Skip to content

System hardening

Hardening reduces a system’s attack surface to the strict minimum: fewer services, fewer privileges, fewer default configurations. It’s the foundation of defense and the opposite of the offense in win-privesc/linux-privesc: every escalation technique those cards exploit is something hardening closes.

Minimal surface uninstall/disable what isn't used (services, roles, features)
Least privilege accounts and processes with just-enough permissions; no "just in case" admin
Defense in depth several layers: if one fails, another contains
Secure by default change default credentials/configs; deny then allow
Known configuration reproducible, versioned baselines (IaC), not manual tweaks
CIS Benchmarks secure configuration guides per OS/product (the de facto standard)
DISA STIGs DoD guides, very strict
SCAP/OpenSCAP automatically assess compliance against a baseline
# measuring against a baseline > hardening "by eye"
- accounts: disable/rename local Administrator, LAPS for unique local passwords
- surface: remove roles/features, SMBv1 off, disable LLMNR/NBT-NS (see ad-llmnr)
- credentials: Credential Guard, restrict admin, Protected Users for key accounts
- app control: WDAC/AppLocker (cuts LOLBins and unsigned binaries, see mal-evasion)
- logging: advanced auditing + Sysmon (see def-sysmon); PowerShell Script Block Logging
- services: minimize daemons; host firewall (nftables); SSH with keys, no direct root
- permissions: review SUID/SGID (see linux-privesc), umask, noexec/nosuid mounts
- kernel: hardened sysctl, unneeded modules out; MAC (SELinux/AppArmor) in enforce
- integrity: AIDE/auditd; packages up to date (see def-patch)
# audit against the baseline and look for what an attacker would look for:
OpenSCAP / CIS-CAT benchmark compliance
WinPEAS/LinPEAS what a local attacker would see (validate hardening closes paths)
Lynis hardening audit on Linux
  • Manage hardening as code (GPO/Ansible/DSC): reproducible, versioned, auditable.
  • Configuration drift: detect changes from the baseline and correct them.
  • Balance with operations: document justified exceptions; don’t break what the business needs.
  • Integrate with patching (Patch management), vulnerability management (Vulnerability management), and detection (Detection & logging).
  • Countless breaches from default configurations (admin/admin credentials, exposed panels, public S3).
  • SMBv1/EternalBlue (WannaCry/NotPetya, 2017): unhardened, unpatched hosts spread the worm.
  • AD hardening (LAPS, tiering, Protected Users) comes from real abuses documented in ad-*.
  • Choose and apply a baseline (CIS/STIG) per system type
  • Minimize services/roles/features and remove legacy protocols (SMBv1, LLMNR)
  • Least privilege on accounts and services; LAPS/no reused local admin
  • App control (WDAC/AppLocker) and MAC (SELinux/AppArmor)
  • Logging/auditing enabled (see Sysmon & telemetry/Detection & logging)
  • Verify with OpenSCAP/Lynis and with WinPEAS/LinPEAS
  • Manage as IaC and watch for configuration drift