Reporting
Each platform audit produces an HTML report that opens with What Changed Since Last Run, then every finding with severity, current versus recommended values, and remediation steps. Exporters turn the same results into the formats below.
The three platform audits
Active Directory
Invoke-ADAudit
211 checks · 15 check families
On-premises Active Directory: Kerberos, ACLs and delegation, certificate services, Group Policy, trusts, privileged accounts, password policy, and Tier 0 protection.
Entra ID / M365
Invoke-EntraAudit
257 checks · 17 check families
Entra ID, Azure, Intune, and Microsoft 365: conditional access, EIDSCA, Exchange Online, SharePoint, Teams, applications, and governance.
Google Workspace
Invoke-GWSAudit
168 checks · 11 check families
Google Workspace: admin management, authentication, Drive, Gmail, groups, OAuth, devices, and logging.
Report formats
- Executive Summary. Board-ready one-page security overview with the Guerrilla Score.
- Technical Report. Every finding with check IDs, current versus recommended values, and remediation steps.
- Remediation Playbook. Phase-based step-by-step guide organized by severity.
- Remediation Scripts. Auto-generated PowerShell scripts with safety checks and rollback comments.
- Budget Justification. Cost-tier remediation grouped for leadership approval.
- Dashboard. Unified multi-platform visual dashboard with score ring and findings table.
- PDF Export. Convert any HTML report to PDF via headless browser.