BTPS Security Package¶
Blue Team PowerShell
Practical Windows security tooling for smaller IT and security teams.
BTPS is a collection of PowerShell scripts, scheduled-task templates, event-monitoring helpers, hardening commands, and incident-response utilities designed to improve visibility and defensive coverage in Windows-centric environments.

Important
BTPS is a defensive administration toolkit, not a substitute for a complete security program. Review every script before deployment, test changes in a non-production environment, and adapt paths, credentials, mail settings, scheduled tasks, and event subscriptions to your organization.
What is included?¶
Monitor lockouts, unlocks, expiring accounts, password activity, and account creation.
PowerShell helpers for SMB signing, NLA, weak SSL removal, DoH, HSTS, file permissions, Kerberos keys, and more.
Tools for suspicious sign-ins, service creation, DNS zone transfers, LDAP binds, Sysmon, WEF, and local port-scan monitoring.
Find newly observed devices and enrich MAC addresses with vendor information.
Utilities for locating user sessions and helping remediate compromised Microsoft 365 accounts.
Installer and task-import helpers provide a starting point for repeatable deployment.
Recommended reading order¶
Start with Getting started, review the Security and deployment safety notes, and then choose the relevant area from Component catalog. For the original, detailed deployment and configuration material—including WinRM over HTTPS, WEF Group Policy settings, certificates, SQL/WEF application setup, installer details, and troubleshooting—see Welcome to The B.T.P.S Security Package’s documentation!. For event collection and alerting, continue to Event monitoring, WEF, and Sysmon. If you are responding to a suspected compromise, see Incident response helpers.