Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ClientInspectorV2 — Azure-based client inventory and drift detection tool that collects Windows configuration data (antivirus, patching, Bitlocker) into LogAnalytics for KQL-driven dashboards and Sentinel alerting. | Kitploit
Tools/GitHubGitHub/knudsenmorten/clientinspectorv2
Defensive ToolsConfiguration AuditingCloud SecurityIncident ResponseLog Analysis
GitHubknudsenmorten/clientinspectorv2

ClientInspectorV2

Azure-based client inventory and drift detection tool that collects Windows configuration data (antivirus, patching, Bitlocker) into LogAnalytics for KQL-driven dashboards and Sentinel alerting.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
275603 years agoReviewed by Kitploit

Introduction to ClientInspector (v2)

ClientInspector

Are you in control? - or are some of your core infrastructure processes like patching, antivirus, bitlocker enablement drifting? Or would you like to do advanced inventory, where you can lookup your warranty state against Lenovo or Dell warranty, then keep reading.

Check out ClientInspector, which can help you get great insight to your complete client environment.

ClientInspector is free to the community - built to be a cool showcase of how you can bring back data from your clients using Azure Log Ingestion Pipeline, Azure Data Collection Rules, Azure LogAnalytics; view them with Azure Monitor & Azure Dashboards - and get "drift-alerts" using Microsoft Sentinel.

Video 3m 01s - Dashboards

Archicture & flow of ClientInspector

ClientInspector (v2) is uploading the collected data into custom logs in Azure LogAnalytics workspace - using Log ingestion API, Azure Data Collection Rules (DCR) and Azure Data Collection Endpoints (DCE).

Archicture

Sample Dashboards

KPIs

Antivirus

Bluescreens

Disclaimer

It is important for me to state that I'm not trying to build a separate management tool, which will compete with Microsoft security and management stack.

Nothing beats Microsoft Azure/M365 management and security stack. They are rock star solutions.

But I'm really passioned about the logging capabilities and the power to bring data back from clients, servers, cloud and 3rd party systems - and getting cool valueable information out of the data.

I have a similar solution for servers - ServerInspector. Unfortunately, it is not public.

Big Thanks to the great people in Microsoft product teams - you are rock stars 😄

Happy hunting 😄


Quick Links

What data is being collected ?
Desired State Dashboards - How to get insight of my environment from the data ?
How do I query the data? - Kusto (KQL) is the answer
Architecture, Schema & Networking
Implementation
Dependencies
Running ClientInspector.ps1 - 3 modes
Sample output of ClientInspector
Security
Layout of ClientInspector data-set
Verbose-mode & More help
Cost - How much does it cost to store these data ? Bug findings, please inform me
Contact

Videos of solution

Video 3m 19s - Running ClientInspector using commandline (normal mode)
Video 1m 40s - Automatic creation of 2 tables & DCRs (verbose mode)
Video 1m 37s - Automatic creation of 2 tables & DCRs (normal mode)
Video 1m 34s - See schema of DCR and table)
Video 2m 19s - Data manipulation
Video 1m 58s - Kusto queries against data
Video 3m 01s - Dashboards
Video 0m 48s - Sample usage of data - lookup against Lenovo warranty db
Video 7m 25s - Deployment via ClientInspector DeploymentKit


What data is being collected ?

ClientInspector can be used to collect lots of great information of from your Windows clients - and send the data to Azure LogAnalytics Custom Tables.

The script collects the following information (settings, information, configuration, state):

  1. User Logged On to Client
  2. Computer information - bios, processor, hardware info, Windows OS info, OS information, last restart
  3. Installed applications, both using WMI and registry
  4. Antivirus Security Center from Windows - default antivirus, state, configuration
  5. Microsoft Defender Antivirus - all settings including ASR, exclusions, realtime protection, etc
  6. Office - version, update channel config, SKUs
  7. VPN client - version, product
  8. LAPS - version
  9. Admin By Request (3rd party) - version
  10. Windows Update - last result (when), windows update source information (where), pending updates, last installations (what)
  11. Bitlocker - configuration
  12. Eventlog - look for specific events including logon events, blue screens, etc.
  13. Network adapters - configuration, installed adapters
  14. IP information for all adapters
  15. Local administrators group membership
  16. Windows firewall - settings for all 3 modes
  17. Group Policy - last refresh
  18. TPM information - relavant to detect machines with/without TPM

Feel free to add more cool data-collections to suit your needs. If you want to take part in the community, please send me an email with your collections, if you think they can be of benefit of the whole community.


Source data - what data can I use ?

You can use any source data which can be retrieved into Powershell (wmi, cim, external data, rest api, xml-format, json-format, csv-format, etc.)

It is very important to understand, that the data typically needs to be manipulated before sending them - to ensure they are valid and any irrelevant data has been removed.

ClientInspector uses all of the 24 functions within the Powershell module, AzLogDcIngestPS, to handle source data manipulation to remove "noice" in data, to rename prohibited colums in tables/DCR - and support needs for transparency with extra insight like UserLoggedOn, CollectionTime, Computer:

Examples of how to use functions Convert-CimArrayToObjectFixStructure, Add-CollectionTimeToAllEntriesInArray, Add-ColumnDataToAllEntriesInArray, ValidateFix-AzLogAnalyticsTableSchemaColumnNames, Build-DataArrayToAlignWithSchema, Filter-ObjectExcludeProperty
#-------------------------------------------------------------------------------------------
# Collecting data (in)
#-------------------------------------------------------------------------------------------
	
Write-Output ""
Write-Output "Collecting Bios information ... Please Wait !"

$DataVariable = Get-CimInstance -ClassName Win32_BIOS

#-------------------------------------------------------------------------------------------
# Preparing data structure
#-------------------------------------------------------------------------------------------

# convert CIM array to PSCustomObject and remove CIM class information
$DataVariable = Convert-CimArrayToObjectFixStructure -data $DataVariable -Verbose:$Verbose

# add CollectionTime to existing array
$DataVariable = Add-CollectionTimeToAllEntriesInArray -Data $DataVariable -Verbose:$Verbose
Download Tool