RedPatch
Headlines refreshed Sun Oct 11, 11:45 AM ET (1 h ago) · content checked against vendor docs

⊞ Windows 11 security

Windows 11, locked down.

Windows 11 already ships with most of the protection a typical PC needs. Much of it is on by default, but it is easy to switch off by accident and hard to tell what state it is in. This guide covers each setting to check, the read-only command that shows its current state, and the official Microsoft page behind it. It applies to Windows 11 version 24H2 and later (25H2 and 26H2 are now out too). Every tip was checked against Microsoft Learn and Microsoft Support on 2026-10-11.

40 tips · 17 tools · every one sourced

Latest Windows 11 advisories

  1. Nippon Columbia malware incident exposes 8.6 million karaoke fan recordsBleepingComputer · Oct 11
  2. Cyber exec arrested in case allegedly tied to ShinyHunters hackersBleepingComputer · Oct 10
  3. Why TLP should not replace your internal information classification, (Sat, Oct 10th)SANS Internet Storm Center · Oct 10
  4. Microsoft 365 incident readiness for Microsoft Engage CenterWindows Release Health · Oct 9
  5. Windows 11, version 26H1 known issues and notificationsWindows Release Health · Oct 9
  6. CVE-2026-62744 Microsoft Windows Media Foundation Remote Code Execution VulnerabilityMicrosoft Security Update Guide · Oct 9

All Windows 11 headlines →

1. Antivirus and tamper protection

Confirm Microsoft Defender Antivirus is actually running

everyone

Defender is the built-in antivirus. If another antivirus product is installed or a setting was changed, Defender can quietly drop into passive mode.

Open Windows Security > Virus & threat protection. Real-time protection should be On. In PowerShell, check that RealTimeProtectionEnabled is True and AMRunningMode reads Normal.

Check — read-only
Get-MpComputerStatus | Select-Object AMRunningMode, AntivirusEnabled, RealTimeProtectionEnabled, AntivirusSignatureLastUpdated
Changes your system
Update-MpSignature

Source: Get-MpComputerStatus (Microsoft Learn)

Keep tamper protection on

everyone

Malware often tries to switch off antivirus before it does damage. Tamper protection blocks changes to Defender's key settings, including changes made through the registry, and changes pushed by management tools such as Group Policy can appear to succeed but are blocked.

Windows Security > Virus & threat protection > Virus & threat protection settings > Manage settings > Tamper Protection: On. Managed fleets set it in Intune or the Defender portal so it cannot be switched off locally. The check command returns True when it is on.

Check — read-only
Get-MpComputerStatus | Select-Object IsTamperProtected, RealTimeProtectionEnabled

Source: Configure tamper protection on Windows devices (Microsoft Learn)

Run a Microsoft Defender Offline scan when you suspect a rootkit

everyone

Some malware hides while Windows is running. An offline scan reboots into a trusted environment and scans before that malware can load.

Windows Security > Virus & threat protection > Scan options > Microsoft Defender Antivirus (offline scan). Save your work first, because the PC restarts.

Check — read-only
Get-MpThreatDetection
Changes your system
Start-MpWDOScan

Source: Microsoft Defender Offline (Microsoft Learn)

Turn on Controlled folder access to slow down ransomware

power user

Controlled folder access lets only trusted apps change files in protected folders such as Documents, Pictures and Desktop. Unknown programs are blocked from encrypting them.

Windows Security > Virus & threat protection > Ransomware protection > Controlled folder access. Start in Audit mode, review the blocked-app events, allow the apps you trust, then switch to Enabled.

Check — read-only
Get-MpPreference | Select-Object EnableControlledFolderAccess, ControlledFolderAccessProtectedFolders
Changes your system
Set-MpPreference -EnableControlledFolderAccess AuditMode

Source: Configure controlled folder access (Microsoft Learn)

Deploy Attack Surface Reduction (ASR) rules in audit mode first

admin

ASR rules block common attack behaviors. Examples are Office apps spawning child processes, credential theft from LSASS, and attackers dropping vulnerable signed drivers.

