cisagov/ScubaGear
Automation to assess the state of your M365 tenant against CISA's baselines observed · 2026-08-28
Health v2 · maintenance only
85/100
- Activity 99
- Release rhythm 59
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 93
- age_days: 1504
- days_rel: 118
- days_push: 7
- n_releases_24m: 6
Adoption not part of the score
2650 stars · 379 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
ScubaGear is a PowerShell-based assessment tool that checks whether a Microsoft 365 tenant's configuration conforms to CISA's Secure Configuration Baselines. It queries M365 APIs, evaluates settings with Open Policy Agent Rego policies, and generates HTML, JSON, and CSV reports.
Use cases
- assess my M365 tenant against CISA secure configuration baselines
- audit Exchange Online and Teams security settings
- check Entra ID identity and access configuration compliance
- generate compliance reports for Microsoft 365 security posture
- verify SharePoint and Power Platform security settings
- map M365 controls to NIST 800-53 and MITRE ATT&CK
When to choose
- you administer a Microsoft 365 tenant and want automated baseline compliance checks
- you need CISA SCuBA baseline assessments with visual HTML reports
- you want policy-as-code security evaluation using OPA and Rego
- you need controls mapped to NIST SP 800-53 or MITRE ATT&CK
When to avoid
- you need to assess Google Workspace tenants (use ScubaGoggles instead)
- you need continuous real-time monitoring rather than point-in-time assessment
- your environment is not Microsoft 365
- you need an agent-based or always-on security tool
Facets
cli-tool · maturity active
security monitoring cli security developer-tools cloud-computing windows cross-platform cli m365 cisa open-policy-agent rego security-baselines tenant-assessment powershell compliance scuba reporting automation
10 sources
- readme: https://github.com/cisagov/ScubaGear · fetched 2026-08-28 · de124e9bfc52
- homepage: https://www.cisa.gov/resources-tools/services/secure-cloud-business-applications-scuba-project · fetched 2026-08-29 · cc9ef40dd0c1
- site_page: https://www.cisa.gov/about · fetched 2026-08-29 · 46b39cd497d8
- site_page: https://www.cisa.gov/about/divisions-offices · fetched 2026-08-29 · e90d4b26e2a4
- site_page: https://www.cisa.gov/about/regions · fetched 2026-08-29 · b5723310e002
- site_page: https://www.cisa.gov/about/leadership · fetched 2026-08-29 · ae28fd113963
- site_page: https://www.cisa.gov/about/doing-business-cisa · fetched 2026-08-29 · 582c57d633b2
- site_page: https://www.cisa.gov/about/cisa-central · fetched 2026-08-29 · 167294190ec7
- site_page: https://www.cisa.gov/about/contact-us · fetched 2026-08-29 · cc8295ea668a
- site_page: https://www.cisa.gov/about/contact-us/subscribe-updates-cisa · fetched 2026-08-29 · 44890ece1e2d
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| cisagov/ScubaGear | main | 85 |
For agents
markdown · JSON · MCP: product_card(name="cisagov/ScubaGear")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem