Where Does LuLu Store Firewall Rules?
Objective-See LuLu keeps firewall rules in /Library/Objective-See/LuLu/rules.plist with preferences beside it, managed through the Rules window and import/export.
Last updated
LuLu stores rules outside your home folder in the system Library under Objective-See. The rules.plist there holds every allow and block verdict with paths, hashes, and expiry data. Preferences sit beside it in the same folder.
The Rules window is the intended editor with filtering by rule origin. Hand copying the plist works in a pinch but version drift between machines causes subtle breakage. Export and import exist for exactly this reason and validate on the way in.
Where LuLu stores this, by platform
/Library/Objective-See/LuLu/rules.plist
All firewall verdicts plus preferences.plist beside it. Needs admin to touch directly. Prefer Rules window export and import for backups.
Frequently asked questions
How do I back up LuLu rules?
Use the Rules window import and export actions rather than copying the plist by hand. Raw copies can mismatch plist schema versions across releases. Exported files move cleanly between machines on compatible versions.
Which rules did I create myself?
Open the Rules window and filter by User to see hand made entries apart from Apple and baseline defaults. Signed apps match by bundle identifier so updates keep their rules. Double click any row to reveal its program paths.
Notice an outdated path? Let us know.