Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Chuks Awunor chose Rust for the Windows endpoint agent behind GuardsArm’s SOC because the agent runs with elevated privileges and handles data an attacker can shape. He cites memory safety without a garbage collector, predictable resource use, a single self-contained binary, and direct Windows API access through the windows crates. He also accepted real costs: slower early development, longer compile times than Go, harder hiring, and extra work to wrap awkward Windows APIs. This article walks through his reasoning, the comparison points he raised against C++, C#/.NET, and Go, and the limits that a language choice cannot remove.

Why an endpoint agent is a security-sensitive program

An endpoint agent sits on every machine it protects, and that position is what makes it risky. Awunor describes the Windows agent for GuardsArm’s SOC as a long-running privileged process. It parses command lines, file paths, network data, and event logs, and much of that content can be influenced by an attacker who is already trying to evade detection. If the agent crashes, is corrupted, or can be tricked into misbehaving, the attacker gains a foothold in the one component that was supposed to watch for them.

That is the core of his argument. In his words: “If you are building security tooling, the tool itself is part of your attack surface.” The implication is that a flaw in the monitoring software is not just a bug in a product. It is a route into the environment the product protects.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What Awunor valued in Rust

Awunor’s reasons are specific, and it helps to separate them, because each one addresses a different part of the agent’s risk.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Memory safety without a garbage collector

Rust’s compiler enforces memory-safety rules in safe code, including ownership and borrowing checks that prevent many use-after-free and data-race bugs before the program runs. Awunor wanted those guarantees without a garbage collector. A collector would add runtime behavior the agent would have to live with, and he preferred to control memory lifetimes explicitly. He also notes that the borrow checker forces ownership and lifetime decisions early in development. That is a cost in the short term, discussed below, and a benefit later, because the design has to be settled before the code is written rather than discovered during an incident.

Predictable resource use

For a process that runs continuously on every endpoint, Awunor says he wanted a flat memory and CPU profile without collector pauses or runtime overhead. This is his stated experience and reasoning. The article does not include measurements, benchmarks, or telemetry from the GuardsArm agent, so it should not be read as a verified comparison of footprint against other languages.

A single self-contained binary

Rust compiles to a native executable that can be deployed as one file. For an agent that must be installed, updated, and verified across a fleet, fewer runtime dependencies means fewer moving parts on each machine. Awunor presents this as a deployment advantage, not as a guarantee that the binary is free of vulnerabilities.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Direct Windows API access through the windows crates

The agent needs to call Win32 directly. Awunor points to the windows crates as the route to those APIs from Rust. This is the part of his decision that most directly reflects the platform, and it is also the part that brings the most friction, discussed in the next section.

Rank #2
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Where the Windows boundary stays unsafe

Rust does not remove unsafe code from a Windows agent. Awunor states plainly that Win32 calls still involve explicit unsafe blocks. Those blocks are where the compiler’s guarantees stop, because the caller has to uphold the invariants the Windows API expects, such as valid pointers, correct buffer lengths, and correct handle lifetimes.

He also reports that some Windows APIs are awkward enough to need thin safe wrappers. Writing those wrappers is a design task of its own. A wrapper that is too permissive passes the risk along to every caller, and one that is too clever becomes its own review burden. The practical consequence is that a team adopting Rust for a Windows agent should expect to maintain a small, deliberately reviewed layer of interop code, and should treat that layer as the place where security review concentrates.

How the alternatives compare on the same axes

Awunor compares Rust with C++, C#/.NET, and Go. His article does not rank them on a single scale, and the table below keeps that restraint. The Rust column reflects his account. For the other languages, the article gives few specific observations, so the table uses general language properties where they are well established and marks everything else “Not stated in the article.” Nothing in the table is a measured result.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Axis Rust (author’s account) C++ C#/.NET Go
Memory-safety model Compiler-enforced in safe code; explicit unsafe blocks for Win32 calls Manual memory management; safety depends on coding discipline and tooling Managed memory through the runtime Managed memory through the runtime
Garbage collector and runtime footprint No garbage collector; single self-contained binary No garbage collector Garbage-collected runtime Garbage-collected runtime
Windows API access and interop Through the windows crates; some thin safe wrappers needed Native access; not stated in the article Interop layer; not stated in the article Interop layer; not stated in the article
Concurrency model Author reports avoiding data races in the design Not stated in the article Not stated in the article Not stated in the article
Developer productivity and compile time Slower initial writing; longer compile times than Go Not stated in the article Not stated in the article Shorter compile times than Rust, per the author
Engineers with Windows-internals experience Recruiting is difficult for people with Rust and Windows-internals experience Not stated in the article Not stated in the article Not stated in the article

The table shows why a simple “best language” answer does not hold up. Rust gives Awunor the properties he wanted for this agent, and it charges him in writing speed, build time, and hiring. A team with strong C++ Windows-internals skills, an existing C++ codebase, or a need to ship quickly may weigh those same factors differently.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

The costs he reports

Slower initial development

Awunor reports that the early phase was slower than it would have been in some alternatives, largely because the ownership and lifetime model requires decisions up front. The payoff he describes comes later, when fewer design questions remain open.

Longer compile times

Compile times were longer than with Go, which he names as a daily friction point. Build speed matters more for a security tool that ships often, so teams should measure their own build pipeline rather than assume his experience carries over.

Hiring

He reports that finding people who know both Rust and Windows internals is hard. For a small security team, this can matter as much as any technical property of the language.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Windows-specific abstraction work

The occasional need for safe wrappers around awkward APIs adds design and review work that a team using a more mature Windows-native binding path might not face in the same form. This is the cost most closely tied to his platform choice.

Rank #4
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-C Type TrustKey T120
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

What a memory-safe language does not settle

The Office of the National Cyber Director’s 2024 technical report, Back to the Building Blocks: A Path Toward Secure and Measurable Software, supports the core of Awunor’s position. It states that memory-safe languages can eliminate most memory-safety errors, and it encourages building new products in them: “For new products, choosing to build in a memory safe programming language is an early architecture decision that can deliver significant security benefits.”

The same report is equally clear about the limits. It says there is no one-size-fits-all cybersecurity solution, and that using a memory-safe language cannot eliminate every cybersecurity risk. It also includes a statistic that is often quoted without its context. The report attributes to industry analysis the figure of “up to 70 percent,” which describes the share of security vulnerabilities in memory-unsafe languages that were patched and assigned a CVE designation and that were due to memory-safety issues. That is a share of one specific group of vulnerabilities, not a share of all vulnerabilities in all software.

For an endpoint agent, a memory-safe language addresses one class of defect. It does not address the rest of the work that keeps the agent trustworthy:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Secure design of what the agent is allowed to do, and under which conditions it may act on attacker-controlled input.
  • Testing, including fuzzing of the parsers that handle command lines, paths, network data, and event logs.
  • Controls over how the agent is updated, signed, and verified on each endpoint.
  • Regular review of every unsafe block and wrapper that touches Win32.
  • Threat modeling of the endpoint as a whole, including how the agent could be disabled, tampered with, or used to escalate privileges.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Practical notes for Windows teams considering Rust

Microsoft Learn’s overview of developing on Windows with Rust, last updated 2026-09-29, describes Rust as designed for performance, reliability, and memory safety without a garbage collector. It identifies Cargo, crates, and rustup as the core tools and points to Windows setup guidance and resources for the windows crate. The page also flags a Smart App Control compatibility note for the unsigned toolchain. Teams that rely on Smart App Control should check that note before standardizing on a build environment.

Best Value
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

If your team is learning the language, The Rust Programming Language, the official online book from the Rust Project, is the standard starting point. Its current text assumes Rust 1.97.0 or later, released 2026-07-09, and uses Rust 2024 Edition idioms. A paperback and ebook edition are available through No Starch Press. Learning the language is not required to read or evaluate this decision, but it is the most direct route for a team that will write the code.

When this reasoning applies to your own agent

Awunor’s argument transfers best when several conditions hold at once. Use the following as a checklist rather than a verdict.

  • The agent runs with elevated privileges and processes input that an attacker can influence.
  • It is deployed broadly enough that a memory-safety defect would reach many machines.
  • Your team has, or can reliably hire, engineers who can write and review Rust and the Windows interop it needs.
  • You can accept slower early development and longer build times in exchange for compiler-enforced memory rules in safe code.
  • You are prepared to review the unsafe boundary as a permanent part of the codebase.

If most of those conditions are missing, a different language may serve you well, and the security work described above still applies regardless of the language you choose.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What this article can and cannot establish

Awunor’s essay is a first-person engineering rationale. It describes his decision, his reasons, and the costs he observed. It does not include benchmark methodology, source code, production telemetry, an incident record, or an independent comparison, and it does not measure the agent’s footprint, reliability, or concurrency behavior. Treat his statements about flat resource use, predictable memory and CPU behavior, and avoiding data races as experience and reasoning, not as verified outcomes. The page is dated September 24, and the year is not shown in the article text, so the dates above come from the other sources cited.

GuardsArm presents managed SOC and MDR services and a managed service provider partner program on its website. Awunor’s essay identifies the agent as serving GuardsArm’s SOC. That context explains why the agent exists, but it does not change the technical reasoning, which stands on its own terms.

The choice of Rust is a defensible response to a real risk in endpoint software. It is not a shortcut to a secure agent, and Awunor’s own account is careful to say the same.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.