awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
HotCakeX avatar

HotCakeX/Harden-Windows-Security

0
View on GitHub↗
4,139 星标·303 分支·C#·mit·12 次浏览hotcakex.github.io↗

Harden Windows Security

Harden-Windows-Security is a security hardening tool and framework designed to reduce the attack surface of the Windows operating system through policy enforcement. It provides a collection of security presets and templates to implement official hardening standards across multiple devices.

The project distinguishes itself through a comprehensive execution control system, featuring a manager for Windows Application Control and a kernel protection suite. It implements strict trust models, including kernel-mode driver whitelisting, signed policy implementation on the EFI partition, and code integrity policy management to restrict untrusted software.

The capability surface extends to hardware-rooted boot validation, UEFI lockdown, and virtualization-based isolation for sensitive workloads. It also covers data protection via volume encryption, network security through domain filtering, and identity management including multi-factor unlock enforcement and credential isolation.

Automation is supported through headless execution modes and command-line interfaces for security task orchestration and policy edits.

Features

  • Windows Hardening - Implements a set of scripts and configurations to reduce the attack surface of the Windows operating system through policy enforcement.
  • Application Execution Controls - Manages application control settings to prevent the execution of unauthorized or malicious software.
  • Windows Security Hardening - Implements official security hardening methods and removes unnecessary features to protect Windows against advanced threats.
  • System Hardening - Provides a collection of security presets and templates for implementing official hardening standards across multiple Windows devices.
  • System Security Hardening - Applies official security configurations and removes unnecessary features to protect against advanced threats.

