Skip to content

Latest commit

 

History

History
37 lines (27 loc) · 1.38 KB

File metadata and controls

37 lines (27 loc) · 1.38 KB

Security Policy

Simple NetMon changes Windows Firewall rules and stores a sensitive record of which applications talked to which hosts. We take security reports seriously. See THREAT_MODEL.md for the assets, trust boundaries and accepted risks.

Supported versions

Version Supported
latest main / newest release ✅
older releases ❌

Reporting a vulnerability

Please do not open a public issue for security problems.

Report privately through GitHub:

  1. Go to the repository's Security tab → Report a vulnerability (GitHub Private Vulnerability Reporting).
  2. Include a description, affected version/commit, reproduction steps, and the impact you observed.

We aim to acknowledge a report within 7 days and to agree a disclosure timeline with you. Please give us a reasonable window to ship a fix before any public disclosure. We're happy to credit you (or keep you anonymous — your call).

Scope notes

  • The local dashboard has no authentication and relies on a loopback bind. Exposing -addr to a non-loopback interface without adding auth is a misconfiguration, not a vulnerability in itself — but reports of ways to reach it unexpectedly are welcome.
  • Parser robustness (ETW property and DNS QueryResults parsing) is in scope; crashes or memory issues from malformed provider input are valid reports.