Documentation / Start here
Overview
What GURDN is, in one page.
GURDN is a Windows desktop application. It watches the part of the machine that decides how it connects to networks, works out when something about that has meaningfully changed, and can carry out a small set of protective actions when you authorise them.
It is local. There is no account, no server it has to reach, and no mandatory telemetry. Observation, assessment, decisions and the record all happen on the machine.
What it covers
Six surfaces. Two of them GURDN can change; the rest it reads.
- DNS. Which resolvers each interface is configured to use, and whether they changed from what GURDN last recorded. Can set interface resolvers to a configuration you choose, then read them back to confirm.
- Routing. The routing table, joined to the interface list, to name the path traffic actually takes. Observation only.
- Network adapters. Which interfaces exist, their type and status, their addresses, prefix lengths, DHCP origin, gateways and MTU. Observation only.
- Wi-Fi. The associated network, its security type, and how that compares with previous associations of the same network. Observation only.
- Firewall. The host firewall profile in force and whether it is enabled, read from the local firewall policy store. Can enable a profile, and can add and remove its own filters through the Windows Filtering Platform, inside a transaction.
- VPN state. Whether a VPN interface is present and carrying traffic. Observation only.
What it does with what it sees
A single reading is not interesting. GURDN compares each observation against what that network looked like last time, groups changes that happened together, and judges the group rather than the parts. A resolver change on its own is ordinary. A resolver change alongside a new adapter and a firewall profile change, seconds apart, on a network joined for the first time, is worth telling you about.
When it does act, the sequence is fixed: capture the current state and the way back from it, require authorisation, apply the change through the privileged service, read the machine back, and commit only if the read back agrees. If it does not, the recorded undo runs. See the response engine.
What it is not
- Not an antivirus, and not a replacement for one. It looks at configuration, not at files or processes.
- Not a VPN. It provides no connectivity and routes nothing.
- Not a packet capture tool. It reads settings, not the contents of traffic.
- Not a cloud service, and not a dashboard over a fleet of machines.
- Not a guarantee. It narrows one category of risk and shows its evidence.
Honesty about what it cannot see
GURDN reports Unknown as its own state. A question it could not answer is never folded into a healthy result, because an unanswered question is not a clean bill of health. Where Windows exposes no capability, it reports Not supported rather than working around it or staying quiet.
The limitations page lists the boundaries in full.