Windows-SysAdmin-ProSuite is an enterprise-grade, research-aligned automation platform for Windows Server, Windows 10/11, Active Directory, Identity and Access Management, enterprise PKI, WSUS, Group Policy, ITSM, Blue Team, and DFIR operations — authored and maintained by Luiz Hamilton Silva (@brazilianscriptguy).
Built around production-oriented PowerShell and VBScript automation, reusable administrative frameworks, structured logging, deterministic packaging, and GitHub Actions-based release engineering, the suite addresses seven core operational pillars:
| Pillar | Scope |
|---|---|
| 🔐 Identity & Access Management | Active Directory lifecycle · LDAP/SSO · IAM · credential hygiene |
| 🔏 Enterprise PKI & Certificate Services | AD CS · CA administration · certificate lifecycle · repository management |
| 🖥️ ITSM-Aligned Provisioning | Standardized Windows workstation and server lifecycle automation |
| 🛡️ Cybersecurity & Hardening | Group Policy · security baselines · configuration control · drift remediation |
| 🔬 Digital Forensics & DFIR | EVTX analysis · event correlation · evidence collection · incident response |
| 🔄 Update & Infrastructure Management | WSUS · SUSDB · DNS · DHCP · network services · infrastructure administration |
| 📋 Operational Auditability | Structured .log output · .csv reporting · validation · traceable execution |
Tooling is engineered around runtime safety, explicit administrative intent, deterministic logging, operational traceability, PowerShell 5.1 compatibility, and controlled change management.
This repository is not intended as a collection of isolated demonstrations or disposable scripts. It is a cohesive automation and administration suite designed for production-oriented use across:
| Environment | Primary Use Case |
|---|---|
| 🏛️ Public sector & judicial institutions | Compliance-driven administration · standardized provisioning · operational audit trails |
| 🏢 Enterprise & hybrid infrastructures | Active Directory · PKI · WSUS · DNS · DHCP · GPO · Windows Server administration |
| 🔐 IAM & identity engineering | AD lifecycle · LDAP/SSO integration · access governance · credential hygiene |
| 🔏 PKI & certificate services | AD CS · Certificate Authority administration · certificate lifecycle and repository management |
| 🛡️ Blue Team / DFIR operations | Threat hunting · EVTX analysis · incident response · forensic collection |
| 📋 Governance, risk & compliance teams | GPO enforcement · configuration control · ITSM-aligned change management |
| 🎓 Academic & research environments | Citeable automation and security tooling supported by documented research |
Ten specialized functional modules — independently usable and collectively integrated through a common engineering, documentation, and release model.
The repository release architecture manages 12 distribution packages: the 10 functional modules below plus the aggregate
All-Repository-FilesandREADMEs-Files-Packagedistributions.
The GitHub Actions release pipeline manages 12 canonical distribution packages using synchronized CHANGELOG headings, managed tag prefixes, release matrices, ZIP archives, SHA256 manifests, and GitHub Releases.
| Distribution Package | Classification |
|---|---|
ADCS-Management-Tools |
Functional module |
AD-SSO-Integrations |
Functional module |
All-Repository-Files |
Aggregate repository distribution |
BlueTeam-Tools |
Functional module |
Core-ScriptLibrary |
Functional module |
GPO-Templates |
Functional module |
ITSM-Templates-SVR |
Functional module |
ITSM-Templates-WKS |
Functional module |
ProSuite-Hub |
Functional module |
READMEs-Files-Package |
Aggregate documentation distribution |
SysAdmin-Tools |
Functional module |
WSUS-Management-Tools |
Functional module |
Nested components under SysAdmin-Tools retain dedicated release identities while participating in parent and repository-wide distributions. Changes to applicable nested components therefore propagate to their standalone package, SysAdmin-Tools, and All-Repository-Files.
