[Open Source] Lightweight PowerShell Hardening Script for Windows 11
This is an open-source PowerShell script designed to harden Windows 11 systems by leveraging native OS security features. It restricts PowerShell script execution, disables Windows Script Host, closes remote management ports, disables SMBv1, enables Microsoft Defender Attack Surface Reduction rules, and disables hidden administrative shares. The script aims to reduce the attack surface against ransomware, phishing, lateral movement, and network worms without relying on third-party software.
AI Analysis
Technical Summary
The Windows 11 Hardened Edition is a minimalist PowerShell security hardening script that enforces execution policy restrictions (RemoteSigned), disables Windows Script Host to block common malware vectors, disables WinRM remote management ports, removes legacy SMBv1 protocol to prevent network worm exploits, enables Microsoft Defender Attack Surface Reduction and Controlled Folder Access for ransomware protection, and disables hidden admin shares (C$, ADMIN$) to prevent lateral movement. It uses native Windows security capabilities to reduce the attack surface and improve endpoint security on Windows 11 without adding third-party software overhead.
Potential Impact
By applying these security hardening measures, the script reduces the risk of unauthorized script execution, remote code execution via WinRM, malware execution through Windows Script Host, network-based worm propagation via SMBv1, ransomware encryption via Defender protections, and lateral movement through administrative shares. This lowers the attack surface and mitigates multiple common attack vectors on Windows 11 endpoints.
Mitigation Recommendations
This script provides a proactive security hardening approach and is intended to be run by administrators on Windows 11 systems. Since it is an open-source tool, users should review the code before deployment. There is no indication of a vulnerability or exploit requiring patching. No vendor advisory or official patch is applicable. Users should follow the usage instructions to run the script with administrative privileges and reboot to apply the policies.
[Open Source] Lightweight PowerShell Hardening Script for Windows 11
Description
This is an open-source PowerShell script designed to harden Windows 11 systems by leveraging native OS security features. It restricts PowerShell script execution, disables Windows Script Host, closes remote management ports, disables SMBv1, enables Microsoft Defender Attack Surface Reduction rules, and disables hidden administrative shares. The script aims to reduce the attack surface against ransomware, phishing, lateral movement, and network worms without relying on third-party software.
Reddit Discussion
Hi everyone,
I built a lightweight, open-source PowerShell script designed to harden **Windows 11** endpoints using native OS security capabilities—without relying on heavy third-party software/bloat.
### 🛡️ What it does:
* **PowerShell Execution Restriction:** Sets execution policy to `RemoteSigned` to prevent unauthorized local script execution.
* **WinRM & WSH Mitigation:** Disables Windows Script Host to block `.vbs` / `.js` malware vectors and closes remote management ports.
* **Network Hardening:** Disables SMBv1 to protect against network-based lateral movement and exploits (e.g., WannaCry).
* **Defender ASR & Exploit Guard:** Enables Controlled Folder Access (ransomware protection) and blocks malicious downloads via PowerShell.
* **Admin Share Lockdown:** Disables hidden admin shares (`C$`, `ADMIN$`) to restrict unauthorized lateral movement.
---
### 🚀 How to use:
Open PowerShell as Administrator.
Run: `.\Windows11_Hardening.ps1`
Reboot to apply all policies.
---
🔗 **GitHub Repository:** https://github.com/Hasan0101-lab/Windows_11_Hardened_Edition
I’d love to get feedback from the community on code structure, additional hardening rules, or potential compatibility edge cases. Feel free to review the code or leave a ⭐ if you find it useful!
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Windows 11 Hardened Edition is a minimalist PowerShell security hardening script that enforces execution policy restrictions (RemoteSigned), disables Windows Script Host to block common malware vectors, disables WinRM remote management ports, removes legacy SMBv1 protocol to prevent network worm exploits, enables Microsoft Defender Attack Surface Reduction and Controlled Folder Access for ransomware protection, and disables hidden admin shares (C$, ADMIN$) to prevent lateral movement. It uses native Windows security capabilities to reduce the attack surface and improve endpoint security on Windows 11 without adding third-party software overhead.
Potential Impact
By applying these security hardening measures, the script reduces the risk of unauthorized script execution, remote code execution via WinRM, malware execution through Windows Script Host, network-based worm propagation via SMBv1, ransomware encryption via Defender protections, and lateral movement through administrative shares. This lowers the attack surface and mitigates multiple common attack vectors on Windows 11 endpoints.
Mitigation Recommendations
This script provides a proactive security hardening approach and is intended to be run by administrators on Windows 11 systems. Since it is an open-source tool, users should review the code before deployment. There is no indication of a vulnerability or exploit requiring patching. No vendor advisory or official patch is applicable. Users should follow the usage instructions to run the script with administrative privileges and reboot to apply the policies.
Technical Details
- Source Type
- Subreddit
- blueteamsec+AskNetsec+Information_Security
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Domain
- null
- Newsworthiness Assessment
- {"score":38,"reasons":["external_link","newsworthy_keywords:rce","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":["rce"],"foundNonNewsworthy":[]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6a6e628cbf32cb7a344f4a31
Added to database: 08/01/2026, 21:18:04 UTC
Last enriched: 08/01/2026, 21:18:29 UTC
Last updated: 08/01/2026, 21:18:29 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.