Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →
All 27 checks on this page
- 18.6.4 DNS Client
- Ensure Default IPv6 DNS Servers Are Turned Off
- 18.6.5 Fonts
- Ensure Font Providers Are Disabled
- 18.6.7 Lanman Server
- Ensure SMB Server Audits Clients That Do Not Support Encryption
- Ensure SMB Server Audits Clients That Do Not Support Signing
- Ensure SMB Server Audits Insecure Guest Logons
- Ensure SMB Server Authentication Rate Limiter Delay Is 2000 Milliseconds Or More
- Ensure SMB Server Authentication Rate Limiter Is Enabled
- Ensure SMB Server Minimum Version Is Mandated As 3.1.1
- Ensure SMB Server Remote Mailslots Are Disabled
- 18.6.8 Lanman Workstation
- Ensure SMB Client Audits Insecure Guest Logons
- Ensure SMB Client Audits Servers That Do Not Support Encryption
- Ensure SMB Client Audits Servers That Do Not Support Signing
- Ensure SMB Client Insecure Guest Logons Are Disabled
- Ensure SMB Client Minimum Version Is Mandated As 3.1.1
- Ensure SMB Client Remote Mailslots Are Disabled
- Ensure SMB Client Requires Encryption
- 18.6.9 Link-Layer Topology Discovery
- Ensure Mapper I/O (LLTDIO) Driver Is Disabled
- Ensure Responder (RSPNDR) Driver Is Disabled
- 18.6.10 Microsoft Peer-to-Peer Networking Services
- Ensure Microsoft Peer-To-Peer Networking Services Are Turned Off
- 18.6.11 Network Connections
- Ensure Installation And Configuration Of Network Bridge Is Prohibited
- Ensure Use Of Internet Connection Sharing Is Prohibited
- 18.6.14 Network Provider
- Ensure Hardened UNC Paths Are Configured For NETLOGON And SYSVOL Shares
- 18.6.19 TCPIP Settings
- Ensure IPv6 Is Disabled Via DisabledComponents
- 18.6.20 Windows Connect Now
- Ensure Access Of The Windows Connect Now Wizards Is Prohibited
- Ensure Configuration Of Wireless Settings Using Windows Connect Now Is Disabled
- 18.6.21 Windows Connection Manager
- Ensure Simultaneous Connections To The Internet Or A Windows Domain Are Minimized
- 18.6.23 WLAN Service
- Ensure Automatic Connection To Suggested Open Hotspots Is Disabled
18.6.4 DNS Client
Ensure Default IPv6 DNS Servers Are Turned Off
Finding: Default IPv6 DNS servers are not turned off.
Checks whether the DNS client is prevented from using the default IPv6 DNS server addresses provided by Windows.
This rule fails when disableIPv6DefaultDnsServers is not true.
Rationale: Most enterprise networks rely on private IPv4 addressing; disabling the built-in IPv6 DNS servers removes an attack surface whose traffic is harder to monitor.
Impact: Windows will not use the default IPv6 DNS server addresses.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Network > DNS Client and set Turn off default IPv6 DNS Servers to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient" /v DisableIPv6DefaultDnsServers /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Reconnaissance (TA0043)
18.6.5 Fonts
Ensure Font Providers Are Disabled
Finding: Font providers are enabled.
Checks whether Windows is prevented from downloading fonts and font catalog data from an online font provider.
This rule fails when enableFrontProviders is not false.
Rationale: In a managed environment all system changes should be tested and approved by IT; blocking on-demand font downloads keeps the endpoint from reaching an external provider.
Impact: Windows enumerates only locally installed fonts and will not contact an online font provider.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Network > Fonts and set Enable Font Providers to Disabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v EnableFontProviders /t REG_DWORD /d 0 /f
- Framework mappings
- CIS Controls v8: 16.5 Use Up-to-Date and Trusted Third-Party Software Components
- NIST SP 800-53 Rev. 5: SI-7 Software, Firmware, and Information Integrity; SR-11 Component Authenticity
- PCI DSS v4.0.1: 6.3.3 Install security patches promptly, critical ones within a month; 12.3.4 Annually assess whether hardware and software in use remain supported
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
18.6.7 Lanman Server
Ensure SMB Server Audits Clients That Do Not Support Encryption
Finding: SMB server does not audit clients that do not support encryption.