AI 搜索

探索更多 awesome 仓库

用简单的语言描述您的需求 —— AI 将根据相关性为您从数千个精选开源项目中进行排序。

Start searching with AI
  • Executable Blocking - Prevents unknown or untrusted executable files from launching to reduce the risk of malicious code.
  • Driver Blocklisting - Implements block rules for vulnerable kernel-mode and user-mode drivers to prevent loading insecure code.
  • Firmware Boot Interfaces - Implements hardware-rooted boot validation using UEFI secure variables to ensure only trusted code executes during startup.
  • Boot Validation - Uses UEFI secure variables and firmware checks to ensure only trusted code executes during the boot process.
  • Kernel Driver Whitelisting - Implements a whitelist-only policy for kernel-mode drivers to block unauthorized third-party drivers.
  • Secure Boot Loaders - Ensures the device boots using only software trusted by the original equipment manufacturer via cryptographic verification.
  • Vulnerable Driver Blocking - Removes trust from all kernel-mode drivers unless explicitly allowed to prevent driver-based attacks.
  • Application Control Management - Provides a utility for creating and deploying code integrity policies to restrict the execution of untrusted software and drivers.
  • File Integrity Verifiers - The product extracts code integrity hashes and examines signatures to verify the authenticity of executable files.
  • Credential Security - Isolates hashes and tickets in a secure partition to prevent credential theft attacks.
  • Security Policy Enforcers - Pushes application control and software blocking policies to devices in audit or enforced modes.
  • Kernel Code Integrity Protections - Ensures only trusted, signed code loads into critical system processes via a kernel-level security model.
  • Kernel Driver Whitelisting - Implements a strict trust model that blocks all kernel-mode drivers unless they are explicitly allowed.
  • Kernel Protection Suites - Provides a set of configurations for securing the boot process and blocking vulnerable drivers via UEFI and secure boot settings.
  • Activity-Based Policy Generation - Automatically generates application control policies by analyzing system execution logs for observed behavior.
  • Code Integrity Policies - Creates, edits, and validates code integrity policies to control which applications can run on a device.
  • Security Hardening Presets - Configures system protections using predefined templates or usage intents to match specific security needs.
  • Firmware-Based Policy Protection - Implements signed policy files on the EFI partition to protect policies from modification via secure boot.
  • Security Policy Management - Deploys security policies to workstations and verifies device compliance using calculated security scores.
  • Explicit Trust Models - Enforces a trust model where applications must be explicitly trusted before they are permitted to run.
  • Execution Policy Managers - Deploys and manages base and supplemental execution policies in both audit and enforced modes.
  • System Hardening - Implements official security configurations and removes unnecessary features to reduce the operating system attack surface.
  • Application Firewalls - The product links firewall policies to specific applications using administrator-defined tags.
  • Compliance And Policy - Verifies workstations against security policies and generates compliance scores based on current system settings.
  • Resolution Locking - The product integrates DNS clients with filtering platforms to allow only approved domain name resolutions.
  • Application Isolation Containers - The product uses containers to isolate applications and protect the platform from vulnerabilities in third-party libraries.
  • Background Security Services - Offloads high-privilege configuration tasks to a dedicated background system service to maintain security boundaries.
  • DMA Attack Protections - Blocks external peripherals from gaining unauthorized memory access to prevent DMA-based attacks.
  • Firmware Security Lockdowns - Requires physical access and credentials to disable security measures, preventing changes via registry or policy.
  • Memory Overwrite Lock Protections - Protects the memory overwrite lock setting via secure variables to guard against advanced memory attacks.
  • SMM Protections - Monitors the highest privilege level of the processor to prevent unauthorized access to system memory.
  • UEFI Configuration Protections - Requires a password to enter UEFI settings to prevent unauthorized hardware or firmware configuration changes.
  • Application Sandboxing - The product runs applications in a lightweight isolated desktop environment to prevent them from affecting the host.
  • Behavioral Threat Detection - The product analyzes the real-time behavior of applications to detect threats without relying on known signatures.
  • OS Exploit Mitigations - The product mitigates malware that uses exploits by applying protections to the operating system or specific applications.
  • Compliance Verification Tools - Provides automated assessment and reporting of a workstation's adherence to security hardening policies via a compliance score.
  • Credential-Linked Encryption - Links data encryption keys to user credentials to ensure data is only accessible upon sign-in.
  • Security Policy Synchronizations - Fetches predefined security standards and configuration policies from a remote management tenant for fleet deployment.
  • AI-Powered Threat Detection - The product uses cloud-based AI and machine learning to identify and block new malware rapidly.
  • Executable Dependency Isolations - The product implements sandboxing restrictions so that only the main executable can utilize its dependencies.
  • Just-in-Time Access - Requires explicit user approval when an application requests administrative privileges to prevent silent installation.
  • Malicious Domain Filtering - The product prevents applications from accessing internet domains known to host phishing scams and malicious content.
  • Multi-Factor Device Unlocking - Requires a combination of biometrics, PINs, and trusted signals to unlock the device.
  • Preboot Authentications - The product mandates a USB startup key and a PIN to authenticate the user before the operating system boots.
  • Web Content Filtering - The product blocks access to phishing websites and the download of malicious files via early warning systems.
  • Cloud Management Deployment - Enables uploading predefined hardening standards to cloud management tenants for fleet-wide device configuration.
  • Security Operations Automation - Triggers policy edits and file analysis via command-line interfaces or URI schemes to streamline repetitive security workflows.
  • Signed Privilege Elevation - Requires public key infrastructure signature validation before allowing an application to elevate its privileges.
  • Storage Encryption - Implements full-volume encryption to protect sensitive data on lost or stolen devices.
  • Trusted Execution Environments - The product creates a trusted execution environment in memory to isolate sensitive application data from the host.
  • Virtualization-Based Isolation - Creates secure memory partitions and lightweight environments to isolate sensitive workloads from the host operating system.
  • Ransomware Protection - Prevents malicious apps and ransomware from modifying data in critical system and user folders.
  • Hardware-Based Behavioral Analysis - The product analyzes CPU execution patterns using hardware-integrated technology to identify characteristic ransomware attacks.
  • Security Audit Logs - Maintains detailed logs of security processing actions to facilitate auditing and technical troubleshooting.
  • Security Lab Environments - Script for hardening Windows system configurations.
  • Star 历史

    hotcakex/harden-windows-security 的 Star 历史图表hotcakex/harden-windows-security 的 Star 历史图表

    常见问题解答

    hotcakex/harden-windows-security 是做什么的?

