Windows Hardening¶
Reducing the attack surface of Windows hosts and servers through configuration.
Why It Matters¶
Default Windows installations prioritize compatibility over security. Hardening closes the gaps attackers rely on (weak authentication, legacy protocols, excessive privilege) and is the configuration side of the same coin as the detection work in a blue team.
Reference¶
Baselines¶
Start from a published baseline rather than a blank checklist:
| Baseline | Source |
|---|---|
| Microsoft Security Baselines | Security Compliance Toolkit |
| CIS Benchmarks | CIS Windows Benchmarks |
| DISA STIGs | DoD STIGs |
Key Areas¶
| Area | Controls |
|---|---|
| Accounts | Rename and disable default accounts, enforce a strong password policy, use LAPS for local admin passwords |
| Authentication | Disable LM/NTLMv1, require SMB signing, disable SMBv1, disable LLMNR and NetBIOS |
| Privilege | Remove local admin rights, use separate admin accounts, apply least privilege |
| Attack surface | Uninstall unneeded roles and features, disable unused services, host firewall on |
| Application control | AppLocker or WDAC to allowlist executables |
| Patching | Timely updates via WSUS, Intune, or SCCM |
| Logging | Enable advanced audit policy, PowerShell script block logging, and forward to a SIEM |
| Defender | Enable Defender, controlled folder access, and attack surface reduction rules |
How I Use It¶
I apply a CIS or Microsoft baseline through Group Policy or Intune rather than hand-configuring each host, then tune exceptions. The Harden-DomainController and System-Hardening scripts in this toolkit apply a baseline set of these controls, and audit logging ties back to the detection side.
Test baselines before deploying
Security baselines can break legacy applications and protocols. Pilot them on a test group, confirm what breaks, and remediate before a wide rollout.