Automation for technicians present at the machine
The Technician Toolkit is a menu-driven PowerShell suite of 48 tools for IT technicians. It turns the repetitive parts of the job — onboarding, diagnostics, security audits, network sweeps, cloud assessments, and migrations — into guided, reportable, and repeatable operations.
What it is
Every tool is a standalone PowerShell script that auto-elevates, walks the technician through what it needs with real-time feedback, and — for anything diagnostic — emits a polished dark-themed HTML report you can attach straight to a ticket. There are no opaque one-liners and nothing runs silently when a human is watching.
The hub, GRIMOIRE, ties it together: a categorized launcher that auto-elevates, downloads any missing scripts from GitHub on first use, and returns to the menu after each tool finishes. Every tool still runs independently without the hub, so nothing forces you through the launcher.
The toolkit is built for technicians working physically at a machine or
through a full interactive remote session (RDP, Enter-PSSession,
WinRM). For non-interactive, parameter-only execution through Kaseya VSA LiveConnect, RMM
hooks, or scheduled runners, see the LiveConnect
companion suite — 21 scripts rewritten from scratch with no menus,
prompts, or interactive calls.
Two ways to run it
As of 5.0 the suite ships in two forms that run the same tools from the same source — the application drives the scripts, it does not replace them.
The application is one portable .exe with
PowerShell 7 hosted inside it, so the target machine needs no runtime, no modules, and no
internet connection. It runs tools in a real window with live output and watches for the
HTML reports they produce — built for carrying on a USB stick and walking up to a machine.
Install with winget install CursedTechnocrat.TechnicianToolkit or
download it from Releases
(x64 and ARM64). The 5.0 binaries are not yet code-signed, so SmartScreen will warn on first
run — check the SHA-256 in the release notes against your download.
The scripts are 48 .ps1 files plus the
shared module, running on the Windows PowerShell 5.1 already on every machine. They remain
the primary documented path and the best fit for remote sessions, scripted runs, or
dropping a single tool onto a box.
Six functional categories
Stand up new machines, push software, install drivers and printers, fix and patch Windows Update, and chain it all into reusable recipes.
Audit system health, services, disks, SMART, firmware, and battery — then roll every HTML report into one index.
BitLocker, security baselines, Active Directory management and access reviews, certificates, persistence, TPM, and Defender — audited or enforced.
Diagnose connectivity, sweep subnets, run tools over WinRM, and audit Wi-Fi and VPN posture.
Survey Azure, M365, Intune, Teams, SharePoint, and Entra ID for licensing, hygiene, and exposure.
Validate cloud readiness, back up before reimaging, migrate profiles, and discover Outlook data.
Recipes, not just tools
RITUAL is the toolkit's meta-tool: it runs an ordered sequence of scripts as a single named recipe and rolls every result into one HTML report with per-step status, duration, and links to each child report. It ships with six built-in recipes and accepts custom PSD1 recipe files of your own.
New-machine bring-up: join, harden, install, encrypt, and capture a starting-state report.
Pre-reimage workflow: confirm cloud readiness, find mail data, back up, then clean.
Quarterly machine review across system, accounts, disks, services, certs, and Defender.
Read-only endpoint security posture rollup.
Read-only network posture: diagnostics, discovery, Wi-Fi, and VPN.
Cloud control-plane posture across the whole tenant in one sign-in.
Reports that travel with the ticket
Diagnostic tools share a common HTML report template — six summary cards, color-coded status badges, and per-section detail tables — saved to a configurable log directory. CODEX indexes every report on disk into one rollup, while RITUAL bundles the output of a fresh recipe run.
Two newer shared-module features round this out. Technician notes let any tool capture timestamped session notes (Info / Action / Warning / Issue / Resolution) and export them to an HTML report with a plain-text Ticket Summary block sized for pasting straight into a ticket comment. And Teams telemetry — wired into every incident-worthy failure path — fires a webhook notification when something high-impact fails, so a botched domain join or an active malware detection pings the channel instead of scrolling past in a console.
The naming
Every tool carries an arcane codename that doubles as an acronym — GRIMOIRE, COVENANT,
PALADIN, CONDUIT — so the suite reads like a spellbook rather than a folder of
audit-disk-v2-final.ps1 scripts. The theme is cosmetic; the
acronyms are functional. P.A.L.A.D.I.N., for instance, is the Protection
Auditor that Logs Antivirus, Defender, Intrusions & Notifications.
Running it
The scripts run on Windows PowerShell 5.1+ as Administrator, with the shared
TechnicianToolkit.psm1 module co-located alongside the scripts —
GRIMOIRE downloads it automatically, and any single tool fetches it on first run. Each tool's
detail page carries a copy-paste Quick
Launch one-liner that downloads the script from GitHub into your current folder and runs it,
bypassing execution policy for that session only. An optional config.json
(set up via the HEARTH wizard) pre-fills org name, log paths, webhook, and
per-tool defaults to cut down on prompts. The application needs none of this — Windows 10
1809 or later is enough.
These scripts change system settings, install software and updates, and can alter domain membership in ways that require a reboot. Save your work before running, and use at your own risk.
The toolkit is free software under the GNU GPL v3 or later: run it on client machines at any scale, modify it for your own shop, and share your changes under the same terms. Written and maintained by John Joseph Bejarana (@CursedTechnocrat).