GURDN

Documentation / Start here

Glossary

The vocabulary, written for a first encounter.

These are the words the product and this documentation use. Each definition is written for a first encounter rather than for someone who already knows.

Observation
One reading of one part of the Windows connectivity configuration, recorded with whether it succeeded, partly succeeded or could not be read.
Baseline
What a given network looked like when GURDN last recorded it. Changes are judged against this rather than against a universal idea of normal.
Diff
The typed difference between the current observation and the baseline. A diff is a fact, not yet a judgement.
Correlation
Grouping changes that happened together. A resolver change alone is ordinary; a resolver change with a new adapter and a firewall profile change is a different matter.
Detection rule
A check that turns correlated changes into a finding with a severity and a confidence, and records the inputs it used.
Trust
What GURDN knows about a network from previous encounters, including the decision the user made about it. A new network is never trusted by default.
Policy
The configuration that decides what GURDN may propose and what it must ask about before acting.
Authorisation
The recorded consent that permits a change. Different operations require different levels, and an expired authorisation cannot be reused.
Privileged service
The Windows service that performs the operations needing elevation, under its own restricted identity, reachable only through a local endpoint limited to the system account and administrators.
IPC
Inter-process communication. Here, the named pipe between the engine and the privileged service, which rejects remote clients and refuses an oversized message before allocating memory for it.
WFP
The Windows Filtering Platform, the interface GURDN uses for firewall filters. Filters are registered under a provider GURDN owns, so the platform itself distinguishes them from everyone else’s.
Resolver
The DNS server an interface is configured to ask. Changing it changes where every later name lookup goes, which is why GURDN watches it.
Reconciliation
Checking, after a restart or an interruption, what actually happened. It observes and reports; it never replays a change.
Rollback
Undoing applied steps in reverse order using the undo each recorded before it ran.
Protective mode
A single authorised state that applies a set of protections together and can be turned off again, showing what it applied and what it will undo.
Unknown
A state of its own, meaning GURDN could not get an answer. It is never folded into a healthy result.
Degraded
Some capabilities are unavailable while others still work. The product says which.
Audit record
The local, chained record of what GURDN observed, decided, was authorised to do, and did. An altered or missing entry breaks the chain and is reported.