# simeononsecurity/Windows-Optimize-Harden-Debloat

Enhance the security and privacy of your Windows 10 and Windows 11 deployments with our fully optimized, hardened, and debloated script. Adhere to industry best practices and Department of Defense STIG/SRG requirements for optimal performance and security.

Repository: https://github.com/simeononsecurity/Windows-Optimize-Harden-Debloat
Canonical: https://ross.abutalabs.com/products/windows-optimize-harden-debloat
Homepage: https://simeononsecurity.com/github/optimizing-and-hardening-windows10-deployments/
Language: PowerShell
License: MIT
License Family: permissive
Topics: windows, stig-compliant, mitigations, privacy, automation, debotnet, windows10, hardware-requirements, microsoft, harden, debloat, cyber, stigs, windows-defender, privacy-script, windows-desktop, windows-10, telemetry, hardening, security
Last push: 2025-04-25T01:37:25+00:00

## Health v2 (maintenance only)
Score: 31/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 18, release rhythm 8, longevity 100
- inputs: {"age_days": 2233, "days_push": 496, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1387, forks 97 (observed 2026-08-28T04:04:35.133013+00:00)

## What it is
A PowerShell script that automates optimization, hardening, and debloating of Windows 10 and Windows 11 systems. It applies security and privacy configurations recommended by the DoD, NSA, Microsoft, and PrivacyTools.io, including STIG/SRG-aligned mitigations, telemetry blocking, and bloatware removal.

## Use cases
- harden windows 10 and 11 for security
- remove bloatware from windows
- block windows telemetry
- apply dod stig settings to a personal pc
- automate windows privacy configuration
- optimize a fresh windows install
- disable invasive windows features by script

## When to choose
- you want a one-shot, automated hardening and debloating of a personal Windows machine
- you need a starting point toward DoD STIG/SRG compliance on a desktop
- you want recommended mitigations without breaking Windows Update, Defender, or the Store

## When to avoid
- you need full enterprise compliance including branding and banner configurations
- you require a guaranteed no-break solution for every possible system configuration
- you need a GUI tool rather than a PowerShell script

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, configuration-management, workflow-automation, privacy
- domain: security, windows, privacy, developer-tools
- platform: windows, cli
- tags: windows-hardening, debloat, stig-compliance, telemetry-blocking, powershell-script, windows-10, windows-11, system-optimization, automation

## Member repositories
- simeononsecurity/Windows-Optimize-Harden-Debloat (main) score 31

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:35.133013+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:39:51.132597+00:00, confidence not recorded.
  - readme: https://github.com/simeononsecurity/Windows-Optimize-Harden-Debloat (fetched 2026-08-28T04:04:35.133013+00:00, sha 80b2b6f331db)
- Data as of 2026-08-30T08:39:29.467469+00:00.
