Windows Contextual Hardening & Exposure Auditor
120+ security checks with context-aware intelligence
AZAD is an enterprise-grade security analyzer for Windows endpoints that combines:
- 150+ security checks (memory, authentication, network, PowerShell, accounts, system)
- Context Intelligence (detects EDR, Azure AD, Intune, domain, form factor)
- Adaptive scoring (adjusts risk based on real compensating controls)
- 100% defensive (read-only, offline, agentless)
Unlike traditional scanners, AZAD understands your environment and gives accurate risk assessment.
Traditional Scanners:
Laptop with CrowdStrike + Intune? Score: 65/100 ⚠️
Unmanaged desktop? Score: 65/100 ⚠️
❌ No context awareness
❌ False positives
❌ Can't prioritize
AZAD:
Laptop with CrowdStrike + Intune? AZAD Score: 18/100 ✅
Unmanaged desktop? AZAD Score: 72/100 🔴
✅ Context-aware
✅ Accurate priorities
5 Core Layers:
Auto-detects:
- Form Factor (Laptop/Desktop/Server/VM)
- Domain (Workgroup/Domain/Azure AD)
- Management (Intune/MDM)
- EDR (15+ products: CrowdStrike, SentinelOne, Defender ATP...)
- GPO Lockdown Level (0-100)
120+ checks:
- Memory: LSASS PPL, Credential Guard, VBS/HVCI, WDigest
- Auth: NTLM/LM, SMB signing, RDP NLA, ASR rules
- Network: Port exposure, SMBv1, LLMNR/NetBIOS
- PowerShell: AMSI, CLM, Script Block Logging
- Accounts: Local admins, password policies
- System: Secure Boot, BitLocker, audit policies
Adaptive risk calculation:
Base Risk + Context Adjustments = AZAD Score
Example:
Base: +35 (missing controls)
- EDR detected: -15
- Intune: -10
- Azure AD: -5
- GPO HIGH: -10
= AZAD Score: 0/100 ✅
- JSON for SIEM/SOAR
- HTML dashboard with MITRE mapping
- Executive summary
- Automated remediation
- Reversible changes
- Stealth/Safe/Hard modes
The first context-aware endpoint security metric
| Score | Rating | Risk Level |
|---|---|---|
| 0-25 | 🟢 EXCELLENT | Enterprise-grade |
| 26-50 | 🟡 GOOD | Above average |
| 51-75 | 🟠 NEEDS WORK | Notable gaps |
| 76-100 | 🔴 CRITICAL | Severe exposure |
| 100+ | ⚫ EMERGENCY | Isolate immediately |
Real Examples:
Fortune 500 Laptop (Intune + CrowdStrike): 12/100 ✅
SMB Domain PC (basic GPO): 45/100 🟡
Home PC (no management): 78/100 🔴
git clone https://github.com/leoferrer15/AZAD
git clone
cd azad
python azad_v1.1.pySample Output:
🧠 Context: LAPTOP | AZURE_AD | Intune ✅ | CrowdStrike ✅
⚖️ AZAD Score: 18/100 ✅ EXCELLENT
🎯 Top Priority: Disable SMBv1
📊 Reports: azad_report.html + .json
| Feature | AZAD | CrowdStrike | Tanium | Qualys |
|---|---|---|---|---|
| Context-Aware | ✅ | ❌ | ❌ | ❌ |
| Offline/Agentless | ✅ | ❌ | ❌ | ❌ |
| EDR Detection | ✅ 15+ | ❌ | ❌ | ❌ |
| Open Source | ✅ | ❌ | ❌ | ❌ |
| Cost | Free | High | Very High | High |
Perfect for:
- Incident response triage
- Air-gapped/OT environments
- BYOD assessments
- Compliance audits (NIST, CIS)
- MSP client reporting
Blue Teams: Rapid triage, posture tracking
Auditors: Compliance evidence, gap analysis
Sysadmins: GPO validation, baseline verification
MSPs: Client benchmarking, value demonstration
v2.1 (Q4 2025): PDF export, unified reports, 25+ EDR detections
v2.2 (Q1 2026): CIS/MSFT baselines, drift detection
v3.0 (Q2 2026): Auto-hardening, rollback, "Get to Score 25" mode
v4.0 (Q3 2026): Fleet dashboard, API, remote scanning
- ⭐ Star this repo to support the project
- 🐛 Report bugs via Issues
- 💡 Suggest features via Discussions
- 🤝 Contribute code via Pull Requests
MIT License - see LICENSE
Why MIT? Maximum freedom, enterprise-friendly, encourages adoption
- Issues: GitHub Issues
- Twitter: @AZADSecurity (#AZADScore)
- Email: Azad.endpoint@gmail.com
Our Mission: Make AZAD Score the industry standard for endpoint security posture
Just like CVSS for vulnerabilities
⭐ Star if AZAD helps you assess endpoints accurately ⭐
Documentation • Whitepaper • Benchmarks