question",
          "name": "LuLu vs Little Snitch?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Start with LuLu for free alerts/rules. Buy Little Snitch when you need DNS encryption, rich monitoring, curated blocklist UX or commercial support."
          }
        },
        {
          "@type": "Question",
          "name": "Can LuLu block browser trackers?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Partially via block lists and endpoint-scoped rules, with platform limits (hostname blocking depends on APIs the browser uses). Dedicated content blockers still help inside the browser."
          }
        },
        {
          "@type": "Question",
          "name": "Is Objective-See still maintaining LuLu?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. The product page and GitHub releases continue to ship 4.x updates; it has not been discontinued."
          }
        },
        {
          "@type": "Question",
          "name": "Does LuLu send my data to the cloud?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Update checks hit Objective-See version metadata; VirusTotal lookups only occur if you click through (hash in URL). Connection decisions stay local."
          }
        },
        {
          "@type": "Question",
          "name": "Is LuLu safe to install?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "LuLu is a long-running open-source project from Objective-See with notarized downloads and a public GitHub history. As with any system extension, download only from objective-see.org or the GitHub releases you trust, verify checksums when provided, and approve the extension yourself in System Settings."
          }
        },
        {
          "@type": "Question",
          "name": "Is LuLu better than Little Snitch?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Better on price and openness: LuLu is free. Little Snitch is better on monitor depth, DNS encryption, curated blocklists, and commercial polish. Most people should try LuLu first and upgrade only if those paid features become daily needs."
          }
        },
        {
          "@type": "Question",
          "name": "Does LuLu replace the macOS firewall?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. Keep Apple's firewall for inbound control if you use it. LuLu focuses on outbound connection approval. They solve different sides of the problem."
          }
        },
        {
          "@type": "Question",
          "name": "Will LuLu slow down my Mac?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "For normal desktop use the overhead is small compared with full security suites. The bigger cost is human: alert fatigue if you install dozens of noisy apps at once. Use passive mode only after you trust your rule baseline."
          }
        },
        {
          "@type": "Question",
          "name": "Can I use LuLu for free on a work Mac?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The software is free for commercial use under its open-source licence, but your employer may restrict system extensions. Get IT approval before installing on managed devices."
          }
        }
      ],
      "isPartOf": {
        "@id": "https://bundl.run/apps/lulu"
      }
    }
  ]
}
```