HardeningKitty and Windows Hardening Settings
-
Updated
Jul 21, 2026 - PowerShell
HardeningKitty and Windows Hardening Settings
🛡️ Security & Privacy Hardening Tool for Windows 11 25H2 — 630+ Settings, 7 Modules, BAVR Pattern.
A desktop/web app for security engineers and Active Directory administrators to load, browse, compare, audit, and baseline-check Group Policy Object (GPO) backups — without needing a domain controller.
Windows Server 安全基线巡检脚本,PowerShell 全自动检测账户策略、防火墙、审计日志、服务、补丁、共享、注册表等 15 大模块,输出工程师风 HTML 安全报告。
Windows 11 security hardening tool with STIG V2R9 & CIS Level 1-aligned baselines, privacy, debloat, networking, and gaming — Apply/Restore Default with restore-point safeguards.
Windows-Server-Homelab zur Härtung von Active Directory: Security Policies per GPMC/ADAC – starke Kennwortrichtlinien, Kontosperrung, User Rights Assignment und Fine-Grained Password Policies (FGPP). Inklusive kurzer Tests, Validierung mit gpresult/RSOP und klarer, reproduzierbarer Dokumentation.
This Powershell Script compares your local Security Policies to the Microsoft Security Baseline.
DevSec Nginx Baseline - InSpec Profile (CIS Benchmark Controls Added)
Active Directory multi-domain lab with PowerShell automation, OUs, GPOs, and DHCP/DNS configuration.
M365 & Entra ID Security Baseline. Deployed Conditional Access, Intune device compliance, and Purview DLP; achieved 100% MFA enrollment and 98% device compliance, reducing incidents by 40%.
SentinelOne policy configuration enabling automatic scanning of USB and external storage devices on Windows and macOS endpoints.
Public, audit-ready security baseline with hardware root of trust, signed evidence, and CI-validated controls.
Read-only PowerShell module that assesses Microsoft Intune/Entra tenant health against a versioned check catalog and produces a deterministic, pseudonymized, scored findings report. Built on GraphKit — never writes to a tenant.
This repository is focused on collecting, organizing, and maintaining security hardening guidelines, practices, and references for various environments. The objective is to provide a centralized knowledge base to improve system security, reduce attack surfaces, and follow best practices for cybersecurity.
AWS Security baseline — multi-account guardrails, SCPs, and Security Hub via Terraform
Local Linux hardening snapshot audit for SSH, sysctl, and privileged-account checks.
Read-only Microsoft 365 and Entra ID identity baseline capture and drift detection in a single PowerShell script
A Conditional Access framework for Microsoft Entra ID: a baseline is an operating model, not a set of JSON files. Personas + resource tiers, governed exceptions, TAP-first onboarding, ring enablement, and a shipped runbook.
Practical security baselines for Linux hosts, web services, and GitHub repositories.
Add a description, image, and links to the security-baseline topic page so that developers can more easily learn about it.
To associate your repository with the security-baseline topic, visit your repo's landing page and select "manage topics."