Checks whether the SMB server logs an event when a connecting SMB client does not support encryption.
This rule fails when lanmanServerAuditClientDoesNotSupportEncryption is not true.
Rationale: Visibility into unencrypted SMB traffic lets defenders find legacy clients that expose the environment to interception attacks.
Impact: Each connection from a client that lacks encryption support is recorded as an audit event.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Network > Lanman Server and set Audit client does not support encryption to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\LanmanServer" /v AuditClientDoesNotSupportEncryption /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 8.5 Collect Detailed Audit Logs
- NIST SP 800-53 Rev. 5: AU-3 Content of Audit Records; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation; SI-4 System Monitoring
- PCI DSS v4.0.1: 9.4.5 Keep a log-based inventory of electronic media holding cardholder data; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.5 Record account creation, privilege elevation, and other credential changes
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure SMB Server Audits Clients That Do Not Support Signing
Finding: SMB server does not audit clients that do not support signing.
Checks whether the SMB server logs an event when a connecting SMB client does not support signing.
This rule fails when lanmanServerAuditClientDoesNotSupportSigning is not true.
Rationale: Awareness of unsigned SMB traffic helps identify legacy clients that leave the environment open to interception and tampering attacks.
Impact: Each connection from a client that lacks signing support is recorded as an audit event.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Network > Lanman Server and set Audit client does not support signing to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\LanmanServer" /v AuditClientDoesNotSupportSigning /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 8.5 Collect Detailed Audit Logs
- NIST SP 800-53 Rev. 5: AU-3 Content of Audit Records; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation; SI-4 System Monitoring
- PCI DSS v4.0.1: 9.4.5 Keep a log-based inventory of electronic media holding cardholder data; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.5 Record account creation, privilege elevation, and other credential changes
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure SMB Server Audits Insecure Guest Logons
Finding: SMB server does not audit insecure guest logons.
Checks whether the SMB server logs an event when a client connects using the guest account.
This rule fails when lanmanServerAuditInsecureGuestLogon is not true.
Rationale: Insecure guest logons allow unauthenticated access to shares; auditing them surfaces this risky access pattern.
Impact: Each insecure guest logon to the SMB server is recorded as an audit event.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Network > Lanman Server and set Audit insecure guest logon to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\LanmanServer" /v AuditInsecureGuestLogon /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 8.5 Collect Detailed Audit Logs
- NIST SP 800-53 Rev. 5: AU-3 Content of Audit Records; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation; SI-4 System Monitoring
- PCI DSS v4.0.1: 9.4.5 Keep a log-based inventory of electronic media holding cardholder data; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.5 Record account creation, privilege elevation, and other credential changes
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure SMB Server Authentication Rate Limiter Delay Is 2000 Milliseconds Or More
Finding: SMB server authentication rate limiter delay is less than 2000 milliseconds.
Checks the delay the SMB server enforces after an invalid authentication attempt.
This rule fails when lanmanServerInvalidAuthDelayTime is less than 2000000000 ns (2000 milliseconds).
Rationale: A delay of at least two seconds between failed NTLM or PKU2U attempts makes SMB brute-force attacks impractically slow.
Impact: None; 2000 milliseconds (two seconds) is the default behavior.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Network > Lanman Server and set Set authentication rate limiter delay (milliseconds) to Enabled: 2000 or more.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\LanmanServer" /v InvalidAuthenticationDelayTimeInMs /t REG_DWORD /d 2000 /f
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure SMB Server Authentication Rate Limiter Is Enabled
Finding: SMB server authentication rate limiter is disabled.
Checks whether the SMB server authentication rate limiter, which throttles repeated failed authentication attempts, is enabled.
This rule fails when lanmanServerEnableAuthRateLimiter is not true.
Rationale: Inserting a delay between failed NTLM or PKU2U authentication attempts dramatically slows SMB brute-force attacks.
Impact: None; this is the default behavior on current Windows builds.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Network > Lanman Server and set Enable authentication rate limiter to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\LanmanServer" /v EnableAuthRateLimiter /t REG_DWORD /d 1 /f
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure SMB Server Minimum Version Is Mandated As 3.1.1
Finding: SMB server minimum version is not mandated as 3.1.1.
