Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →
All 44 checks on this page
- Ensure Bluetooth Audio Gateway Service Is Disabled
- Ensure Bluetooth Support Service Is Disabled
- Ensure Computer Browser Service Is Disabled
- Ensure Downloaded Maps Manager Service Is Disabled
- Ensure GameInput Service Is Disabled
- Ensure Geolocation Service Is Disabled
- Ensure IIS Admin Service Is Disabled
- Ensure Infrared Monitor Service Is Disabled
- Ensure Link-Layer Topology Discovery Mapper Service Is Disabled
- Ensure Microsoft FTP Service Is Disabled
- Ensure Microsoft iSCSI Initiator Service Is Disabled
- Ensure OpenSSH SSH Server Is Disabled
- Ensure Peer Name Resolution Protocol Service Is Disabled
- Ensure Peer Networking Grouping Service Is Disabled
- Ensure Peer Networking Identity Manager Service Is Disabled
- Ensure PNRP Machine Name Publication Service Is Disabled
- Ensure Print Spooler Service Is Disabled
- Ensure Problem Reports And Solutions Control Panel Support Is Disabled
- Ensure Remote Access Auto Connection Manager Is Disabled
- Ensure Remote Desktop Configuration Service Is Disabled
- Ensure Remote Desktop Services Is Disabled
- Ensure Remote Desktop Services UserMode Port Redirector Is Disabled
- Ensure Remote Procedure Call (RPC) Locator Is Disabled
- Ensure Remote Registry Service Is Disabled
- Ensure Routing And Remote Access Service Is Disabled
- Ensure Server Service Is Disabled
- Ensure Simple TCP/IP Services Is Disabled
- Ensure SNMP Service Is Disabled
- Ensure Special Administration Console Helper Is Disabled
- Ensure SSDP Discovery Service Is Disabled
- Ensure UPnP Device Host Is Disabled
- Ensure Web Management Service Is Disabled
- Ensure Windows Error Reporting Service Is Disabled
- Ensure Windows Event Collector Service Is Disabled
- Ensure Windows Media Player Network Sharing Service Is Disabled
- Ensure Windows Mobile Hotspot Service Is Disabled
- Ensure Windows Push Notifications System Service Is Disabled
- Ensure Windows PushToInstall Service Is Disabled
- Ensure Windows Remote Management (WS-Management) Is Disabled
- Ensure World Wide Web Publishing Service Is Disabled
- Ensure Xbox Accessory Management Service Is Disabled
- Ensure Xbox Live Auth Manager Is Disabled
- Ensure Xbox Live Game Save Is Disabled
- Ensure Xbox Live Networking Service Is Disabled
Ensure Bluetooth Audio Gateway Service Is Disabled
Finding: Bluetooth Audio Gateway Service is not disabled.
Checks that the service backing the audio-gateway role of the Bluetooth Hands-Free Profile is disabled.
This rule fails when the Bluetooth Audio Gateway Service service is present and its startType is not DISABLED.
Rationale: Bluetooth carries inherent wireless risks and its traffic is often weakly encrypted, so it should not be permitted on high-security workstations.
Impact: Bluetooth hands-free audio devices will not work with the computer.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Bluetooth Audio Gateway Service, and set its startup type to Disabled.
From the command line:
sc.exe config BTAGService start= disabled
Set-Service -Name BTAGService -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure Bluetooth Support Service Is Disabled
Finding: Bluetooth Support Service is not disabled.
Checks that the service supporting discovery and pairing of remote Bluetooth devices is disabled.
This rule fails when the Bluetooth Support Service service is present and its startType is not DISABLED.
Rationale: Bluetooth carries inherent wireless risks and its traffic is often weakly encrypted, so it should not be permitted on high-security workstations.
Impact: Installed Bluetooth devices may stop working and new devices cannot be discovered or paired; some Windows components such as Devices and Printers may misbehave.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Bluetooth Support Service, and set its startup type to Disabled.
From the command line:
sc.exe config bthserv start= disabled
Set-Service -Name bthserv -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure Computer Browser Service Is Disabled
Finding: Computer Browser is not disabled.
