Skip to content

License

Ryan edited this page Jul 25, 2026 · 2 revisions

License

The Windows Security Audit Project is released under the MIT License with extended terms supplementing (but not replacing) the canonical MIT text. This page mirrors the canonical project LICENSE.md in full.

In the event of conflict between the extended terms and the MIT License, the MIT License governs.


Quick Reference

✅ Permitted 📋 Required ❌ Disallowed
Commercial use Include copyright notice (none in MIT itself)
Modification Include license text
Distribution
Private use
Sublicensing

The software is provided with no warranty. Use at your own risk; test in non-production environments first. See the extended terms below for compliance-tooling-specific disclaimers.


MIT License

Copyright (c) 2024-2026 Sandler73

Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.


Additional Terms and Notices

The following additional terms supplement but do not replace the MIT License above. In the event of a conflict, the MIT License text shall govern.

1. Disclaimer of Warranty

THE SOFTWARE IS PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS. THE AUTHORS, COPYRIGHT HOLDERS, AND CONTRIBUTORS MAKE NO REPRESENTATIONS OR WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING BUT NOT LIMITED TO:

(a) Warranties of Merchantability -- No warranty that the Software is of merchantable quality, fit for sale, or suitable for commercial use.

(b) Fitness for a Particular Purpose -- No warranty that the Software will meet your specific requirements, fulfill a particular need, or perform in a manner you expect. This includes, without limitation, use in production environments, regulated industries, critical infrastructure, safety-critical systems, classified networks, or any environment where software failure or inaccurate audit findings could result in harm to persons, property, or organizational reputation.

(c) Non-Infringement -- No warranty that the Software does not infringe upon the intellectual property rights, patents, trademarks, trade secrets, or copyrights of any third party.

(d) Accuracy or Completeness -- No warranty that the Software, its documentation, audit findings, severity ratings, cross-framework mappings, remediation guidance, compliance scoring, or behavior is accurate, complete, reliable, current, or free of errors, defects, false positives, false negatives, or harmful components. The Software is not a substitute for qualified human security review, formal compliance assessment, or accredited third-party audit.

(e) Uninterrupted or Error-Free Operation -- No warranty that the Software will operate without interruption, that defects will be corrected, or that the Software is free of bugs, vulnerabilities, or security flaws.

(f) Compatibility -- No warranty that the Software is compatible with any particular hardware, Windows edition, Windows version, build number, Windows feature, PowerShell version, PowerShell edition, domain configuration, group policy state, third-party security product, EDR agent, antivirus product, or other component, or that it will remain compatible with future versions of any dependency.

(g) Security -- No warranty that the Software provides adequate security protections, that its findings reflect actual security posture, that its severity ratings reflect actual risk, that its cross-framework mappings are exhaustive or correct for any particular regulatory regime, or that the Software is free from exploitable vulnerabilities. While the Software incorporates security best practices (including read-only-by-default operation, dual-confirmation gating on remediation, parameter validation, no external network calls, no credential handling, and zero external dependencies), these measures do not constitute a guarantee of security or compliance.

(h) Data Integrity -- No warranty that the Software will not cause loss, corruption, or unauthorized modification of data, files, system configurations, registry settings, group policies, audit policies, service configurations, scheduled tasks, certificate stores, or Windows feature states.

(i) System Modification -- The Software, when invoked with remediation flags (-RemediateIssues, -AutoRemediate, -RemediationBundle, or similar), is designed to make system-level modifications to Microsoft Windows operating systems, including but not limited to: registry changes, audit policy changes, service configuration changes, group policy template modifications, scheduled task creation/modification, Windows feature enable/disable, firewall rule changes, and Defender configuration changes. Users acknowledge that such modifications carry inherent risks, including but not limited to: failed boots, domain membership disruption, application breakage, group policy conflicts, AD authentication failures, RDP lockout, and operational service disruption. Users accept full responsibility for any consequences arising from the use of remediation features.

(j) Compliance Outcomes -- No warranty that use of the Software, or remediation of findings reported by the Software, will result in any particular compliance, audit, certification, attestation, or regulatory outcome. Compliance frameworks evolve continuously; the Software's interpretation of any framework is subject to change and may differ from the interpretation of an accredited assessor or regulatory body. Users requiring formal compliance attestation must engage qualified human auditors.

