A PowerShell security audit tool for Windows 10 and 11.
Win-Audit checks common Windows security settings, reports anything worth reviewing, and can optionally apply a limited set of remediation steps.
The audit itself is read-only.
Win-Audit currently covers more than 50 checks across areas including:
- Secure Boot and TPM
- BitLocker
- Microsoft Defender
- Windows Firewall
- local accounts and password policy
- UAC
- SMB and RDP
- VBS, HVCI and Credential Guard
- exploit mitigations
- services and scheduled tasks
- listening ports
- event log configuration
- selected Active Directory, IIS and SQL Server checks when present
Each finding includes a severity and a stable finding ID.
The script also calculates a simple hardening score to make repeated scans easier to compare.
- Windows 10 or Windows 11
- PowerShell 5.1 or newer
- Administrator access for checks that require elevated privileges
PowerShell 7 is supported but not required.
Run a full audit:
.\Win-Audit.ps1Run a quicker scan:
.\Win-Audit.ps1 -FastOnly print the summary:
.\Win-Audit.ps1 -SummarySuppress console output and only write reports:
.\Win-Audit.ps1 -QuietWrite reports to another directory:
.\Win-Audit.ps1 -OutputDir C:\ReportsIf PowerShell blocks the script:
powershell -ExecutionPolicy Bypass -File .\Win-Audit.ps1A normal run can generate:
| File | Purpose |
|---|---|
Win-Audit-Report.html |
Human-readable HTML report |
Win-Audit-Report.json |
Machine-readable report used by the remediation script |
Win-Audit-Report.md |
Markdown summary |
Win-Audit-Report.txt |
Plain-text report |
Win-Audit-Remediation.txt |
Suggested remediation steps |
Reports can contain information about the scanned machine, including hostnames, accounts and listening ports.
Do not commit your own scan results to a public repository.
Invoke-WinAuditRemediation.ps1 can apply fixes for a subset of findings.
See what can be changed:
.\Invoke-WinAuditRemediation.ps1 -ListOnlyPreview low-risk fixes:
.\Invoke-WinAuditRemediation.ps1 -FixSafeOnly -WhatIfApply them:
.\Invoke-WinAuditRemediation.ps1 -FixSafeOnlyHigher-impact fixes require confirmation:
.\Invoke-WinAuditRemediation.ps1 -FixConfirmFirstNot every finding has an automatic fix. Anything without a reviewed remediation action is left for manual review.
[+] Disk Encryption (BitLocker)
[OK ] C: BitLocker FullyEncrypted, Protection On
[+] Memory Integrity & Virtualization Security
[OK ] HVCI (Memory Integrity) Running
[OK ] Virtualization-Based Security Running
=================================================
Hardening Index: 94 / 100
Duration: 32 seconds
OK Findings: 105
Suggestions: 13
Warnings: 0
=================================================
Win-Audit is a general-purpose security inspection tool, not a compliance scanner.
Some checks are inspired by Lynis and CIS guidance, but the project is not affiliated with CIS and is not a replacement for CIS-CAT or an official benchmark assessment.
Some results depend on the machine's role and configuration. For example, Microsoft Defender may legitimately be disabled when another antivirus product is active.
Review important findings against the relevant Microsoft or vendor documentation before making changes.
The current version has primarily been tested on Windows 11 Pro. Other Windows editions and configurations may behave differently.
Win-Audit.ps1
Main audit script
Invoke-WinAuditRemediation.ps1
Optional remediation tool
CHANGELOG.md
Release history
CONTRIBUTING.md
Contribution notes
Bug reports and fixes are welcome, particularly for checks that behave differently across Windows editions or configurations.
See CONTRIBUTING.md.
MIT. See LICENSE.