TestimoX provides forest-aware Active Directory, Windows, infrastructure, and authorized benchmark assessment. It discovers the real target scope, collects shared data once, evaluates typed rules, and produces explicit coverage with integrity-protected results.
This public repository is the place to get community help, report a problem, request a rule or integration, and discuss how TestimoX works with Maester. It does not contain the TestimoX source code.
Website · Maester integration · Assessment contract · Discussions
- Report a TestimoX problem
- Report a TestimoX.Maester integration problem
- Request a rule or benchmark improvement
- Request a product feature
- Report a documentation problem
- Ask a question or share an idea
Search existing issues and discussions first. Use an issue for a reproducible defect or concrete piece of work. Use a discussion for questions, design ideas, deployment patterns, and community experience.
flowchart LR
Targets["AD forests, domains, DCs, Windows hosts, workloads"]
Engine["TestimoX assessment engine"]
Contract["Typed assessment document<br/>coverage + signed outcomes"]
Adapter["TestimoX.Maester"]
Maester["Maester reports, notifications, and CI"]
Targets --> Engine
Engine --> Contract
Contract --> Adapter
Adapter --> Maester
TestimoX owns target discovery, collection, applicability, outcomes, benchmark authorization, coverage, and artifact integrity. Maester owns orchestration, presentation, notifications, and CI. The adapter does not query Active Directory once per test or duplicate TestimoX rule logic.
The current module uses Maester's Pester custom-test contract on Maester 2.x and on Maester 3.x compatibility hosts. A future native Maester 3 path will use the same typed TestimoX assessment document after Maester publishes an external-provider API.
The free Maester path is intended to include the complete current TestimoX rule catalog, forest-aware and multi-domain collection, locally authorized benchmark outcomes, explicit target and rule coverage, signed portable results, and Maester reporting and CI.
Licensed TestimoX capabilities add richer evidence, investigation records, Office/PDF/full JSON reporting where supported, localization, branding, historical workspaces, replay and comparison, monitoring, scheduling, organizational policy, governed remediation, deployment, scale, and commercial support.
Assessment coverage is not the paywall. The commercial value is what an organization can prove, package, customize, retain, operate, and remediate after the scan.
Open an issue here when:
- a TestimoX result, target, coverage count, or warning looks wrong
- TestimoX missed a forest, domain, controller, computer, or workload
- a package, signature, CLI, or
TestimoX.Maesterimport failed - you need a TestimoX rule, benchmark, workload, or integration improvement
Use Maester upstream when the problem reproduces without TestimoX and concerns the generic Maester engine, report rendering, notification delivery, or built-in Maester checks.
Issues and discussions are public. Never post:
- credentials, tokens, private keys, certificates with private keys, or license material
- raw audit packages, unredacted assessment JSON, or evidence files
- internal host names, domain names, user names, IP addresses, or file paths you cannot disclose
- proprietary benchmark source text, rationale, remediation text, or desired configuration values
Use sanitized coverage counts, stable error codes, and the minimum redacted excerpt needed to explain the problem. For a security vulnerability, use GitHub's private vulnerability reporting instead of a public issue.
Thank you for helping make TestimoX better.
