A free, powerful Windows desktop application for monitoring, managing, and diagnosing Microsoft Defender for Endpoint — built with WPF and .NET 8
✓ Free & Open Source ✓ No Account Required ✓ Windows 10/11 ✓ .NET 8
One tool to view, analyze, diagnose, and manage your endpoint security configuration
Comprehensive security posture assessment with actionable recommendations, category breakdowns, and priority-based remediation guidance.
View deployed WDAC policies, scan files against policy, run CiTool commands, and analyze Code Integrity configuration.
Manage USB and removable device policies. View, create, edit, and export device control configurations with a visual policy editor.
Monitor Attack Surface Reduction rules status, enforcement mode, and recent block/audit events with detailed event analysis.
Parse firewall logs, view WFP filter summaries, browse firewall rules, and analyze network policy enforcement.
Analyze Defender support bundles (MpSupportFiles.cab), parse logs, detect issues, and export diagnostic reports.
Connect to Azure OpenAI or OpenAI to get AI-powered security analysis, risk summaries, and remediation suggestions.
Capture network traces with netsh, configure scenarios and providers, and auto-stop on firewall drops with the built-in drop monitor.
Create and evaluate compliance policies against your endpoint, including DISA STIG baselines for Defender AV and Firewall.
Run CiTool.exe commands directly from the app — list policies, refresh CI engine, get device ID, and view live streaming output.
Connect to remote machines via WinRM or PsExec to monitor and diagnose MDE on other workstations across your network.
Built-in reference for MDE components, ASR rules, and troubleshooting scenarios with links to official documentation.
Deploy via MSI with dual scheduled tasks: SYSTEM collects telemetry every 8 hours, the logged-on user uploads to Azure using their Entra identity. No secrets on endpoints.
Upload health snapshots to an Azure Function App or directly to Blob Storage. Managed Identity auth, Table Storage for Power BI dashboards, Gov Cloud supported.
Modern Fluent WPF interface with Mica backdrop, designed for Windows 10 & 11
Dashboard Overview
App Control View
Device Control
Free and open source. No account required.