HardeningKitty and Windows Hardening Settings
-
Updated
Jul 21, 2026 - PowerShell
HardeningKitty and Windows Hardening Settings
🛡️ Security & Privacy Hardening Tool for Windows 11 25H2 — 630+ Settings, 7 Modules, BAVR Pattern.
A desktop/web app for security engineers and Active Directory administrators to load, browse, compare, audit, and baseline-check Group Policy Object (GPO) backups — without needing a domain controller.
Windows Server 安全基线巡检脚本,PowerShell 全自动检测账户策略、防火墙、审计日志、服务、补丁、共享、注册表等 15 大模块,输出工程师风 HTML 安全报告。
Windows 11 security hardening tool with STIG V2R9 & CIS Level 1-aligned baselines, privacy, debloat, networking, and gaming — Apply/Restore Default with restore-point safeguards.
Laravel Secure Baseline provides a fast, non-destructive scan to detect security misconfigurations in Laravel 10/11: env vars, session/cookie flags (Secure/HttpOnly/SameSite), permissive CORS, headers (HSTS, XFO, XCTO, Referrer-Policy, CSP suggestion), exposed debug routes, and version age. Runs locally/CI with ✅/
Active Directory multi-domain lab with PowerShell automation, OUs, GPOs, and DHCP/DNS configuration.
This Powershell Script compares your local Security Policies to the Microsoft Security Baseline.
Windows-Server-Homelab zur Härtung von Active Directory: Security Policies per GPMC/ADAC – starke Kennwortrichtlinien, Kontosperrung, User Rights Assignment und Fine-Grained Password Policies (FGPP). Inklusive kurzer Tests, Validierung mit gpresult/RSOP und klarer, reproduzierbarer Dokumentation.
DevSec Nginx Baseline - InSpec Profile (CIS Benchmark Controls Added)
M365 & Entra ID Security Baseline. Deployed Conditional Access, Intune device compliance, and Purview DLP; achieved 100% MFA enrollment and 98% device compliance, reducing incidents by 40%.
Public, audit-ready security baseline with hardware root of trust, signed evidence, and CI-validated controls.
Local Linux hardening snapshot audit for SSH, sysctl, and privileged-account checks.
This repository is focused on collecting, organizing, and maintaining security hardening guidelines, practices, and references for various environments. The objective is to provide a centralized knowledge base to improve system security, reduce attack surfaces, and follow best practices for cybersecurity.
Practical tweaks & hardening via curated registry edits
AWS Security baseline — multi-account guardrails, SCPs, and Security Hub via Terraform
Website for HardenLab
Reference Microsoft Intune deployment for Bumblebee — configuration profiles, policies and deployment guidance
Read-only Microsoft 365 and Entra ID identity baseline capture and drift detection in a single PowerShell script
Add a description, image, and links to the security-baseline topic page so that developers can more easily learn about it.
To associate your repository with the security-baseline topic, visit your repo's landing page and select "manage topics."