Checks the minimum Server Message Block dialect the SMB server will negotiate with clients.
This rule fails when lanmanServerMinSmb2Dialect is not SMB_3_1_1.
Rationale: SMB 3.1.1 is the most modern, secure dialect and supports encryption; mandating it blocks older, weaker SMB versions on the server.
Impact: Legacy clients or third-party devices that do not support SMB 3.1.1 will be unable to connect.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Network > Lanman Server and set Mandate the minimum version of SMB to Enabled: 3.1.1.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\LanmanServer" /v MinSmb2Dialect /t REG_DWORD /d 785 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure SMB Server Remote Mailslots Are Disabled
Finding: SMB server remote mailslots are enabled.
Checks whether the SMB server uses the legacy remote mailslots protocol over the computer browser service.
This rule fails when lanmanServerEnableMailslots is not false.
Rationale: Remote mailslots is an old SMBv1-based inter-process communication protocol linked to denial-of-service, buffer-overflow, and remote-code-execution vulnerabilities.
Impact: Any feature relying on remote mailslots on the server will stop functioning.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Network > Lanman Server and set Enable remote mailslots to Disabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Bowser" /v EnableMailslots /t REG_DWORD /d 0 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Initial Access (TA0001)
18.6.8 Lanman Workstation
Ensure SMB Client Audits Insecure Guest Logons
Finding: SMB client does not audit insecure guest logons.
Checks whether the SMB client logs an event when it connects to a server using the guest account.
This rule fails when lanmanWorkstationAuditInsecureGuestLogon is not true.
Rationale: Insecure guest logons allow unauthenticated access to shares; auditing them on the client surfaces this risky access pattern.
Impact: Each insecure guest logon made by the SMB client is recorded as an audit event.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Network > Lanman Workstation and set Audit insecure guest logon to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\LanmanWorkstation" /v AuditInsecureGuestLogon /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 8.5 Collect Detailed Audit Logs
- NIST SP 800-53 Rev. 5: AU-3 Content of Audit Records; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation; SI-4 System Monitoring
- PCI DSS v4.0.1: 9.4.5 Keep a log-based inventory of electronic media holding cardholder data; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.5 Record account creation, privilege elevation, and other credential changes
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure SMB Client Audits Servers That Do Not Support Encryption
Finding: SMB client does not audit servers that do not support encryption.
Checks whether the SMB client logs an event when the SMB server it connects to does not support encryption.
This rule fails when lanmanWorkstationAuditServerDoesNotSupportEncrypt is not true.
Rationale: Visibility into unencrypted SMB server connections helps defenders find legacy servers that expose the environment to interception attacks.
Impact: Each connection to a server that lacks encryption support is recorded as an audit event.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Network > Lanman Workstation and set Audit server does not support encryption to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\LanmanWorkstation" /v AuditServerDoesNotSupportEncryption /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 8.5 Collect Detailed Audit Logs
- NIST SP 800-53 Rev. 5: AU-3 Content of Audit Records; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation; SI-4 System Monitoring
- PCI DSS v4.0.1: 9.4.5 Keep a log-based inventory of electronic media holding cardholder data; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.5 Record account creation, privilege elevation, and other credential changes
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure SMB Client Audits Servers That Do Not Support Signing
Finding: SMB client does not audit servers that do not support signing.
Checks whether the SMB client logs an event when the SMB server it connects to does not support signing.
This rule fails when lanmanWorkstationAuditServerDoesNotSupportSigning is not true.
Rationale: Awareness of unsigned SMB server connections helps identify legacy servers that leave the environment open to interception and tampering attacks.
Impact: Each connection to a server that lacks signing support is recorded as an audit event.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Network > Lanman Workstation and set Audit server does not support signing to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\LanmanWorkstation" /v AuditServerDoesNotSupportSigning /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 8.5 Collect Detailed Audit Logs
- NIST SP 800-53 Rev. 5: AU-3 Content of Audit Records; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation; SI-4 System Monitoring
- PCI DSS v4.0.1: 9.4.5 Keep a log-based inventory of electronic media holding cardholder data; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.5 Record account creation, privilege elevation, and other credential changes
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure SMB Client Insecure Guest Logons Are Disabled
Finding: SMB client insecure guest logons are enabled.
