System hardening
Hardening reduces a system’s attack surface to the strict minimum: fewer services, fewer privileges, fewer default configurations. It’s the foundation of defense and the opposite of the offense in win-privesc/linux-privesc: every escalation technique those cards exploit is something hardening closes.
Principles
Section titled “Principles”Minimal surface uninstall/disable what isn't used (services, roles, features)Least privilege accounts and processes with just-enough permissions; no "just in case" adminDefense in depth several layers: if one fails, another containsSecure by default change default credentials/configs; deny then allowKnown configuration reproducible, versioned baselines (IaC), not manual tweaksBaselines and benchmarks
Section titled “Baselines and benchmarks”CIS Benchmarks secure configuration guides per OS/product (the de facto standard)DISA STIGs DoD guides, very strictSCAP/OpenSCAP automatically assess compliance against a baseline# measuring against a baseline > hardening "by eye"Windows hardening (summary)
Section titled “Windows hardening (summary)”- accounts: disable/rename local Administrator, LAPS for unique local passwords- surface: remove roles/features, SMBv1 off, disable LLMNR/NBT-NS (see ad-llmnr)- credentials: Credential Guard, restrict admin, Protected Users for key accounts- app control: WDAC/AppLocker (cuts LOLBins and unsigned binaries, see mal-evasion)- logging: advanced auditing + Sysmon (see def-sysmon); PowerShell Script Block LoggingLinux hardening (summary)
Section titled “Linux hardening (summary)”- services: minimize daemons; host firewall (nftables); SSH with keys, no direct root- permissions: review SUID/SGID (see linux-privesc), umask, noexec/nosuid mounts- kernel: hardened sysctl, unneeded modules out; MAC (SELinux/AppArmor) in enforce- integrity: AIDE/auditd; packages up to date (see def-patch)Verification
Section titled “Verification”# audit against the baseline and look for what an attacker would look for:OpenSCAP / CIS-CAT benchmark complianceWinPEAS/LinPEAS what a local attacker would see (validate hardening closes paths)Lynis hardening audit on LinuxBlue Team / operation
Section titled “Blue Team / operation”- Manage hardening as code (GPO/Ansible/DSC): reproducible, versioned, auditable.
- Configuration drift: detect changes from the baseline and correct them.
- Balance with operations: document justified exceptions; don’t break what the business needs.
- Integrate with patching (Patch management), vulnerability management (Vulnerability management), and detection (Detection & logging).
Real-world cases
Section titled “Real-world cases”- Countless breaches from default configurations (admin/admin credentials, exposed panels, public S3).
- SMBv1/EternalBlue (WannaCry/NotPetya, 2017): unhardened, unpatched hosts spread the worm.
- AD hardening (LAPS, tiering, Protected Users) comes from real abuses documented in ad-*.
Testing checklist
Section titled “Testing checklist”- Choose and apply a baseline (CIS/STIG) per system type
- Minimize services/roles/features and remove legacy protocols (SMBv1, LLMNR)
- Least privilege on accounts and services; LAPS/no reused local admin
- App control (WDAC/AppLocker) and MAC (SELinux/AppArmor)
- Logging/auditing enabled (see Sysmon & telemetry/Detection & logging)
- Verify with OpenSCAP/Lynis and with WinPEAS/LinPEAS
- Manage as IaC and watch for configuration drift