Pick rules from Microsoft's reference list. Add each one in AuditMode and watch for event ID 1122 (audited detections) in Event Viewer for a few weeks. Then switch the clean rules to Enabled (block). Add-MpPreference adds rules without overwriting the ones you already have. The example below audits 'Block abuse of exploited vulnerable signed drivers'.

Check — read-only
Get-MpPreference | Select-Object AttackSurfaceReductionRules_Ids, AttackSurfaceReductionRules_Actions
Changes your system
Add-MpPreference -AttackSurfaceReductionRules_Ids 56a863a9-875e-4185-98a7-b882c64b5ce5 -AttackSurfaceReductionRules_Actions AuditMode

Source: Attack surface reduction rules reference (Microsoft Learn)

2. App control and safe testing

Use Smart App Control, which can now be turned back on without a reinstall

everyone

Smart App Control blocks malicious and untrusted apps before they run. It used to need a clean install to turn back on. Microsoft Support now says recent Windows updates let you turn it on again from the Windows Security app without one.

Windows Security > App & browser control > Smart App Control settings > On. Exceptions: S mode devices need S mode turned off and a reset, and PCs with optional diagnostic data off still need a reset or reinstall. There is no way to let one specific app through, so if an important app is blocked you may have to turn Smart App Control off. In the check command, 0 = Off, 1 = Enforce, 2 = Evaluation.

Check — read-only
reg query "HKLM\SYSTEM\CurrentControlSet\Control\CI\Policy" /v VerifiedAndReputablePolicyState

Source: Smart App Control FAQ (Microsoft Support)

Businesses: build App Control for Business policy from the Smart App Control template

admin

Application control is one of the most effective defenses against executable malware. The Smart App Control policy ships as an example you can extend to trust your line-of-business apps.

Start from %windir%\schemas\CodeIntegrity\ExamplePolicies\SmartAppControl.xml. Remove the 'Enabled:Conditional Windows Lockdown Policy' option. Deploy in audit mode, review the CodeIntegrity events, then enforce. On enterprise-managed devices, Smart App Control switches off within 48 hours unless the user turns it on first.

Check — read-only
CiTool.exe --list-policies

Source: Application Control for Windows (Microsoft Learn)

Open suspicious files in Windows Sandbox, not on your real desktop

power user

Sandbox is a disposable virtual machine that the hypervisor isolates from your PC. Everything in it is deleted when you close it.

Requires Pro, Enterprise or Education (not supported on Home). Enable the 'Windows Sandbox' optional feature and reboot. Networking is ON by default. For untrusted files, use a .wsb configuration file that turns networking off and maps the folder read-only.

Check — read-only
Get-WindowsOptionalFeature -Online -FeatureName Containers-DisposableClientVM
Changes your system
Enable-WindowsOptionalFeature -Online -FeatureName Containers-DisposableClientVM -All

Source: Windows Sandbox (Microsoft Learn)

Turn on reputation-based protection (SmartScreen and PUA blocking)

everyone

SmartScreen warns about malicious sites and downloads. Potentially unwanted app (PUA) blocking stops adware and bundleware installers.

Windows Security > App & browser control > Reputation-based protection settings. Turn on 'Check apps and files', 'SmartScreen for Microsoft Edge', 'Potentially unwanted app blocking' and 'Phishing protection'.

Check — read-only
Get-MpPreference | Select-Object PUAProtection
Changes your system
Set-MpPreference -PUAProtection Enabled

Source: App & browser control in the Windows Security app (Microsoft Support)

3. Disk encryption (BitLocker)

Make sure your drive is actually encrypted

everyone

A stolen laptop with an unencrypted drive gives away every file on it. On supported devices, Device Encryption turns on automatically when you first sign in with a Microsoft account or a work or school account. With a local account it does not. Check rather than assume.

Settings > Privacy & security > Device encryption (Home), or BitLocker drive encryption (Pro and up). In the check command, ProtectionStatus should read On. 'Off' means unprotected, which includes a suspended drive.

