awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descoperă cele mai bune repository-uri open source cu căutare AI.

ExploreazăCăutări recomandateAlternative open-sourceSoftware self-hostedBlogHartă site
ProiectServer MCPDespreCum realizăm clasamentulPresă
LegalConfidențialitateTermeni
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
0x6d69636b avatar

0x6d69636b/windows_hardening

0
View on GitHub↗
2,631 stele·329 fork-uri·PowerShell·MIT·8 vizualizări

Windows Hardening

Windows Hardening este un framework de automatizare bazat pe PowerShell conceput pentru evaluarea securității și gestionarea configurației în mediile Windows. Oferă o suită de utilitare administrative pentru a impune benchmark-uri de securitate standard din industrie, a audita conformitatea sistemului și a reduce suprafața totală de atac a mașinilor gazdă.

Proiectul se distinge prin oferirea de capabilități specializate pentru gestionarea configurației la nivel de întreprindere, inclusiv capacitatea de a transforma constatările de securitate în obiecte de politică de grup (GPO) implementabile. De asemenea, integrează gestionarea stării sistemului, permițând administratorilor să captureze și să exporte setările de registry și configurațiile sistemului în formate portabile pentru a asigura backup-uri fiabile și puncte de restaurare înainte de a aplica măsuri de hardening.

Dincolo de hardening-ul de bază, setul de instrumente acoperă o gamă largă de operațiuni de securitate, cum ar fi filtrarea traficului de rețea bazată pe host, eliminarea software-ului și a serviciilor de fundal inutile și monitorizarea activității la nivel de sistem. Facilitează o postură de securitate consistentă în mediile de rețea prin compararea stărilor curente ale sistemului față de linii de bază predefinite și generarea de rapoarte de conformitate acționabile pentru remediere.

Features

  • Windows Security Hardening - Enforces industry-standard security benchmarks and system configurations to reduce the attack surface of Windows host machines.
  • Windows Security Hardening - Applies industry-standard security benchmarks to Windows systems to reduce the attack surface and protect against unauthorized access.
  • Registry Policy Enforcements - Modifies system registry keys and security policies to enforce hardening benchmarks and reduce the attack surface.
  • PowerShell - Executes modular PowerShell scripts to perform system audits, apply security configurations, and manage background services.
  • GPO Transformation Utilities - Transforms security configuration findings into deployable group policy objects for centralized enterprise management.
  • System Configuration Backups - Captures and exports registry and system settings to create reliable restore points before applying security hardening.
  • Network Access Restrictions - Defines firewall rules to block unauthorized outbound connections and prevent malicious process migration.
  • Attack Surface Analysis - Minimizes potential entry points by removing unnecessary software and restricting network traffic.
  • Compliance Security Audits - Evaluates current system configurations against industry-standard security benchmarks and generates detailed compliance reports.
  • Security and Compliance - Provides a security assessment framework that evaluates operating system settings against hardening standards.
  • Network Traffic Filtering - Configures host-based firewall rules to restrict unauthorized outbound connections and mitigate malicious process communication.
  • System Configuration Auditing - Compares current system settings against predefined security baselines to identify compliance gaps and generate remediation reports.
  • System Configuration Snapshots - Captures system registry and configuration states into portable formats for reliable backups and restoration.
  • Backup and Recovery Utilities - Captures and restores system settings to ensure environment stability during security hardening and remediation processes.
  • Configuration Backups - Captures current system configurations into a portable format to ensure previous states can be restored easily.
  • Group Policy Management - Transforms security findings into deployable policies for centralized management across enterprise network environments.
  • Group-Wide Security Policy Configurations - Transforms security configuration findings into deployable policies to ensure consistent security settings across network machines.
  • Security Finding Converters - Transforms security finding lists into group policy objects to enable centralized management and consistent deployment.
  • Pre-installed App Removals - Removes pre-installed applications and unnecessary background services to minimize the system attack surface.
  • System Activity Monitoring - Tracks process activity and detects suspicious behavior by recording events across the operating system.

Istoric stele

Graficul istoricului de stele pentru 0x6d69636b/windows_hardeningGraficul istoricului de stele pentru 0x6d69636b/windows_hardening

Căutare AI

Explorează mai multe repository-uri excelente

Descrie ce ai nevoie în limbaj simplu — AI-ul sortează mii de proiecte open source selectate în funcție de relevanță.

