Ross ROSS = Recommend OSS · open-source software intelligence for agents

silverhack/monkey365

Monkey365 is an open-source security assessment tool for Microsoft 365, Azure, and Microsoft Entra ID. It helps security professionals identify misconfigurations, review cloud security posture, and evaluate environments against industry security best practices and compliance standards. observed · 2026-08-28

github.com/silverhack/monkey365 · homepage · PowerShell · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

97/100

  • Activity 96
  • Release rhythm 96
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 27.5
  • age_days: 1594
  • days_rel: 26
  • days_push: 26
  • n_releases_24m: 19

Full methodology

Adoption not part of the score

1332 stars · 141 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Monkey365 is an open-source PowerShell-based security assessment framework for Microsoft 365, Azure, and Microsoft Entra ID. It collects tenant configuration data, evaluates it against security best practices and CIS benchmarks, and generates HTML, JSON, and CSV reports of misconfigurations.

Use cases

  • audit my Microsoft 365 tenant for security misconfigurations
  • run a CIS benchmark compliance check on Azure subscriptions
  • assess Entra ID security posture before an audit
  • generate an HTML report of Exchange Online and SharePoint security issues
  • review Microsoft Teams and Purview configuration against best practices
  • automate cloud security posture assessments with JSON output
  • check M365 tenant configuration as an incident responder

When to choose

  • you need a self-contained PowerShell tool with no dependency on Az, Microsoft Graph SDK, or ExchangeOnlineManagement modules
  • you want consolidated M365, Azure, and Entra ID assessments in a single report
  • you need CIS benchmark and compliance checks for Microsoft cloud workloads
  • you support multiple authentication methods including service principals and certificates for unattended scans

When to avoid

  • you need security scanning for AWS, GCP, or non-Microsoft clouds
  • you want continuous runtime monitoring or intrusion detection rather than point-in-time configuration reviews
  • you need a GUI-driven vulnerability scanner rather than a PowerShell CLI
  • your environment has no PowerShell availability (e.g., non-Windows without PowerShell Core installed)

Facets

cli-tool · maturity active

security vulnerability-scanning monitoring developer-tools security cloud-computing penetration-testing windows cross-platform cli microsoft-365 azure entra-id cloud-security-posture cis-benchmark compliance powershell-module security-assessment exchange-online sharepoint-online microsoft-teams purview devops

2 sources

Member repositories

RepositoryRoleHealth v2
silverhack/monkey365main97

For agents

markdown · JSON · MCP: product_card(name="silverhack/monkey365")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem