HardeningKitty and Windows Hardening Settings
-
Updated
Aug 31, 2026 - PowerShell
HardeningKitty and Windows Hardening Settings
🛡️ Security & Privacy Hardening Tool for Windows 11 25H2 — 630+ Settings, 7 Modules, BAVR Pattern.
A desktop/web app for security engineers and Active Directory administrators to load, browse, compare, audit, and baseline-check Group Policy Object (GPO) backups — without needing a domain controller.
Security baseline for managing Linux devices with Microsoft Intune — Ubuntu autoinstall enrollment, custom compliance policies, and hardening scripts for Defender, firewall, encryption and updates.
Windows Server 安全基线巡检脚本,PowerShell 全自动检测账户策略、防火墙、审计日志、服务、补丁、共享、注册表等 15 大模块,输出工程师风 HTML 安全报告。
Windows 11 security hardening tool with STIG V2R9 & CIS Level 1-aligned baselines, privacy, debloat, networking, and gaming — Apply/Restore Default with restore-point safeguards.
Active Directory multi-domain lab with PowerShell automation, OUs, GPOs, and DHCP/DNS configuration.
This Powershell Script compares your local Security Policies to the Microsoft Security Baseline.
Windows-Server-Homelab zur Härtung von Active Directory: Security Policies per GPMC/ADAC – starke Kennwortrichtlinien, Kontosperrung, User Rights Assignment und Fine-Grained Password Policies (FGPP). Inklusive kurzer Tests, Validierung mit gpresult/RSOP und klarer, reproduzierbarer Dokumentation.
Baseline → remediate → verify hardening of my macOS daily driver — Lynis audit, CIS guidance, verified from an attacker VM
DevSec Nginx Baseline - InSpec Profile (CIS Benchmark Controls Added)
Public, audit-ready security baseline with hardware root of trust, signed evidence, and CI-validated controls.
M365 & Entra ID Security Baseline. Deployed Conditional Access, Intune device compliance, and Purview DLP; achieved 100% MFA enrollment and 98% device compliance, reducing incidents by 40%.
SentinelOne policy configuration enabling automatic scanning of USB and external storage devices on Windows and macOS endpoints.
IntuneCanvas — Paint the Full Picture of Your Intune Environment
Read-only PowerShell module that assesses Microsoft Intune/Entra tenant health against a versioned check catalog and produces a deterministic, pseudonymized, scored findings report. Built on GraphKit — never writes to a tenant.
Local Linux hardening snapshot audit for SSH, sysctl, and privileged-account checks.
Enterprise AWS Landing Zone with Terraform: Organizations, SCPs, CloudTrail, Config, GuardDuty and reusable governance modules.
Hardened AWS Terraform baseline: IAM least-privilege, S3 SSE-KMS, CloudTrail, security groups, KMS rotation. With tfsec + checkov CI.
To associate your repository with the security-baseline topic, visit your repo's landing page and select "manage topics."