Start searching with AI

Colecții curatoriate care includ Windows Hardening

Colecții selectate manual în care apare Windows Hardening.
  • Securizarea serverelor și instrumente de audit

Întrebări frecvente

Ce face 0x6d69636b/windows_hardening?

Windows Hardening este un framework de automatizare bazat pe PowerShell conceput pentru evaluarea securității și gestionarea configurației în mediile Windows. Oferă o suită de utilitare administrative pentru a impune benchmark-uri de securitate standard din industrie, a audita conformitatea sistemului și a reduce suprafața totală de atac a mașinilor gazdă.

Care sunt principalele funcționalități ale 0x6d69636b/windows_hardening?

Principalele funcționalități ale 0x6d69636b/windows_hardening sunt: Windows Security Hardening, Registry Policy Enforcements, PowerShell, GPO Transformation Utilities, System Configuration Backups, Network Access Restrictions, Attack Surface Analysis, Compliance Security Audits.

Care sunt câteva alternative open-source pentru 0x6d69636b/windows_hardening?

Alternativele open-source pentru 0x6d69636b/windows_hardening includ: builtbybel/privatezilla — Privatezilla is a Windows privacy hardening tool designed to audit security settings, remove pre-installed software,… itm4n/privesccheck — PrivescCheck is a PowerShell-based security auditing tool designed to scan Windows configurations for potential… the1812/malware-patch — Malware-Patch is a collection of administrative utilities and controllers designed to manage software permissions and… flick9000/winscript — Winscript is a modular configuration framework designed for the administration and hardening of Windows environments.… pentestmonkey/windows-privesc-check — Windows-privesc-check is an automated security auditing tool designed to identify misconfigurations and… hotcakex/harden-windows-security — Harden-Windows-Security is a security hardening tool and framework designed to reduce the attack surface of the…

Alternative open-source pentru Windows Hardening

Proiecte open-source similare, clasificate după numărul de funcționalități comune cu Windows Hardening.
  • builtbybel/privatezillaAvatar builtbybel

    builtbybel/privatezilla

    3,723Vezi pe GitHub↗

    Privatezilla is a Windows privacy hardening tool designed to audit security settings, remove pre-installed software, and block outbound telemetry data. It functions as an operating system security auditor and a telemetry blocker to restrict data transmission from third-party applications. The project provides automated utilities for removing built-in applications and cloud services. It employs firewall rules and host file restrictions to prevent unauthorized information collection and stop data transmission to external servers. The tool covers a broad range of system management capabilities,

    C#debloatpowershellprivacy
    Vezi pe GitHub↗3,723
  • itm4n/privesccheckAvatar itm4n

    itm4n/PrivescCheck

    3,860Vezi pe GitHub↗

    PrivescCheck is a PowerShell-based security auditing tool designed to scan Windows configurations for potential privilege escalation paths and local host vulnerabilities. It functions as a vulnerability assessment utility that analyzes system settings and registry configurations to identify weaknesses that could allow unauthorized administrative access. The tool automates internal security reconnaissance and post-exploitation data collection to gather environmental information. It serves as a security compliance reporter by exporting scan results into structured formats, including HTML, CSV,

    PowerShellpentest-toolpentestingprivilege-escalation
    Vezi pe GitHub↗3,860
  • the1812/malware-patchAvatar the1812

    the1812/Malware-Patch

    5,466Vezi pe GitHub↗

    Malware-Patch is a collection of administrative utilities and controllers designed to manage software permissions and prevent unauthorized privilege elevation within Windows system settings. It functions as a UAC policy configuration tool and administrative access controller that blocks specific software from gaining administrator privileges. The project employs a stateless permission management approach, meaning it enforces authorization blocks without requiring a persistent background service process. It achieves this by using digital signature filtering to match certificates of signed bina

    C#csharpmalware-protectionuac-authorization
    Vezi pe GitHub↗5,466
  • flick9000/winscriptAvatar flick9000

    flick9000/winscript

    2,535Vezi pe GitHub↗

    Winscript is a modular configuration framework designed for the administration and hardening of Windows environments. It utilizes script-based task orchestration to automate system setup, privacy enforcement, and performance tuning through direct interaction with system APIs and registry keys. The project distinguishes itself by providing a unified toolkit that combines OS deployment automation with bulk software provisioning. It generates unattended installation files to bypass hardware requirements and manual setup prompts, while simultaneously managing the silent installation of third-part

    CSSbloatwarecleanupdebloat
    Vezi pe GitHub↗2,535
  • Vezi toate cele 30 alternative pentru Windows Hardening→