
EnableWindowsLogSettings
Documentation and scripts to properly enable Windows event logs.

Documentation and scripts to properly enable Windows event logs.

PowerShell scripts to automatically create rules for Windows firewall

An open-source, single-script CVE scanner for RMM-managed fleets. Pure PowerShell 7 — joins your RMM software inventory against NVD, CISA KEV, EPSS…

An Active Defense and EDR software to empower Blue Teams

Open-source platform to secure and manage endpoints via MDM, patch management, software deployment, and osquery-powered visibility with compliance…

PowerShell toolkit to audit, harden, and hunt for insecure NTLM/SMB usage, addressing CVE-2025-50154 credential leak risks with event log analysis…

A BOF to determine Windows Defender exclusions.

Audits Windows event log settings against best-practice guidelines and Sigma-rule detectability, with automated configuration for DFIR readiness.

This repository contains a script that you can run on your (windows) machine to mitigate CVE-2021-44228

This script checks for Administrator privileges and then sets the necessary DWord values in the Windows registry to enable the hardware-level…

PowerShell script to check Windows hotfix status for CVE-2020-0601 and detect exploitation attempts. Includes XML import for ControlUp Script-Based…

Script to update Windows Recovery Environment to patch against CVE-2022-41099

PowerShell script to apply Windows registry mitigation for CVE-2018-3639 (Speculative Store Bypass), enabling automated security hardening against…

Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.

Monitors Windows Security logs for failed RDP attempts and automatically blocks abusive IPs via Windows Firewall, with configurable thresholds and…

Guide and automated PowerShell scripts to resolve CVE-2024-20666 patch failures in Windows Recovery Environment by resizing recovery partitions and…

To fight against Windows security breach PrintNightmare! (CVE-2021-34527, CVE-2021-1675)

Zabbix Template to monitor for Windows Event Viewer event's related to Netlogon Elevation of Privilege Vulnerability - CVE-2020-1472. Monitors event…