HardeningKitty and Windows Hardening Settings
-
Updated
Aug 31, 2026 - PowerShell
HardeningKitty and Windows Hardening Settings
🛡️ Security & Privacy Hardening Tool for Windows 11 25H2 — 630+ Settings, 7 Modules, BAVR Pattern.
A desktop/web app for security engineers and Active Directory administrators to load, browse, compare, audit, and baseline-check Group Policy Object (GPO) backups — without needing a domain controller.
Security baseline for managing Linux devices with Microsoft Intune — Ubuntu autoinstall enrollment, custom compliance policies, and hardening scripts for Defender, firewall, encryption and updates.
Windows Server 安全基线巡检脚本,PowerShell 全自动检测账户策略、防火墙、审计日志、服务、补丁、共享、注册表等 15 大模块,输出工程师风 HTML 安全报告。
A security baseline for vibe coding with Claude Code: a CLAUDE.md that sets the rules, plus permissions, hooks and read-only subagents that enforce the parts a long session forgets.
Windows 11 security hardening tool with STIG V2R9 & CIS Level 1-aligned baselines, privacy, debloat, networking, and gaming — Apply/Restore Default with restore-point safeguards.
Active Directory multi-domain lab with PowerShell automation, OUs, GPOs, and DHCP/DNS configuration.
DevSec Nginx Baseline - InSpec Profile (CIS Benchmark Controls Added)
This Powershell Script compares your local Security Policies to the Microsoft Security Baseline.
Windows-Server-Homelab zur Härtung von Active Directory: Security Policies per GPMC/ADAC – starke Kennwortrichtlinien, Kontosperrung, User Rights Assignment und Fine-Grained Password Policies (FGPP). Inklusive kurzer Tests, Validierung mit gpresult/RSOP und klarer, reproduzierbarer Dokumentation.
Baseline → remediate → verify hardening of my macOS daily driver — Lynis audit, CIS guidance, verified from an attacker VM
Public, audit-ready security baseline with hardware root of trust, signed evidence, and CI-validated controls.
Secure AWS network as code: three isolated tiers, least-privilege dual firewall, KMS-encrypted CloudTrail and flow log vault with object lock, and a CI gate (Checkov + tfsec + tflint) that blocks misconfigurations before apply.
SentinelOne policy configuration enabling automatic scanning of USB and external storage devices on Windows and macOS endpoints.
M365 & Entra ID Security Baseline. Deployed Conditional Access, Intune device compliance, and Purview DLP; achieved 100% MFA enrollment and 98% device compliance, reducing incidents by 40%.
Read-only PowerShell module that assesses Microsoft Intune/Entra tenant health against a versioned check catalog and produces a deterministic, pseudonymized, scored findings report. Built on GraphKit — never writes to a tenant.
IntuneCanvas — Paint the Full Picture of Your Intune Environment
Safe, read-only PowerShell tools for auditing Windows security posture without changing system configuration.
To associate your repository with the security-baseline topic, visit your repo's landing page and select "manage topics."