Documentation / Start here
Glossary
The vocabulary, written for a first encounter.
These are the words the product and this documentation use. Each definition is written for a first encounter rather than for someone who already knows.
- Observation
- One reading of one part of the Windows connectivity configuration, recorded with whether it succeeded, partly succeeded or could not be read.
- Baseline
- What a given network looked like when GURDN last recorded it. Changes are judged against this rather than against a universal idea of normal.
- Diff
- The typed difference between the current observation and the baseline. A diff is a fact, not yet a judgement.
- Correlation
- Grouping changes that happened together. A resolver change alone is ordinary; a resolver change with a new adapter and a firewall profile change is a different matter.
- Detection rule
- A check that turns correlated changes into a finding with a severity and a confidence, and records the inputs it used.
- Trust
- What GURDN knows about a network from previous encounters, including the decision the user made about it. A new network is never trusted by default.
- Policy
- The configuration that decides what GURDN may propose and what it must ask about before acting.
- Authorisation
- The recorded consent that permits a change. Different operations require different levels, and an expired authorisation cannot be reused.
- Privileged service
- The Windows service that performs the operations needing elevation, under its own restricted identity, reachable only through a local endpoint limited to the system account and administrators.
- IPC
- Inter-process communication. Here, the named pipe between the engine and the privileged service, which rejects remote clients and refuses an oversized message before allocating memory for it.
- WFP
- The Windows Filtering Platform, the interface GURDN uses for firewall filters. Filters are registered under a provider GURDN owns, so the platform itself distinguishes them from everyone else’s.
- Resolver
- The DNS server an interface is configured to ask. Changing it changes where every later name lookup goes, which is why GURDN watches it.
- Reconciliation
- Checking, after a restart or an interruption, what actually happened. It observes and reports; it never replays a change.
- Rollback
- Undoing applied steps in reverse order using the undo each recorded before it ran.
- Protective mode
- A single authorised state that applies a set of protections together and can be turned off again, showing what it applied and what it will undo.
- Unknown
- A state of its own, meaning GURDN could not get an answer. It is never folded into a healthy result.
- Degraded
- Some capabilities are unavailable while others still work. The product says which.
- Audit record
- The local, chained record of what GURDN observed, decided, was authorised to do, and did. An altered or missing entry breaks the chain and is reported.