    Harden-Windows-Security is a security hardening tool and framework designed to reduce the attack surface of the Windows operating system through policy enforcement. It provides a collection of security presets and templates to implement official hardening standards across multiple devices.

    hotcakex/harden-windows-security 的主要功能有哪些?

    hotcakex/harden-windows-security 的主要功能包括:Windows Hardening, Application Execution Controls, Windows Security Hardening, System Hardening, System Security Hardening, Executable Blocking, Driver Blocklisting, Firmware Boot Interfaces。

    hotcakex/harden-windows-security 有哪些开源替代品?

    hotcakex/harden-windows-security 的开源替代品包括: drduh/os-x-security-and-privacy-guide — This project is a comprehensive security hardening and privacy management guide for macOS. It provides a set of… drduh/macos-security-and-privacy-guide — This project is a security hardening guide and privacy configuration manual for macOS. It provides a comprehensive set… crowdsecurity/crowdsec — CrowdSec is a collaborative, distributed security engine designed for threat detection and infrastructure protection.… google/santa — Santa is a binary authorization system for macOS designed to control and monitor which binaries can execute based on… evilsocket/opensnitch — Opensnitch is a host-based application firewall for Linux that monitors and intercepts outbound network connections in… open-policy-agent/opa — This project is a unified, cloud-native policy engine designed to decouple authorization and security logic from…

    Harden Windows Security 的开源替代方案

    相似的开源项目,按与 Harden Windows Security 的功能重合度排序。
    • drduh/os-x-security-and-privacy-guidedrduh 的头像

      drduh/OS-X-Security-and-Privacy-Guide

      22,444在 GitHub 上查看↗

      This project is a comprehensive security hardening and privacy management guide for macOS. It provides a set of instructions and checklists for reducing the system attack surface through manual configuration, policy enforcement, and a layered defense strategy. The guide emphasizes a system auditing framework, using binary analysis, system logs, and packet inspection to verify that security controls and application sandboxing are functioning as intended. It offers tool-agnostic recommendations, defining security goals while allowing users to select their own third-party software for implementa

      在 GitHub 上查看↗22,444
    • drduh/macos-security-and-privacy-guidedrduh 的头像

      drduh/macOS-Security-and-Privacy-Guide

      22,449在 GitHub 上查看↗

      This project is a security hardening guide and privacy configuration manual for macOS. It provides a comprehensive set of instructions for configuring system settings to improve privacy, reduce the attack surface, and implement a malware defense framework. The guide covers technical methods for validating software notarization, verifying application sandboxing, and auditing system activity. It distinguishes itself by providing detailed workflows for restricting high-risk features and applying advanced security configurations to protect the operating system. The documentation covers several k

      appledisk-encryptiondnscrypt-proxy
      在 GitHub 上查看↗22,449
    crowdsecurity/crowdseccrowdsecurity 的头像

    crowdsecurity/crowdsec

    12,574在 GitHub 上查看↗

    CrowdSec is a collaborative, distributed security engine designed for threat detection and infrastructure protection. It functions as an intrusion detection system that parses logs and network traffic to identify malicious patterns, utilizing a bucket-based threshold detection model to aggregate events and trigger alerts. The platform is built on a modular architecture that includes a centralized local API server for managing security signals and a relational database for persistent storage of remediation decisions. What distinguishes the project is its decoupled enforcement model, which offl

    Goattacks-preventiondetectionids
    在 GitHub 上查看↗12,574
  • google/santagoogle 的头像

    google/santa

    4,510在 GitHub 上查看↗

    Santa is a binary authorization system for macOS designed to control and monitor which binaries can execute based on defined trust rules. It functions as application whitelisting software that prevents unauthorized programs from running by verifying them against cryptographic hashes and signing certificates. The system provides execution monitoring by recording every binary launch event to create a visible software execution trail. It enables centralized audit logging to track successful and denied application launches across multiple devices, ensuring enterprise device compliance through syn

    Objective-C++
    在 GitHub 上查看↗4,510
  • 查看 Harden Windows Security 的所有 30 个替代方案→