Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →
Ensure Certificate Padding Is Enabled
Finding: Authenticode certificate padding check is not enforced.
Checks whether WinVerifyTrust performs strict Authenticode signature verification for Portable Executable files in both the native and 32-bit (Wow6432Node) registry views.
This rule fails when either enableCertPaddingCheck or enableCertPaddingCheckWow6432Node is not true.
Rationale: Without strict padding checks, content can be appended to a signed PE file without invalidating its signature, enabling remote code execution (CVE-2013-3900).
Impact: Installers that extract content from non-validated portions of signed files may be affected.
Remediation
Open Computer Configuration > Policies > Administrative Templates > MS Security Guide > Enable Certificate Padding and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\Cryptography\Wintrust\Config" /v EnableCertPaddingCheck /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Wintrust\Config" /v EnableCertPaddingCheck /t REG_DWORD /d 1 /f
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure NetBT NodeType Is Set To P-node
Finding: NetBT NodeType is not set to P-node.
Checks whether NetBIOS over TCP/IP name resolution uses the P-node (point-to-point) method, which queries a WINS server only and never broadcasts.
This rule fails when nodeType is not P.
Rationale: P-node stops the host from sending NetBIOS broadcasts, mitigating NBT-NS name-service poisoning attacks that trick a host into resolving names to an attacker.
Impact: NetBIOS name resolution requires a reachable WINS server; if none is available and the name is not cached locally, resolution fails.
Remediation
Open Computer Configuration > Policies > Administrative Templates > MS Security Guide > NetBT NodeType configuration and set it to Enabled: P-node (recommended).
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Services\NetBT\Parameters" /v NodeType /t REG_DWORD /d 2 /f
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure SMB V1 Client Driver Is Disabled
Finding: SMB v1 client driver is started.
Checks whether the legacy SMBv1 client driver (MRxSmb10) is prevented from starting.
This rule fails when smbV1ClientDriverStart is not false.
Rationale: SMBv1 is a decades-old protocol far more vulnerable to attack than SMBv2/SMBv3 and has been the vector for widespread worms; disabling the client driver removes that exposure.
Impact: Some legacy systems, applications, or appliances that only speak SMBv1 may no longer communicate with the host.
Remediation
Open Computer Configuration > Policies > Administrative Templates > MS Security Guide > Configure SMB v1 client driver and set it to Enabled: Disable driver (recommended).
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Services\mrxsmb10" /v Start /t REG_DWORD /d 4 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure SMB V1 Server Is Disabled
Finding: SMB v1 server protocol is enabled.
Checks whether server-side processing of the SMBv1 protocol is disabled.
This rule fails when smbV1Server is not false.
Rationale: SMBv1 is a decades-old protocol far more vulnerable to attack than SMBv2/SMBv3; leaving the server side enabled exposes the host to SMBv1-based exploits and lateral movement.
Impact: Some legacy systems, applications, or appliances that only speak SMBv1 may no longer connect to this host.
Remediation
Open Computer Configuration > Policies > Administrative Templates > MS Security Guide > Configure SMB v1 server and set it to Disabled.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" /v SMB1 /t REG_DWORD /d 0 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Structured Exception Handling Overwrite Protection Is Enabled
Finding: Structured Exception Handling Overwrite Protection is disabled.
Checks whether SEHOP run-time protection is enabled by confirming exception-chain validation is not disabled.
This rule fails when disableExceptionChainValidation is not false.
Rationale: SEHOP blocks exploits that use the Structured Exception Handler overwrite technique, protecting applications at run time regardless of how they were compiled.
Impact: Some older applications (e.g. legacy Cygwin, Skype, or Armadillo-protected apps) may not work correctly.
Remediation
Open Computer Configuration > Policies > Administrative Templates > MS Security Guide > Enable Structured Exception Handling Overwrite Protection (SEHOP) and set it to Enabled.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\kernel" /v DisableExceptionChainValidation /t REG_DWORD /d 0 /f
- Framework mappings
- CIS Controls v8: 10.5 Enable Anti-Exploitation Features
- NIST SP 800-53 Rev. 5: SI-16 Memory Protection
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure WDigest Authentication Is Disabled
Finding: WDigest authentication stores plaintext credentials in memory.
Checks whether WDigest is prevented from caching a copy of the user's plaintext password in LSASS memory.
This rule fails when useLogonCredential is not false.
Rationale: When WDigest is enabled, LSASS keeps the user's plaintext password in memory where credential-theft tools can harvest it.
Impact: None; this matches the default behavior on Windows 8.1 and newer.
Remediation
Open Computer Configuration > Policies > Administrative Templates > MS Security Guide > WDigest Authentication (disabling may require KB2871997) and set it to Disabled.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest" /v UseLogonCredential /t REG_DWORD /d 0 /f
- Framework mappings
- CIS Controls v8: 3.11 Encrypt Sensitive Data at Rest
- NIST SP 800-53 Rev. 5: AU-9 Protection of Audit Information; IA-5 Authenticator Management; SC-28 Protection of Information at Rest
- NIST SP 800-171 Rev. 2: 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital; 3.13.16 Protect the confidentiality of CUI at rest
- CMMC 2.0 Level 2: MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital; SC.L2-3.13.16 Protect the confidentiality of CUI at rest
- PCI DSS v4.0.1: 3.1.1 Stored account data policies and procedures kept documented, current, and applied; 3.3.2 Encrypt sensitive authentication data stored before authorization completes; 3.3.3 Issuers limit and protect any stored sensitive authentication data; 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls; 3.5.1.3 Manage disk-level encryption access independently of operating system authentication; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
- Risk
- Insecure Use of Secrets
- MITRE ATT&CK tactic
- Credential Access (TA0006)