Check — read-only
Get-BitLockerVolume | Select-Object MountPoint, VolumeStatus, ProtectionStatus, EncryptionMethod, EncryptionPercentage

Source: Device encryption in Windows (Microsoft Support)

Know where your BitLocker recovery key is before you need it

everyone

Firmware updates, TPM resets or hardware changes can trigger a recovery prompt. Without the recovery key, the data is gone.

Personal devices: sign in at aka.ms/myrecoverykey with your Microsoft account and match the key ID. Work devices: the key should be backed up to Entra ID or AD. Print a copy and store it offline. The check command shows the protectors, including the recovery password, so run it privately.

Check — read-only
manage-bde -protectors -get C:

Source: Find your BitLocker recovery key (Microsoft Support)

Turn BitLocker on with a recovery password from the command line

admin

Scripted enablement keeps a whole fleet consistent and makes sure a recovery protector exists before encryption starts.

From an elevated prompt, turn on BitLocker for the OS drive and add a recovery password protector in one step. Back up the key to Entra ID or AD before you walk away. Use XTS-AES 256 if your policy requires it.

Check — read-only
manage-bde -status C:
Changes your system
manage-bde -on C: -recoverypassword

Source: manage-bde on (Microsoft Learn)

Don't leave BitLocker suspended after maintenance

power user

BIOS updates often suspend BitLocker for a reboot or two. While it is suspended, the encryption key sits on the disk as an unprotected 'clear key', so anyone with the drive can read it.

After firmware work, confirm ProtectionStatus is On (a suspended drive reads Off). If not, resume it.

Check — read-only
Get-BitLockerVolume -MountPoint C: | Select-Object ProtectionStatus
Changes your system
Resume-BitLocker -MountPoint C:

Source: BitLocker overview (Microsoft Learn)

4. Sign-in, credentials and admin rights

Sign in with Windows Hello (PIN, face or fingerprint) instead of a password

everyone

Windows Hello credentials are generated inside the device's TPM, and the PIN never leaves the device. Windows Hello has built-in brute-force protection, so a PIN is not a weaker choice than a password.

Settings > Accounts > Sign-in options. Set up a PIN, plus Facial recognition or Fingerprint if your hardware supports it.

Source: Windows Hello for Business (Microsoft Learn)

Use passkeys and manage which apps can reach them

everyone

Passkeys are phishing-resistant. The private key never leaves your device, and it only works on the real site it was made for.

When a site offers 'create a passkey', save it to Windows Hello. Starting in Windows 11 24H2, Windows asks for your consent before an app can use passkeys. Review or change which apps are allowed in Settings > Privacy & security > Passkey access.

Source: Support for passkeys in Windows (Microsoft Learn)

Turn on Administrator protection (new, off by default)

power user

Your admin account normally runs with a reduced token. With Administrator protection, each elevation needs Windows Hello approval and runs under a separate, hidden admin profile whose token is thrown away afterward. Malware can no longer silently gain admin rights.

It became available with update KB5120998 and is off by default. Use Windows Security > Account protection > Administrator protection (rolling out gradually), or the policy 'User Account Control: Configure type of Admin Approval Mode' = 'Admin Approval Mode with Administrator protection'. Restart afterward. Don't use it on Windows 365 Cloud PCs, Azure Virtual Desktop session hosts, or devices that need Hyper-V.

Source: Administrator protection (Microsoft Learn)

Use a standard account for daily work

everyone

Most malware needs admin rights to dig in. A standard user account removes that by default and costs nothing.

Create a separate admin account for installs. Change your everyday account to Standard in Settings > Accounts > Other users. Elevate only when a prompt asks. If the check command prints a line, your account is in the local Administrators group.

Check — read-only
whoami /groups | findstr /i "S-1-5-32-544"

Source: User Account Control overview (Microsoft Learn)

Confirm Credential Guard is running on business machines

admin

Credential Guard keeps NTLM hashes and Kerberos tickets in an isolated, virtualization-protected process. That blocks pass-the-hash and pass-the-ticket theft.

It is on by default on domain-joined Windows 11 22H2+ devices that meet the license and hardware requirements. Enterprise and Education support it; Pro does not. In the check command, an output containing 1 means Credential Guard is running. Test apps first: NTLMv1 single sign-on, Kerberos DES and unconstrained delegation stop working.

