Documentation
How GURDN works, in detail
Written from the implementation. Where something is observation only, it says so. Where a capability depends on the Windows configuration, it says so. Where something is not implemented, it says that too.
New to GURDNStart with the overviewWhat the product is, what it watches, and what it does not claim.TechnicalStart with the architectureThe four layers, the privilege boundary, and the contract across it.OperatorsStart with installationWhat is installed where, what the installer refuses, and how to read the states.Security reviewersStart with the security modelTrust boundaries, authorisation, update verification, and the limits.
Start here
What GURDN is, in one page.
The pipeline from a Windows reading to a verified change.
The vocabulary, written for a first encounter.
What it watches
How readings are taken, normalised and compared.
Resolver observation, change detection and authorised changes.
Route observation and why ambiguity is reported rather than resolved.
Association, security type and network identity.
Profile state, and filters owned through the Windows Filtering Platform.
How it acts
What must be true before anything changes.
Capture, authorise, apply, verify, commit.
Why a successful call is not evidence.
Rollback, reconciliation and refusing to force a mismatch.
Engineering
Interface, engine, privileged service, Windows.
Trust boundaries, the IPC contract and the threat model.
Signature, key standing, downgrade and staging containment.
What is stored, where, and what leaves the machine.
Operating it
What is installed, where, and what the installer refuses.
The states you may see, and what each one means.
What GURDN cannot see, cannot do, and does not replace.
Engineering complete is not the same as released.