
Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence, network telemetry, and hunts known campaign IOCs.
Enterprise-Grade Windows Security Posture & Threat-Hunting Assessment Tool
Developed by Amish Kumar — Security Researcher / Security Engineer
CVE-2026-50656
Windows Defender Security Auditor is a comprehensive, non-intrusive PowerShell-based security assessment tool designed for enterprise-wide deployment across Windows endpoints and servers. It performs deep inspection of Microsoft Defender configuration, OS security posture, credential security, persistence mechanisms, network activity, and known threat indicators — all in READ-ONLY mode.
Originally built to assess exposure related to CVE-2026-50656, the tool has evolved into a full-spectrum Windows security auditor suitable for SOC teams, security engineers, penetration testers, and system administrators.
[!IMPORTANT] This tool does not exploit any vulnerability. It reads and reports — nothing more.
| Platform | Version |
|---|---|
| Windows 10 | All supported builds |
| Windows 11 | All supported builds |
| Windows Server 2019 | Standard / Datacenter |
| Windows Server 2022 | Standard / Datacenter |
| Windows Server 2025 | Standard / Datacenter |
Requirements:
.txt file for enterprise collection| # | Module | Description |
|---|---|---|
| 01 | System Information | OS, build, machine role, domain status, TPM, BitLocker, uptime |
| 02 | Patch Status | Windows Update inventory, patch age analysis |
| 03 | Defender Status | Engine version, signatures, real-time protection, tamper protection, service health |
| 04 | Defender Configuration | Security feature toggles, cloud protection, PUA, controlled folder access |
| 05 | Defender Exclusions | Path, process, extension, and IP exclusion review |
| 06 | Attack Surface Reduction | ASR rule inventory with GUID-to-name mapping, enforcement state, missing critical rules |
| 07 | Threat History | Recent Defender detections within lookback period |
| 08 | Operational Events | Defender event log analysis for tampering, disabling, and suspicious activity |
| 09 | Process Ancestry | MsMpEng.exe parent-child validation |
| 10 | Process Hunt | Security-relevant processes with command-line capture, suspicious path detection |
| 11 | SYSTEM Privilege Hunt | Interpreter processes running as SYSTEM |
| 12 | Event 4688 | Process creation telemetry for threat hunting |
| 13 | Service Creation | Event 7045 analysis for new service installations |
| 14 | Scheduled Tasks | Active task inventory with suspicious action detection (encoded commands, remote URIs) |
| 15 | User Review | Local admins, all accounts, failed logons (4625), RDP sessions (4624 Type 10) |
| 16 | IOC Hunting | Known campaign artifacts (setup.mjs, bun-dl, etc.) |
| 17 | Hash Validation | SHA1 comparison against known malicious file hashes |
| 18 | Network Review | Enriched TCP connections, listening ports, DNS cache IOC correlation |
| 19 | Secure Boot / VBS | Secure Boot, Device Guard, VBS status |
| 20 | Registry Persistence | Run/RunOnce, Winlogon, IFEO hijacks, WMI event subscriptions |
| 21 | Credential Security | WDigest caching, LSA Protection (RunAsPPL), Credential Guard |
| 22 | PowerShell Security | Script Block Logging, Module Logging, Transcription, CLM, suspicious script blocks |
| 23 | Firewall | Profile status (Domain/Private/Public), default actions |
| 24 | SMB Security | SMBv1 status, signing requirements, non-default shares |
| 25 | Startup Persistence | Startup folders, System32 modifications, loaded drivers |
| 26 | Final Assessment | Severity summary, consolidated findings, ShieldBreak determination |
git clone https://github.com/eh-amish/Windows-Defender-Security-Auditor-CVE-2026-50656-.git
cd Windows-Defender-Security-Auditor(CVE-2026-50656)-
# Open PowerShell as Administrator, then:
Set-ExecutionPolicy -ExecutionPolicy Bypass -Scope Process
.\CVE-2026-50656_MsMpEng_Audit.ps1
The script will:
AMISH_SecurityAudit_<HOSTNAME>_<YYYYMMDD_HHmmss>.txt
powershell -ExecutionPolicy Bypass -File .\CVE-2026-50656_MsMpEng_Audit.ps1
PsExec.exe \\TARGET_HOST -s powershell -ExecutionPolicy Bypass -File "\\share\CVE-2026-50656_MsMpEng_Audit.ps1"
powershell.exe -ExecutionPolicy Bypass -File "\\FileServer\SecurityAudit\CVE-2026-50656_MsMpEng_Audit.ps1"
.txt files from each endpoint for centralized review$Hosts = @("SERVER01", "SERVER02", "WS-PC01", "WS-PC02")
$ScriptBlock = Get-Content .\CVE-2026-50656_MsMpEng_Audit.ps1 -Raw
foreach ($H in $Hosts) {
Invoke-Command -ComputerName $H -ScriptBlock ([scriptblock]::Create($ScriptBlock))
}
___ __ ___________ __ __
/ | / |/ / _/ __// / / /
/ /| | / /|_/ // / _\ \ / /_/ /
/ ___ |/ / / // / /__ \/ __ /
/_/ |_/_/ /_/___/____/_/ /_/
SECURITY RESEARCHER
========================================================================
AMISH SECURITY RESEARCH
========================================================================
WINDOWS SECURITY AUDITOR v2.0.0
======================================================================
MODULE 03 - MICROSOFT DEFENDER STATUS
======================================================================
Product Version : 4.18.26060.3008
Engine Version : 1.1.26060.3008
Real-Time Protection : True
Tamper Protection : True
Signature Age : 4.2 hours
[PASS] Defender Engine meets original CVE threshold.
Current : 1.1.26060.3008
Required : 1.1.26060.3008
======================================================================
FINDINGS SUMMARY
======================================================================