Windows security posture, assessed in minutes.
WinSecMon is a read-only, agentless assessment engine that inspects a Windows host against 282 checks across 21 security domains — from Active Directory and ADCS to attack paths, accounts, and host exposure — and produces forensic-grade, tamper-evident reports.
Illustrative output from a lab domain controller. Outcome totals sum to the full 282-check run; N/A covers checks that self-gate as not applicable to that host, such as Entra and M365 checks with no Graph access. Three of the findings are shown — a real report lists them all.
Built for real Windows estates
One pass surfaces the misconfigurations and attack paths that matter — mapped to the techniques adversaries actually use.
Active Directory
Privileged group hygiene, delegation, Kerberos weaknesses, AdminSDHolder and domain-head ACLs.
Certificate Services (ADCS)
ESC1–ESC11 template and enrollment misconfigurations, including HTTP web-enrollment relay (ESC8).
Attack paths
DCSync rights, dangerous ACLs and privilege-escalation chains toward tier-0 assets.
Accounts & policy
Password policy, stale and non-expiring accounts, LAPS, audit policy and account hardening.
Host exposure
Exposed services, legacy protocols (SMBv1, PSv2), firewall posture and remote-access surface.
Forensic evidence
Every report ships with a SHA-256 evidence manifest and tamper-evident integrity verification.
An executive briefing, not a wall of text
Every scan produces a self-contained, interactive HTML report — a risk score, maturity rating and live charts up top, then evidence-backed findings mapped to MITRE ATT&CK, CIS and ANSSI below. Here’s the executive summary, rendered exactly as the tool builds it.
ScaryByte WINSECMON — Security Posture Report
Executive summary. WINSECMON evaluated 282 security controls across host hardening, Active Directory, attack-surface, credential-exposure and cloud-tenant posture, producing 55 scored findings. The environment carries 5 failures (0 Critical, 0 High) and 13 warnings, giving a composite risk score of 25/100 at maturity level 4/5.
- Passed 37
- Warnings 13
- Failures 5
Visual at a glance
Risk score, maturity and live charts turn a 282-check scan into a one-screen posture summary anyone can read.
Adversary kill-chain
Findings roll up into a seven-stage attack chain — from external recon to cloud pivot — colour-coded by where you’re exposed or hardened.
Evidence & remediation
Each finding carries the observed evidence, framework mappings and a concrete fix — with a SHA-256 manifest so the report is tamper-evident.
Three steps, no infrastructure
Drop the package on a host, run it elevated, and collect a signed report. No server, database or agent required.
Run
Launch WINSECMON.exe elevated. It self-elevates and runs entirely in memory,
read-only.
Assess
Collectors gather host, AD, ADCS and policy state; 282 checks evaluate posture against known techniques.
Report
Get HTML, CSV and JSON reports with severity, evidence and remediation — plus an integrity manifest.
The flow runs one way only: Windows host → read-only collectors → check engine → evidence and findings → signed report and integrity manifest. Nothing is written back to the host, nothing is remediated automatically, and nothing keeps running after the scan ends.
What it tests, bottom-up
Read-only collectors feed six assessment groups; 282 ATT&CK-mapped checks score the evidence and roll it up into one signed, tamper-evident report.
What WinSecMon reaches, and what it does not.
Read-only collectors gather state from the hosts and directory services they can reach. Cloud surfaces are optional and environment-gated: without Entra or Graph access the related checks report Not Applicable rather than passing silently.
- Available — workstations, member servers, domain controllers, Active Directory and AD CS, assessed directly from the host.
- Optional — Entra ID and Microsoft 365, assessed only when the environment is present.
- Environment-gated — Microsoft Graph checks, which require credentials and network access that many estates deliberately withhold.
- Offline / air-gapped — the run still completes and still produces a signed report; network-dependent checks report Not Applicable.
Everything converges on one execution and one signed, tamper-evident report in HTML, CSV and JSON with an integrity manifest.
Coverage that keeps growing
WinSecMon’s detection coverage expanded fast through the 2.0 release series — total checks grew 78% and Active Directory / identity coverage grew 157% in twelve days, all read-only and evidence-backed.
The v2.0.0 release series is historical and was measured against a 20-domain taxonomy. v3.0.0 is a separate, current milestone measured against 21 domains, so the two are drawn as distinct eras rather than one continuous curve. Exact figures are in the table below.
Chart data (accessible table)
| Release | Date | Total checks | Domains |
|---|---|---|---|
| v2.0.0-rc.1 | 8 June 2026 | 137 | 20 |
| v2.0.0-rc.6 | 15 June 2026 | 165 | 20 |
| v2.0.0-rc.11 | 17 June 2026 | 184 | 20 |
| v2.0.0 / v3.0.0-beta | 20 June 2026 | 244 | 20 |
| v3.0.0 (current) | 12 August 2026 | 282 | 21 |
All 21 security domains
Every domain is listed, including the smallest. Select one to highlight it. Counts come straight from the shipped check registry.
