Harden TLS on Windows without touching the registry by hand. Toggle protocols by
Client and Server role, order cipher suites, apply one of six built-in templates,
and export a deployable PowerShell script or .reg file. Portable executable, no
installer.
Enable or disable SSL 2.0 through TLS 1.3 independently for Client and Server roles. Clear insecure flags on anything that should not be running in a production environment.
Cipher Suite Ordering
Full Windows SCHANNEL cipher list with strength classification. Click any row to toggle. Exported PowerShell sets the priority order via the Cryptography policy key, no Group Policy editor required.
Six Built-in Templates
Best Practices (NIST SP 800-52 Rev 2), CIS Benchmark L1 / L2, Genetec Security Center 5.11+, PCI DSS 4.0, FIPS 140-2, and Windows Default. One click, everything configured.
PowerShell + REG Export
Generate a deployable .ps1 or importable .reg file from any configuration. Every export includes author, version, and copyright header. Copy to clipboard or download directly.
Genetec-Aware
Dedicated Genetec SC 5.11+ template tuned for Security Center deployments. Accounts for mixed Omnicast and SV32 environments where legacy Archivers are still in the field.
Portable EXE, Zero Install
Single portable executable. Drop it on a USB, a technician share, or a jump server. UAC elevation is built into the manifest. No installer, no registry entries for the app itself.
Want a heads-up when the alpha drops? Send a note to contact@hans.study with "Study CryptoConfig" in the subject and you will be on the list.
Cookie and analytics preferences
Two tools run by default to help me understand how the site is used. You can turn either off at any time. Cloudflare's server-side analytics is always on and never sees your identity.