WinGuard
CIS, STIG and the Microsoft baseline for Windows Server, in one air-gap-safe PowerShell script
PowerShell · Windows Server
Audits a Windows Server host against CIS Benchmarks (Level 1), DISA STIGs and the Microsoft Security Baseline in a single pass, then adds its own hardening-posture scanner and a set of air-gap isolation checks. It detects the build number and the domain role itself and applies the matching rules — a domain controller gets the DC variant of every rule that has one, rather than being failed against member-server expectations. Between 750 and 990 checks depending on the host.
The Windows counterpart to RHELGuard: same check model, same report schema, same options, so a mixed estate can be audited and tracked the same way.
- One file, no dependencies. PowerShell 3.0 and up. Nothing is installed, downloaded or resolved, and the HTML report ships a strict CSP so it cannot phone home either. Works on Server Core with no network, no DNS and no default route.
- Runs without administrator rights. Registry policy — the bulk of CIS and STIG — plus services, firewall, TLS config, Defender state, accounts, ports and shares all work unprivileged. What genuinely needs elevation is marked
SKIP (administrator required)and excluded from the score, instead of quietly failing. - Drift without a SIEM. Feed the previous run back with
-Baselineand the report flags every check that is NEW, REGRESSED, FIXED or CHANGED. Documented deviations go in a waiver file and read asWAIVEDwith the reason attached. - Built for transfer.
-Bundlepacks the reports with a MANIFEST and SHA256SUMS and prints the bundle hash for the media transfer log. Each report records the SHA-256 of the script that produced it, so an auditor can prove which build ran.-Strictexits 2 while any FAIL remains, for pipelines. - Findings you can act on. HTML, JSON and CSV out. Every finding cites the recommendation number for the detected OS, and every FAIL or WARN carries the exact PowerShell or
gpedit.mscfix.
Two honest limits. Microsoft publishes baseline content for Server 2022 and 2025 only — on 2016 and 2019 the report says so rather than scoring zero, and CIS covers that ground heavily anyway. And -IncludeDomainPolicy is off by default because it is the one check that leaves the host: a single LDAP query to the machine's own domain controller. On a domain member it separates "the domain covers this" (WARN) from "nothing covers this" (FAIL) — deliberately not a PASS, since the local value still governs the built-in Administrator.
MIT licensed.