BTPS Security Package

Blue Team PowerShell

Practical Windows security tooling for smaller IT and security teams.

BTPS is a collection of PowerShell scripts, scheduled-task templates, event-monitoring helpers, hardening commands, and incident-response utilities designed to improve visibility and defensive coverage in Windows-centric environments.

BTPS shield logo

Important

BTPS is a defensive administration toolkit, not a substitute for a complete security program. Review every script before deployment, test changes in a non-production environment, and adapt paths, credentials, mail settings, scheduled tasks, and event subscriptions to your organization.

What is included?

Account & password alerts

Monitor lockouts, unlocks, expiring accounts, password activity, and account creation.

Component catalog
Windows hardening

PowerShell helpers for SMB signing, NLA, weak SSL removal, DoH, HSTS, file permissions, Kerberos keys, and more.

Component catalog
Event monitoring

Tools for suspicious sign-ins, service creation, DNS zone transfers, LDAP binds, Sysmon, WEF, and local port-scan monitoring.

Event monitoring, WEF, and Sysmon
Device discovery

Find newly observed devices and enrich MAC addresses with vendor information.

Component catalog
Incident response

Utilities for locating user sessions and helping remediate compromised Microsoft 365 accounts.

Incident response helpers
Scheduled deployment

Installer and task-import helpers provide a starting point for repeatable deployment.

Getting started