Read-only · Agentless · Offline-capable

Every Windows endpoint,
audited — and provably so.

EWSAF runs modular, read-only checks across Windows endpoints and servers, then turns the results into evidence-backed reports your security, governance, and audit teams can all trust — without installing an agent or touching production systems.

Read-only by design No agent to install Works fully offline SHA-256 evidence chain
Findings map to controls in
  • CIS Benchmark
  • NIST 800-53
  • NIST CSF
  • ISO 27001
  • PCI DSS
  • HIPAA
  • SOC 2
  • Essential Eight
How an audit run works

Four steps, no moving parts to trust blindly

The same sequence runs every time, on every host — which is exactly what makes the output defensible.

01

Discover

Point EWSAF at a Windows host or server. It reads posture using native OS tooling only — nothing is installed.

02

Execute checks

Each of the 60 modules runs in its own independent failure domain, strictly read-only, with no mutation operations.

03

Preserve evidence

Raw command output is captured as-is and indexed into EvidenceManifest.json and AuditManifest.json with SHA-256 hashes.

04

Report

Executive and technical deliverables are generated locally — ready for governance, operations, or audit review.

Not just IT departments — anyone running critical systems

Any organization with Windows endpoints or servers carries audit and compliance exposure. Three sectors below are backed by a documented engagement pattern further down this page; EWSAF is built to fit well beyond them too.

Also built for
IT & managed services
Education
Logistics
Retail
Legal
Public sector

How teams put an audit run to work

These are representative engagement patterns describing how EWSAF is typically deployed for each scenario, based on common deployment patterns for organizations of this shape — not disclosures of a specific named customer.

Healthcare · 600+ endpoints

Clinical workstation hardening ahead of a HIPAA review

3 weeks → 2 daysEvidence prep time
600+Endpoints covered, zero agents
100%Runs completed with clinical systems untouched
Challenge
A distributed clinical environment needed defensible evidence of endpoint hardening before a HIPAA Security Rule review, without installing anything on machines tied to patient care.
Approach
Ran EWSAF's baseline and identity modules across nursing-station and admin workstations from portable media, entirely read-only, with no agent install and no scheduled downtime required.
Outcome
Produced hashed evidence manifests and an executive summary mapped to HIPAA technical safeguards, cutting the usual multi-week manual evidence-gathering cycle to under two days.
BFSI · Mid-market NBFC

Board-level evidence for a regulator-facing audit cycle

40+Findings mapped to CIS & NIST controls
0Production changes made during assessment
1Signed manifest per host, ready for the auditor
Challenge
An internal audit team needed control-by-control evidence for a board and regulator review, but could not risk an agent-based scanner touching production trading and core-banking-adjacent hosts.
Approach
Used the free and premium module tiers together to cover account hygiene, RDP/SMB exposure, and privileged-access posture, with compliance mapping run against CIS and NIST 800-53 controls.
Outcome
Delivered a signed, tamper-evident report package the internal audit team could hand to the board and external assessors directly, with every finding traceable back to raw evidence.
Manufacturing · Plant-floor Windows hosts

Auditing legacy OT-adjacent machines without touching uptime

12Legacy hosts assessed, some over a decade old
SMBv1Legacy protocol exposure flagged for remediation
OfflineEntire assessment run with no network egress
Challenge
Plant-floor Windows hosts running older builds could not tolerate an agent install or any risk of disrupting a production line, but still needed a documented security baseline.
Approach
Ran EWSAF from removable media on each host during a scheduled maintenance window, entirely offline, surfacing legacy protocol and patch-posture exposure without any change to the running configuration.
Outcome
Gave the plant's IT lead a prioritized, evidence-backed remediation list — including legacy SMBv1 exposure that had gone undetected — without a single minute of unplanned downtime.
60 modules, two tiers

Start free. Unlock deeper checks when you need them.

Every EWSAF install ships with the full baseline catalog. A signed offline license unlocks the advanced module set — no reinstall, no change to your evidence pipeline.

Free baseline

Modules 001–040

Everything needed to run a complete audit and generate governance-ready reports, forever, at no cost.

  • Local account & privilege hygiene checks
  • OS hardening baseline checks
  • Patch & update posture visibility
  • Network exposure & listening service checks
  • Logging & audit policy configuration checks
  • Baseline compliance mapping output
  • Full executive & technical reporting suite
  • Evidence manifests with SHA-256 hashes

Premium modules

Modules 041–060

Deeper, higher-signal checks for teams that need to go beyond the baseline — unlocked with one signed license file.

  • Deep service analysis
  • AppLocker effective policy review
  • Credential exposure controls
  • WinRM hardening deep checks
  • Backup & recovery posture
  • DLP policy controls
  • Defender ASR deep profile

Full catalog: 60 modules, organized by what you actually evaluate a security tool by

Grouped into eight areas — identity, endpoint protection, network, logging, platform integrity, infrastructure roles, patch/baseline, and deep AD hardening — so you can see coverage at a glance instead of scrolling a flat list. Expand a group, or search by name or module ID.

40 free 20 premium

Latest release

Every downloadable package is hashed the moment it's published, so what you download is exactly what was signed off.

Loading the latest release…
Simple, per-system pricing

Pay only for the modules you unlock

The free tier is not a trial. You can download, install, and use the baseline modules indefinitely without ever purchasing premium.

Baseline

Free tier

₹0/ forever

Modules 001–040, full reporting, and evidence manifests — no license file required.

  • 40 baseline audit modules, always unlocked
  • Executive and technical reports included
  • Works fully offline, no account needed
  • No trial clock — keep using it
Get the latest release
Already on the free tier? Nothing changes underfoot. Premium only adds a signed license file — your evidence, reports, and workflow stay exactly the same.

Frequently asked questions

Do I need to install an agent on every endpoint?

No. EWSAF is agentless — it runs read-only checks using native OS tooling and does not require any persistent service to be installed on the endpoint.

Does EWSAF send any data outside my network?

No. EWSAF is offline-ready: evidence capture and report generation happen locally, and the analyst narrative uses a lightweight local text process with no external model dependency.

What happens if I never buy a premium license?

Nothing is taken away. Modules 001–040 and the full reporting suite remain fully installable and usable, indefinitely, at no cost.

How is premium pricing calculated?

Premium is priced per audited system, per year: INR 5000/system/year or USD 65/system/year, depending on your billing currency.

How do I purchase or renew a premium license?

Contact [email protected]. Licenses are issued offline as a signed file with entitlements and an expiration date set by the issuer, and activate on any machine — no per-device binding required.

Is the evidence EWSAF collects tamper-evident?

Yes. Every run produces an EvidenceManifest.json and an AuditManifest.json containing SHA-256 hashes of captured artifacts and generated reports.

Can non-technical stakeholders understand the reports?

Yes. ExecutiveSummary.html is written for governance and leadership audiences, with a plain-language local narrative, while TechnicalReport.html gives engineering teams the full detail they need.

Where can I get help running an audit or reading a report?

Reach the technical support team at [email protected].

Ready to see what your Windows fleet actually looks like?