THE ENTIRE RISK AS TO THE QUALITY, PERFORMANCE, ACCURACY, SECURITY, AND RESULTS OBTAINED FROM THE SOFTWARE IS WITH YOU. SHOULD THE SOFTWARE PROVE DEFECTIVE, INACCURATE, OR INCOMPLETE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING, REPAIR, OR CORRECTION.

2. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL THE AUTHORS, COPYRIGHT HOLDERS, CONTRIBUTORS, OR ANY PARTY WHO MODIFIES AND/OR REDISTRIBUTES THE SOFTWARE BE LIABLE FOR ANY OF THE FOLLOWING, WHETHER BASED ON WARRANTY, CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, OR ANY OTHER LEGAL THEORY, EVEN IF SUCH PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES:

(a) Direct Damages -- Any direct financial loss, cost, or expense arising from the use or inability to use the Software, or from acting upon its findings.

(b) Indirect Damages -- Any loss or damage that does not arise directly from the Software but is a consequence of a direct loss.

(c) Incidental Damages -- Any cost incurred as a result of a primary loss caused by the Software, including but not limited to costs of substitute goods, services, technology, or compensating controls.

(d) Consequential Damages -- Any loss resulting as a secondary consequence of the use or failure of the Software, including but not limited to loss of revenue, profit, business, goodwill, anticipated savings, data, use, regulatory standing, certification status, or insurance coverage.

(e) Special Damages -- Any loss arising from special circumstances particular to the user that were not foreseeable at the time the Software was obtained.

(f) Punitive or Exemplary Damages -- Any damages imposed as punishment or to set an example, regardless of the nature of the claim.

(g) Loss of Data -- Any loss, corruption, destruction, or unauthorized disclosure of data, regardless of whether such data was created, stored, processed, transmitted, or managed by the Software.

(h) System Damage -- Any damage to computer systems, networks, hardware, software, drivers, configurations, or infrastructure arising from the installation, use, operation, or removal of the Software, including but not limited to: registry corruption, group policy conflicts, broken application states, boot failures, Active Directory replication issues, certificate-store corruption, audit policy collisions, denied logons, RDP lockouts, or any data loss resulting from remediation operations.

(i) Audit Findings -- Any direct or indirect consequences of acting (or failing to act) upon findings reported by the Software, including but not limited to: false positives, false negatives, missed vulnerabilities, misclassified severities, incorrect cross-framework mappings, incomplete remediation guidance, unintended remediation side effects, or any business or regulatory decision based on the Software's output.

(j) Third-Party Claims -- Any claims brought by third parties, including auditors, regulators, customers, partners, or law-enforcement agencies, against the user arising from the user's use of the Software or reliance on its findings.

IF ANY JURISDICTION DOES NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR CERTAIN TYPES OF DAMAGES, THE LIABILITY OF THE AUTHORS AND CONTRIBUTORS SHALL BE LIMITED TO THE MAXIMUM EXTENT PERMITTED BY THE APPLICABLE LAW OF THAT JURISDICTION.

IN NO EVENT SHALL THE TOTAL AGGREGATE LIABILITY OF THE AUTHORS, COPYRIGHT HOLDERS, AND CONTRIBUTORS FOR ALL CLAIMS ARISING OUT OF OR RELATED TO THE SOFTWARE EXCEED THE AMOUNT PAID BY YOU FOR THE SOFTWARE (WHICH IS ZERO, AS THE SOFTWARE IS PROVIDED FREE OF CHARGE).

3. Indemnification

You agree to indemnify, defend, and hold harmless the authors, copyright holders, and contributors from and against any and all claims, demands, actions, liabilities, damages, losses, costs, and expenses (including reasonable attorneys' fees) arising out of or related to:

(a) Your use or misuse of the Software;

(b) Your violation of any applicable law, regulation, contract, or third-party right in connection with your use of the Software;

(c) Any content, data, registry change, audit policy change, group policy change, service change, or system configuration change made by the Software under your direction or control;

(d) Your modification, redistribution, or sublicensing of the Software;

(e) Any claim that your use of the Software, or your reliance on its findings, caused damage to a third party;

(f) Any claim arising from a regulatory proceeding, audit, certification review, or insurance claim involving the Software's output;

(g) Any claim arising from operational disruption caused by remediation operations performed by the Software.

4. User Responsibility

You are solely responsible for:

(a) Suitability -- Ensuring the suitability of this Software for your intended use, system configuration, regulatory regime, and operational context.