The suite follows a common engineering and operational-safety contract:
- ✅ PowerShell 5.1 first — PowerShell 7.x compatibility maintained where applicable
- ✅ Explicit administrative intent — potentially disruptive operations require controlled execution and appropriate confirmation semantics
- ✅ Validation-first execution — prerequisites, dependencies, targets, and operational state are validated before applicable changes
- ✅ Idempotent behavior where practical — repeated execution should converge toward the intended state without unnecessary changes
- ✅ Structured logging and reporting — significant operations produce traceable
.log,.csv, or equivalent structured output where applicable - ✅ No silent failures — actionable errors, warnings, and validation results are surfaced to the operator
- ✅ Credential hygiene by design — production secrets and credentials are externalized rather than embedded in source code
- ✅ Least-privilege administration — privileged operations are constrained to the access required for the requested task
- ✅ Post-change verification — applicable administrative operations validate resulting state after execution
- ✅ ITSM-aligned change management — provisioning, maintenance, remediation, and lifecycle workflows emphasize repeatability and auditability
- ✅ Deterministic release engineering — managed packages use canonical names, automated ZIP creation, SHA256 integrity manifests, and component-specific release metadata
Repository quality and security controls are continuously evaluated through PSScriptAnalyzer, SARIF reporting, CodeQL, Gitleaks, formatting controls, and GitHub Actions CI, with findings feeding controlled remediation and engineering cycles.
CI findings provide operational visibility and support controlled remediation while release automation maintains deterministic package naming, integrity validation, and traceability.
The repository is predominantly PowerShell, with supporting technologies used where required by integration, legacy administration, reporting, and database-maintenance scenarios.
| Language / Technology | Primary Use |
|---|---|
| PowerShell | Windows administration · IAM · AD CS · WSUS · DFIR · ITSM · automation |
| VBScript | Legacy Windows and workstation automation |
| T-SQL / SQL | WSUS SUSDB maintenance and database operations |
| HTML / Web assets | GUI components, documentation, and report presentation |
| PHP | LDAP / SSO integration examples |
| .NET | Active Directory and SSO integration examples |
| Python / Flask | Cross-platform LDAP / SSO integration examples |
| Node.js | Cross-platform LDAP / SSO integration examples |
| Java / Spring Boot | Enterprise LDAP / SSO integration examples |
Exact language percentages may change as the repository evolves; GitHub's repository language statistics remain the authoritative current measurement.
Windows-SysAdmin-ProSuite combines production-oriented Windows systems engineering with research-informed practices in cybersecurity, Identity and Access Management (IAM), Active Directory, enterprise PKI, Group Policy, WSUS, Digital Forensics & Incident Response (DFIR), and IT governance.
The project is structured to support academic, technical, institutional, professional, and policy-oriented citation, providing persistent research identifiers through Zenodo DOI, structured citation metadata through CITATION.cff, and author attribution through ORCID.
APA:
Roberto da Silva, L. H. (2026). Windows-SysAdmin-ProSuite (Version 1.8.8) [Computer software]. Zenodo. https://doi.org/10.5281/zenodo.18487320
Repository DOI: 10.5281/zenodo.18487320
Version: 1.8.8
License: MIT
Citation metadata: CITATION.cff
2025
Roberto da Silva, Luiz Hamilton
"SQL Syntax Models for Building Parsers to Query Event Logs in EVTX Format"
Revista FT — Computer Science, Vol. 29, Issue 142, January 2025
ISSN: 1678-0817 · Qualis: B2
DOI: 10.69849/revistaft/th102502121360
Presents a structured SQL-oriented methodology for querying and parsing Windows Event Log (EVTX) data, supporting security auditing, incident investigation, event correlation, authentication analysis, and Active Directory traceability.
2017 — Federal University of Pernambuco (UFPE)
Roberto da Silva, Luiz Hamilton
"Event Logs: Applying a Log Analysis Model for Auditing Event Record Registration"
Federal University of Pernambuco (UFPE), 2017
Master's Thesis · Computer Science
Keywords: Log Auditing · Digital Forensics · Event Logs · Security Monitoring
Defines a structured methodology for event-log auditing and digital forensic analysis, applying Syslog principles and PowerShell-driven workflows to security-event examination, forensic readiness, operational monitoring, and governance.
2024
Roberto da Silva, Luiz Hamilton
Event Logs: Applying a Log Analysis Model for Auditing Event Record Registration
Sorian, 1st ed., 2024
Print ISBN: 978-65-5453-346-1 · eBook ISBN: 978-65-5453-366-9
DOI: 10.54466/sorianed.978-65-5453-366-9
A practitioner-focused scholarly work on Windows Event Log auditing, forensic readiness, security-event analysis, and vulnerability identification, connecting research methodology with PowerShell-enabled operational workflows.
