← Back to ProDirt Apps
🖥️ Windows Single EXE Free · Source-Available

NTFS Folder Audit

Audit NTFS folder permissions across any local path or UNC share

Built by a working MSP engineer — the tool I wished existed. Free, forever.

Download Free → View on GitHub
Free
No licence key. No trial timer. No feature gating. No account.
Every feature works the moment you download it. If it saves you an afternoon of clicking through Security tabs, you're welcome to buy me a coffee ☕ — that's the whole business model, and nothing in the app changes whether you do or not.

Stop Wrestling with icacls and PowerShell

NTFS Folder Audit gives you a fast, readable view of who has access to what across any Windows file share. Scan a local path or a UNC share, expand the folder tree, click any folder to see exactly who has access and where it came from, and hand your client a self-contained interactive HTML report — no PowerShell required.

NTFS Folder Audit scanning a folder tree with the permissions grid

The permissions grid — identity, access type, decoded rights, and inheritance state at a glance.

See what it produces, before downloading anything:
Example scan report  ·  Example comparison report

Genuine output from a sample file server — four folders with broken inheritance, an over-permissive share, and a Deny rule. Search it, expand the tree, open the permission panels. That is what a scan hands you.

🔒 It Never Phones Home

No telemetry. No analytics. No HTTP client anywhere in the source. It reads the filesystem and writes the report you asked for — that's all. Drop it on an isolated or air-gapped network and it behaves identically. The only URLs in the whole app are three links in the About dialog that open in your browser when you click them.

✓ Safe to run on a client's file server

No network connections, no data leaves the machine, no account, no watermarks on reports. What you scan stays with you.

🔧 What It Does

Permissions Grid

Scan any local path or UNC share to a depth you choose. Every folder shows identity, access type, decoded rights, inheritance state and flags.

Broken Inheritance Detection

Instantly flag folders whose ACLs are set explicitly instead of inherited — the first thing worth reviewing in any audit. One click filters the tree to only those folders.

Ownership & Orphaned SIDs

See the owner account per folder — including unresolvable SIDs left behind by deleted accounts, so nothing hides.

Side-by-Side Comparison

Point it at a share and its backup, or two folders that should match, and it highlights every folder whose permissions differ — plus anything present on only one side. See a live example →

Interactive HTML & CSV Export

A self-contained HTML report — searchable, expandable, no external dependencies — you can email to anyone. Or a flat CSV for a spreadsheet or ticketing system. See a live example →

Access-Denied Event Log

Folders your account can't read are surfaced in an event log rather than silently reported as empty — so you always know what you missed.

Command-Line / Headless

The same engine runs from the CLI for scheduled audits: --path, --output, --csv, --depth, --exclude-system, --open.

No Installation

A single self-contained EXE with the .NET runtime bundled in. Copy it to a tools folder, a server, or a USB stick and run — nothing touches Program Files.

⬇️ Download & Run

Grab the latest NTFSFolderAudit.exe from GitHub Releases. There's no installer — copy it and run.

Run it as Administrator. It works without elevation, but any folder whose ACL your account can't read comes back as access-denied (surfaced in the event log, never silently skipped).

The download is ~155 MB because the .NET runtime is bundled inside — the trade for "copy it to any server and it just runs."

⚠️ "Windows protected your PC"? That's expected.

The EXE isn't code-signed with an (expensive) EV certificate, so the first time you run it Windows SmartScreen may show a blue "Windows protected your PC" screen. That's SmartScreen not recognising a new, unsigned app yet — not a virus detection. Click More info → Run anyway. The warning fades once enough people have run the release.

Don't take my word that it's clean. Here's the independent VirusTotal scan of the release EXE → — 70+ antivirus engines, verify it yourself.

👤 Who It's For

MSP Technicians

Audit a client file server fast — drop the EXE on the box, scan, export a report, done. Free to use in paid client work.

IT Admins

Document permissions before a migration and catch broken inheritance before it becomes a support ticket.

Sysadmins

Compare permissions across a share and its backup to verify a migration landed correctly — instant diff.

Compliance & Audit

Produce readable permission reports for reviews without writing a line of PowerShell.

📋 Requirements

📜 Licence

PolyForm Shield 1.0.0 — free to use, not free to resell. In plain terms:

Note: this is a source-available licence, not an OSI open-source one — GitHub lists it as "Other." Using it to deliver IT work to your clients is exactly what it's for; the noncompete only covers selling the software itself.

Free, single EXE, no install, no telemetry. Copy it to any server and run.

Download NTFS Folder Audit — Free →

Saved you an afternoon? Buy me a coffee ☕