ACHILLES is a PowerShell-based system hardening automation tool that establishes, verifies, and continuously restores a system’s Root of Trust using globally recognized security standards.
It converts security frameworks into actionable checks, automated remediation, and clear compliance reporting.
- ✅ Standards-based system hardening
- 🔍 Automated security audits (Pass / Fail)
- 🛠️ One-click remediation
- 📄 HTML compliance reports
- 🔄 Drift detection & recovery
- 🪟 Native Windows PowerShell support
Deploy & Operate ACHILLES
Deployment & Operation Guide
Supported Systems
• Windows 10 / 11
• Windows Server
• PowerShell 5.1+
Step 1 — Clone or Download
git clone https://github.com/OmarFadel112/Automated-system-hardening-checklist-tool.git
cd Automated-system-hardening-checklist-tool
Step 2 — Allow Script Execution
Set-ExecutionPolicy RemoteSigned
Why this is required:
PowerShell blocks unsigned scripts by default.
RemoteSigned allows:
• Local scripts → run without signing
• Downloaded scripts → must be signed
This is the minimum safe execution policy for PowerShell automation.
Security Note ACHILLES modifies system-level registry keys and security policies. Some changes (e.g., USB storage, firewall rules, encryption) may impact normal system behavior.
Security breaches are rarely caused by broken software — they are caused by misconfiguration.
- Default settings are insecure
- Manual hardening does not scale
- Hardened systems drift over time
ACHILLES solves this by enforcing repeatable, auditable, and automated hardening.
Hardening is not a one-time checklist.
ACHILLES treats hardening as a closed-loop lifecycle:
- Establish a secure baseline
- Continuously audit the system
- Detect configuration drift
- Automatically remediate deviations
- Restore the Root of Trust
ACHILLES organizes security controls into four critical domains to ensure complete coverage.
- Disable guest and anonymous accounts
- Enforce least privilege (UAC)
- Control user access paths
Mapped Standards
- NIST AC-2
- ISO 27001 A.9.2
- DISA STIGs
- Enforce full disk encryption (BitLocker)
- Protect data at rest from physical compromise
Mapped Standards
- NIST 800-171 (3.13.11)
- CIS Benchmarks
- Enable host-based firewalls
- Disable legacy and unnecessary services
- Block removable storage (USB)
Mapped Standards
- NIST CM-7 (Least Functionality)
- ISO 27001 A.12.6.1
- Compliance status reporting
- Logging and audit readiness
- Clear security posture visibility
ACHILLES strictly aligns with:
- NIST SP 800-53
- ISO/IEC 27001
- DISA STIGs
- CIS Benchmarks
No assumptions. No guessing. Only prescriptive guidance.
ACHILLES uses a PowerShell-based checklist automation engine.
-
Audit
- Scans the system against the defined baseline
-
Report
- Generates an HTML compliance report (Pass / Fail)
-
Remediate
- Automatically applies secure configurations
- Restores the trusted baseline
- Windows endpoint hardening
- Pre-deployment system validation
- Compliance preparation (ISO / NIST / CIS)
- Drift detection after updates
- Blue team / SOC baseline enforcement
- Windows OS
- PowerShell 5.1+
- Administrative privileges
ACHILLES applies system-level security changes. Always review controls and test in a non-production environment before deployment.
This project is under active development and intended for:
- Cybersecurity learning
- Internal hardening automation
- Blue team and defensive security use cases
This project is licensed under the MIT License.
Copyright (c) 2025 Mousa M. Mousa, Omar Fadel, Marwan Ramadan, Fares Sobhy.