2009
Roberto da Silva, Luiz Hamilton
Computer Networking Technology: Using GPOs to Secure Corporate Domains
Ciência Moderna, 1st ed., 2009
ISBN: 978-85-7393-835-7
DOI: 10.54236/edcimo.001
Focused on the application of Group Policy Objects (GPOs) to secure and standardize Windows domain environments through centralized policy enforcement, Active Directory administration, security baselines, configuration governance, and domain-level hardening.
Luiz Hamilton Silva — @brazilianscriptguy
Identity & Access Management · Active Directory · Windows Server Architecture · Enterprise PKI · PowerShell Automation · Windows Security · Digital Forensics & Incident Response
The project is maintained at the intersection of enterprise Windows engineering, identity architecture, cybersecurity, infrastructure automation, PKI, DFIR, and applied research.
Its engineering model emphasizes:
- Production-oriented automation for Windows Server and Windows 10/11 environments
- Identity engineering across Active Directory, LDAP, SSO, and IAM workflows
- Enterprise PKI administration through Active Directory Certificate Services and certificate lifecycle management
- Infrastructure management spanning Group Policy, DNS, DHCP, WSUS, SUSDB, and Windows services
- Security engineering and DFIR through event-log analysis, forensic readiness, security auditing, and incident-response tooling
- Reproducibility and auditability through structured logging, deterministic packaging, SHA256 integrity validation, and controlled release automation
- Research-informed engineering connecting academic methodology with operational systems administration and cybersecurity practice
Windows-SysAdmin-ProSuite represents the convergence of operational Windows engineering, identity and security architecture, automation, and research — developed as a maintainable, auditable, reproducible, and citeable open-source platform.
Contributions are welcome. Review CONTRIBUTING.md before submitting a pull request.
- Pull requests — bug fixes, documentation improvements, security improvements, automation enhancements, and new tools aligned with repository engineering principles
- Attribution — reuse and derivative works must comply with the repository's MIT License terms
- Academic / institutional reuse — cite the repository DOI or use the metadata provided in
CITATION.cff - Security disclosures — follow the
SECURITY.mdresponsible-disclosure process - Release governance — component naming and CHANGELOG structures should remain compatible with the automated 12-package release architecture
"Engineering secure, auditable, and scalable Windows automation for enterprise and public-sector environments — grounded in operational practice and research."
© 2026 Luiz Hamilton Silva · MIT License · CHANGELOG · CITATION
Core Expertise: PowerShell automation · Windows PowerShell 5.1 · PowerShell 7 · Windows systems administration · Windows Server · Windows 10 · Windows 11 · Active Directory · Active Directory Domain Services · AD DS · Active Directory Certificate Services · AD CS · enterprise PKI · Public Key Infrastructure · Certificate Authority administration · CA maintenance · certificate lifecycle management · certificate repository management · certificate hygiene · Identity and Access Management · IAM · LDAP · LDAPS · Single Sign-On · SSO · authentication integration · Group Policy · Group Policy Objects · GPO · GPO lifecycle management · DNS · DHCP · Windows Server Update Services · WSUS · SUSDB · Windows Internal Database · WID · SQL Server · patch management · update infrastructure · WSUS maintenance · WSUS cleanup · SUSDB reindexing · network infrastructure administration · system configuration · software deployment · ITSM · workstation lifecycle management · server lifecycle management · security hardening · configuration baselines · configuration drift remediation · least privilege · credential hygiene · Blue Team · Digital Forensics and Incident Response · DFIR · incident response · Windows Event Log monitoring · EVTX analysis · event correlation · threat hunting · security auditing · compliance · governance · structured logging · operational traceability · validation-first automation · idempotent automation · PowerShell modular architecture · GUI administration · GitHub Actions · CI/CD · release automation · automated CHANGELOG management · Semantic Versioning · deterministic packaging · NuGet packaging · ZIP distribution · SHA256 integrity validation · PSScriptAnalyzer · SARIF · CodeQL · EditorConfig · Prettier · Gitleaks · secure DevOps · enterprise automation · Windows infrastructure automation · public-sector IT