Check — read-only
(Get-CimInstance -ClassName Win32_DeviceGuard -Namespace root\Microsoft\Windows\DeviceGuard).SecurityServicesRunning

Source: Configure Credential Guard (Microsoft Learn)

Run LSASS as a protected process (LSA protection)

power user

LSA protection stops unprotected processes from reading LSASS memory or injecting code into it. That is where credential-dumping tools go.

Windows Security > Device security > Core isolation details > Local Security Authority protection: On, then restart. Admins can set RunAsPPL to 2 (no UEFI lock) or 1 (UEFI lock); this is enforced on Windows 11 22H2 and later. Before enforcing on a fleet, audit plug-ins and drivers first and look for CodeIntegrity events 3065 and 3066.

Check — read-only
reg query "HKLM\SYSTEM\CurrentControlSet\Control\Lsa" /v RunAsPPL
Changes your system
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa" /v RunAsPPL /t REG_DWORD /d 2 /f

Source: Configure added LSA protection (Microsoft Learn)

Rotate local admin passwords with Windows LAPS

admin

The same local admin password on every PC means one stolen hash opens them all. Windows LAPS is built into Windows. It sets a unique, rotating password per device and backs it up to Entra ID or AD.

Configure the LAPS policy (backup directory, password age, complexity) through Intune or GPO. Read passwords with Get-LapsAADPassword (Entra) or Get-LapsADPassword (AD), and limit who has the read permission. Reset-LapsPassword forces an immediate rotation.

Check — read-only
Get-LapsADPassword -Identity <ComputerName>
Changes your system
Reset-LapsPassword

Source: Use Windows LAPS PowerShell cmdlets (Microsoft Learn)

Use Sudo for Windows in its safest mode

power user

Sudo (Windows 11 24H2+) lets you elevate one command from a normal terminal, so you don't keep an admin shell open. Microsoft warns it can become a privilege-escalation path in some configurations. The default mode runs the elevated command in a new window; 'Inline' mode is the most convenient but carries the most risk.

Settings > System > Advanced > Enable sudo. Keep 'In a new window' (forceNewWindow), the default, unless you understand the inline risks. To set the mode from the command line, run the change command from an elevated prompt.

Changes your system
sudo config --enable forceNewWindow

Source: Sudo for Windows (Microsoft Learn)

5. Kernel and firmware protections

Turn on Memory integrity (HVCI)

everyone

Memory integrity uses the hypervisor to check kernel-mode code before it runs. That blocks many driver-based and kernel exploits. It is on by default on most new Windows 11 devices.

Windows Security > Device security > Core isolation details > Memory integrity: On, then restart. If an incompatible driver blocks it, update or remove that driver rather than leaving the feature off. In the check command, an output containing 2 means memory integrity is running.

Check — read-only
(Get-CimInstance -ClassName Win32_DeviceGuard -Namespace root\Microsoft\Windows\DeviceGuard).SecurityServicesRunning

Source: Enable memory integrity (Microsoft Learn)

Keep the Microsoft Vulnerable Driver Blocklist on

everyone

Attackers load legitimately signed but vulnerable drivers to get kernel access ('bring your own vulnerable driver'). The blocklist stops known bad ones. It has been on by default since the Windows 11 2022 update. Microsoft updates the list quarterly and ships it in the monthly Windows updates.

Windows Security > Device security > Core isolation details > Microsoft Vulnerable Driver Blocklist: On. It is forced on when Memory integrity, Smart App Control or S mode is on. Admins who want the newest list can deploy Microsoft's downloadable blocklist through App Control for Business. Also turn on the ASR rule 'Block abuse of exploited vulnerable signed drivers'.

Source: Microsoft recommended driver block rules (Microsoft Learn)

Confirm Secure Boot is on and has the 2023 certificates

power user

The original 2011 Secure Boot certificates began expiring in June 2026. PCs without the 2023 certificates still boot and still get normal Windows updates, but they can no longer receive new security protections for the early boot process.

