Skip to content

Security: arnabnandy7/svcguardian

Security

SECURITY.md

Security Policy

Supported Versions

Service Guardian is pre-1.0. Security fixes target the main branch.

Reporting a Vulnerability

Please do not open a public issue for a suspected vulnerability.

Report security concerns by emailing:

arnab_nandy7@yahoo.com

Include:

  • Affected version or commit
  • Windows version and PowerShell version
  • Steps to reproduce
  • Expected and actual behavior
  • Any relevant timeline output with secrets removed

You should receive an initial response within 7 days.

Security Scope

Security-relevant issues include:

  • Unsafe service configuration changes
  • Privilege escalation paths
  • Incorrect attribution that could mislead investigations
  • Sensitive data exposure in timeline exports
  • Unsafe handling of paths, config files, or logs

Operational Notes

Service Guardian can modify Windows service startup configuration when run with repair enabled from an elevated shell. Review the configured policy before using:

.\svcguardian.ps1 status

The attribution feature is best effort. Windows may not record the executable that changed a service unless the correct audit policy and object auditing are enabled.

There aren't any published security advisories