Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ServerSecurityAudit — PowerShell-based Windows Server Security Audit Engine by Cyb3rint3l Labs. Measures alignment with the NIS2 directive and maps findings to MITRE ATT&CK tactics & CIS Controls v8 practices. Generates interactive HTML dashboards & structured JSON datasets. | Kitploit
Tools/GitHubGitHub/cyb3rint3l-labs/serversecurityaudit
Configuration AuditingThreat IntelligenceIncident Response
GitHubcyb3rint3l-labs/serversecurityaudit

ServerSecurityAudit

PowerShell-based Windows Server Security Audit Engine by Cyb3rint3l Labs. Measures alignment with the NIS2 directive and maps findings to MITRE ATT&CK tactics & CIS Controls v8 practices. Generates interactive HTML dashboards & structured JSON datasets.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website
4786 months agoReviewed by Kitploit

🛡️ Windows Server Security Audit (NIS2 Alignment)

License PowerShell Platform NIS2 Ready MITRE ATT&CK CIS Controls

📋 Overview

A modular PowerShell-based engine designed to perform deep security hygiene audits on Windows Server systems. It delivers actionable risk scoring mapped to NIS2 Directive (Article 21), MITRE ATT&CK, and CIS Controls v8, generating forensic-ready HTML and JSON outputs.

The engine executes 30+ weighted checks across 6 Strategic Domains covering 12 critical security disciplines to ensure a holistic defense-in-depth posture.

It runs entirely offline, has no external dependencies or call home capabilities.

⚠️ Disclaimer

While designed to be non-intrusive, this script performs extensive WMI, Registry, and File System queries. These operations may cause temporary CPU/Disk spikes or trigger EDR/Monitoring alerts.

🎯 Key Capabilities

  • 🇪🇺 NIS2 Compliance Aligned: Every check is mapped directly to Directive (EU) 2022/2555 articles (Vulnerability Handling, Risk Analysis, Basic Cyber Hygiene, Network Security, Access Control, Cryptography, Business Continuity).
  • 📊 Risk-Based Scoring: Prioritises vulnerabilities (Critical/Warning/Info) based on exploitability impact. Furthermore, findings are mapped to MITRE ATT&CK tactics and CIS Controls v8 practices.
  • 🕵️ Sensitive Data Discovery: Detects exposed credentials in user profiles and Inetpub locations in the form of filenames (e.g., "passwords.txt", "credentials.docx") across 15+ languages (🇬🇧 EN, 🇬🇷 GR, 🇩🇪 DE, 🇳🇱 DU, 🇫🇷 FR, 🇮🇹 IT, 🇪🇸 ES, 🇵🇹 PT, 🇵🇱 PL, 🇨🇿 CZ, 🇭🇺 HU, 🇷🇴 RO, 🇧🇬 BG & Nordic 🇸🇪🇳🇴🇩🇰🇫🇮🇮🇸) using Regex.
  • 📝 Forensic-Ready Reporting: Generates a self-contained HTML Dashboard and JSON datasets for ingestion with third-party toolset.
  • ⚙️Compatibility: Tested on Windows Server 2016, 2019, 2022, and 2025 (Desktop Experience), en-US Locale.

🖼️ Dashboard Overview

🖼️ Findings per domain

🧩 Security Checks & Framework Mappings

🚨 High-Impact Checks (Weight: 20 pts)

Failure in these areas represents an immediate compromise risk (e.g., Ransomware, Data Breach, Man-in-the-Middle).

📖 Full Documentation: For a complete list of all 30+ checks, weights, and technical details, please consult the Detailed Checks & Scoring Documentation.

🔐 Integrity Verification

Current Version (1.0.1) Hash (SHA-256):

6BCD6B9B821DC997A19F78D7B545EFFCCEACBEA9F66883BE4F47C716EDB3559D

Verify via PowerShell:

root@kitploit:~

(Get-FileHash .\ServerSecurityAudit.ps1 -Algorithm SHA256).Hash -eq "6BCD6B9B821DC997A19F78D7B545EFFCCEACBEA9F66883BE4F47C716EDB3559D"


Author: Konstantinos Xanthopoulos, Founder & Principal Consultant @ Cyb3rint3l Labs

Download Tool
#Check NameSecurity Impact / RationaleCompliance Mapping
01OS Patching & Update SourceContinuous Vulnerability ManagementCIS Control 7 (IG1)
02RDP & NLA StatusRansomware Entry VectorMITRE T1133
03Credential Guard & LSAOS Credential Dumping ProtectionMITRE T1003
04Saved UNC Paths & VaultLateral Movement RiskMITRE T1552
05Auth & Kerberos HardeningNTLM Relay / Kerberoasting PreventionMITRE T1557/T1558
06Firewall State & LoggingSecure Network ConfigurationCIS Control 4 (IG1)
07SMB Protocol SecurityExploitation of Remote ServicesMITRE T1210
08LLMNR & mDNS StatusMan-in-the-Middle / ResponderMITRE T1557
09WPAD StatusTraffic Interception PreventionMITRE T1557
10Endpoint ProtectionMalware Defenses (AV/EDR)CIS Control 10 (IG1)
11Print Spooler ServicePrivilege Escalation (PrintNightmare)MITRE T1068
12Plaintext Password FilesUnsecured Credentials DiscoveryMITRE T1552
13Drive Encryption (BitLocker)Data Protection at RestCIS Control 3 (IG1)
14Local Admin GroupLeast Privilege EnforcementCIS Control 5 (IG1)
15Forensic Audit & LoggingDefense Evasion DetectionMITRE T1562
16VSS Writers StatusData Recovery & Ransomware ResilienceCIS Control 11 (IG1)