SentinelBro vulnerability scanner
Vulnerability scanner for Windows systems
SentinelBro helps cybersecurity professionals and system administrators view and manage structured security configuration checks efficiently, with a user-friendly interface for categorized security standards and technical guidance on Windows systems. Downloads are limited to registered, verified users.

What SentinelBro checks
- Checks if antivirus is installed and running
- Verifies if audit policy is enabled and logs are being recorded
- Monitors Windows Firewall rules and open ports
- Checks Group Policy security settings
- Verifies if Windows updates (KB patches) are installed
- Checks PowerShell execution policy security
- Analyzes critical Windows Registry security settings
- Checks if SIEM log forwarders are configured and working
- Inspects startup programs and scheduled tasks
- Reads and analyzes system logs for security events
- Verifies critical Windows services are running
- Checks user accounts and their privileges
- Collects detailed system and device information
- Verifies the latest Microsoft security updates
- Provides a final security analysis summary
- Recursively tracks changes across folders and files via Recurse Monitor
- Lists and audits all installed applications (Apps)
- Detects unwanted or malicious applications and lets you remove them (Delete)
- Scans process memory for suspicious RWX regions typical of C2/beacon implants
- Uses a "sleeping beacon" heuristic to catch memory that gets encrypted and decrypted over time
- Searches for and attempts to decode Cobalt Strike configuration blocks by signature
- Monitors live per-process network traffic (ETW-based)
- Detects lateral-movement indicators — active RDP/SMB/WinRM connections and sessions
- Detects listening ports and VPN/tunnel tooling
- Lists saved Wi-Fi network history and the MAC addresses of devices on the network
- Flags shared folders/drives with risky "Everyone: Full Control" permissions
- Distinguishes file copy, move, and delete operations via the USN Journal
- Scans the disk for unusually large files
- Lets you clear USB device history with confirmation and a local audit log
- Extends Autoruns coverage to Winlogon, IFEO, AppInit/AppCert DLLs, and WMI event subscriptions
- Checks boot configuration (BCD/bootmgr) settings
- Lists all elevated (SYSTEM/Administrator) processes
- Lists OS restore points with dates
- Shows crash (BSOD) and unexpected restart history
- Checks environment variables, PATH folders, and PATH-hijacking risk
- Runs threat-intel scans against the LOLBAS and LOLDriver (BYOVD) databases
- Checks whether the installed Windows version has reached end of life (EOL)
- Provides step-by-step, regedit-free GUI remediation guidance for every check
Full detail on every release
Each published version gets its own page with a changelog, release date, and technical notes.
View release historySecurity, taken seriously
- All connections are encrypted; session cookies are server-controlled only
- Every sign-in and registration attempt is written to an audit log
- Verification codes are stored hashed and expire quickly
Audit your Windows systems today
Registration takes about two minutes. SentinelBro handles the rest.
Get startedSentinelBro release 2.0.0 · ~5 MB
