TestimoX is a local-first Active Directory security, resilience, and remediation-evidence platform. It assesses forests, domains, domain controllers, Group Policy, PKI, DNS, replication, privileged access, Windows systems, and supporting infrastructure through its CLI, PowerShell, service, monitoring, reporting, and integration surfaces.
This public repository is the community front door for the whole TestimoX product. Ask for help, report a problem, challenge an assessment result, request a rule or mapping, suggest an integration, or propose an improvement here. The repository does not contain the private TestimoX source code.
Website · Get started · Maester integration · Rule catalog · Pricing · Discussions
- Report a TestimoX problem
- Challenge an assessment or report result
- Request a rule, control, or framework mapping
- Report a TestimoX.Maester integration problem
- Report another integration problem
- Request a product feature
- Report a documentation problem
- Ask a question or share an idea
Search existing issues and discussions first. Use an issue for a reproducible defect, incorrect result, or concrete piece of work. Use a discussion for questions, deployment patterns, design ideas, and community experience.
Open an issue here when:
- a TestimoX result, severity, score, target, affected object, coverage count, or warning looks wrong;
- TestimoX missed a forest, domain, controller, computer, workload, or expected rule;
- a CLI, PowerShell, service, monitoring, package, signature, import, replay, report, or export workflow failed;
- a remediation step, public reference, compliance mapping, or explanation is missing or misleading;
- a TestimoX integration needs a compatibility or projection improvement;
- the public documentation or installation path is incomplete.
Use GitHub private vulnerability reporting for a security problem. Use commercial contact for licensing, a delivered audit, enterprise deployment, or support covered by an agreement.
Maester is a first-class TestimoX integration with its own support route. TestimoX.Maester projects a signed TestimoX assessment into Maester for users who want its Pester orchestration, reports, notifications, or CI workflow. TestimoX remains the collection and assessment owner, and the normal TestimoX CLI and PowerShell workflows do not require Maester.
Use the dedicated TestimoX.Maester form when TestimoX data, coverage, packages, or the adapter are involved. Use Maester upstream only when the same problem reproduces without TestimoX and concerns Maester's own engine, built-in tests, report rendering, notifications, or CI behavior. Other adapters keep their own generic integration route.
Include only the minimum sanitized information needed to reproduce or understand the problem:
- TestimoX version and the surface used: CLI, PowerShell, service, monitoring, report, API, or integration;
- supported Windows and PowerShell/.NET versions where relevant;
- rule or finding identifier, target type, and requested versus observed coverage;
- expected behavior, actual behavior, and the smallest safe reproduction;
- stable error or warning codes and a short redacted diagnostic excerpt;
- whether the result is new, unchanged, resolved, or regressed when history is involved.
Issues and discussions are public. Never post:
- credentials, tokens, activation codes, license files, private keys, or certificates containing private keys;
- raw audit packages, unredacted assessment JSON, databases, reports, or evidence files;
- internal host, domain, user, group, tenant, IP, URL, or file-path details you cannot disclose;
- proprietary benchmark text, rationale, remediation text, desired values, or source documents;
- logs or screenshots you have not reviewed and sanitized.
Use fictional replacements consistently when identities matter to the explanation. For a security vulnerability or a report that cannot be safely reduced, use a private route and share only the minimum necessary data.
Community support in this repository is public and best effort. Complete core assessment findings are not hidden behind a support contract.
Licensed support, commercial third-party use, partner operation, enterprise deployment, custom development, and delivered audit engagements are separate services. See Support routes before sending private material.
Thank you for helping make TestimoX better.
