Security fixes are applied to the latest public release when maintainers can reproduce and correct the issue.
Use GitHub's Private vulnerability reporting or a private Security Advisory for vulnerabilities that could expose systems, credentials, or data. Do not publish exploitable details in a public issue.
Include only the information needed to reproduce the problem:
- affected project version;
- affected Windows/PowerShell version;
- minimal reproduction steps;
- expected and actual behavior;
- sanitized error output.
Do not include passwords, access tokens, private keys, domain names, usernames, computer names, customer data, internal IP addresses, screenshots containing personal data, or unredacted logs.
- Use the toolkit only on systems you own or are authorized to administer.
- Review the source and test it outside production before deployment.
- Use least privilege and restrict ADMIN$/SMB access to trusted management networks.
- Verify the hash and source of downloaded third-party tools.
- Do not disable or bypass endpoint protection. Create an allow rule only after your security team has reviewed the exact file and hash.
- Keep Windows, PowerShell, PsExec, and endpoint-security products current.
This policy covers the PowerShell and VBScript source code maintained in this repository. Vulnerabilities in PsExec or other Microsoft components should be reported through Microsoft's security channels.