Checks that the legacy Computer Browser service, which maintains and serves a list of networked computers, is disabled or not installed.
This rule fails when the Computer Browser service is present and its startType is not DISABLED.
Rationale: This legacy service generates noisy master-browser election traffic and lets anyone enumerate online machines and shares, aiding attacker reconnaissance.
Impact: The network list of computers and their shares will no longer be maintained.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Computer Browser, and set its startup type to Disabled.
From the command line:
sc.exe config Browser start= disabled
Set-Service -Name Browser -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Discovery (TA0007)
Ensure Downloaded Maps Manager Service Is Disabled
Finding: Downloaded Maps Manager is not disabled.
Checks that the service giving applications access to downloaded maps is disabled.
This rule fails when the Downloaded Maps Manager service is present and its startType is not DISABLED.
Rationale: Mapping features can leak the device location and pull data from third parties, which is undesirable in high-security environments.
Impact: Applications will be unable to access downloaded map data.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Downloaded Maps Manager, and set its startup type to Disabled.
From the command line:
sc.exe config MapsBroker start= disabled
Set-Service -Name MapsBroker -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure GameInput Service Is Disabled
Finding: GameInput Service is not disabled.
Checks that the service exposing keyboards, mice and game controllers through the GameInput API is disabled.
This rule fails when the GameInput Service service is present and its startType is not DISABLED.
Rationale: The GameInput API pipes input via Direct Memory Access to reduce latency, which increases the risk of keystrokes and other input being captured by an attacker.
Impact: Input devices will be unable to use the GameInput API.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select GameInput Service, and set its startup type to Disabled.
From the command line:
sc.exe config GameInputSvc start= disabled
Set-Service -Name GameInputSvc -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure Geolocation Service Is Disabled
Finding: Geolocation Service is not disabled.
Checks that the service that tracks the system location and manages geofences is disabled.
This rule fails when the Geolocation Service service is present and its startType is not DISABLED.
Rationale: Revealing device location to software is generally undesirable and should not occur on high-security workstations.
Impact: Applications will be unable to obtain location data or geofence notifications.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Geolocation Service, and set its startup type to Disabled.
From the command line:
sc.exe config lfsvc start= disabled
Set-Service -Name lfsvc -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Discovery (TA0007)
Ensure IIS Admin Service Is Disabled
Finding: IIS Admin Service is not disabled.
Checks that the IIS Admin service, which administers the IIS metabase for SMTP and FTP, is disabled or not installed.
This rule fails when the IIS Admin Service service is present and its startType is not DISABLED.
Rationale: Running web-server components on a workstation greatly expands its attack surface and raises the chance of successful remote attack.
Impact: IIS, including its Web, SMTP and FTP services, will not function.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select IIS Admin Service, and set its startup type to Disabled.
From the command line:
sc.exe config IISADMIN start= disabled
Set-Service -Name IISADMIN -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Infrared Monitor Service Is Disabled
Finding: Infrared monitor service is not disabled.
Checks that the service that detects in-range infrared devices and launches file transfer is disabled or not installed.
This rule fails when the Infrared monitor service service is present and its startType is not DISABLED.
Rationale: Infrared connections, especially automatic file transfer, can be a route for data compromise; more secure connection methods should be used.
Impact: Infrared file transfers will no longer work.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Infrared monitor service, and set its startup type to Disabled.
From the command line:
sc.exe config irmon start= disabled
Set-Service -Name irmon -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure Link-Layer Topology Discovery Mapper Service Is Disabled
Finding: Link-Layer Topology Discovery Mapper is not disabled.
Checks that the service that builds a network map of PCs and devices is disabled.
This rule fails when the Link-Layer Topology Discovery Mapper service is present and its startType is not DISABLED.
Rationale: The topology-discovery feature can be abused to enumerate and connect to network devices; disabling it prevents responses to discovery requests.
Impact: The Windows Network Map will not function correctly.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Link-Layer Topology Discovery Mapper, and set its startup type to Disabled.
