Security
HERALD
AD account roster & access-level review.
Answers the two questions a customer security review asks — what authentication controls are in place, and who has an account and what can each of them do? Scores the domain password and lockout policy (and any fine-grained PSOs) as Strong / Acceptable / Weak in paste-ready prose, expands effective nested group membership, and classifies every account as Domain Administrator, Delegated Administrator, Elevated (custom group), or Standard User with review flags. Exports HTML plus a review CSV the customer can mark up. Read-only.
Quick Launch
Run HERALD
Run in an elevated PowerShell window. Downloads herald.ps1
from CursedTechnocrat/TechnicianToolkit and executes it.
Set-ExecutionPolicy Bypass -Scope Process -Force; $f="$(Get-Location)\herald.ps1"; irm https://raw.githubusercontent.com/CursedTechnocrat/TechnicianToolkit/main/herald.ps1 -OutFile $f; [IO.File]::WriteAllText($f,[IO.File]::ReadAllText($f,[Text.Encoding]::UTF8),[Text.UTF8Encoding]::new($true)); & $f