Check that Secure Boot is on. Then check whether the 'Windows UEFI CA 2023' certificate is in the db. Install pending Windows updates and any OEM firmware update. Most devices get the new certificates automatically. Run the check command from an elevated PowerShell.

Check — read-only
Confirm-SecureBootUEFI; [System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).bytes) -match 'Windows UEFI CA 2023'

Source: Windows Secure Boot certificate expiration and CA updates (Microsoft Support)

Check the overall hardware security level in one place

everyone

Windows Security's Device security page summarizes core isolation, the security processor (TPM), Secure Boot and data encryption. It is a quick way to see whether the hardware protections are actually active.

Windows Security > Device security. Read the Hardware security capability line at the bottom, and open each card that shows a warning. The check command reports the TPM state from an elevated PowerShell.

Check — read-only
Get-Tpm

Source: Device security in the Windows Security app (Microsoft Support)

6. Network protection

Keep Windows Firewall on for every profile

everyone

The firewall blocks unsolicited inbound connections. Turning it off 'just to test' and forgetting is one of the most common misconfigurations.

Windows Security > Firewall & network protection. Domain, Private and Public should all read 'Firewall is on'. Mark café and hotel Wi-Fi as a Public network.

Check — read-only
Get-NetFirewallProfile | Select-Object Name, Enabled, DefaultInboundAction, DefaultOutboundAction
Changes your system
Set-NetFirewallProfile -Profile Domain,Public,Private -Enabled True

Source: Manage Windows Firewall with the command line (Microsoft Learn)

Review inbound allow rules and remove stale ones

power user

Apps add firewall exceptions when you install them and rarely remove them. Old rules leave ports open after the app is gone.

List the enabled inbound allow rules. Remove the ones for software you no longer use, from wf.msc or with Remove-NetFirewallRule.

Check — read-only
Get-NetFirewallRule -Direction Inbound -Action Allow -Enabled True | Select-Object DisplayName, Profile, DisplayGroup

Source: Manage Windows Firewall with the command line (Microsoft Learn)

Turn on Defender Network protection

admin

Network protection extends SmartScreen-style blocking to every app, not just Edge. It stops connections to known phishing, malware and command-and-control hosts.

From an elevated PowerShell, start in AuditMode, review the events, then set Enabled (block mode). Managed fleets configure it in Intune endpoint security.

Check — read-only
Get-MpPreference | Select-Object EnableNetworkProtection
Changes your system
Set-MpPreference -EnableNetworkProtection AuditMode

Source: Turn on network protection (Microsoft Learn)

See what is listening and talking on your PC

power user

An unexpected listening port or outbound connection is often the first sign of unwanted software.

Run the check command to list listening ports and the processes that own them. TCPView (Sysinternals) shows the same data live in a GUI.

Check — read-only
Get-NetTCPConnection -State Listen | Select-Object LocalAddress, LocalPort, OwningProcess, @{n='Process';e={(Get-Process -Id $_.OwningProcess).ProcessName}}

Source: Get-NetTCPConnection (Microsoft Learn)

7. Updates and patching

Install Windows updates promptly and check the last patch date

everyone

Most real-world compromises exploit bugs that already have a fix. Microsoft's monthly security release is the second Tuesday of each month.

Settings > Windows Update > Check for updates. Restart when asked, because an update isn't finished installing until the device restarts.

Check — read-only
Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 5 HotFixID, Description, InstalledOn

Source: Windows Update FAQ (Microsoft Support)

Manage business updates with Windows Update client policies (formerly Windows Update for Business)

admin

Microsoft renamed 'Windows Update for Business' to 'Windows Update client policies'. The policies let you ring updates, set deferrals and enforce deadlines without running WSUS.

Through GPO or Intune, set quality-update deferrals (max 30 days), feature-update deferrals (max 365 days) and compliance deadlines. Pausing is limited to 35 days. Use Windows Autopatch on top of these policies if you want Microsoft to orchestrate the rings.

Check — read-only
reg query "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /s

Source: Windows Update client policies (Microsoft Learn)

Patch your apps too with winget

power user

Browsers, PDF readers, runtimes and archivers are attacked as often as Windows is. winget (Windows Package Manager) can list and update most of them in one step.

