GURDN

Limitations

What GURDN cannot do

A security product that describes only its strengths cannot be assessed. These are the boundaries, and most are permanent properties of running on one endpoint rather than gaps waiting to be filled.

01Outside the machine

Things no Windows application can reach

Several of the things people hope a tool like this will fix are simply not on your machine.

Carrier infrastructure
No visibility into a mobile network, SIM provisioning, carrier account security or the signalling behind them. GURDN reports what Windows says about a mobile broadband interface and nothing further.
Upstream networks
Your provider, transit networks and the route beyond your gateway are outside the endpoint and cannot be observed from it.
Routers and firmware
A compromised router sits below Windows. GURDN may observe a consequence, such as a resolver that changed, but cannot inspect or repair the device.
Other devices
GURDN protects the Windows machine it runs on. It is not an agent for the phones, consoles and appliances sharing the network.

02Inside the machine

Where an endpoint application stops

An adversary already in control
Someone with administrative rights can stop the service and alter the stored record. The audit chain makes that detectable; it does not make it impossible.
Physical access
Outside what any application can defend against.
Files and processes
Not GURDN’s subject. It is not an antivirus and does not replace one.
Traffic contents
GURDN reads configuration, not packets. It is not a capture tool, a web filter or a content inspector.

03Honest phrasing

Claims GURDN does not make

These phrases are common in security marketing. None is true of GURDN, and none is true of any product.

Unhackable
No product makes a machine unhackable. GURDN narrows one category of risk at the connectivity layer and shows its evidence.
SIM protection
A SIM and a carrier account are held by your carrier. A Windows application that claimed to defend them would be lying.
Replaces Windows Firewall
GURDN uses the firewall capabilities Windows provides, adds filters under its own provider, and reports what it sees.
Guaranteed protection
GURDN reports what it observed, what it could not observe, and what it changed. The value is in that honesty, not in a guarantee.

04Platform

Where the product runs

Windows on 64-bit x86. There is no macOS, Linux, Android, iOS or browser version, because the security interfaces GURDN uses are specific to Windows. Where a capability is unavailable on a particular configuration, GURDN reports it as not supported rather than working around it.

The documentation covers the limits of observation and action in more detail.