awesome-repositories.com
Blog
MCP
awesome-repositories.com

Découvrez les meilleurs dépôts open-source grâce à notre recherche par IA.

ExplorerRecherches sélectionnéesAlternatives open sourceLogiciels auto-hébergésBlogPlan du site
ProjetÀ proposNotre méthodologiePresseServeur MCP
Mentions légalesConfidentialitéConditions d'utilisation
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
HotCakeX avatar

HotCakeX/Harden-Windows-Security

0
View on GitHub↗
4,139 stars·303 forks·C#·mit·9 vueshotcakex.github.io↗

Harden Windows Security

Harden-Windows-Security is a security hardening tool and framework designed to reduce the attack surface of the Windows operating system through policy enforcement. It provides a collection of security presets and templates to implement official hardening standards across multiple devices.

The project distinguishes itself through a comprehensive execution control system, featuring a manager for Windows Application Control and a kernel protection suite. It implements strict trust models, including kernel-mode driver whitelisting, signed policy implementation on the EFI partition, and code integrity policy management to restrict untrusted software.

The capability surface extends to hardware-rooted boot validation, UEFI lockdown, and virtualization-based isolation for sensitive workloads. It also covers data protection via volume encryption, network security through domain filtering, and identity management including multi-factor unlock enforcement and credential isolation.

Automation is supported through headless execution modes and command-line interfaces for security task orchestration and policy edits.

