CyberArk Security Audit
A comprehensive PowerShell-based security assessment tool for CyberArk Privileged Access Management (PAM) platforms. Designed for offensive security professionals, red teamers, and penetration testers.
This tool is designed to run REMOTELY against CyberArk servers via network. It does NOT need to be executed on the CyberArk servers themselves. All checks are performed over the network using PVWA API, port scanning, and web testing.
This tool performs security checks including CIS Benchmark compliance, vendor best practices, blackbox testing, network security analysis, CVE-specific vulnerability checks (including 2025 CVEs), machine identity security, secrets management, zero standing privileges (ZSP) assessment, identity governance, and enhanced security checks.
| Feature | Description |
|---|---|
| Remote Auditing | All checks performed remotely via network - no need to install on CyberArk servers |
| OPSEC Mode | Stealth scanning with configurable delays, jitter, and reduced detection footprint |
| Proxy Support | Route all traffic through Burp Suite, ZAP, or other intercepting proxies |
| Timing Attacks | Detect user enumeration and blind injection via response timing analysis |
| JWT Security | Test for none algorithm bypass, key confusion, weak signing algorithms |
| WebSocket Testing | Discover real-time endpoints and test for Cross-Site WebSocket Hijacking |
| WAF Evasion | Test encoding bypasses, HTTP Parameter Pollution, request smuggling |
| User-Agent Rotation | Randomized or custom User-Agent strings to evade fingerprinting |
| Parallel Execution | Optional parallel execution for faster scans |
| Quiet Mode | Reduced console output for automation and scripting |
| Credential Security | Secure handling with memory cleanup after use |
| Comprehensive Reporting | HTML dashboard, 7 CSV files, and structured JSON for programmatic use |
| PoC Evidence | Request/Response proof-of-concept included in HTML report for penetration testing |
| Selective Execution | Run only specific check categories (portscan, CVE, blackbox, authenticated, network) |
| False Positive Reduction | Baseline fingerprinting to eliminate SPA catch-all false positives |
| Identity Auth Testing | StartAuthentication/ForgotUsername info disclosure and enumeration checks |
| Requirement | Minimum | Recommended |
|---|---|---|
| PowerShell | 7.0 | 7.x (latest) |
| .NET Framework | 4.5 | 4.8+ |
| Operating System | Windows 10/Server 2016 | Windows 11/Server 2022 |
| Memory | 2 GB available | 4 GB available |
| Audit Phase | Access Required |
|---|---|
| Phase 1 (Unauthenticated) | Network access to PVWA (HTTPS/443) |
| Phase 2 (Authenticated) | CyberArk API credentials with Vault Admin or Auditor role |
This script is fully self-contained and uses only native PowerShell and .NET Framework capabilities. No additional tools or modules need to be installed.
The script leverages:
System.Net.Sockets.TcpClient, System.Net.Security.SslStream for network and TLS analysisInvoke-WebRequest, Invoke-RestMethod for HTTP/API testingSystem.Security.Cryptography.X509Certificates for certificate analysisOpen PowerShell and run:
$PSVersionTable.PSVersion
Ensure the Major version is 7 or higher. If not, download PowerShell 7.x.
Note: This script requires PowerShell 7.0 or later. Windows PowerShell 5.1 is not supported.
Option A: Clone the repository (recommended)
git clone https://github.com/Logisek/HuntCyberArk.git
cd HuntCyberArk
Option B: Download directly
# Download to current directory
Invoke-WebRequest -Uri "https://raw.githubusercontent.com/Logisek/HuntCyberArk/main/CyberArk-Security-Audit.ps1" -OutFile "CyberArk-Security-Audit.ps1"
If you encounter script execution errors, temporarily allow script execution:
# Check current policy
Get-ExecutionPolicy
# Set for current session only (recommended)
Set-ExecutionPolicy -ExecutionPolicy Bypass -Scope Process
# Or unblock the downloaded script
Unblock-File -Path .\CyberArk-Security-Audit.ps1
For proper TLS testing, ensure your PowerShell session supports TLS 1.2+:
# Enable TLS 1.2 (recommended to add to your profile)
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
Verify you can reach the PVWA server:
# Test basic connectivity
Test-NetConnection -ComputerName pvwa.domain.com -Port 443
# Test HTTPS endpoint
Invoke-WebRequest -Uri "https://pvwa.domain.com/PasswordVault/" -UseBasicParsing -TimeoutSec 10
PowerShell 7 provides improved performance and better TLS support:
# Windows (winget)
winget install Microsoft.PowerShell
# Windows (manual)
# Download from: https://github.com/PowerShell/PowerShell/releases
The audit runs in two phases, each with different authentication requirements:
External/blackbox testing that can be run without any credentials:
Use Case: Penetration testing, external security assessments, quick reconnaissance