GURDN

Documentation

How GURDN works, in detail

Written from the implementation. Where something is observation only, it says so. Where a capability depends on the Windows configuration, it says so. Where something is not implemented, it says that too.

Start here

What GURDN is, in one page.
The pipeline from a Windows reading to a verified change.
The vocabulary, written for a first encounter.

What it watches

How readings are taken, normalised and compared.
Resolver observation, change detection and authorised changes.
Route observation and why ambiguity is reported rather than resolved.
Association, security type and network identity.
Profile state, and filters owned through the Windows Filtering Platform.

How it acts

What must be true before anything changes.
Capture, authorise, apply, verify, commit.
Why a successful call is not evidence.
Rollback, reconciliation and refusing to force a mismatch.

Engineering

Interface, engine, privileged service, Windows.
Trust boundaries, the IPC contract and the threat model.
Signature, key standing, downgrade and staging containment.
What is stored, where, and what leaves the machine.

Operating it

What is installed, where, and what the installer refuses.
The states you may see, and what each one means.
What GURDN cannot see, cannot do, and does not replace.
Engineering complete is not the same as released.