Features

  • Windows Hardening - Implements a set of scripts and configurations to reduce the attack surface of the Windows operating system through policy enforcement.
  • Application Execution Controls - Manages application control settings to prevent the execution of unauthorized or malicious software.
  • Windows Security Hardening - Implements official security hardening methods and removes unnecessary features to protect Windows against advanced threats.
  • System Hardening - Provides a collection of security presets and templates for implementing official hardening standards across multiple Windows devices.
  • System Security Hardening - Applies official security configurations and removes unnecessary features to protect against advanced threats.
  • Executable Blocking - Prevents unknown or untrusted executable files from launching to reduce the risk of malicious code.
  • Driver Blocklisting - Implements block rules for vulnerable kernel-mode and user-mode drivers to prevent loading insecure code.
  • Firmware Boot Interfaces - Implements hardware-rooted boot validation using UEFI secure variables to ensure only trusted code executes during startup.
  • Boot Validation - Uses UEFI secure variables and firmware checks to ensure only trusted code executes during the boot process.
  • Kernel Driver Whitelisting - Implements a whitelist-only policy for kernel-mode drivers to block unauthorized third-party drivers.
  • Secure Boot Loaders - Ensures the device boots using only software trusted by the original equipment manufacturer via cryptographic verification.
  • Vulnerable Driver Blocking - Removes trust from all kernel-mode drivers unless explicitly allowed to prevent driver-based attacks.
  • Application Control Management - Provides a utility for creating and deploying code integrity policies to restrict the execution of untrusted software and drivers.
  • File Integrity Verifiers - The product extracts code integrity hashes and examines signatures to verify the authenticity of executable files.
  • Credential Security - Isolates hashes and tickets in a secure partition to prevent credential theft attacks.
  • Security Policy Enforcers - Pushes application control and software blocking policies to devices in audit or enforced modes.
  • Kernel Code Integrity Protections - Ensures only trusted, signed code loads into critical system processes via a kernel-level security model.
  • Kernel Driver Whitelisting - Implements a strict trust model that blocks all kernel-mode drivers unless they are explicitly allowed.
  • Kernel Protection Suites - Provides a set of configurations for securing the boot process and blocking vulnerable drivers via UEFI and secure boot settings.
  • Activity-Based Policy Generation - Automatically generates application control policies by analyzing system execution logs for observed behavior.
  • Code Integrity Policies - Creates, edits, and validates code integrity policies to control which applications can run on a device.
  • Security Hardening Presets - Configures system protections using predefined templates or usage intents to match specific security needs.
  • Firmware-Based Policy Protection - Implements signed policy files on the EFI partition to protect policies from modification via secure boot.
  • Security Policy Management - Deploys security policies to workstations and verifies device compliance using calculated security scores.
  • Explicit Trust Models - Enforces a trust model where applications must be explicitly trusted before they are permitted to run.
  • Execution Policy Managers - Deploys and manages base and supplemental execution policies in both audit and enforced modes.
  • System Hardening - Implements official security configurations and removes unnecessary features to reduce the operating system attack surface.
  • Application Firewalls - The product links firewall policies to specific applications using administrator-defined tags.
  • Compliance And Policy - Verifies workstations against security policies and generates compliance scores based on current system settings.
  • Resolution Locking - The product integrates DNS clients with filtering platforms to allow only approved domain name resolutions.
  • Application Isolation Containers - The product uses containers to isolate applications and protect the platform from vulnerabilities in third-party libraries.
  • Background Security Services - Offloads high-privilege configuration tasks to a dedicated background system service to maintain security boundaries.
  • DMA Attack Protections - Blocks external peripherals from gaining unauthorized memory access to prevent DMA-based attacks.
  • Firmware Security Lockdowns - Requires physical access and credentials to disable security measures, preventing changes via registry or policy.
  • Memory Overwrite Lock Protections - Protects the memory overwrite lock setting via secure variables to guard against advanced memory attacks.
  • SMM Protections - Monitors the highest privilege level of the processor to prevent unauthorized access to system memory.
  • UEFI Configuration Protections - Requires a password to enter UEFI settings to prevent unauthorized hardware or firmware configuration changes.
  • Application Sandboxing - The product runs applications in a lightweight isolated desktop environment to prevent them from affecting the host.
  • Behavioral Threat Detection - The product analyzes the real-time behavior of applications to detect threats without relying on known signatures.
  • OS Exploit Mitigations - The product mitigates malware that uses exploits by applying protections to the operating system or specific applications.
  • Compliance Verification Tools - Provides automated assessment and reporting of a workstation's adherence to security hardening policies via a compliance score.
  • Credential-Linked Encryption - Links data encryption keys to user credentials to ensure data is only accessible upon sign-in.
  • Security Policy Synchronizations - Fetches predefined security standards and configuration policies from a remote management tenant for fleet deployment.
  • AI-Powered Threat Detection - The product uses cloud-based AI and machine learning to identify and block new malware rapidly.
  • Executable Dependency Isolations - The product implements sandboxing restrictions so that only the main executable can utilize its dependencies.
  • Just-in-Time Access - Requires explicit user approval when an application requests administrative privileges to prevent silent installation.
  • Malicious Domain Filtering - The product prevents applications from accessing internet domains known to host phishing scams and malicious content.
  • Multi-Factor Device Unlocking - Requires a combination of biometrics, PINs, and trusted signals to unlock the device.
  • Preboot Authentications - The product mandates a USB startup key and a PIN to authenticate the user before the operating system boots.
  • Web Content Filtering - The product blocks access to phishing websites and the download of malicious files via early warning systems.
  • Cloud Management Deployment - Enables uploading predefined hardening standards to cloud management tenants for fleet-wide device configuration.
  • Security Operations Automation - Triggers policy edits and file analysis via command-line interfaces or URI schemes to streamline repetitive security workflows.
  • Signed Privilege Elevation - Requires public key infrastructure signature validation before allowing an application to elevate its privileges.
  • Storage Encryption - Implements full-volume encryption to protect sensitive data on lost or stolen devices.
  • Trusted Execution Environments - The product creates a trusted execution environment in memory to isolate sensitive application data from the host.
  • Virtualization-Based Isolation - Creates secure memory partitions and lightweight environments to isolate sensitive workloads from the host operating system.
  • Ransomware Protection - Prevents malicious apps and ransomware from modifying data in critical system and user folders.
  • Hardware-Based Behavioral Analysis - The product analyzes CPU execution patterns using hardware-integrated technology to identify characteristic ransomware attacks.
  • Security Audit Logs - Maintains detailed logs of security processing actions to facilitate auditing and technical troubleshooting.
  • Security Lab Environments - Script for hardening Windows system configurations.

Historique des stars

Graphique de l'historique des stars pour hotcakex/harden-windows-securityGraphique de l'historique des stars pour hotcakex/harden-windows-security

Recherche par IA

Explorez plus de dépôts awesome

Décrivez vos besoins en langage naturel — l'IA classe des milliers de projets open source sélectionnés par pertinence.

