More free tools →

Hardened

Is this Windows machine hardened? Run one script, drop the file, and see which security settings are missing, in plain English with the fix for each. Covers account policy, user rights, audit policy, and the registry settings that actually matter.

Runs entirely in your browser. Nothing is uploaded, stored, or sent to us.

1Collect the machine's configuration

This is the same collector the WorksOnMine uses. Run it from an elevated PowerShell, which matters more here: without elevation the security policy, user rights, and audit policy cannot be read at all, and most of the baseline simply cannot be evaluated. It changes nothing.

2Drop the file here

What this is, and what it is not

This is our own baseline of well-established Windows security settings. It is not a DISA STIG or CIS Benchmark assessment and does not claim conformance with either. Many of these settings also appear in those benchmarks, because they are the same well-known Windows settings, but the rules, thresholds, and wording here are ours.

If you need a real STIG assessment for an audit, use DISA's own SCAP Compliance Checker, which is free and authoritative. This tool is for the much more common case: finding the obvious gaps on a machine quickly, without installing a scanner.

Checking one machine by hand is a useful afternoon.

RFF evaluates every endpoint against a baseline continuously, shows you which ones drifted, and can put them back.

Start free for 100 endpoints

What gets checked

43 checks across four areas Windows keeps in four different places, which is the main reason this is tedious to do by hand: the registry, the local security database (via secedit), user-rights assignment, and the advanced audit policy (via auditpol).

High severity

Medium severity

Low severity

Honest limits

This finds obvious gaps; it does not replace a scanner. File ACLs and service configuration are not covered, and a rule whose input the collector never read is reported as not checked rather than guessed. Coverage is shown next to the score for exactly that reason.

FAQ

How do I check if a Windows machine is hardened?

Run the collector script from an elevated PowerShell and drop the resulting file on this page. It scores the machine against 43 checks covering account and lockout policy, user-rights assignment, audit policy, and the registry settings that carry the most security weight, and gives you the fix for each gap.

Is this a DISA STIG or CIS Benchmark scan?

No. These are our own rules describing well-established Windows security settings. They are not a copy of any CIS Benchmark or DISA STIG and do not claim conformance with either. If you need a real STIG assessment for an audit, use DISA’s own SCAP Compliance Checker, which is free and authoritative.

Why does it need administrator rights?

Without elevation the collector cannot read security policy, user rights, or audit policy at all, so most of the baseline cannot be evaluated. Note that being signed in as an administrator is not the same as running elevated: with UAC on, a normal PowerShell or ISE window has a filtered token. The tool detects a non-elevated snapshot and says so rather than quietly scoring it.

Does a missing setting count as a failure?

Only when we know the collector actually looked. A rule whose input was never collected is reported as "not checked", never as a pass or a gap. Coverage is shown as prominently as the score, because a hardening report that counts unreadable settings as compliant is worse than no report at all.

Is anything uploaded?

No. The snapshot is scored entirely in your browser. Nothing is uploaded, stored, or sent to us, and the collector is open source so you can read it before running it.

Open source

Hardened is MIT-licensed at github.com/deadarcher/hardened. The rules and the checking engine on this page are byte-identical to the repo copies, and our CI fails the build if they ever drift. Self-host it with one line of Docker:

docker run --rm -p 8080:80 ghcr.io/deadarcher/hardened:latest

A check that reads wrong against a modern baseline? Open an issue - rule disagreements are exactly the feedback this wants.

Built by the RFF team. More free Windows tools.