About the Toolkit · v5.1

Automation for technicians present at the machine

The Technician Toolkit is a menu-driven PowerShell suite of 48 tools for IT technicians. It turns the repetitive parts of the job — onboarding, diagnostics, security audits, network sweeps, cloud assessments, and migrations — into guided, reportable, and repeatable operations.

What it is

Every tool is a standalone PowerShell script that auto-elevates, walks the technician through what it needs with real-time feedback, and — for anything diagnostic — emits a polished dark-themed HTML report you can attach straight to a ticket. There are no opaque one-liners and nothing runs silently when a human is watching.

The hub, GRIMOIRE, ties it together: a categorized launcher that auto-elevates, downloads any missing scripts from GitHub on first use, and returns to the menu after each tool finishes. Every tool still runs independently without the hub, so nothing forces you through the launcher.

The toolkit is built for technicians working physically at a machine or through a full interactive remote session (RDP, Enter-PSSession, WinRM). For non-interactive, parameter-only execution through Kaseya VSA LiveConnect, RMM hooks, or scheduled runners, see the LiveConnect companion suite — 21 scripts rewritten from scratch with no menus, prompts, or interactive calls.

Two ways to run it

As of 5.0 the suite ships in two forms that run the same tools from the same source — the application drives the scripts, it does not replace them.

The application is one portable .exe with PowerShell 7 hosted inside it, so the target machine needs no runtime, no modules, and no internet connection. It runs tools in a real window with live output and watches for the HTML reports they produce — built for carrying on a USB stick and walking up to a machine. Install with winget install CursedTechnocrat.TechnicianToolkit or download it from Releases (x64 and ARM64). The 5.0 binaries are not yet code-signed, so SmartScreen will warn on first run — check the SHA-256 in the release notes against your download.

The scripts are 48 .ps1 files plus the shared module, running on the Windows PowerShell 5.1 already on every machine. They remain the primary documented path and the best fit for remote sessions, scripted runs, or dropping a single tool onto a box.

Six functional categories

48 tools

Recipes, not just tools

RITUAL is the toolkit's meta-tool: it runs an ordered sequence of scripts as a single named recipe and rolls every result into one HTML report with per-step status, duration, and links to each child report. It ships with six built-in recipes and accepts custom PSD1 recipe files of your own.

Onboard

New-machine bring-up: join, harden, install, encrypt, and capture a starting-state report.

COVENANT → SIGIL → CONJURE → CIPHER → AUSPEX → ARTIFACT
Retire

Pre-reimage workflow: confirm cloud readiness, find mail data, back up, then clean.

TETHER → EXHUME → ARCHIVE → CLEANSE
HealthCheck

Quarterly machine review across system, accounts, disks, services, certs, and Defender.

AUSPEX → WARD → THRESHOLD → AUGUR → GARGOYLE → ARTIFACT → PALADIN
SecuritySweep

Read-only endpoint security posture rollup.

SIGIL → TALON → TOTEM → PALADIN → ARTIFACT
NetworkSweep

Read-only network posture: diagnostics, discovery, Wi-Fi, and VPN.

LEYLINE → LANTERN → BEACON → PORTAL
TenantSweep

Cloud control-plane posture across the whole tenant in one sign-in.

TALISMAN → RELIQUARY → GOLEM → WRAITH → CONCLAVE → GROVE

Reports that travel with the ticket

Diagnostic tools share a common HTML report template — six summary cards, color-coded status badges, and per-section detail tables — saved to a configurable log directory. CODEX indexes every report on disk into one rollup, while RITUAL bundles the output of a fresh recipe run.

Two newer shared-module features round this out. Technician notes let any tool capture timestamped session notes (Info / Action / Warning / Issue / Resolution) and export them to an HTML report with a plain-text Ticket Summary block sized for pasting straight into a ticket comment. And Teams telemetry — wired into every incident-worthy failure path — fires a webhook notification when something high-impact fails, so a botched domain join or an active malware detection pings the channel instead of scrolling past in a console.

The naming

Every tool carries an arcane codename that doubles as an acronym — GRIMOIRE, COVENANT, PALADIN, CONDUIT — so the suite reads like a spellbook rather than a folder of audit-disk-v2-final.ps1 scripts. The theme is cosmetic; the acronyms are functional. P.A.L.A.D.I.N., for instance, is the Protection Auditor that Logs Antivirus, Defender, Intrusions & Notifications.

Running it

The scripts run on Windows PowerShell 5.1+ as Administrator, with the shared TechnicianToolkit.psm1 module co-located alongside the scripts — GRIMOIRE downloads it automatically, and any single tool fetches it on first run. Each tool's detail page carries a copy-paste Quick Launch one-liner that downloads the script from GitHub into your current folder and runs it, bypassing execution policy for that session only. An optional config.json (set up via the HEARTH wizard) pre-fills org name, log paths, webhook, and per-tool defaults to cut down on prompts. The application needs none of this — Windows 10 1809 or later is enough.

These scripts change system settings, install software and updates, and can alter domain membership in ways that require a reboot. Save your work before running, and use at your own risk.

The toolkit is free software under the GNU GPL v3 or later: run it on client machines at any scale, modify it for your own shop, and share your changes under the same terms. Written and maintained by John Joseph Bejarana (@CursedTechnocrat).