Start searching with AI

Alternatives open source à Harden Windows Security

Projets open source similaires, classés selon le nombre de fonctionnalités partagées avec Harden Windows Security.
  • drduh/os-x-security-and-privacy-guideAvatar de drduh

    drduh/OS-X-Security-and-Privacy-Guide

    22,444Voir sur GitHub↗

    This project is a comprehensive security hardening and privacy management guide for macOS. It provides a set of instructions and checklists for reducing the system attack surface through manual configuration, policy enforcement, and a layered defense strategy. The guide emphasizes a system auditing framework, using binary analysis, system logs, and packet inspection to verify that security controls and application sandboxing are functioning as intended. It offers tool-agnostic recommendations, defining security goals while allowing users to select their own third-party software for implementa

    Voir sur GitHub↗22,444
  • drduh/macos-security-and-privacy-guideAvatar de drduh

    drduh/macOS-Security-and-Privacy-Guide

    22,449Voir sur GitHub↗

    This project is a security hardening guide and privacy configuration manual for macOS. It provides a comprehensive set of instructions for configuring system settings to improve privacy, reduce the attack surface, and implement a malware defense framework. The guide covers technical methods for validating software notarization, verifying application sandboxing, and auditing system activity. It distinguishes itself by providing detailed workflows for restricting high-risk features and applying advanced security configurations to protect the operating system. The documentation covers several k

    appledisk-encryptiondnscrypt-proxy
    Voir sur GitHub↗22,449
  • crowdsecurity/crowdsecAvatar de crowdsecurity

    crowdsecurity/crowdsec

    12,574Voir sur GitHub↗

    CrowdSec is a collaborative, distributed security engine designed for threat detection and infrastructure protection. It functions as an intrusion detection system that parses logs and network traffic to identify malicious patterns, utilizing a bucket-based threshold detection model to aggregate events and trigger alerts. The platform is built on a modular architecture that includes a centralized local API server for managing security signals and a relational database for persistent storage of remediation decisions. What distinguishes the project is its decoupled enforcement model, which offl

    Goattacks-preventiondetectionids
    Voir sur GitHub↗12,574
  • google/santaAvatar de google

    google/santa

    4,510Voir sur GitHub↗

    Santa is a binary authorization system for macOS designed to control and monitor which binaries can execute based on defined trust rules. It functions as application whitelisting software that prevents unauthorized programs from running by verifying them against cryptographic hashes and signing certificates. The system provides execution monitoring by recording every binary launch event to create a visible software execution trail. It enables centralized audit logging to track successful and denied application launches across multiple devices, ensuring enterprise device compliance through syn

    Objective-C++
    Voir sur GitHub↗4,510
Voir les 30 alternatives à Harden Windows Security→

Questions fréquentes

Que fait hotcakex/harden-windows-security ?

Harden-Windows-Security is a security hardening tool and framework designed to reduce the attack surface of the Windows operating system through policy enforcement. It provides a collection of security presets and templates to implement official hardening standards across multiple devices.

Quelles sont les fonctionnalités principales de hotcakex/harden-windows-security ?

Les fonctionnalités principales de hotcakex/harden-windows-security sont : Windows Hardening, Application Execution Controls, Windows Security Hardening, System Hardening, System Security Hardening, Executable Blocking, Driver Blocklisting, Firmware Boot Interfaces.

Quelles sont les alternatives open-source à hotcakex/harden-windows-security ?

Les alternatives open-source à hotcakex/harden-windows-security incluent : drduh/os-x-security-and-privacy-guide — This project is a comprehensive security hardening and privacy management guide for macOS. It provides a set of… drduh/macos-security-and-privacy-guide — This project is a security hardening guide and privacy configuration manual for macOS. It provides a comprehensive set… crowdsecurity/crowdsec — CrowdSec is a collaborative, distributed security engine designed for threat detection and infrastructure protection.… google/santa — Santa is a binary authorization system for macOS designed to control and monitor which binaries can execute based on… evilsocket/opensnitch — Opensnitch is a host-based application firewall for Linux that monitors and intercepts outbound network connections in… open-policy-agent/opa — This project is a unified, cloud-native policy engine designed to decouple authorization and security logic from…