Introducing Anti-Venom Secure Resolve
Roaming DNS is still the quiet gap in endpoint security.
Users leave the office. VPN split-tunnel fights the roaming client. Windows 11 enables encrypted DNS in Settings. Browsers send queries around the OS resolver. The SIEM gets a vendor export from last month — not proof that a block happened on this laptop, for this user, now.
Anti-Venom Secure Access already covers the browser: session telemetry, verdict watermarks, AI-tool visibility, and policy in Chrome, Edge, and Firefox — correlated in Browsing Insights and investigations.
Today we name the network half:
Anti-Venom Secure Resolve
Dual-Strike XISEM’s first-party endpoint DNS protection — a lightweight bolt-on that works with Secure Access, not instead of it.
• Browser — Anti-Venom Secure Access — Tabs, sessions, phishing paths, SaaS and AI-tool policy
• Network / resolver — Anti-Venom Secure Resolve — OS and app DNS before traffic leaves the endpoint
Same Anti-Venom family. Different surface. One correlated picture in the console.
Why two products?
No single hook sees every query.
• Secure Access — inside the browser, including DoH bypass paths and session-level policy
• Secure Resolve — at the system resolver: apps, scripts, and background agents that never open a tab
Together they cover home ISP routers, split-tunnel VPN, Win10/Win11 encrypted DNS, and non-browser software that still phones home over DNS. Neither replaces your EDR. Both feed Dual-Strike XISEM’s evidence doctrine — neutral facts in, correlated posture and investigations out.
What Secure Resolve does
Paired with the Dual-Strike XISEM Agent on Windows 10 and 11:
• Local-first policy — lists cached on the endpoint; cloud for sync and evidence
• VPN- and NRPT-aware — internal zones stay on VPN DNS; yields to known relays instead of fighting them
• Encrypted upstream — aligned with modern Windows DoH/DoT
• Evidence in the same pane — batched query and block events for ASPIRE, COBRA², and investigations
• MSP policy packs — one baseline, per-client exceptions, approve/deny without a second vendor console
• Learning mode first — log would-block before enforce, like Secure Access
Defense in depth: Resolve blocks C2 and unwanted categories at the resolver. Secure Access enforces browser policy on what users actually visit. When browser DoH bypasses OS DNS, Secure Access still sees it. When malware resolves a domain outside the browser, Secure Resolve still sees it.
Your DNS, your choice
Already on DNSFilter or another DNS Gateway? Keep it. Third-party DNS stays in the open integration fabric — evidence in, correlation out. Secure Resolve is the first-party bolt-on for MSPs who want policy and unblock workflow inside Dual-Strike XISEM. Run either, or both while you migrate.
Who it is for
MSPs standardizing browser and resolver policy on one console. vCISO teams tired of “DNS active” posture with no per-endpoint proof. Distributed shops where legacy roaming clients break on VPN and Win11. Existing Secure Access customers adding resolver coverage without a second product story.
Availability
Anti-Venom Secure Resolve ships on the Dual-Strike XISEM Agent 8.8+ line as a bolt-on SKU — same release train as the Windows agent and Edge Scan Sensor.
• Now — Product naming and MSP preview enrollment
• Next — Windows resolver preview — audit mode and DNS evidence in investigations
• GA — Enforce mode, unified block/unblock with existing DNS Gateways, in-console policy packs
Early access: Reply here or reach us via dual-strike.com — share your Secure Access footprint, VPN mix, and any third-party DNS Gateway.
Already on Secure Access? No browser redeploy required. Resolve adds the resolver layer when you are ready.
Downloads (agent + extension today): dual-strike.com/downloads
Secure Access protects the browser. Secure Resolve protects the resolver. Dual-Strike XISEM connects both to identity, device, and investigation — so DNS is evidence, not a checkbox.
Anti-Venom Secure Access and Anti-Venom Secure Resolve are components of Dual-Strike XISEM. Third-party DNS integrations remain optional. Confirm current GA status on dual-strike.com before customer commitments.


