Documentation / Operating it
Limitations
What GURDN cannot see, cannot do, and does not replace.
This page exists because the alternative is letting a reader assume. Most of what follows is a permanent property of running on one endpoint rather than a gap waiting to be filled.
Outside the machine
- Carrier infrastructure. GURDN has no visibility into a mobile network, SIM provisioning, carrier account security, or the signalling systems behind them. It reports what Windows says about a mobile broadband interface and nothing further. Any product claiming otherwise from a Windows application is describing something it cannot do.
- Your provider and the wider internet. Transit networks and the route beyond your gateway are not observable from the endpoint.
- Routers and firmware. A compromised router sits below Windows. GURDN may observe a consequence, such as a resolver that changed, but it cannot inspect, verify or repair the device.
- Other devices. GURDN protects the Windows machine it runs on. It is not an agent for the phones, consoles and appliances on the same network.
Inside the machine
- An adversary who already has administrative control. They can stop the service and alter the stored record. The audit chain makes that detectable; it does not make it impossible.
- Physical access. Outside what any application can defend against.
- Files, processes and malware. Not GURDN's subject. It is not an antivirus and does not replace one.
- Traffic contents. GURDN reads configuration, not packets.
Limits of observation
- An adapter hidden by a filter driver is invisible to the Windows API GURDN uses.
- Changes that start and finish between two observations are not seen. For interfaces, addresses and routes that window is milliseconds; for resolver, firewall and wireless security changes it is the polling interval.
- Where several interfaces carry a default route, GURDN reports the ambiguity rather than choosing.
- Without a resolvable gateway, network identity rests on forgeable signals, and GURDN marks it weak.
- No local observation establishes that an attack is occurring, so no rule concludes one is.
Limits of action
- Routing, Wi-Fi, adapters and VPN state are observation only.
- Ordinary Windows Firewall rule management is not implemented; it needs an interface this build does not use, and the request is answered Not supported.
- A firewall profile governed by Group Policy is refused rather than written locally.
- GURDN refuses to undo a change whose current state no longer matches what it applied, rather than overwriting someone else's change.
Platform
Windows on 64-bit x86 only. There is no macOS, Linux, Android, iOS or browser version. Where Windows exposes no capability, GURDN reports it as unsupported rather than working around it.
What GURDN does not guarantee
It does not make a machine unhackable, it does not guarantee protection, and it does not promise that a network is safe. It reports what it observed, what it could not observe, and what it changed. The value is in that, not in a guarantee.
See also troubleshooting for how unsupported and unknown states appear in use.