awesome-windows-domain-hardening
by PaulSec
A curated list of awesome Security Hardening techniques for Windows.
AI summary
Security Hardening Techniques
Provides a curated list of security hardening techniques for Windows
- stars
- 1.8K
- forks
- 265
- watching
- 121
- awesome lists
- 5
- entries
- 69
What's in the list
69 links in 13 sections, with live GitHub stats.activeno commit in 2y
Initial foothold
- EMET
Deploy to Workstations (End of line in July 2018 - Consider keeping EMET for Windows 7 but prioritize upgrades to Windows 10 and Edge)
- AppLocker
Use to block exec content from running in user locations (home dir, profile path, temp, etc)
- Here you go
Hardening against DMA Attacks? and an interesting article from
- PowerShell logging
Enable (v3+) & command process logging
- Block Office macros
(Windows & Mac) on content downloaded from the Internet
- WEF
Deploy security tooling that monitors for suspicious behavior. Consider using to forward only interesting events to your SIEM or logging system
Initial foothold / Limit capability by blocking/restricting attachments via email/download:
- these file types
Ensure are blocked
- Excel file extensions
Block forgotten/unused : IQY, SLK
Initial foothold
- Preventing activation of OLE packages
in Office with the PackagerPrompt registry setting
Reconnaissance
- GPO
Increase security on sensitive s
- (Microsoft ATA)
Evaluate deployment of behavior analytics
- NetCease
Use to prevent unprivileged session enumeration
- Samri10
Use to prevent unprivileged local admin collection (this fix already exists in Windows 10 1607 and above)
Lateral Movement
- (KB2871997)
Configure GPO to prevent local accounts from network authentication . In addition to this KB, is recommending two other changes in the registry:
- (Microsoft LAPS)
Ensure local administrator account passwords are automatically changed & remove extra local admin accounts
- (Windows Firewall)
Limit workstation to workstation communication
Privilege Escalation
- (including GPP)
Remove files with passwords in SYSVOL
- PAWs
Provide Privileged Access Workstations or for all highly privileged work. Those should never have access to the Internet
- (FGPP)
Use Managed Service Accounts for SAs when possible
- Fine-Grained Password Policy
For systems that do not support Managed Service Accounts, deploy a to ensure the passwords are >32 characters
- LM/NTLMv1
Ensure all computers are talking NTLMv2 & Kerberos, deny
Protect Administration Credentials
- Protected Users group
Add all admin accounts to (requires Windows 2012 R2 DCs)
Protect Administration Credentials / Admin workstations & servers:
Strengthen/Remove Legacy
- LDAP signing
Enforce
- SMB signing
Enable (& encryption where poss.)
- shims
Use to enable old applications that require admin privileges to work by believing they have them
Tools
- PingCastle
an Active Directory audit tool (and free!) with pretty good metrics
Responder
A LLMNR, NBT-NS and MDNS poisoner
BloodHound
Six Degrees of Domain Admin
AD Control Path
Active Directory Control Paths auditing and graphing tools
PowerSploit
A PowerShell Post-Exploitation Framework
PowerView
Situational Awareness PowerShell framework
Empire
PowerShell and Python post-exploitation agent
Mimikatz
Utility to extract plaintexts passwords, hash, PIN code and kerberos tickets from memory but also perform pass-the-hash, pass-the-ticket or build Golden tickets
Tools Cheatsheets
(Beacon, PowerView, PowerUp, Empire, ...)
UACME
Defeating Windows User Account Control
- Windows System Internals
(Including Sysmon etc.)
Hardentools
Collection of simple utilities designed to disable a number of "features" exposed by Windows
CrackMapExec
A swiss army knife for pentesting Windows/Active Directory environments
Rubeus
Rubeus is a C# toolset for raw Kerberos interaction and abuses
- Koadic
Koadic, or COM Command & Control, is a Windows post-exploitation rootkit
SILENTTRINITY
A post-exploitation agent powered by Python, IronPython, C#/.NET
Videos
Slides
Additional resources
Sysmon SecuriTay's configuration file
template with default high-quality event tracing
Nothing in this list matches your filter.
Featured in 5 awesome lists
Each link jumps to the spot where the list mentions awesome-windows-domain-hardening.
More related projects
hausec/adape-script1.1K
emilyanncr/windows-post-exploitation528
nextronsystems/aptsimulator2.5K
antoniococo/sharpyshell922
bluscreenofjeff/red-team-infrastructure-wiki4.2K
bats3c/shad0w2.1K
donnemartin/haxor-news4K
govolution/avet1.7K
s1ckb0y1337/active-directory-exploitation-cheat-sheet5.7K
alessandroz/lazagne9.7K
donnemartin/saws5.3K
donnemartin/gitsome7.6K
netspi/esc283
kkawakam/rustyline1.6K