Run 'winget upgrade' to list available updates, which changes nothing. Run 'winget upgrade --all' to install them. Install new software with 'winget install' from the default sources instead of random download sites.

Check — read-only
winget upgrade
Changes your system
winget upgrade --all

Source: winget upgrade command (Microsoft Learn)

Check Windows release health before and after Patch Tuesday

admin

Microsoft posts known issues and safeguard holds for each update. Checking first saves you from rolling a broken patch across a fleet.

Bookmark the Windows release health page and open the known-issues list for your version (24H2, 25H2 or 26H2). Read it before broad deployment.

Source: Windows release health (Microsoft Learn)

8. Baselines, auditing and monitoring

Compare your settings to the Microsoft Security Baseline

admin

Microsoft publishes a tested baseline for each Windows release. The Security Compliance Toolkit currently includes Windows 11 v24H2, v25H2 and v26H2 baselines. It is the fastest way to find settings that differ from Microsoft's recommendations.

Download the Security Compliance Toolkit. Unzip the baseline for your Windows 11 version and Policy Analyzer. Use Policy Analyzer to compare your GPOs or local policy against the baseline. Apply it with GPO or Intune security baselines after testing.

Source: Windows security baselines (Microsoft Learn)

Audit a single machine with HardeningKitty (audit mode only)

power user

HardeningKitty scores a PC against curated finding lists, including Microsoft baselines and CIS-style lists, and writes a CSV report. Audit mode only reads settings.

Install the module from the project's GitHub. Run Audit mode from an elevated PowerShell and read the report. HailMary mode WRITES settings and can break systems; its built-in backup is not a full system backup, so take an image first. The project was written for English Windows, and results may be wrong in other languages.

Check — read-only
Invoke-HardeningKitty -Mode Audit -Log -Report
Changes your system
Invoke-HardeningKitty -Mode HailMary -Log -Report -FileFindingList <list.csv>

Source: HardeningKitty (scipag on GitHub)

Log what really happens with Sysmon

admin

Sysmon records process creation with full command lines, network connections, driver loads, process access and more in the Windows event log. That gives you the detail to investigate an incident.

Download Sysmon from Sysinternals and install it with a filtered configuration file. Events land in Applications and Services Logs > Microsoft > Windows > Sysmon > Operational. Forward them to your SIEM.

Check — read-only
Get-Service Sysmon* ; Get-WinEvent -LogName 'Microsoft-Windows-Sysmon/Operational' -MaxEvents 5
Changes your system
sysmon64 -accepteula -i C:\Tools\sysmon-config.xml

Source: Sysmon (Microsoft Learn / Sysinternals)

Review what starts automatically with Autoruns

power user

Persistence is how malware survives a reboot. Autoruns shows every auto-start location (Run keys, services, scheduled tasks, drivers, WMI and more) in one view.

Run Autoruns as administrator. Use the 'Hide Signed Microsoft Entries' option to focus on third-party items, and check VirusTotal results for anything unfamiliar. Uncheck an entry rather than deleting it until you're sure. The command-line version (check command) lists all entries as CSV with hashes and signature checks, hiding Microsoft entries.

Check — read-only
autorunsc64.exe -accepteula -a * -c -h -s -m

Source: Autoruns (Microsoft Learn / Sysinternals)

Inspect suspicious processes with Process Explorer

power user

Task Manager hides a lot. Process Explorer shows parent/child process trees, loaded DLLs and open handles, which makes an odd process much easier to trace.

Run as administrator. Turn on signature verification and VirusTotal checks from the Options menu. Unsigned processes running from user-writable folders deserve a closer look.

Source: Process Explorer (Microsoft Learn / Sysinternals)

Track Administrator protection elevations

admin

With Administrator protection on, elevations are logged as ETW events. Event 15031 records an approved elevation and 15032 a denied, failed or timed-out one. That gives you an audit trail of who ran what as admin.

Enable the Microsoft-Windows-LUA ETW provider (GUID {93c05d69-51a3-485e-877f-1806a8731346}) with logman or WPR. Filter on event IDs 15031 and 15032, and open the .etl file in Windows Performance Analyzer.

Changes your system
logman start AdminProtectionTrace -p {93c05d69-51a3-485e-877f-1806a8731346} -ets

Source: Administrator protection, monitoring and reporting events (Microsoft Learn)

Follow CISA's Known Exploited Vulnerabilities list for Windows

admin

KEV lists the CVEs that attackers are actively exploiting. Patching those first is the highest-value move when you can't patch everything at once.

Filter the KEV catalog for vendor 'Microsoft' and product 'Windows'. Compare it to your patch status. Each entry carries a remediation due date; treat it as a priority guide.

Source: Known Exploited Vulnerabilities Catalog (CISA)

Tools worth knowing

Windows Security appbuilt-in

Built-in dashboard for antivirus, firewall, app and browser control, device security (core isolation, LSA protection, driver blocklist) and account protection.

When: First stop on any Windows 11 PC to see what is on or off.

Get-MpComputerStatus / Get-MpPreferencebuilt-in

PowerShell cmdlets that report Defender engine, signature, real-time and tamper-protection status, plus ASR, controlled folder access and network protection settings.

When: Scripted health checks and fleet audits.

manage-bdebuilt-in

Command-line tool that shows and manages BitLocker status and protectors.

When: Checking encryption state, listing recovery protectors, enabling BitLocker in scripts.

Get-BitLockerVolumebuilt-in

PowerShell cmdlet that reports BitLocker status, method and encryption percentage per volume.

When: Quick object-based BitLocker checks and reporting.

winget (Windows Package Manager)built-in

Command-line package manager to install and update apps from trusted sources.

When: Keeping third-party apps patched. 'winget upgrade' lists pending updates.

Sudo for Windowsbuilt-in

Runs one elevated command from an unelevated terminal (Windows 11 24H2+).

When: Occasional admin commands without keeping an admin shell open.

Windows Sandboxbuilt-in

Disposable, hypervisor-isolated Windows desktop that is wiped on close.

When: Opening untrusted files or testing unknown software (Pro, Enterprise or Education).

Windows LAPSbuilt-in

Built-in local administrator password rotation, backed up to Entra ID or Active Directory.

When: Any organization with more than a handful of PCs.

Sysinternals Autorunsfree

Shows every auto-start location on the system.

When: Hunting persistence, cleaning up startup bloat.

Sysinternals Process Explorerfree

Advanced task manager with process trees, signature checks and VirusTotal lookups.

When: Investigating a suspicious or resource-hungry process.

Sysinternals Sysmonfree

Detailed system activity logging to the Windows event log.

When: Detection, threat hunting and incident investigation, usually forwarded to a SIEM.

Sysinternals TCPViewfree

Live view of TCP/UDP endpoints and their owning processes.

When: Spotting unexpected listeners or outbound connections.

Microsoft Security Compliance Toolkitfree

Microsoft's security baselines (including Windows 11 v24H2, v25H2 and v26H2) plus Policy Analyzer and LGPO.

When: Comparing and applying recommended Group Policy settings.

HardeningKittyfree

Open-source PowerShell module that audits Windows settings against finding lists and reports a score.

When: Auditing standalone or lab machines. Use audit mode, and HailMary only with a full backup.

App Control for Business / CiToolbuilt-in

Windows code-integrity application control. CiTool lists and refreshes active policies.

When: Allow-listing apps on managed devices, building on the Smart App Control template.

Microsoft Defender Offlinebuilt-in

Boot-time scan from a trusted environment for rootkits and persistent malware.

When: When you suspect an infection that hides while Windows is running.

MSRC Security Update Guidefree

Microsoft's official database of CVEs and the updates that fix them.

When: Researching a specific CVE or planning Patch Tuesday.

Other platforms

Go deeper

networks.jelia.nycHow the internet actually moves your data — packets, DNS, routing, TLS. waves.jelia.nycElectromagnetism explained — Wi-Fi, 2.4 GHz, Bluetooth and why RF leaks. lib.jelia.nycThe library — security, Linux, assembly and networking books on the shelf. blog.redpatch.usRedPatch field notes.