WinSentinel scans your Windows machine for firewall gaps, missing updates, weak accounts, exposed services, and dozens of other misconfigurations, then scores your posture out of 100. Everything you need to install it, understand what it audits, and (with Pro) manage a whole fleet is here. The full single-machine tool is free and unlimited.
# install the free CLI from NuGet (needs the .NET SDK)
dotnet tool install --global WinSentinel.Cli
# audit this machine and score its security posture
winsentinel --audit
New to WinSentinel? The CLI reference walks through install, updates, and every command in detail.
Every command, option, and exit code: audit, score, fix-all, history & trends, ignore rules, compliance mapping, benchmarks, inventory, export, monitor, scheduled scans, and self-update.
Read the reference →The full catalog of what WinSentinel checks — firewall, updates, Defender, accounts, network, encryption, PowerShell, event logs, browser and application security, and more — with the risk each check catches.
Browse the modules →Turn standalone agents into a managed fleet: activate a Pro license, run the agent daemon on each machine, and connect them to the central control plane for fleet-wide posture, remote commands, and policy push.
Set up your fleet →Give your security team scoped access: invite members as admin, auditor, or viewer; issue and rotate API tokens; and audit who did what across the fleet from the immutable action log.
Read the RBAC guide →Free is a powerful standalone security agent on one machine — every audit module, one-click fixes, real-time monitoring, scheduled scans, and PDF reports, all local and unlimited. Pro turns those agents into a managed fleet with a control plane: a fleet-wide posture dashboard, remote scan/fix dispatch, policy push, cross-node compliance rollups, and RBAC for teams.
WinSentinel.Cli global tool.Install the free CLI, run winsentinel --audit, and know your Windows security posture in seconds.