Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Windows-Defender-Security-Auditor-CVE-2026-50656- — Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence, network telemetry, and hunts known campaign IOCs. | Kitploit
Tools/GitHubGitHub/eh-amish/windows-defender-security-auditor-cve-2026-50656-
Defensive ToolsIndicator of Compromise (IOC) ManagementPersistence MechanismsVulnerability AnalysisConfiguration AuditingInformation GatheringNetwork SecurityThreat Intelligence

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Misconfiguration
Incident Response
Log Analysis
GitHubeh-amish/windows-defender-security-auditor-cve-2026-50656-

Windows-Defender-Security-Auditor-CVE-2026-50656-

Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence, network telemetry, and hunts known campaign IOCs.

View Repository
201 month agoNot yet reviewed
Share

Windows Defender Security Auditor

Enterprise-Grade Windows Security Posture & Threat-Hunting Assessment Tool

Developed by Amish Kumar — Security Researcher / Security Engineer


CVE-2026-50656


Overview

Windows Defender Security Auditor is a comprehensive, non-intrusive PowerShell-based security assessment tool designed for enterprise-wide deployment across Windows endpoints and servers. It performs deep inspection of Microsoft Defender configuration, OS security posture, credential security, persistence mechanisms, network activity, and known threat indicators — all in READ-ONLY mode.

Originally built to assess exposure related to CVE-2026-50656, the tool has evolved into a full-spectrum Windows security auditor suitable for SOC teams, security engineers, penetration testers, and system administrators.

[!IMPORTANT] This tool does not exploit any vulnerability. It reads and reports — nothing more.


Supported Platforms

PlatformVersion
Windows 10All supported builds
Windows 11All supported builds
Windows Server 2019Standard / Datacenter
Windows Server 2022Standard / Datacenter
Windows Server 2025Standard / Datacenter

Requirements:

  • PowerShell 5.1 or later
  • Administrator privileges (recommended for full assessment)
  • No third-party dependencies — uses built-in Windows cmdlets only

Key Features

  • 26 Security Assessment Modules covering every critical attack surface
  • Auto-detects machine role — Workstation, Server, or Domain Controller
  • Color-coded severity output — CRITICAL (Red), HIGH (Orange), MEDIUM (Yellow), INFO (Cyan), PASS (Green)
  • Auto-exports results to a timestamped .txt file for enterprise collection
  • Severity-based findings summary with total counts
  • Zero dependencies — runs on any Windows machine with PowerShell 5.1+
  • 100% READ-ONLY — no system modifications of any kind

Security Assessment Modules

#ModuleDescription
01System InformationOS, build, machine role, domain status, TPM, BitLocker, uptime
02Patch StatusWindows Update inventory, patch age analysis
03Defender StatusEngine version, signatures, real-time protection, tamper protection, service health
04Defender ConfigurationSecurity feature toggles, cloud protection, PUA, controlled folder access
05Defender ExclusionsPath, process, extension, and IP exclusion review
06Attack Surface ReductionASR rule inventory with GUID-to-name mapping, enforcement state, missing critical rules
07Threat HistoryRecent Defender detections within lookback period
08Operational EventsDefender event log analysis for tampering, disabling, and suspicious activity
09Process AncestryMsMpEng.exe parent-child validation
10Process HuntSecurity-relevant processes with command-line capture, suspicious path detection
11SYSTEM Privilege HuntInterpreter processes running as SYSTEM
12Event 4688Process creation telemetry for threat hunting
13Service CreationEvent 7045 analysis for new service installations
14Scheduled TasksActive task inventory with suspicious action detection (encoded commands, remote URIs)
15User ReviewLocal admins, all accounts, failed logons (4625), RDP sessions (4624 Type 10)
16IOC HuntingKnown campaign artifacts (setup.mjs, bun-dl, etc.)
17Hash ValidationSHA1 comparison against known malicious file hashes
18Network ReviewEnriched TCP connections, listening ports, DNS cache IOC correlation
19Secure Boot / VBSSecure Boot, Device Guard, VBS status
20Registry PersistenceRun/RunOnce, Winlogon, IFEO hijacks, WMI event subscriptions
21Credential SecurityWDigest caching, LSA Protection (RunAsPPL), Credential Guard
22PowerShell SecurityScript Block Logging, Module Logging, Transcription, CLM, suspicious script blocks
23FirewallProfile status (Domain/Private/Public), default actions
24SMB SecuritySMBv1 status, signing requirements, non-default shares
25Startup PersistenceStartup folders, System32 modifications, loaded drivers
26Final AssessmentSeverity summary, consolidated findings, ShieldBreak determination

Quick Start

1. Download

git clone https://github.com/eh-amish/Windows-Defender-Security-Auditor-CVE-2026-50656-.git
cd Windows-Defender-Security-Auditor(CVE-2026-50656)-

2. Run (Administrator Recommended)

# Open PowerShell as Administrator, then:
Set-ExecutionPolicy -ExecutionPolicy Bypass -Scope Process
.\CVE-2026-50656_MsMpEng_Audit.ps1

3. Review Results

The script will:

  • Display color-coded findings in the terminal
  • Auto-save a full report to the same directory:
    AMISH_SecurityAudit_<HOSTNAME>_<YYYYMMDD_HHmmss>.txt
    

Usage Examples

Single Workstation Assessment

powershell -ExecutionPolicy Bypass -File .\CVE-2026-50656_MsMpEng_Audit.ps1

Remote Execution via PsExec

PsExec.exe \\TARGET_HOST -s powershell -ExecutionPolicy Bypass -File "\\share\CVE-2026-50656_MsMpEng_Audit.ps1"

Enterprise Deployment via GPO / SCCM / Intune

  1. Place the script on a network share accessible to all endpoints
  2. Create a scheduled task or GPO startup script:
    powershell.exe -ExecutionPolicy Bypass -File "\\FileServer\SecurityAudit\CVE-2026-50656_MsMpEng_Audit.ps1"
    
  3. Collect the output .txt files from each endpoint for centralized review

PowerShell Remoting (Multiple Hosts)

$Hosts = @("SERVER01", "SERVER02", "WS-PC01", "WS-PC02")
$ScriptBlock = Get-Content .\CVE-2026-50656_MsMpEng_Audit.ps1 -Raw

foreach ($H in $Hosts) {
    Invoke-Command -ComputerName $H -ScriptBlock ([scriptblock]::Create($ScriptBlock))
}

Sample Output

    ___    __  ___________ __  __
   /   |  /  |/  /  _/ __// / / /
  / /| | / /|_/ // / _\ \ / /_/ /
 / ___ |/ /  / // / /__ \/ __  /
/_/  |_/_/  /_/___/____/_/ /_/

        SECURITY RESEARCHER

========================================================================
                    AMISH SECURITY RESEARCH
========================================================================

               WINDOWS SECURITY AUDITOR v2.0.0

======================================================================
 MODULE 03 - MICROSOFT DEFENDER STATUS
======================================================================
 Product Version                      : 4.18.26060.3008
 Engine Version                       : 1.1.26060.3008
 Real-Time Protection                 : True
 Tamper Protection                    : True
 Signature Age                        : 4.2 hours

[PASS] Defender Engine meets original CVE threshold.
       Current  : 1.1.26060.3008
       Required : 1.1.26060.3008

======================================================================
 FINDINGS SUMMARY
======================================================================
Download Tool