---
title: CIS Windows 11 MS Security Guide: 6 Checks | Wartiva
description: Wartiva's 6 checks for section 18.4, MS Security Guide, of the CIS Microsoft Windows 11 Stand-alone Benchmark, with rationale and remediation.
url: https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/ms-security-guide.html
updated: 2026-10-07
---

CIS Microsoft Windows 11 Stand-alone Benchmark · Section 18.4

# Windows 11 MS Security Guide: 6 Checks

Wartiva runs 6 checks for section 18.4, MS Security Guide, of the CIS Microsoft Windows 11 Stand-alone Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. [How Wartiva works →](https://wartiva.com/platform.html)

## [Ensure Certificate Padding Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/ms-security-guide.html#certificate-padding-is-enabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.4

**Finding:** Authenticode certificate padding check is not enforced.

Checks whether WinVerifyTrust performs strict Authenticode signature verification for Portable Executable files in both the native and 32-bit (Wow6432Node) registry views.

This rule fails when either `enableCertPaddingCheck` or `enableCertPaddingCheckWow6432Node` is not `true`.

**Rationale:** Without strict padding checks, content can be appended to a signed PE file without invalidating its signature, enabling remote code execution (CVE-2013-3900).

**Impact:** Installers that extract content from non-validated portions of signed files may be affected.

### Remediation

Open **Computer Configuration > Policies > Administrative Templates > MS Security Guide > Enable Certificate Padding** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Microsoft\Cryptography\Wintrust\Config" /v EnableCertPaddingCheck /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Wintrust\Config" /v EnableCertPaddingCheck /t REG_DWORD /d 1 /f
```

Risk

Vulnerability

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

## [Ensure NetBT NodeType Is Set To P-node](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/ms-security-guide.html#netbt-nodetype-is-set-to-p-node)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.4

**Finding:** NetBT NodeType is not set to P-node.

Checks whether NetBIOS over TCP/IP name resolution uses the P-node (point-to-point) method, which queries a WINS server only and never broadcasts.

This rule fails when `nodeType` is not `P`.

**Rationale:** P-node stops the host from sending NetBIOS broadcasts, mitigating NBT-NS name-service poisoning attacks that trick a host into resolving names to an attacker.

**Impact:** NetBIOS name resolution requires a reachable WINS server; if none is available and the name is not cached locally, resolution fails.

### Remediation

Open **Computer Configuration > Policies > Administrative Templates > MS Security Guide > NetBT NodeType configuration** and set it to **Enabled: P-node (recommended)**.

From the command line:

```powershell
reg add "HKLM\SYSTEM\CurrentControlSet\Services\NetBT\Parameters" /v NodeType /t REG_DWORD /d 2 /f
```

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components

Risk

Vulnerability

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

## [Ensure SMB V1 Client Driver Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/ms-security-guide.html#smb-v1-client-driver-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.4

**Finding:** SMB v1 client driver is started.

Checks whether the legacy SMBv1 client driver (MRxSmb10) is prevented from starting.

This rule fails when `smbV1ClientDriverStart` is not `false`.

**Rationale:** SMBv1 is a decades-old protocol far more vulnerable to attack than SMBv2/SMBv3 and has been the vector for widespread worms; disabling the client driver removes that exposure.

**Impact:** Some legacy systems, applications, or appliances that only speak SMBv1 may no longer communicate with the host.

### Remediation

Open **Computer Configuration > Policies > Administrative Templates > MS Security Guide > Configure SMB v1 client driver** and set it to **Enabled: Disable driver (recommended)**.

From the command line:

```powershell
reg add "HKLM\SYSTEM\CurrentControlSet\Services\mrxsmb10" /v Start /t REG_DWORD /d 4 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## [Ensure SMB V1 Server Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/ms-security-guide.html#smb-v1-server-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.4

**Finding:** SMB v1 server protocol is enabled.

Checks whether server-side processing of the SMBv1 protocol is disabled.

This rule fails when `smbV1Server` is not `false`.

**Rationale:** SMBv1 is a decades-old protocol far more vulnerable to attack than SMBv2/SMBv3; leaving the server side enabled exposes the host to SMBv1-based exploits and lateral movement.

**Impact:** Some legacy systems, applications, or appliances that only speak SMBv1 may no longer connect to this host.

### Remediation

Open **Computer Configuration > Policies > Administrative Templates > MS Security Guide > Configure SMB v1 server** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" /v SMB1 /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## [Ensure Structured Exception Handling Overwrite Protection Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/ms-security-guide.html#structured-exception-handling-overwrite-protection-is-enabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.4

**Finding:** Structured Exception Handling Overwrite Protection is disabled.

Checks whether SEHOP run-time protection is enabled by confirming exception-chain validation is not disabled.

This rule fails when `disableExceptionChainValidation` is not `false`.

**Rationale:** SEHOP blocks exploits that use the Structured Exception Handler overwrite technique, protecting applications at run time regardless of how they were compiled.

**Impact:** Some older applications (e.g. legacy Cygwin, Skype, or Armadillo-protected apps) may not work correctly.

### Remediation

Open **Computer Configuration > Policies > Administrative Templates > MS Security Guide > Enable Structured Exception Handling Overwrite Protection (SEHOP)** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\kernel" /v DisableExceptionChainValidation /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

Vulnerability

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## [Ensure WDigest Authentication Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/ms-security-guide.html#wdigest-authentication-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.4

**Finding:** WDigest authentication stores plaintext credentials in memory.

Checks whether WDigest is prevented from caching a copy of the user's plaintext password in LSASS memory.

This rule fails when `useLogonCredential` is not `false`.

**Rationale:** When WDigest is enabled, LSASS keeps the user's plaintext password in memory where credential-theft tools can harvest it.

**Impact:** None; this matches the default behavior on Windows 8.1 and newer.

### Remediation

Open **Computer Configuration > Policies > Administrative Templates > MS Security Guide > WDigest Authentication (disabling may require KB2871997)** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest" /v UseLogonCredential /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 3.11 Encrypt Sensitive Data at Rest
- **NIST SP 800-53 Rev. 5**: AU-9 Protection of Audit Information; IA-5 Authenticator Management; SC-28 Protection of Information at Rest
- **NIST SP 800-171 Rev. 2**: 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital; 3.13.16 Protect the confidentiality of CUI at rest
- **CMMC 2.0 Level 2**: MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital; SC.L2-3.13.16 Protect the confidentiality of CUI at rest
- **PCI DSS v4.0.1**: 3.1.1 Stored account data policies and procedures kept documented, current, and applied; 3.3.2 Encrypt sensitive authentication data stored before authorization completes; 3.3.3 Issuers limit and protect any stored sensitive authentication data; 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls; 3.5.1.3 Manage disk-level encryption access independently of operating system authentication; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography

Risk

Insecure Use of Secrets

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