From the command line:
sc.exe config lltdsvc start= disabled
Set-Service -Name lltdsvc -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Discovery (TA0007)
Ensure Microsoft FTP Service Is Disabled
Finding: Microsoft FTP Service is not disabled.
Checks that the service that makes the computer an FTP server is disabled or not installed.
This rule fails when the Microsoft FTP Service service is present and its startType is not DISABLED.
Rationale: Hosting an FTP server, particularly a non-secure one, on a workstation greatly increases its attack surface.
Impact: The computer will not operate as an FTP server.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Microsoft FTP Service, and set its startup type to Disabled.
From the command line:
sc.exe config FTPSVC start= disabled
Set-Service -Name FTPSVC -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Microsoft iSCSI Initiator Service Is Disabled
Finding: Microsoft iSCSI Initiator Service is not disabled.
Checks that the service managing iSCSI sessions to remote targets is disabled.
This rule fails when the Microsoft iSCSI Initiator Service service is present and its startType is not DISABLED.
Rationale: iSCSI relies on the weak CHAP authentication protocol, which exposes credentials unless traffic is isolated or encrypted; it is inappropriate for secured workstations.
Impact: The computer will be unable to log in to or access iSCSI targets directly.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Microsoft iSCSI Initiator Service, and set its startup type to Disabled.
From the command line:
sc.exe config MSiSCSI start= disabled
Set-Service -Name MSiSCSI -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure OpenSSH SSH Server Is Disabled
Finding: OpenSSH SSH Server is not disabled.
Checks that the OpenSSH server service is disabled or not installed.
This rule fails when the OpenSSH SSH Server service is present and its startType is not DISABLED.
Rationale: Hosting an SSH server on a workstation greatly increases its attack surface and remote exposure.
Impact: The workstation will not be able to act as an SSH host.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select OpenSSH SSH Server, and set its startup type to Disabled.
From the command line:
sc.exe config sshd start= disabled
Set-Service -Name sshd -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Peer Name Resolution Protocol Service Is Disabled
Finding: Peer Name Resolution Protocol is not disabled.
Checks that the serverless PNRP peer name-resolution service is disabled or not installed.
This rule fails when the Peer Name Resolution Protocol service is present and its startType is not DISABLED.
Rationale: Distributed, serverless name resolution is less controllable than centralized name services maintained by authorized staff.
Impact: Some peer-to-peer and collaborative applications, such as Remote Assistance, may not work.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Peer Name Resolution Protocol, and set its startup type to Disabled.
From the command line:
sc.exe config PNRPsvc start= disabled
Set-Service -Name PNRPsvc -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Discovery (TA0007)
Ensure Peer Networking Grouping Service Is Disabled
Finding: Peer Networking Grouping is not disabled.
Checks that the peer-to-peer grouping service is disabled or not installed.
This rule fails when the Peer Networking Grouping service is present and its startType is not DISABLED.
Rationale: Distributed, serverless peer name resolution is less controllable than centralized name services maintained by authorized staff.
Impact: Some applications, such as HomeGroup, may not work.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Peer Networking Grouping, and set its startup type to Disabled.
From the command line:
sc.exe config p2psvc start= disabled
Set-Service -Name p2psvc -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Discovery (TA0007)
Ensure Peer Networking Identity Manager Service Is Disabled
Finding: Peer Networking Identity Manager is not disabled.
Checks that the identity service for PNRP and peer-to-peer grouping is disabled or not installed.
This rule fails when the Peer Networking Identity Manager service is present and its startType is not DISABLED.
Rationale: Distributed, serverless peer name resolution is less controllable than centralized name services maintained by authorized staff.
Impact: PNRP and peer grouping, and applications such as HomeGroup and Remote Assistance, may not work.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Peer Networking Identity Manager, and set its startup type to Disabled.
From the command line:
sc.exe config p2pimsvc start= disabled
Set-Service -Name p2pimsvc -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Discovery (TA0007)
Ensure PNRP Machine Name Publication Service Is Disabled
Finding: PNRP Machine Name Publication Service is not disabled.
