MDE Toolkit

A free, powerful Windows desktop application for monitoring, managing, and diagnosing Microsoft Defender for Endpoint — built with WPF and .NET 8

✓ Free & Open Source   ✓ No Account Required   ✓ Windows 10/11   ✓ .NET 8

The two biggest additions in recent releases. Both are built for the same question: is this machine safe right now, and if not, what do I do about it?

Updated v3.3.1 & 3.3.2

⚔️ Attack Surface Reduction, rebuilt

ASR rules now get a proper workspace: one grid that tells you what mode every rule is really in and where that setting came from, plus a new Events page for investigating what got blocked and safely tuning it.

  • See the truth, not the registry. Rule state is merged from Intune, Group Policy and Defender itself — rules set locally no longer show as “Not Configured”.
  • Know who set it. A new Source column tells you whether a rule came from Intune, GPO, or someone typing on that machine.
  • Investigate blocks. Repeats are grouped by rule and process, so 400 blocks of one app read as one tuning problem.
  • Exclusions that expire. Create a 4-hour or 30-day exclusion with a required justification — it reverts itself even if the app is closed.
See what changed →
New Preview

🔎 Machine Investigator

Type in up to 25 device names and get a one-page verdict for each — healthy, needs attention, or investigate now — with the evidence and the fix attached. No hunting queries to write.

  • One click, sixteen questions. Vulnerabilities, alerts, odd processes, logon failures, persistence and config gaps, gathered in a single pass.
  • A verdict you can act on. 🟢 / 🟡 / 🔴 with a one-line reason, then the facts behind it.
  • Every finding comes with a fix. Click a row for the PowerShell, Intune and GPO remediation.
  • No AI required. The default engine is deterministic local rules — nothing leaves your machine and every claim traces to a data row.
How it works →

Everything You Need to Monitor & Manage MDE

One tool to view, analyze, diagnose, and manage your endpoint security configuration

📊

Security Score

Comprehensive security posture assessment with actionable recommendations, category breakdowns, and priority-based remediation guidance.

🛡️

App Control (WDAC)

View deployed WDAC policies, scan files against policy, run CiTool commands, and analyze Code Integrity configuration.

💾

Device Control

Manage USB and removable device policies. View, create, edit, and export device control configurations with a visual policy editor.

⚔️

ASR Rules

See every Attack Surface Reduction rule's enforcement mode and whether it is pushed by Intune/GPO or set locally. Investigate blocks and warn-bypasses grouped by rule and process, then create audited permanent or auto-expiring exclusions. Learn more →

🔎

Machine Investigator Preview

Triage up to 25 devices at once from Advanced Hunting. Each one gets a plain-English verdict, the evidence behind it, and copy-paste remediation. Learn more →

🔥

Firewall & WFP

Parse firewall logs, view WFP filter summaries, browse firewall rules, and analyze network policy enforcement.

🔍

Diagnostics

Analyze Defender support bundles (MpSupportFiles.cab), parse logs, detect issues, and export diagnostic reports.

🤖

AI Analysis

Connect to Azure OpenAI or OpenAI to get AI-powered security analysis, risk summaries, and remediation suggestions.

🌐

Network Tracing

Capture network traces with netsh, configure scenarios and providers, and auto-stop on firewall drops with the built-in drop monitor.

Compliance Manager

Create and evaluate compliance policies against your endpoint, including DISA STIG baselines for Defender AV and Firewall.

🖥️

CiTool Integration

Run CiTool.exe commands directly from the app — list policies, refresh CI engine, get device ID, and view live streaming output.

📡

Remote Support

Connect to remote machines via WinRM or PsExec to monitor and diagnose MDE on other workstations across your network.

📚

Knowledge Base

Built-in reference for MDE components, ASR rules, and troubleshooting scenarios with links to official documentation.

🏢

Enterprise Fleet Monitoring

Deploy via MSI with dual scheduled tasks: SYSTEM collects telemetry every 8 hours, the logged-on user uploads to Azure using their Entra identity. No secrets on endpoints.

☁️

Azure Ingestion

Upload health snapshots to an Azure Function App or directly to Blob Storage. Managed Identity auth, Table Storage for Power BI dashboards, Gov Cloud supported.

See It In Action

Modern Fluent WPF interface with Mica backdrop, designed for Windows 10 & 11

Download MDE Toolkit

Free and open source. No account required.

Recommended
📦

GitHub Releases

Download the latest build from GitHub

Download from GitHub

Version 3.3.2 · What's new

🛠️

Build from Source

Clone the repository and build with .NET 8 SDK

View Source on GitHub

Requires .NET 8 SDK

System Requirements

  • ✓ Windows 10 version 1809 or later / Windows 11
  • ✓ .NET 8 Desktop Runtime
  • ✓ Administrator privileges recommended for full functionality
  • ✓ CiTool.exe requires Windows 11 22H2+ or Windows Server 2025+