Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ScubaGear — Automation to assess the state of your M365 tenant against CISA's baselines | Kitploit
Tools/GitHubGitHub/cisagov/scubagear
Defensive ToolsConfiguration AuditingCloud SecurityIdentity & Access Management (IAM)MisconfigurationEmail Security
GitHubcisagov/scubagear

ScubaGear

Automation to assess the state of your M365 tenant against CISA's baselines

View Repository
2.6k377344 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Website
Share

ScubaGear Logo

[![GitHub Release][github-release-img]][release] [![PSGallery Release][psgallery-release-img]][psgallery] [![CI Pipeline][ci-pipeline-img]][ci-pipeline] [![Functional Tests][functional-test-img]][functional-test] [![GitHub License][github-license-img]][license] [![GitHub Downloads][github-downloads-img]][release] [![PSGallery Downloads][psgallery-downloads-img]][psgallery] [![GitHub Issues][github-issues-img]][github-issues]

ScubaGear is an assessment tool that verifies that a Microsoft 365 (M365) tenant’s configuration conforms to the policies described in the Secure Cloud Business Applications (SCuBA) Secure Configuration Baseline documents.

[!NOTE] This documentation can be read using GitHub Pages.

Target Audience

ScubaGear is for M365 administrators who want to assess their tenant environments against CISA Secure Configuration Baselines.

Overview

ScubaGear uses a three-step process:

  • Step One - PowerShell code queries M365 APIs for various configuration settings.
  • Step Two - It then calls Open Policy Agent (OPA) to compare these settings against Rego security policies written per the baseline documents.
  • Step Three - Finally, it reports the results of the comparison as HTML, JSON, and CSV.

ScubaGear Assessment Process Diagram

Key Features

Baseline Security Coverage

SCuBA controls have been mapped to both NIST SP 800-53 and the MITRE ATT&CK framework.

  • Baselines

    • Microsoft Entra ID: Identity and access management policies
    • Security Suite: Advanced threat protection settings
    • Exchange Online: Email security and compliance configurations
    • Power BI: Cloud-based data visualization tool security settings
    • Power Platform: Low-code application security settings
    • SharePoint: Document collaboration and access controls
    • Teams: Communication and meeting security policies
  • Removed Policies

Scuba Configuration UI

SCuBA now includes a graphical user interface that makes it easier than ever to create and manage your YAML configuration files. This intuitive tool helps reduce the complexity of manual editing and streamlines the configuration process for your organization. For more information review the Configuration UI documentation.

UI Key Features:

  • Launch with Start-ScubaConfigApp
  • Step-by-step setup wizard covering all configuration options
  • Real-time validation with live YAML preview
  • Microsoft Graph integration for user and group selection
  • Seamless import/export of existing configuration files

Ideal for users who prefer a visual interface over command-line tools.

ScubaGear Output

  • HTML Reports: Interactive, user-friendly compliance reports. Sample BaselineReports.html
  • JSON Output: Structured results for reporting and parsing. Sample ScubaResults.json
  • CSV Export: Spreadsheet-compatible data for analysis. Sample ScubaResults.csv

Getting Started

Before launching ScubaGear, it's important to ensure your environment is properly configured. This includes having the necessary dependencies and permissions in place.

Please review the prerequisites section to verify that your system meets all requirements. This will help avoid errors during execution and ensure a smooth experience when using ScubaGear.

[!NOTE] After installing ScubaGear in your environment, we recommend using the built-in update functions and features when you need to update to the latest version. See the Update Guide for more information.

Quick Start Guide

ScubaGear can be run multiple times to properly evaluate baseline settings.

  1. First Run (No Configuration File): Start ScubaGear without a configuration file. This initial run generates a baseline template of your environment's current settings. It does not make changes but helps you understand the default posture.

  2. Subsequent Runs (With Configuration File): After reviewing and editing the generated configuration file, run ScubaGear again with the configuration file as input. This allows ScubaGear to compare your intended settings against the actual environment and elevate discrepancies accordingly.

[!IMPORTANT] ScubaGear has specific prerequisites and relies on defined configuration values to properly evaluate your Microsoft 365 tenant. After your initial assessment run, review the results thoroughly. Address any identified gaps by updating your tenant configuration or documenting risk acceptances in a YAML configuration file using exclusions, annotations, or omissions. Refer to the sections below for detailed guidance.

This iterative approach ensures ScubaGear is aligned with your environment and that all policy evaluations are based on your customized baseline.

1. Install ScubaGear

To install ScubaGear from PSGallery, open a PowerShell 5 terminal on a Windows computer and install the module:

# Install ScubaGear
Install-Module -Name ScubaGear

2. Install Dependencies

# Install the minimum required dependencies
Install-ScubaDependencies

3. Verify Installation

# Check the version
Invoke-SCuBA -Version

4. Run Your First Assessment

[!IMPORTANT] If you are running v2.0.0 with interactive login against a non-commercial tenant such as gcc or gcchigh, include the -M365Environment parameter. In a future release ScubaGear will auto-detect the M365 environment and this won't be necessary.

# Assess all products (basic command)
Invoke-SCuBA -ProductNames *

5. Build YAML configuration file

ScubaGear uses a YAML configuration file to define how your environment should be evaluated. This file serves several important purposes:

Download Tool