Checks that the service that publishes the machine name via PNRP is disabled or not installed.
This rule fails when the PNRP Machine Name Publication Service service is present and its startType is not DISABLED.
Rationale: Distributed, serverless peer name resolution is less controllable than centralized name services maintained by authorized staff.
Impact: Some peer-to-peer and collaborative applications, such as Remote Assistance, may not work.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select PNRP Machine Name Publication Service, and set its startup type to Disabled.
From the command line:
sc.exe config PNRPAutoReg start= disabled
Set-Service -Name PNRPAutoReg -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Discovery (TA0007)
Ensure Print Spooler Service Is Disabled
Finding: Print Spooler is not disabled.
Checks that the Print Spooler service, which queues print jobs and drives printers, is disabled.
This rule fails when the Print Spooler service is present and its startType is not DISABLED.
Rationale: Disabling the Print Spooler mitigates the PrintNightmare vulnerability (CVE-2021-34527) and other attacks that target the service.
Impact: Users will be unable to print, including printing to file formats such as PDF that use the spooler.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Print Spooler, and set its startup type to Disabled.
From the command line:
sc.exe config Spooler start= disabled
Set-Service -Name Spooler -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure Problem Reports And Solutions Control Panel Support Is Disabled
Finding: Problem Reports and Solutions Control Panel Support is not disabled.
Checks that the service supporting the Problem Reports and Solutions control panel is disabled.
This rule fails when the Problem Reports and Solutions Control Panel Support service is present and its startType is not DISABLED.
Rationale: This service reports issues to and from Microsoft; blocking it reduces the risk of exposing sensitive corporate information.
Impact: Viewing and sending system-level problem reports and solutions to Microsoft may stop working.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Problem Reports and Solutions Control Panel Support, and set its startup type to Disabled.
From the command line:
sc.exe config wercplsupport start= disabled
Set-Service -Name wercplsupport -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure Remote Access Auto Connection Manager Is Disabled
Finding: Remote Access Auto Connection Manager is not disabled.
Checks that the service that auto-dials a remote connection when a program references a remote name or address is disabled.
This rule fails when the Remote Access Auto Connection Manager service is present and its startType is not DISABLED.
Rationale: Automatic demand-dial connections should be user-initiated, not started automatically by the system, in a high-security environment.
Impact: Dial-on-demand will no longer operate; remote dial-in and VPN connections must be started manually.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Remote Access Auto Connection Manager, and set its startup type to Disabled.
From the command line:
sc.exe config RasAuto start= disabled
Set-Service -Name RasAuto -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure Remote Desktop Configuration Service Is Disabled
Finding: Remote Desktop Configuration is not disabled.
Checks that the Remote Desktop Configuration service, which handles RDP configuration and session maintenance in SYSTEM context, is disabled.
This rule fails when the Remote Desktop Configuration service is present and its startType is not DISABLED.
Rationale: Remote Desktop access increases risk; high-security environments should permit only local console access.
Impact: Users will be unable to use Remote Assistance.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Remote Desktop Configuration, and set its startup type to Disabled.
From the command line:
sc.exe config SessionEnv start= disabled
Set-Service -Name SessionEnv -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Remote Desktop Services Is Disabled
Finding: Remote Desktop Services is not disabled.
Checks that Remote Desktop Services, which lets users connect interactively to the computer, is disabled.
This rule fails when the Remote Desktop Services service is present and its startType is not DISABLED.
Rationale: Remote Desktop access is a significant remote-attack surface; high-security environments should permit only local console access.
Impact: Remote Desktop Services will not be available on the computer.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Remote Desktop Services, and set its startup type to Disabled.
From the command line:
sc.exe config TermService start= disabled
Set-Service -Name TermService -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Remote Desktop Services UserMode Port Redirector Is Disabled
Finding: Remote Desktop Services UserMode Port Redirector is not disabled.
Checks that the service redirecting printers, drives and ports within RDP sessions is disabled.
