Awesome Lists

awesome-windows-domain-hardening

by PaulSec

awesome listpushed over 6 years ago

A curated list of awesome Security Hardening techniques for Windows.

AI summary

Security Hardening Techniques

Provides a curated list of security hardening techniques for Windows

stars
1.8K
forks
265
watching
121
awesome lists
5
entries
69
View on GitHub

Embed the badge

Show how many awesome lists link to your project. The count updates automatically.

Awesome Lists badge
Markdown
[![Awesome Lists Badge](https://awesome.facts.dev/shield/PaulSec/awesome-windows-domain-hardening/links.svg)](https://awesome.facts.dev/awesome/PaulSec/awesome-windows-domain-hardening)
HTML
<a href="https://awesome.facts.dev/awesome/PaulSec/awesome-windows-domain-hardening"><img src="https://awesome.facts.dev/shield/PaulSec/awesome-windows-domain-hardening/links.svg" alt="Awesome Lists Badge" /></a>
Image URL
https://awesome.facts.dev/shield/PaulSec/awesome-windows-domain-hardening/links.svg

What's in the list

69 links in 13 sections, with live GitHub stats.activeno commit in 2y

Initial foothold

  • EMET

    Deploy to Workstations (End of line in July 2018 - Consider keeping EMET for Windows 7 but prioritize upgrades to Windows 10 and Edge)

  • AppLocker

    Use to block exec content from running in user locations (home dir, profile path, temp, etc)

  • Here you go

    Hardening against DMA Attacks? and an interesting article from

  • PowerShell logging

    Enable (v3+) & command process logging

  • Block Office macros

    (Windows & Mac) on content downloaded from the Internet

  • WEF

    Deploy security tooling that monitors for suspicious behavior. Consider using to forward only interesting events to your SIEM or logging system

Initial foothold / Limit capability by blocking/restricting attachments via email/download:

Initial foothold

Reconnaissance

  • GPO

    Increase security on sensitive s

  • (Microsoft ATA)

    Evaluate deployment of behavior analytics

  • NetCease

    Use to prevent unprivileged session enumeration

  • Samri10

    Use to prevent unprivileged local admin collection (this fix already exists in Windows 10 1607 and above)

Lateral Movement

  • (KB2871997)

    Configure GPO to prevent local accounts from network authentication . In addition to this KB, is recommending two other changes in the registry:

  • (Microsoft LAPS)

    Ensure local administrator account passwords are automatically changed & remove extra local admin accounts

  • (Windows Firewall)

    Limit workstation to workstation communication

Privilege Escalation

  • (including GPP)

    Remove files with passwords in SYSVOL

  • PAWs

    Provide Privileged Access Workstations or for all highly privileged work. Those should never have access to the Internet

  • (FGPP)

    Use Managed Service Accounts for SAs when possible

  • Fine-Grained Password Policy

    For systems that do not support Managed Service Accounts, deploy a to ensure the passwords are >32 characters

  • LM/NTLMv1

    Ensure all computers are talking NTLMv2 & Kerberos, deny

Protect Administration Credentials

Protect Administration Credentials / Admin workstations & servers:

Strengthen/Remove Legacy

  • LDAP signing

    Enforce

  • SMB signing

    Enable (& encryption where poss.)

  • shims

    Use to enable old applications that require admin privileges to work by believing they have them

Tools

  • PingCastle

    an Active Directory audit tool (and free!) with pretty good metrics

  • Responder

    A LLMNR, NBT-NS and MDNS poisoner

  • BloodHound

    Six Degrees of Domain Admin

  • AD Control Path

    Active Directory Control Paths auditing and graphing tools

  • PowerSploit

    A PowerShell Post-Exploitation Framework

  • PowerView

    Situational Awareness PowerShell framework

  • Empire

    PowerShell and Python post-exploitation agent

  • Mimikatz

    Utility to extract plaintexts passwords, hash, PIN code and kerberos tickets from memory but also perform pass-the-hash, pass-the-ticket or build Golden tickets

  • Tools Cheatsheets

    (Beacon, PowerView, PowerUp, Empire, ...)

  • UACME

    Defeating Windows User Account Control

  • Windows System Internals

    (Including Sysmon etc.)

  • Hardentools

    Collection of simple utilities designed to disable a number of "features" exposed by Windows

  • CrackMapExec

    A swiss army knife for pentesting Windows/Active Directory environments

  • Rubeus

    Rubeus is a C# toolset for raw Kerberos interaction and abuses

  • Koadic

    Koadic, or COM Command & Control, is a Windows post-exploitation rootkit

  • SILENTTRINITY

    A post-exploitation agent powered by Python, IronPython, C#/.NET

Videos

Slides

Additional resources

More related projects

Add a GitHub project

Missing a project or an awesome list? Paste its GitHub URL and we fetch it right away.