Checks whether the SMB client is prevented from making insecure guest logons to an SMB server.
This rule fails when allowInsecureGuestAuth is not false.
Rationale: Insecure guest logons grant unauthenticated access to shared folders, an easy foothold for an attacker; the client should reject them.
Impact: The SMB client refuses insecure guest logons, matching the modern Windows default.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Network > Lanman Workstation and set Enable insecure guest logons to Disabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\LanmanWorkstation" /v AllowInsecureGuestAuth /t REG_DWORD /d 0 /f
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure SMB Client Minimum Version Is Mandated As 3.1.1
Finding: SMB client minimum version is not mandated as 3.1.1.
Checks the minimum Server Message Block dialect the SMB client will negotiate with servers.
This rule fails when lanmanWorkstationMinSmb2Dialect is not SMB_3_1_1.
Rationale: SMB 3.1.1 is the most modern, secure dialect and supports encryption; mandating it blocks older, weaker SMB versions on the client.
Impact: Connections to legacy servers or third-party devices that do not support SMB 3.1.1 will fail.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Network > Lanman Workstation and set Mandate the minimum version of SMB to Enabled: 3.1.1.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\LanmanWorkstation" /v MinSmb2Dialect /t REG_DWORD /d 785 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure SMB Client Remote Mailslots Are Disabled
Finding: SMB client remote mailslots are enabled.
Checks whether the SMB client uses the legacy remote mailslots protocol over the Multiple UNC Provider (MUP).
This rule fails when lanmanWorkstationEnableMailslots is not false.
Rationale: Remote mailslots is an old SMBv1-based inter-process communication protocol linked to denial-of-service, buffer-overflow, and remote-code-execution vulnerabilities.
Impact: Any feature relying on remote mailslots on the client will stop functioning.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Network > Lanman Workstation and set Enable remote mailslots to Disabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\NetworkProvider" /v EnableMailslots /t REG_DWORD /d 0 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure SMB Client Requires Encryption
Finding: SMB client does not require encryption.
Checks whether the SMB client requires encryption for its connections.
This rule fails when lanmanWorkstationRequireEncryption is not true.
Rationale: Requiring SMB encryption protects file traffic in transit from interception, which older SMB versions cannot provide.
Impact: Connections to servers or devices that do not support SMB encryption (SMB 3.0 or later) may break.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Network > Lanman Workstation and set Require Encryption to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\LanmanWorkstation" /v RequireEncryption /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 3.10 Encrypt Sensitive Data in Transit
- NIST SP 800-53 Rev. 5: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
- NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- PCI DSS v4.0.1: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
18.6.9 Link-Layer Topology Discovery
Ensure Mapper I/O (LLTDIO) Driver Is Disabled
Finding: Mapper I/O (LLTDIO) driver is enabled.
Checks whether the Mapper I/O (LLTDIO) network protocol driver, used to map network topology, is turned off across all network profiles.
This rule fails unless enableLLTDIO, allowLLTDIOOnDomain, allowLLTDIOOnPublicNet, and prohibitLLTDIOOnPrivateNet are all false.
Rationale: Disabling LLTDIO prevents the host from responding to network topology discovery, reducing the risk of discovering and connecting to unauthorized devices.
Impact: Some real-time applications could experience brief network disconnections.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Network > Link-Layer Topology Discovery and set Turn on Mapper I/O (LLTDIO) driver to Disabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\LLTD" /v EnableLLTDIO /t REG_DWORD /d 0 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\LLTD" /v AllowLLTDIOOnDomain /t REG_DWORD /d 0 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\LLTD" /v AllowLLTDIOOnPublicNet /t REG_DWORD /d 0 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\LLTD" /v ProhibitLLTDIOOnPrivateNet /t REG_DWORD /d 0 /f
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Reconnaissance (TA0043)
Ensure Responder (RSPNDR) Driver Is Disabled
Finding: Responder (RSPNDR) driver is enabled.