This rule fails when the Remote Desktop Services UserMode Port Redirector service is present and its startType is not DISABLED.
Rationale: Preventing redirection of COM, LPT and Plug-and-Play ports reduces avenues for data exfiltration and malicious code transfer inside RDP sessions.
Impact: Printers, drives and ports will not be redirected inside RDP sessions.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Remote Desktop Services UserMode Port Redirector, and set its startup type to Disabled.
From the command line:
sc.exe config UmRdpService start= disabled
Set-Service -Name UmRdpService -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure Remote Procedure Call (RPC) Locator Is Disabled
Finding: Remote Procedure Call (RPC) Locator is not disabled.
Checks that the legacy RPC Locator service, retained only for application compatibility, is disabled.
This rule fails when the Remote Procedure Call (RPC) Locator service is present and its startType is not DISABLED.
Rationale: This legacy service serves no purpose beyond compatibility for very old software and should be disabled unless such an application requires it.
Impact: No impact unless an old, legacy application requires the service.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Remote Procedure Call (RPC) Locator, and set its startup type to Disabled.
From the command line:
sc.exe config RpcLocator start= disabled
Set-Service -Name RpcLocator -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure Remote Registry Service Is Disabled
Finding: Remote Registry is not disabled.
Checks that the service allowing remote users to view and modify the registry is disabled.
This rule fails when the Remote Registry service is present and its startType is not DISABLED.
Rationale: Exposing the registry to remote access is a significant security risk on a secured workstation.
Impact: The registry can be viewed and changed only by local users; some remote management and vulnerability-scanning tools that rely on it will be affected.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Remote Registry, and set its startup type to Disabled.
From the command line:
sc.exe config RemoteRegistry start= disabled
Set-Service -Name RemoteRegistry -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Routing And Remote Access Service Is Disabled
Finding: Routing and Remote Access is not disabled.
Checks that the Routing and Remote Access service, which provides router and remote-access functionality, is disabled.
This rule fails when the Routing and Remote Access service is present and its startType is not DISABLED.
Rationale: Turning a workstation into a router or remote-access server is not an appropriate use in an enterprise-managed environment and expands remote exposure.
Impact: The computer cannot be configured as a Windows router between different connections.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Routing and Remote Access, and set its startup type to Disabled.
From the command line:
sc.exe config RemoteAccess start= disabled
Set-Service -Name RemoteAccess -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Server Service Is Disabled
Finding: Server is not disabled.
Checks that the Server service, which provides file, print and named-pipe sharing over the network, is disabled.
This rule fails when the Server service is present and its startType is not DISABLED.
Rationale: A secure workstation should be a client, not a server; sharing its resources for remote access notably increases the attack surface.
Impact: File, print and named-pipe sharing from this machine will be unavailable; some remote management and scanning tools that rely on it will be affected.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Server, and set its startup type to Disabled.
From the command line:
sc.exe config LanmanServer start= disabled
Set-Service -Name LanmanServer -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Simple TCP/IP Services Is Disabled
Finding: Simple TCP/IP Services is not disabled.
Checks that Simple TCP/IP Services (Character Generator, Daytime, Discard, Echo, Quote of the Day) is disabled or not installed.
This rule fails when the Simple TCP/IP Services service is present and its startType is not DISABLED.
Rationale: These legacy services have little purpose in a modern enterprise and increase network exposure and attack risk.
Impact: The Simple TCP/IP services will not be available.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Simple TCP/IP Services, and set its startup type to Disabled.
From the command line:
sc.exe config simptcp start= disabled
Set-Service -Name simptcp -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure SNMP Service Is Disabled
Finding: SNMP Service is not disabled.
Checks that the SNMP service, which processes inbound SNMP requests, is disabled or not installed.
This rule fails when the SNMP Service service is present and its startType is not DISABLED.
Rationale: Services that accept inbound network connections expand the attack surface; secure workstations should be managed locally.
Impact: The computer will be unable to process SNMP requests.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select SNMP Service, and set its startup type to Disabled.
