MDE Toolkit

A free, powerful Windows desktop application for monitoring, managing, and diagnosing Microsoft Defender for Endpoint — built with WPF and .NET 8

✓ Free & Open Source   ✓ No Account Required   ✓ Windows 10/11   ✓ .NET 8

The two biggest additions in recent releases. Both are built for the same question: is this machine safe right now, and if not, what do I do about it?

Updated v3.3.1 & 3.3.2

⚔️ Attack Surface Reduction, rebuilt

ASR rules now get a proper workspace: one grid that tells you what mode every rule is really in and where that setting came from, plus a new Events page for investigating what got blocked and safely tuning it.

  • See the truth, not the registry. Rule state is merged from Intune, Group Policy and Defender itself — rules set locally no longer show as “Not Configured”.
  • Know who set it. A new Source column tells you whether a rule came from Intune, GPO, or someone typing on that machine.
  • Investigate blocks. Repeats are grouped by rule and process, so 400 blocks of one app read as one tuning problem.
  • Exclusions that expire. Create a 4-hour or 30-day exclusion with a required justification — it reverts itself even if the app is closed.
See what changed →
New Preview

🔎 Machine Investigator

Type in up to 25 device names and get a one-page verdict for each — healthy, needs attention, or investigate now — with the evidence and the fix attached. No hunting queries to write.

  • One click, sixteen questions. Vulnerabilities, alerts, odd processes, logon failures, persistence and config gaps, gathered in a single pass.
  • A verdict you can act on. 🟢 / 🟡 / 🔴 with a one-line reason, then the facts behind it.
  • Every finding comes with a fix. Click a row for the PowerShell, Intune and GPO remediation.
  • No AI required. The default engine is deterministic local rules — nothing leaves your machine and every claim traces to a data row.
How it works →

Everything You Need to Monitor & Manage MDE

One tool to view, analyze, diagnose, and manage your endpoint security configuration

📊

Security Score

Comprehensive security posture assessment with actionable recommendations, category breakdowns, and priority-based remediation guidance.

🛡️

App Control (WDAC)

View deployed WDAC policies, scan files against policy, run CiTool commands, and analyze Code Integrity configuration.

💾

Device Control

Manage USB and removable device policies. View, create, edit, and export device control configurations with a visual policy editor.

⚔️

ASR Rules

See every Attack Surface Reduction rule's enforcement mode and whether it is pushed by Intune/GPO or set locally. Investigate blocks and warn-bypasses grouped by rule and process, then create audited permanent or auto-expiring exclusions. Learn more →

🔎

Machine Investigator Preview

Triage up to 25 devices at once from Advanced Hunting. Each one gets a plain-English verdict, the evidence behind it, and copy-paste remediation. Learn more →

🔥

Firewall & WFP

Parse firewall logs, view WFP filter summaries, browse firewall rules, and analyze network policy enforcement.

🔍

Diagnostics

Analyze Defender support bundles (MpSupportFiles.cab), parse logs, detect issues, and export diagnostic reports.

🤖

AI Analysis

Connect to Azure OpenAI or OpenAI to get AI-powered security analysis, risk summaries, and remediation suggestions.

🌐

Network Tracing

Capture network traces with netsh, configure scenarios and providers, and auto-stop on firewall drops with the built-in drop monitor.

Compliance Manager

Create and evaluate compliance policies against your endpoint, including DISA STIG baselines for Defender AV and Firewall.

🖥️

CiTool Integration

Run CiTool.exe commands directly from the app — list policies, refresh CI engine, get device ID, and view live streaming output.

📡

Remote Support

Connect to remote machines via WinRM or PsExec to monitor and diagnose MDE on other workstations across your network.

📚

Knowledge Base

Built-in reference for MDE components, ASR rules, and troubleshooting scenarios with links to official documentation.

🏢

Enterprise Fleet Monitoring

Deploy via MSI with dual scheduled tasks: SYSTEM collects telemetry every 8 hours, the logged-on user uploads to Azure using their Entra identity. No secrets on endpoints.

☁️

Azure Ingestion

Upload health snapshots to an Azure Function App or directly to Blob Storage. Managed Identity auth, Table Storage for Power BI dashboards, Gov Cloud supported. See the dashboard →

See It In Action

Modern Fluent WPF interface with Mica backdrop, designed for Windows 10 & 11

Download MDE Toolkit

Free and open source. No account required.

Recommended
📦

GitHub Releases

Download the latest build from GitHub

Download from GitHub

Version 3.3.3 · What's new

🛠️

Build from Source

Clone the repository and build with .NET 8 SDK

View Source on GitHub

Requires .NET 8 SDK

System Requirements

  • ✓ Windows 10 version 1809 or later / Windows 11
  • ✓ .NET 8 Desktop Runtime
  • ✓ Administrator privileges recommended for full functionality
  • ✓ CiTool.exe requires Windows 11 22H2+ or Windows Server 2025+