3 ms·
Windows has some additional Local Group Policy rules that are pretty killer in newer versions 1. Attack Surface Reduction Rules - Blocks some commonly seen d
by tsujamin 7y ago
Windows has some additional Local Group Policy rules that are pretty killer in newer versions
1. Attack Surface Reduction Rules - Blocks some commonly seen dodgy techniques
2. Credential Guard - Moves LSASS to an isolated VM (break's VMWare etc though, see 5 if this is a dealbreaker)
3. Application Guard (Enterprise Mode) - Transparently virtualises and isolates Microsoft Edge (same caveat as above)
4. Microsoft Defender MAPS and Block at First Site
5. Run LSASS as a protected process
6. Process creation auditing with commandline
7. Powershell script block logging
Most of this is backed into an windows image I run, but maybe I'm a bit paranoid ;)
[1] https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-exploit-guard https://docs.microsoft.com/en-us/windows/security/threat-pro...
[2] https://docs.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard https://docs.microsoft.com/en-us/windows/security/identity-p...
[3] https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-guard/wd-app-guard-overview https://docs.microsoft.com/en-us/windows/security/threat-pro...
[4] https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/enable-cloud-protection-windows-defender-antivirus https://docs.microsoft.com/en-us/windows/security/threat-pro...
[5] https://docs.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection#BKMK_HowToConfigure https://docs.microsoft.com/en-us/windows-server/security/cre...
[6] https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/component-updates/command-line-process-auditing https://docs.microsoft.com/en-us/windows-server/identity/ad-...
[7] https://www.fireeye.com/blog/threat-research/2016/02/greater_visibilityt.html https://www.fireeye.com/blog/threat-research/2016/02/greater...
- tsujamin 7y agoNot that I've used it yet, but there's also the "Hardening Windows 10 Workstations" guide from the ACSC (it might be a bit overkill though) [1] https://www.cyber.gov.au/sites/default/files/2019-03/hardening_win10_1709.pdf https://www.cyber.gov.au/sites/default/files/2019-03/hardeni...
- acct1771 7y agoCurious, do you run any other OS?
- tsujamin 7y agoMacOS for my primary laptop, Windows for my training/travel laptop, *nix in various other places