Checks whether the Responder (RSPNDR) network protocol driver, which lets the host be discovered via Link-Layer Topology Discovery, is turned off across all network profiles.
This rule fails unless enableRspndr, allowRspndrOnDomain, allowRspndrOnPublicNet, and prohibitRspndrOnPrivateNet are all false.
Rationale: Disabling the Responder prevents the host from participating in network topology discovery, reducing the risk of discovery and connection by unauthorized devices.
Impact: Some real-time applications could experience brief network disconnections.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Network > Link-Layer Topology Discovery and set Turn on Responder (RSPNDR) driver to Disabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\LLTD" /v EnableRspndr /t REG_DWORD /d 0 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\LLTD" /v AllowRspndrOnDomain /t REG_DWORD /d 0 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\LLTD" /v AllowRspndrOnPublicNet /t REG_DWORD /d 0 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\LLTD" /v ProhibitRspndrOnPrivateNet /t REG_DWORD /d 0 /f
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Reconnaissance (TA0043)
18.6.10 Microsoft Peer-to-Peer Networking Services
Ensure Microsoft Peer-To-Peer Networking Services Are Turned Off
Finding: Microsoft Peer-to-Peer Networking Services are not turned off.
Checks whether Microsoft Peer-to-Peer Networking Services, including the Peer Name Resolution Protocol (PNRP), are turned off.
This rule fails when p2PNetworkServicesDisabled is not true.
Rationale: Turning off peer-to-peer networking reduces the overall attack surface associated with distributed name resolution and content distribution protocols.
Impact: All applications that depend on Microsoft peer-to-peer networking will stop working.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Network > Microsoft Peer-to-Peer Networking Services and set Turn off Microsoft Peer-to-Peer Networking Services to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Peernet" /v Disabled /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
18.6.11 Network Connections
Ensure Installation And Configuration Of Network Bridge Is Prohibited
Finding: Installation and configuration of Network Bridge is allowed.
Checks whether users are prevented from installing and configuring a Network Bridge.
This rule fails when ncAllowNetBridgeNla is not false.
Rationale: A Network Bridge lets a host join two network segments, allowing traffic to route between internal and external networks and increasing the attack surface.
Impact: Users can no longer create or configure a Network Bridge.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Network > Network Connections and set Prohibit installation and configuration of Network Bridge on your DNS domain network to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Network Connections" /v NC_AllowNetBridge_NLA /t REG_DWORD /d 0 /f
- Framework mappings
- CIS Controls v8: 4.2 Establish and Maintain a Secure Configuration Process for Network Infrastructure
- NIST SP 800-53 Rev. 5: AC-18 Wireless Access; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan
- NIST SP 800-171 Rev. 2: 3.4.4 Analyze the security impact of changes prior to implementation
- CMMC 2.0 Level 2: CM.L2-3.4.4 Analyze the security impact of changes prior to implementation
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.4.2 Permit untrusted-to-trusted inbound traffic only to authorized public services; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Use Of Internet Connection Sharing Is Prohibited
Finding: Use of Internet Connection Sharing is allowed.
Checks whether users are prevented from enabling Internet Connection Sharing, including the Mobile Hotspot feature.
This rule fails when ncShowSharedAccessUi is not false.
Rationale: Non-administrators should not be able to open the host's Internet connection to nearby mobile devices via Mobile Hotspot.
Impact: Mobile Hotspot cannot be enabled or configured by any user.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Network > Network Connections and set Prohibit use of Internet Connection Sharing on your DNS domain network to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Network Connections" /v NC_ShowSharedAccessUI /t REG_DWORD /d 0 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
18.6.14 Network Provider
18.6.19 TCPIP Settings
Ensure IPv6 Is Disabled Via DisabledComponents
Finding: IPv6 is not disabled via DisabledComponents.
Checks whether all IPv6 components are disabled by setting the TCPIP6 DisabledComponents parameter to 0xff (255).
This rule fails when disabledComponents is not 255.
Rationale: Most enterprise networks have no need for IPv6; disabling its components removes an attack surface that is harder to monitor and mitigates CVE-2024-38063, a TCP/IP remote code execution vulnerability.
