silverhack/monkey365
Monkey365 is an open-source security assessment tool for Microsoft 365, Azure, and Microsoft Entra ID. It helps security professionals identify misconfigurations, review cloud security posture, and evaluate environments against industry security best practices and compliance standards. observed · 2026-08-28
Health v2 · maintenance only
97/100
- Activity 96
- Release rhythm 96
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: 27.5
- age_days: 1594
- days_rel: 26
- days_push: 26
- n_releases_24m: 19
Adoption not part of the score
1332 stars · 141 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Monkey365 is an open-source PowerShell-based security assessment framework for Microsoft 365, Azure, and Microsoft Entra ID. It collects tenant configuration data, evaluates it against security best practices and CIS benchmarks, and generates HTML, JSON, and CSV reports of misconfigurations.
Use cases
- audit my Microsoft 365 tenant for security misconfigurations
- run a CIS benchmark compliance check on Azure subscriptions
- assess Entra ID security posture before an audit
- generate an HTML report of Exchange Online and SharePoint security issues
- review Microsoft Teams and Purview configuration against best practices
- automate cloud security posture assessments with JSON output
- check M365 tenant configuration as an incident responder
When to choose
- you need a self-contained PowerShell tool with no dependency on Az, Microsoft Graph SDK, or ExchangeOnlineManagement modules
- you want consolidated M365, Azure, and Entra ID assessments in a single report
- you need CIS benchmark and compliance checks for Microsoft cloud workloads
- you support multiple authentication methods including service principals and certificates for unattended scans
When to avoid
- you need security scanning for AWS, GCP, or non-Microsoft clouds
- you want continuous runtime monitoring or intrusion detection rather than point-in-time configuration reviews
- you need a GUI-driven vulnerability scanner rather than a PowerShell CLI
- your environment has no PowerShell availability (e.g., non-Windows without PowerShell Core installed)
Facets
cli-tool · maturity active
security vulnerability-scanning monitoring developer-tools security cloud-computing penetration-testing windows cross-platform cli microsoft-365 azure entra-id cloud-security-posture cis-benchmark compliance powershell-module security-assessment exchange-online sharepoint-online microsoft-teams purview devops
2 sources
- readme: https://github.com/silverhack/monkey365 · fetched 2026-08-28 · 1eb473b3b08a
- homepage: https://silverhack.github.io/monkey365/ · fetched 2026-08-29 · 9a42775cf7cc
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| silverhack/monkey365 | main | 97 |
For agents
markdown · JSON · MCP: product_card(name="silverhack/monkey365")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem