Techniques for dynamic policy-based routing of network traffic through a split-tunnel
system after session establishment and during session runtime of a secure access connection. After a secure access connection has been established by an endpoint device, processes running on the endpoint device may attempt to send traffic to a destination by generating
a Domain Name Service (DNS) request. According to the techniques described herein, a capture component running in the kernel may intercept the DNS requests (and new connections / sockets) as they are being created by processes. The capture component may instead
route the DNS requests to a policy engine that applies various DNS and domain-level policy to the DNS request and returns a verdict back to the endpoint device. Using dynamic, real-time policy-based routing of traffic allows for
adaptation to new security threats or changing
network conditions without having to update static policies on each endpoint device.