(b) Backups -- Creating adequate backups of your data, system state, registry, group policy, audit policy, and configurations before running this Software with any remediation flag enabled. The Software does not create system restore points automatically.

(c) Audit-Only Review -- Reviewing the operations the Software would perform by running it in audit-only mode (the default, with no remediation flags) and inspecting the generated reports BEFORE enabling any remediation flag. Reviewing the rollback script generated by -RollbackPath BEFORE applying remediation in production environments.

(d) Pilot Testing -- Testing this Software, including remediation operations, in a non-production environment representative of your production configuration before deploying to systems with important data, services, or compliance obligations.

(e) Integrity -- Maintaining the security of your systems, including verifying the integrity and authenticity of the Software before execution (e.g., via SHA-256 checksum verification published with each release, or by reviewing the source code).

(f) Compliance -- Complying with all applicable laws, regulations, contractual obligations, and third-party license agreements related to your use of the Software, including any organizational policy on automated security tooling, change management, or remediation automation.

(g) Privileged Execution -- Understanding that the Software requires Administrator privileges to perform many checks. Granting Administrator privileges to a script is a security-sensitive operation. You are responsible for verifying the Software's integrity before each privileged execution.

(h) Human Review -- Treating the Software's findings, severity ratings, and remediation guidance as informational input to a human-led decision process, NOT as authoritative compliance attestation. The Software is a tool to support, not replace, qualified human assessment.

(i) Change Management -- Following your organization's change-management processes when applying remediation findings to production systems.

5. Authorized Use and Compliance

(a) Intended Purpose -- This Software is intended for security compliance auditing and configuration hardening of Microsoft Windows operating systems for personal, educational, professional, and authorized organizational use only.

(b) Authorization Required -- You must have explicit authorization to run this Software on any system you do not personally own. Running this Software on systems for which you lack authorization may violate computer-misuse laws (such as the U.S. Computer Fraud and Abuse Act, U.K. Computer Misuse Act 1990, EU NIS2 Directive, or equivalent in your jurisdiction).

(c) Legal Compliance -- You are solely responsible for ensuring that your use of the Software complies with all applicable local, state, provincial, national, and international laws and regulations.

(d) Prohibited Use -- The authors and contributors do not authorize and expressly disclaim any responsibility for the use of this Software:

  • For any unlawful purpose
  • To audit, scan, or modify systems without authorization
  • To circumvent security controls of systems you do not own or operate
  • To facilitate unauthorized access to information systems
  • To violate the rights of others

(e) No Endorsement -- Use of this Software does not imply endorsement, sponsorship, accreditation, certification, or affiliation with:

  • Microsoft Corporation or any Microsoft product
  • Defense Information Systems Agency (DISA)
  • National Institute of Standards and Technology (NIST)
  • Center for Internet Security, Inc. (CIS)
  • National Security Agency (NSA)
  • Cybersecurity and Infrastructure Security Agency (CISA)
  • International Organization for Standardization (ISO)
  • PCI Security Standards Council
  • American Institute of Certified Public Accountants (AICPA)
  • Australian Cyber Security Centre (ACSC)
  • European Union Agency for Cybersecurity (ENISA)
  • U.S. Department of Defense or any federal agency
  • U.S. Department of Health and Human Services (HHS)
  • Any other organization, institution, or individual associated with the cited compliance frameworks

(f) Framework Citations -- This Software references and maps to publicly published security frameworks for educational and audit-tooling purposes. References to these frameworks are nominative use only and do not constitute endorsement by, partnership with, or certification from the publishing organizations.

6. Zero External Dependencies

This Software is engineered to operate as a self-contained PowerShell framework with ZERO external runtime dependencies. Specifically:

(a) No pip, npm, NuGet, or PSGallery dependencies -- The Software does not require, install, or download any package from PyPI, npm, NuGet, the PowerShell Gallery, or any other package repository.

(b) No external network calls -- The Software performs no outbound network requests during audit execution. All checks operate on local-system state.

(c) Windows PowerShell stdlib only -- The Software depends only on built-in PowerShell cmdlets (PowerShell 5.1 Desktop or PowerShell 7.x Core), built-in WMI/CIM classes, built-in registry access, and built-in Windows command-line tools (auditpol.exe, secedit.exe, Get-LocalUser, etc.) shipped with the Windows operating system.