Impact: Connectivity and software that depend on IPv6 (for example Remote Assistance and DirectAccess) will no longer function.
Remediation
Set the registry value DisabledComponents under HKLM\SYSTEM\CurrentControlSet\Services\TCPIP6\Parameters to 0xff (255), or use the CIS custom template under Computer Configuration > Policies > Administrative Templates > Network > TCPIP Settings > Parameters.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Services\TCPIP6\Parameters" /v DisabledComponents /t REG_DWORD /d 255 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Reconnaissance (TA0043)
18.6.20 Windows Connect Now
Ensure Access Of The Windows Connect Now Wizards Is Prohibited
Finding: Access of the Windows Connect Now wizards is allowed.
Checks whether access to the Windows Connect Now (WCN) wizards is prohibited.
This rule fails when disableWcnUi is not true.
Rationale: Allowing standard users to reach the WCN wizard increases the attack surface; WCN was not intended for enterprise scenarios.
Impact: The WCN wizards are turned off and users cannot run tasks such as setting up a wireless router or adding a wireless device.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Network > Windows Connect Now and set Prohibit access of the Windows Connect Now wizards to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WCN\UI" /v DisableWcnUi /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Configuration Of Wireless Settings Using Windows Connect Now Is Disabled
Finding: Configuration of wireless settings using Windows Connect Now is enabled.
Checks whether Windows Connect Now (WCN) registrars for wireless device discovery and configuration are disabled across all media.
This rule fails unless enableRegistrars, disableUPnPRegistrar, disableInBand802DOT11Registrar, disableFlashConfigRegistrar, and disableWPDRegistrar are all false.
Rationale: WCN was designed for home and small-business networks, not enterprise use; disabling it reduces the risk associated with user configuration of wireless settings.
Impact: Windows Connect Now operations are disabled over all media.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Network > Windows Connect Now and set Configuration of wireless settings using Windows Connect Now to Disabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WCN\Registrars" /v EnableRegistrars /t REG_DWORD /d 0 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WCN\Registrars" /v DisableUPnPRegistrar /t REG_DWORD /d 0 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WCN\Registrars" /v DisableInBand802DOT11Registrar /t REG_DWORD /d 0 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WCN\Registrars" /v DisableFlashConfigRegistrar /t REG_DWORD /d 0 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WCN\Registrars" /v DisableWPDRegistrar /t REG_DWORD /d 0 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
18.6.21 Windows Connection Manager
Ensure Simultaneous Connections To The Internet Or A Windows Domain Are Minimized
Finding: Simultaneous connections to the Internet or a Windows domain are not minimized.
Checks whether Windows prevents establishing a Wi-Fi connection while an Ethernet connection is active.
This rule fails when fMininimizeConnections is not PREVENT_WIFI_CONNECTIONS_WHEN_ON_ETHERNET.
Rationale: Blocking bridged network connections stops a user from unknowingly routing traffic between internal and external networks, which risks exposing sensitive internal data.
Impact: While on Ethernet, Windows will not use a WLAN until Ethernet is disconnected; cellular remains available only for services that require it.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Network > Windows Connection Manager and set Minimize the number of simultaneous connections to the Internet or a Windows Domain to Enabled: 3 = Prevent Wi-Fi when on Ethernet.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WcmSvc\GroupPolicy" /v fMinimizeConnections /t REG_DWORD /d 3 /f
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
18.6.23 WLAN Service
Ensure Automatic Connection To Suggested Open Hotspots Is Disabled
Finding: Automatic connection to suggested open hotspots is allowed.
Checks whether Windows is prevented from automatically connecting to suggested open hotspots, networks shared by contacts, and hotspots offering paid services (Wi-Fi Sense).
This rule fails when autoConnectAllowedOEM is not false.
Rationale: Automatically connecting to an open or crowdsourced network can attach the system to a rogue network with malicious intent.
Impact: Users can no longer enable the Wi-Fi Sense automatic-connection features.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Network > WLAN Service > WLAN Settings and set Allow Windows to automatically connect to suggested open hotspots, to networks shared by contacts, and to hotspots offering paid services to Disabled.
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\WcmSvc\wifinetworkmanager\config" /v AutoConnectAllowedOEM /t REG_DWORD /d 0 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)