awesome-windows-domain-hardening

Security Hardening Techniques

Provides a curated list of security hardening techniques for Windows

A curated list of awesome Security Hardening techniques for Windows.

GitHub

2k stars
121 watching
265 forks
last commit: over 6 years ago
Linked from 5 awesome lists

hardeningsecuritywindows

Awesome Windows Domain Hardening / Initial foothold

EMETDeploy to Workstations (End of line in July 2018 - Consider keeping EMET for Windows 7 but prioritize upgrades to Windows 10 and Edge)
AppLockerUse to block exec content from running in user locations (home dir, profile path, temp, etc)
Here you goHardening against DMA Attacks? and an interesting article from
PowerShell loggingEnable (v3+) & command process logging
Block Office macros(Windows & Mac) on content downloaded from the Internet
WEFDeploy security tooling that monitors for suspicious behavior. Consider using to forward only interesting events to your SIEM or logging system

Awesome Windows Domain Hardening / Initial foothold / Limit capability by blocking/restricting attachments via email/download:

these file typesEnsure are blocked
Excel file extensionsBlock forgotten/unused : IQY, SLK

Awesome Windows Domain Hardening / Initial foothold

Preventing activation of OLE packagesin Office with the PackagerPrompt registry setting

Awesome Windows Domain Hardening / Reconnaissance

GPOIncrease security on sensitive s
(Microsoft ATA)Evaluate deployment of behavior analytics
NetCeaseUse to prevent unprivileged session enumeration
Samri10Use to prevent unprivileged local admin collection (this fix already exists in Windows 10 1607 and above)

Awesome Windows Domain Hardening / Lateral Movement

(KB2871997)Configure GPO to prevent local accounts from network authentication . In addition to this KB, is recommending two other changes in the registry:
(Microsoft LAPS)Ensure local administrator account passwords are automatically changed & remove extra local admin accounts
(Windows Firewall)Limit workstation to workstation communication

Awesome Windows Domain Hardening / Privilege Escalation

(including GPP)Remove files with passwords in SYSVOL
PAWsProvide Privileged Access Workstations or for all highly privileged work. Those should never have access to the Internet
(FGPP)Use Managed Service Accounts for SAs when possible
Fine-Grained Password PolicyFor systems that do not support Managed Service Accounts, deploy a to ensure the passwords are >32 characters
LM/NTLMv1Ensure all computers are talking NTLMv2 & Kerberos, deny

Awesome Windows Domain Hardening / Protect Administration Credentials

Protected Users groupAdd all admin accounts to (requires Windows 2012 R2 DCs)

Awesome Windows Domain Hardening / Protect Administration Credentials / Admin workstations & servers:

LLMNRDisable
WPADDisable

Awesome Windows Domain Hardening / Strengthen/Remove Legacy

LDAP signingEnforce
SMB signingEnable (& encryption where poss.)
shimsUse to enable old applications that require admin privileges to work by believing they have them

Awesome Windows Domain Hardening / Tools

PingCastlean Active Directory audit tool (and free!) with pretty good metrics
Responder5,534about 2 years agoA LLMNR, NBT-NS and MDNS poisoner
BloodHound9,972about 2 years agoSix Degrees of Domain Admin
AD Control Path656almost 6 years agoActive Directory Control Paths auditing and graphing tools
PowerSploit11,979about 6 years agoA PowerShell Post-Exploitation Framework
PowerView11,979about 6 years agoSituational Awareness PowerShell framework
Empire7,480over 6 years agoPowerShell and Python post-exploitation agent
Mimikatz19,580about 2 years agoUtility to extract plaintexts passwords, hash, PIN code and kerberos tickets from memory but also perform pass-the-hash, pass-the-ticket or build Golden tickets
Tools Cheatsheets1,044almost 9 years ago(Beacon, PowerView, PowerUp, Empire, ...)
UACME6,448about 2 years agoDefeating Windows User Account Control
Windows System Internals(Including Sysmon etc.)
Hardentools2,935over 2 years agoCollection of simple utilities designed to disable a number of "features" exposed by Windows
CrackMapExec8,501almost 3 years agoA swiss army knife for pentesting Windows/Active Directory environments
SharpSploit1,753about 5 years ago
Rubeus4,199about 2 years agoRubeus is a C# toolset for raw Kerberos interaction and abuses
KoadicKoadic, or COM Command & Control, is a Windows post-exploitation rootkit
SILENTTRINITY2,204almost 3 years agoA post-exploitation agent powered by Python, IronPython, C#/.NET

Awesome Windows Domain Hardening / Videos

Beyond the Mcse: Active Directory for the Security Professional
BSides DC 2016 - PowerShell Security: Defending the Enterprise from the Latest Attack Platform
Six Degrees of Domain Admin... - Andy Robbins, Will Schroeder, Rohan Vazarkar
111 Attacking EvilCorp Anatomy of a Corporate Hack
Red vs Blue: Modern Active Directory Attacks & Defense
Offensive Active Directory with Powershell
Advanced Incident Detection and Threat Hunting using Sysmon and Splunk
Real Solutions From Real Incidents: Save Money and Your Job!
AppLocker Bypass Techniques

Awesome Windows Domain Hardening / Slides

From Workstation To Domain Admin - Why Secure Administration Isn't Secure
Exploiting AD Administrator Insecurities
How to go from Responding to Hunting with Sysinternals Sysmon
111 Attacking EvilCorp Anatomy of a Corporate Hack
Real Solutions From Real Incidents: Save Money and Your Job!

Awesome Windows Domain Hardening / Additional resources

ADSecurity
Harmj0y's blog
Sysmon SecuriTay's configuration file4,828about 2 years agotemplate with default high-quality event tracing
Explaining and adapting Tay’s Sysmon configurationand
Use of PSExec
Preventing Mimikatz attacks
Useful list of Windows Security Log Events
Introducing SharpSploit: A C# Post-Exploitation Library
From Kekeo to Rubeus
Windows oneliners to download remote payload and execute arbitrary code
Configuration guidance for implementing the Windows 10 and Windows Server 2016 DoD Secure Host Baseline settings.1,557almost 4 years ago

Backlinks from these awesome lists:

More related projects: