← Back to catalog
Diagnostics & Reporting

WARD

Local user account audit.

Audits all local user accounts and exports an HTML report — enabled/disabled state, last logon, group membership with every Administrator flagged, and risky-account detection (no password required, password never set, stale 90+ days). Includes a console summary with flagged accounts highlighted.

Quick Launch

Run WARD

Run in an elevated PowerShell window. Downloads ward.ps1 from CursedTechnocrat/TechnicianToolkit and executes it.

Set-ExecutionPolicy Bypass -Scope Process -Force; $f="$(Get-Location)\ward.ps1"; irm https://raw.githubusercontent.com/CursedTechnocrat/TechnicianToolkit/main/ward.ps1 -OutFile $f; [IO.File]::WriteAllText($f,[IO.File]::ReadAllText($f,[Text.Encoding]::UTF8),[Text.UTF8Encoding]::new($true)); & $f
Category
Diagnostics & Reporting
Identifier
WARD
Tags
accounts, inventory