(d) Optional external tooling (not bundled) -- The Software's CI/CD workflows reference Pester (for testing) and PSScriptAnalyzer (for linting). These are optional development-time dependencies; they are NOT required for runtime audit execution. Both are open-source modules published by Microsoft and the PowerShell community, distributed under their own licenses (MIT and BSD-style, respectively).

The "zero external dependencies" design property is a deliberate security and supply-chain integrity decision. It does not constitute a warranty that the Windows operating system itself, the PowerShell engine, or the underlying .NET runtime are free of vulnerabilities.

This License does not extend to Windows, PowerShell, .NET, Pester, PSScriptAnalyzer, or any other platform component. Refer to those components' license terms separately.

7. No Obligation of Support

The authors and contributors are under no obligation to provide technical support, maintenance, updates, patches, bug fixes, security advisories, or any other form of ongoing service or communication related to the Software. Any support provided is at the sole discretion of the authors and may be withdrawn at any time without notice.

The authors and contributors make no commitment to:

  • Maintain compatibility with future Windows releases or feature updates
  • Update cross-framework mappings as compliance frameworks evolve
  • Add new compliance modules
  • Fix reported issues within any particular timeframe
  • Respond to support requests, GitHub Issues, or pull requests
  • Provide commercial-grade support, SLAs, or guaranteed response times

8. Modifications and Contributions

(a) Modifications -- You may modify the Software for your own use. If you distribute modified versions, you must include prominent notice that you have changed the Software, include the date of the changes, and retain this License in its entirety.

(b) Contributions -- By submitting contributions (including but not limited to code, documentation, bug reports, feature requests, compliance-framework mappings, and translations) to this project, you grant the authors a perpetual, worldwide, non-exclusive, royalty-free, irrevocable license to use, reproduce, modify, display, perform, sublicense, and distribute your contributions as part of the Software under the terms of this License.

(c) No Compensation -- You acknowledge that contributions are made voluntarily and that no compensation, credit beyond standard attribution, or other consideration is owed for contributions.

(d) Attestation of Originality -- By contributing, you represent that your contribution is your original work, or that you have all necessary rights to license the contribution under the terms of this License, and that your contribution does not infringe the rights of any third party.

For details on contributing, see Contributing.

9. Termination

This License is effective until terminated. Your rights under this License will terminate automatically without notice if you fail to comply with any of its terms. Upon termination, you shall cease all use and distribution of the Software and destroy all copies in your possession. Sections 1 through 7 shall survive any termination of this License.

10. Governing Law and Severability

(a) Severability -- If any provision of this License is held to be unenforceable or invalid, that provision shall be enforced to the maximum extent permissible, and the remaining provisions shall continue in full force and effect.

(b) Entire Agreement -- This License constitutes the entire agreement between the parties with respect to the Software and supersedes all prior or contemporaneous understandings, agreements, or representations.

(c) Waiver -- The failure of any party to enforce any provision of this License shall not constitute a waiver of that party's right to enforce that provision in the future.


Trademarks

Compliance framework names (CIS, NIST, STIG, HIPAA, GDPR, ISO 27001, PCI DSS, SOC 2, CMMC, ACSC, ENISA, NSA, CISA, etc.) are trademarks of their respective organizations. Their use in this project is for descriptive purposes only and does not imply endorsement, accreditation, or affiliation. See Section 5(e) and 5(f) above.

Reporting License Concerns

If you believe this project is being used in a way that violates the License terms, or if you have questions about license compliance:

  1. Open an issue on GitHub
  2. Or contact the maintainers directly

For security vulnerabilities, see the Security Policy instead -- do not file public issues for vulnerabilities.


Canonical license file: docs/project/LICENSE.md

END OF LICENSE

Windows Security Audit Project

Version 6.6.0 · 16 modules · 4,053 checks


🚀 Getting Started


📚 Reference


🏗️ Architecture


🛠️ Operations


📦 Release Information


🔍 Quick Reference

Frameworks Covered

ACSC · CIS · CISA · CMMC · Core · ENISA · GDPR · HIPAA · ISO 27001 · MS · MS-DefenderATP · NIST · NSA · PCI-DSS · SOC 2 · STIG

Output Formats

HTML · JSON · CSV · XML · Console · 6 browser exports

Status Values

Pass · Fail · Warning · Info · Error

Severity Levels

Critical · High · Medium · Low · Informational


🔗 External Links

Clone this wiki locally