Checks by security domain — v3.0.0 (282 across 21 domains)
| Domain | Checks |
|---|---|
| Anomalies | 55 |
| PrivilegedAccounts | 27 |
| StaleObjects | 26 |
| AttackPaths | 26 |
| Certificates (AD CS) | 24 |
| Hardening | 22 |
| AttackSurface | 15 |
| Defender | 12 |
| M365Exposure | 11 |
| Trusts | 10 |
| CredentialExposure | 8 |
| Policy | 7 |
| EntraDevice | 7 |
| Network | 6 |
| Accounts | 5 |
| CloudExposure | 5 |
| System | 4 |
| Telemetry | 4 |
| Persistence | 4 |
| Vulnerabilities | 2 |
| Firewall | 2 |
Framework mappings (counts of checks carrying at least one reference, not coverage percentages): 185 checks mapped to MITRE ATT&CK across 64 distinct techniques, 36 mapped to CIS guidance and 16 mapped to ANSSI guidance.
Download WinSecMon
WinSecMon 3.0.0 — 282 checks across 21 domains, code-signed and timestamped.
65e217a6281f8e3c889fca8d4af7396473ffe5025fd207098b44770ace521ecfVerify before running:
Get-FileHash .\WINSECMON-v3.0.0-Windows-x64.zip -Algorithm SHA256Get-AuthenticodeSignature .\WINSECMON-v3.0.0\WINSECMON.exe | Format-List Status,
SignerCertificateStatus must be Valid and the signer must be SCARYBYTE (PTY) LTD.
Checksum file: .sha256
The chain you can verify yourself: the published package produces a SHA-256 digest, the executable inside carries an OV Authenticode signature from SCARYBYTE (PTY) LTD, and every report the scanner writes is sealed by its own integrity manifest. The digest and signer above are the authoritative values — the diagram only shows the order in which to check them.
What is WINSECMON?
A read-only, agentless Windows security posture assessment engine from ScaryByte. It inspects a Windows host — and, where available, Active Directory, AD Certificate Services and cloud identity posture — against 282 checks in 21 security domains, then produces evidence-backed reports.
Does WINSECMON install an agent?
No. Nothing is installed and no service is registered. You extract the package and run it.
Does it change system configuration?
No. WINSECMON is read-only by design: it collects and evaluates state, and writes only its own report files to the output directory you choose.
Which Windows versions are supported?
Windows 10, Windows 11 and Windows Server 2016 or later, on x64, with Windows PowerShell 5.1 or later.
Does it need administrator rights?
It runs without them, but many checks cannot read their evidence unelevated and will report Not Applicable. Running as administrator gives a complete assessment.
Does it require internet access?
No. Scanning works offline. Internet access is used only for optional network-dependent checks and for interactive charts in the HTML report; without it, reports render with local assets and all findings, scores and evidence remain complete.
Can it assess Active Directory and AD Certificate Services?
Yes, where that infrastructure is present and reachable from the host running the scan. AD checks need a domain-joined context; AD CS checks read certificate-authority state.
Can it assess Entra ID or Microsoft 365?
There are Entra device and Microsoft 365 exposure checks. Tenant-level assessment is opt-in and requires appropriate permissions; no outbound call is made when the capability is disabled or unavailable.
What happens when an environment is unavailable?
The check reports Not Applicable with the reason, rather than failing. Absent infrastructure never produces a Critical or High finding — a workgroup machine will not be told its domain controller is misconfigured.
What report formats are produced?
Console, JSON, HTML and CSV, plus a SHA-256 evidence manifest so a report can be checked for tampering after the fact.
How do I verify the download?
Compare the published SHA-256 against your copy, then confirm the Authenticode signature:
Get-FileHash .\WINSECMON-v3.0.0-Windows-x64.zip -Algorithm SHA256
Get-AuthenticodeSignature .\WINSECMON-v3.0.0\WINSECMON.exe | Format-List Status, SignerCertificate
Status must be Valid and the signer must be
SCARYBYTE (PTY) LTD. Signing confirms origin and integrity; it is not a
warranty that software is defect-free.
Is WINSECMON open source?
No. It is proprietary software owned by ScaryByte (Pty) Ltd — see the Proprietary Software Notice. The runtime ships as signed PowerShell so you can read exactly what it does before running it with administrator rights, but that is auditability, not an open-source licence.
May I redistribute it?
Not without prior written permission from ScaryByte. Redistribution, resale, sublicensing, public hosting, repackaging and third-party service use are all restricted.
Where should I run it first?
On a lab or non-critical host, so you can review the output and confirm the findings match your expectations before assessing production systems. Always confirm you are authorised to assess a system before scanning it.
How do I report a false positive?
Send the finding through the feedback form below, ideally with the JSON report or the relevant evidence section, so the check logic can be reviewed.
Share results & feedback
Running WinSecMon on a test host? Send us what you found. Upload a scan report or evidence bundle, flag a false positive, or just tell us what worked and what didn't. Every submission is stored securely on our server and reviewed by the team.
Reading the results, not just collecting them
Full documentation covers requirements, trust setup, profiles, the check catalog, and the forensic evidence model.