Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →
Ensure HTTP Proxy Authentication Over Loopback Is Disabled
Finding: HTTP proxy authentication over loopback is allowed.
Checks whether Windows HTTP Services is prevented from authenticating over a loopback interface (at minimum) via the DisableProxyAuthenticationSchemes bitmask.
This rule fails when disableProxyAuthenticationSchemes is less than 256.
Rationale: Limiting the sign-in interface to known, trusted services stops malicious actors from impersonating them over a loopback proxy.
Impact: Windows will not authenticate over a loopback interface (value 256); value 287 additionally disables all authentication protocols.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Center for Internet Security (CIS) > Additional Benchmark Settings > Disable HTTP proxy features: Disable proxy authentication and set it to Enabled: Disable authentication over loopback interfaces or higher.
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings" /v DisableProxyAuthenticationSchemes /t REG_DWORD /d 256 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure Web Proxy Auto-Discovery (WPAD) Is Disabled
Finding: Web Proxy Auto-Discovery (WPAD) is enabled.
Checks whether the Web Proxy Auto-Discovery protocol (WPAD) is disabled for the Windows HTTP Services (WinHTTP) API.
This rule fails when disableWpad is not true.
Rationale: WPAD can be abused to feed a malicious proxy configuration to the host, enabling man-in-the-middle attacks; proxies should be configured explicitly instead.
Impact: All proxies must be configured manually; WPAD detection is stopped for WinHTTP proxy calls.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Center for Internet Security (CIS) > Additional Benchmark Settings > Disable HTTP proxy features: Disable WPAD and set it to Enabled: Checked.
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp" /v DisableWpad /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Exposure
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)