Skip to content

Latest commit

 

History

History
35 lines (25 loc) · 1.28 KB

hardening.md

File metadata and controls

35 lines (25 loc) · 1.28 KB

Hardening

  • disable unnecessary services
  • setup host based firewall
  • run all programs/services with least privileges, separate service users
    • windows: don't miss SEAssignPrimaryTokenPrivilege
    • linux mod_ruid2: mind the capabilities CAP_SETUID, CAP_SETGID
  • use antivirus to find known malware
  • enable process auditing

Windows hardening

TODO

  • Applocker & SRP
  • disable execute downloaded exe