What Rufus does
Rufus 4.15 is a Windows-only utility for writing bootable USB media. It offers standard x64, portable-mode x64, ARM64, and x86 executables. GitHub release metadata reports identical SHA-256 digests for the normal and p-suffixed x64 files, but the p name activates portable settings behavior. Neither executable runs as a Linux application.
Writing an image destroys the target drive's existing partitions and data. Drive filtering reduces risk but does not identify intent, so verify model, capacity, serial where available, and backups before starting. Partition scheme, firmware mode, file system, Secure Boot behavior, and Windows setup customizations must match the target; a completed write is not proof that the image is trustworthy or will boot on a particular system.
A local ISO avoids downloading that image during the write, but do not assume every Rufus workflow needs no network. Particular images can need Syslinux/GRUB components; current Secure Boot revocation data and update checks can also use a connection. Stage and validate the exact image workflow before disconnecting. The optional Windows ISO-download workflow retrieves images from Microsoft endpoints. Its checksum feature computes an image digest, but the operator must compare it with an independently authenticated publisher value; matching a self-computed hash to itself proves nothing about provenance.
GitHub publishes SHA-256 digests and `.sig` assets for release executables. This review did not write a drive, verify a signature locally, download an ISO, compare firmware modes, or test bootability.