
atlant-harden v2.1.1
AtlantHarden - free Windows, browser & Office security hardening. 579 settings incl. 354 DISA STIG controls (Win11/Edge/Chrome/Firefox/Office 365) + ACSC Essential Eight. Source-available for audit.
AtlantHarden — Windows, Browser & Office Security Hardening Tool

AtlantHarden is a comprehensive Windows 10/11 security hardening application with a modern, professional UI. It applies 606 hardening settings — including 354 DISA STIG controls across Windows 11, Edge, Chrome, Firefox, and Office 365 (latest releases), plus the ACSC Essential Eight — through one-click, review-before-apply profiles with full backup and restore. It also includes one-click Windows debloat (remove Store junk and OEM/AV bloat) and a Tighten Up Privacy cleanup. The released build is a single self-contained executable (no .NET runtime to install).
⬇️ Download
Download AtlantHarden v2.1 for Windows
Single .zip, ~63 MB, self-contained — no .NET install required. Extract it, then right-click AtlantHarden.exe → Run as administrator. It's not code-signed yet, so SmartScreen may prompt — choose More info → Run anyway. See all releases and notes.
Features
🛡️ Comprehensive Security Categories
- Windows Defender - Configure real-time protection, PUA detection, and cloud protection
- Attack Surface Reduction - All 19 Microsoft ASR rules for Office, scripts, USB, and ransomware protection
- Network Security - Harden SMB, NTLM, LDAP signing, and disable legacy protocols (DISA STIG tagged)
- Credential Protection - Protect LSASS, disable WDigest, and prevent Mimikatz attacks (DISA STIG tagged)
- Browser Hardening - Secure Edge, Chrome, and Firefox with enterprise policies (DISA STIG: Edge V2R5, Chrome V2R11, Firefox V6R7)
- Office Hardening - Disable macros, DDE, and protect against document-based attacks (DISA STIG: Office 365 ProPlus V3R5)
- Privacy Settings - Turn off telemetry, advertising ID, activity history, tailored experiences, and suggested/promoted content — including a one-click Tighten Up Privacy button
- Bloatware Removal - Remove pre-installed Store junk and games, and detected OEM/AV bloat (McAfee, Norton, WildTangent, and Dell/HP/Lenovo assistant apps) — review-first, nothing removed without your confirmation
- Logging & Auditing - Enable PowerShell logging, process auditing, and event log sizing (DISA STIG tagged)
- File Associations - Neutralize dangerous file types to prevent ransomware
- Windows Firewall - Block LOLBins from network access
- TLS/Cryptography - Disable weak ciphers and enforce modern TLS (DISA STIG tagged)
- System Hardening - UAC, DEP, ASLR, DLL protection, and more (DISA STIG tagged)
- Adobe Reader - Apply STIG-compliant security settings
🎯 Attack Surface Reduction (ASR) Rules
All 19 Microsoft ASR rules are supported with real-time status verification:
- Block Office applications from creating child processes
- Block Office apps from injecting code into other processes
- Block Win32 API calls from Office macros
- Block executable content from email client and webmail
- Block execution of potentially obfuscated scripts
- Block JavaScript/VBScript from launching downloaded content
- Block untrusted/unsigned processes from USB
- Advanced ransomware protection
- Block credential stealing from LSASS
- Block low-prevalence executables
- Block Adobe Reader child processes
- Block Office communication app child processes
- Block WMI event subscription persistence
- Block PSExec/WMI process creation
- Block abuse of vulnerable signed drivers
- Block Safe Mode reboot commands
- Block impersonated system tools
- Block webshell creation for servers
🏛️ DISA STIG Compliance
354 automatable DISA STIG requirements across five products, sourced from the latest
DISA releases and loaded from an auditable, regenerable catalog (Resources/stig-catalog.json):
| Product | STIG Version | Requirements |
|---|---|---|
| Microsoft Windows 11 | V2R7 | 114 |
| Microsoft Edge | V2R5 | 52 |
| Google Chrome | V2R11 | 39 |
| Mozilla Firefox | V6R7 | 43 |
| Microsoft Office 365 ProPlus | V3R5 | 106 |
- Dedicated DISA STIG Compliance category group in the sidebar (one category per product), kept separate from the curated baseline hardening categories
- Per-product compliance breakdown on the dashboard
- Real STIG ID (e.g.
WN11-SO-000195,EDGE-00-000002), Vulnerability ID, and CCIs per setting - Severity mapped to CAT I/II/III — filter and bulk-select STIG: CAT I/II/III within any product
- Org-specific rules (no single correct value) are intentionally excluded from auto-apply
- Catalog generated from Microsoft PowerSTIG + cyber.trackr.live via
tools/Generate-StigCatalog.ps1
🦘 ACSC (Australian Cyber Security Centre) Compliance
34 ACSC Windows Hardening settings based on the July 2024 guidance:
- High Priority Settings - Command Prompt restrictions, Group Policy enforcement, AutoRun disabling
- Medium Priority Settings - Anonymous access restrictions, account lockout policies, DMA protection, removable media controls
- Low Priority Settings - File extension visibility, hidden files, recent documents clearing
- Network Security - SMB/LDAP signing, NTLMv2 enforcement, LLMNR/NetBIOS disabling, WPAD protection
- PowerShell Hardening - Script block logging, module logging, transcription, constrained language mode
🎚️ One-Click Profiles (review before you apply)
Three curated profiles, each with Apply and a Show settings button that opens a scrollable review of every setting (name, description, registry change, current vs. recommended value) before anything is applied:
- Basic (95 settings) - the highest-impact, effectively zero-friction core
- Recommended (325 settings) - the smart default: applies the controls that stop real malware and exploitation (ASR, Defender, SmartScreen, macro/script blocking, credential-theft protection, exploit mitigations) while deliberately skipping high-friction lockdowns. It does not disable browser password managers, InPrivate/Incognito, history deletion, Controlled Folder Access, FIPS, or a BitLocker pre-boot PIN — and is already gaming- and performance-safe.
- Maximum (606 settings) - everything, including the strict DISA STIG lockdowns
Bloatware removal and the privacy cleanup are kept separate from these profiles — they're reached from the dashboard's Cleanup & Privacy section (a one-click Tighten Up Privacy and a review-first Clean Up Bloat), so applying a security profile never uninstalls an app.
Self-protection: before enabling any setting, AtlantHarden allow-lists its own executable for Microsoft Defender ASR and Controlled Folder Access, and keeps Explorer SmartScreen at an overridable level — so this (unsigned) tool can always be relaunched to revert.
💾 Backup & Restore
- Automatic Backups - Creates backup before applying any changes
- System Restore Points - Create Windows System Restore points from the app
- Multiple Versions - Keeps up to 20 timestamped backup versions
- One-Click Restore - Easily revert to any previous state
- REG File Export - Also exports .reg files for manual restoration
📦 Configuration Import/Export
- Export Configuration - Save your selected settings to a JSON file
- Import Configuration - Load settings from a previously exported file
- Command Line Support - Automate deployment with
--configparameter - Silent Mode - Run unattended with
--silent --applyflags - Profile Sharing - Share configurations across multiple systems