Beta  •  WinSecMon is currently under active testing. Builds are pre-release and provided for evaluation.
Public Beta · v3.0.0

Windows security posture, assessed in minutes.

WinSecMon is a read-only, agentless assessment engine that inspects a Windows host against 244 checks across 20 security domains — from Active Directory and ADCS to attack paths, accounts, and host exposure — and produces forensic-grade, tamper-evident reports.

Read-only & non-intrusive Agentless — nothing installed PowerShell 5.1+ / Win 10 & Server 2016+
244
Security checks
20
Coverage domains
100%
Read-only
0
Agents to install
Coverage

Built for real Windows estates

One pass surfaces the misconfigurations and attack paths that matter — mapped to the techniques adversaries actually use.

Active Directory

Privileged group hygiene, delegation, Kerberos weaknesses, AdminSDHolder and domain-head ACLs.

Certificate Services (ADCS)

ESC1–ESC11 template and enrollment misconfigurations, including HTTP web-enrollment relay (ESC8).

Attack paths

DCSync rights, dangerous ACLs and privilege-escalation chains toward tier-0 assets.

Accounts & policy

Password policy, stale and non-expiring accounts, LAPS, audit policy and account hardening.

Host exposure

Exposed services, legacy protocols (SMBv1, PSv2), firewall posture and remote-access surface.

Forensic evidence

Every report ships with a SHA-256 evidence manifest and tamper-evident integrity verification.

The report

An executive briefing, not a wall of text

Every scan produces a self-contained, interactive HTML report — a risk score, maturity rating and live charts up top, then evidence-backed findings mapped to MITRE ATT&CK, CIS and ANSSI below. Here’s the executive summary, rendered exactly as the tool builds it.

Visual at a glance

Risk score, maturity and live charts turn a 244-check scan into a one-screen posture summary anyone can read.

Adversary kill-chain

Findings roll up into a seven-stage attack chain — from external recon to cloud pivot — colour-coded by where you’re exposed or hardened.

Evidence & remediation

Each finding carries the observed evidence, framework mappings and a concrete fix — with a SHA-256 manifest so the report is tamper-evident.

Workflow

Three steps, no infrastructure

Drop the package on a host, run it elevated, and collect a signed report. No server, database or agent required.

1

Run

Launch WINSECMON.exe elevated. It self-elevates and runs entirely in memory, read-only.

2

Assess

Collectors gather host, AD, ADCS and policy state; 244 checks evaluate posture against known techniques.

3

Report

Get HTML, CSV and JSON reports with severity, evidence and remediation — plus an integrity manifest.

Test topology

What it tests, bottom-up

Read-only collectors feed six assessment domains; 244 ATT&CK-mapped checks score the evidence and roll it up into one signed, tamper-evident report.

Signed posture report HTML · CSV · JSON · integrity manifest 244 checks · mapped to MITRE ATT&CK® evidence-backed · severity-scored · false-positive-aware Identity & Active Directory Privilege & Delegation Endpoint Hardening Certificate Services (ADCS) Attack Paths & lateral move Cloud Identity · M365 AD / LDAP objects · ACLs GPO & Policy rights · settings Host & Registry services · config ADCS / PKI templates · CAs Defender & Logs events · signals Entra / M365 tenant · roles Read-only collectors Domains Checks Signed report flows bottom-up ↑
Momentum

Coverage that keeps growing

WinSecMon’s detection coverage expanded fast through the 2.0 release series — total checks grew 78% and Active Directory / identity coverage grew 157% in twelve days, all read-only and evidence-backed.

WINSECMON — Check Coverage Growth Security checks across the v2.0.0 release series · 20 domains · Jun 2026 0 40 80 120 160 200 240 280 137 165 184 244 67 95 114 172 v2.0.0-rc.1 v2.0.0-rc.6 v2.0.0-rc.11 v2.0.0 Jun 8 Jun 15 Jun 17 Jun 20 · beta Total checks AD / identity 12-day growth +78% total +157% AD
Get the beta

Download WinSecMon

Try the current pre-release build on a test or lab host and help shape the 3.0 release.

Windows · PowerShell 5.1+ · ~920 KB

WinSecMon 3.0.0 — Public Beta

Download .zip
Pre-release build. This is a beta under active testing, code-signed with ScaryByte’s publicly trusted SSL.com OV certificate, so Windows shows a verified publisher — no certificate import needed. Run it on a lab or test host first. See the beta notes before deploying.
Integrity: verify the download with the published SHA-256 on the beta page before running. The package self-verifies its own evidence manifest at runtime.
Beta feedback

Share results & feedback

Running the beta on a test host? Send us what you found. Upload a scan report or evidence bundle, flag a false positive, or just tell us what worked and what didn't. Every submission is stored securely on our server and reviewed by the team.

Attach files (optional)

    Submissions are stored privately on the ScaryByte server for the beta team. Please don't include secrets or production credentials — scrub sensitive data first.

    Reading the results, not just collecting them

    Full documentation covers requirements, trust setup, profiles, the check catalog, and the forensic evidence model.