Windows security posture, assessed in minutes.
WinSecMon is a read-only, agentless assessment engine that inspects a Windows host against 244 checks across 20 security domains — from Active Directory and ADCS to attack paths, accounts, and host exposure — and produces forensic-grade, tamper-evident reports.
Built for real Windows estates
One pass surfaces the misconfigurations and attack paths that matter — mapped to the techniques adversaries actually use.
Active Directory
Privileged group hygiene, delegation, Kerberos weaknesses, AdminSDHolder and domain-head ACLs.
Certificate Services (ADCS)
ESC1–ESC11 template and enrollment misconfigurations, including HTTP web-enrollment relay (ESC8).
Attack paths
DCSync rights, dangerous ACLs and privilege-escalation chains toward tier-0 assets.
Accounts & policy
Password policy, stale and non-expiring accounts, LAPS, audit policy and account hardening.
Host exposure
Exposed services, legacy protocols (SMBv1, PSv2), firewall posture and remote-access surface.
Forensic evidence
Every report ships with a SHA-256 evidence manifest and tamper-evident integrity verification.
An executive briefing, not a wall of text
Every scan produces a self-contained, interactive HTML report — a risk score, maturity rating and live charts up top, then evidence-backed findings mapped to MITRE ATT&CK, CIS and ANSSI below. Here’s the executive summary, rendered exactly as the tool builds it.
ScaryByte WINSECMON — Security Posture Report
Executive summary. WINSECMON evaluated 244 security controls across host hardening, Active Directory, attack-surface, credential-exposure and cloud-tenant posture, producing 55 scored findings. The environment carries 5 failures (0 Critical, 0 High) and 13 warnings, giving a composite risk score of 25/100 at maturity level 4/5.
- Passed 37
- Warnings 13
- Failures 5
Visual at a glance
Risk score, maturity and live charts turn a 244-check scan into a one-screen posture summary anyone can read.
Adversary kill-chain
Findings roll up into a seven-stage attack chain — from external recon to cloud pivot — colour-coded by where you’re exposed or hardened.
Evidence & remediation
Each finding carries the observed evidence, framework mappings and a concrete fix — with a SHA-256 manifest so the report is tamper-evident.
Three steps, no infrastructure
Drop the package on a host, run it elevated, and collect a signed report. No server, database or agent required.
Run
Launch WINSECMON.exe elevated. It self-elevates and runs entirely in memory,
read-only.
Assess
Collectors gather host, AD, ADCS and policy state; 244 checks evaluate posture against known techniques.
Report
Get HTML, CSV and JSON reports with severity, evidence and remediation — plus an integrity manifest.
What it tests, bottom-up
Read-only collectors feed six assessment domains; 244 ATT&CK-mapped checks score the evidence and roll it up into one signed, tamper-evident report.
Coverage that keeps growing
WinSecMon’s detection coverage expanded fast through the 2.0 release series — total checks grew 78% and Active Directory / identity coverage grew 157% in twelve days, all read-only and evidence-backed.
Download WinSecMon
Try the current pre-release build on a test or lab host and help shape the 3.0 release.
Share results & feedback
Running the beta on a test host? Send us what you found. Upload a scan report or evidence bundle, flag a false positive, or just tell us what worked and what didn't. Every submission is stored securely on our server and reviewed by the team.
Reading the results, not just collecting them
Full documentation covers requirements, trust setup, profiles, the check catalog, and the forensic evidence model.