# 0x6d69636b/windows_hardening

HardeningKitty and Windows Hardening Settings

Repository: https://github.com/0x6d69636b/windows_hardening
Canonical: https://ross.abutalabs.com/products/windows_hardening
Language: PowerShell
License: MIT
License Family: permissive
Topics: windows, hardening, security, windows-10, blueteam, defense, audit, powershell, windows-hardening, registry, checklist, compliance, bsi, cis, security-baseline, sisyphus, stig, windows-11, windows-server
Last push: 2026-08-26T18:12:11+00:00

## Health v2 (maintenance only)
Score: 86/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 62, longevity 100
- inputs: {"age_days": 3236, "days_push": 7, "days_rel": 43, "gap_med": 574, "n_releases_24m": 2}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2655, forks 328 (observed 2026-08-28T04:07:07.254140+00:00)

## What it is
HardeningKitty is a PowerShell module that audits and hardens Windows systems against security baselines such as CIS Benchmarks, Microsoft Security Baselines, DoD STIG, and BSI SiSyPHuS. It reads registry and system configuration, assesses compliance against finding lists, and can apply hardening settings including via its HailMary mode.

## Use cases
- audit windows 10 against cis benchmarks
- harden windows 11 registry settings with powershell
- check windows server compliance with dod stig
- apply bsi sisyphus hardening recommendations
- generate a windows security baseline audit report
- automate windows hardening for a home pc without group policy editor

## When to choose
- you need to audit or enforce Windows security baselines from CIS, STIG, Microsoft, or BSI
- you want scriptable, registry-based hardening on Windows 10/11 or Windows Server
- you manage Windows Home editions lacking the Group Policy Editor

## When to avoid
- you need hardening for Linux or macOS systems
- you require a GUI-driven compliance tool with centralized reporting
- your environment cannot run unsigned or third-party PowerShell scripts and you cannot obtain the signed scip AG build

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, configuration-management, developer-tools
- domain: security, windows, legal
- platform: windows
- tags: hardening, cis-benchmarks, stig, bsi-sisyphus, audit, blueteam, registry, security-baseline, automation

## Member repositories
- 0x6d69636b/windows_hardening (main) score 86

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:07:07.254140+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:18:29.628419+00:00, confidence not recorded.
  - readme: https://github.com/0x6d69636b/windows_hardening (fetched 2026-08-28T04:07:07.254140+00:00, sha cc0c4a4406aa)
- Data as of 2026-08-30T08:39:29.467469+00:00.