From the command line:
sc.exe config SNMP start= disabled
Set-Service -Name SNMP -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Discovery (TA0007)
Ensure Special Administration Console Helper Is Disabled
Finding: Special Administration Console Helper is not disabled.
Checks that the service allowing administrators remote command-prompt access via Emergency Management Services is disabled or not installed.
This rule fails when the Special Administration Console Helper service is present and its startType is not DISABLED.
Rationale: A remotely accessible command prompt that permits remote management tasks is a significant security risk.
Impact: Users will not have a remote command prompt through Emergency Management Services.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Special Administration Console Helper, and set its startup type to Disabled.
From the command line:
sc.exe config sacsvr start= disabled
Set-Service -Name sacsvr -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure SSDP Discovery Service Is Disabled
Finding: SSDP Discovery is not disabled.
Checks that the SSDP Discovery service, which finds and advertises SSDP/UPnP devices, is disabled.
This rule fails when the SSDP Discovery service is present and its startType is not DISABLED.
Rationale: UPnP allows automatic discovery and attachment to network devices, which secured workstations should not advertise or perform.
Impact: SSDP-based devices will not be discovered.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select SSDP Discovery, and set its startup type to Disabled.
From the command line:
sc.exe config SSDPSRV start= disabled
Set-Service -Name SSDPSRV -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Discovery (TA0007)
Ensure UPnP Device Host Is Disabled
Finding: UPnP Device Host is not disabled.
Checks that the UPnP Device Host service, which hosts UPnP devices on the computer, is disabled.
This rule fails when the UPnP Device Host service is present and its startType is not DISABLED.
Rationale: UPnP allows automatic discovery and attachment to network devices, which secured workstations should not advertise or perform.
Impact: Hosted UPnP devices will stop working and no new hosted devices can be added.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select UPnP Device Host, and set its startup type to Disabled.
From the command line:
sc.exe config upnphost start= disabled
Set-Service -Name upnphost -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Web Management Service Is Disabled
Finding: Web Management Service is not disabled.
Checks that the Web Management Service, which enables remote and delegated IIS management, is disabled or not installed.
This rule fails when the Web Management Service service is present and its startType is not DISABLED.
Rationale: Remote web administration of IIS on a workstation greatly increases its attack surface and chance of successful remote attack.
Impact: Remote web-based management of IIS will be unavailable.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Web Management Service, and set its startup type to Disabled.
From the command line:
sc.exe config WMSvc start= disabled
Set-Service -Name WMSvc -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Windows Error Reporting Service Is Disabled
Finding: Windows Error Reporting Service is not disabled.
Checks that the Windows Error Reporting service, which reports program failures and delivers solutions, is disabled.
This rule fails when the Windows Error Reporting Service service is present and its startType is not DISABLED.
Rationale: Reporting errors directly to Microsoft offers no benefit to the enterprise and risks unknowingly exposing sensitive data.
Impact: Error reporting and the display of diagnostic and repair results may not work correctly.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Windows Error Reporting Service, and set its startup type to Disabled.
From the command line:
sc.exe config WerSvc start= disabled
Set-Service -Name WerSvc -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure Windows Event Collector Service Is Disabled
Finding: Windows Event Collector is not disabled.
Checks that the Windows Event Collector service, which manages WS-Management event subscriptions from remote sources, is disabled.
This rule fails when the Windows Event Collector service is present and its startType is not DISABLED.
Rationale: Remote connections to secure workstations should be minimized, with management performed locally.
Impact: Event subscriptions cannot be created and forwarded events cannot be accepted; some remote management and audit tools depend on this service.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Windows Event Collector, and set its startup type to Disabled.
From the command line:
sc.exe config Wecsvc start= disabled
Set-Service -Name Wecsvc -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Windows Media Player Network Sharing Service Is Disabled
Finding: Windows Media Player Network Sharing Service is not disabled.
Checks that the service sharing Windows Media Player libraries over UPnP is disabled or not installed.
This rule fails when the Windows Media Player Network Sharing Service service is present and its startType is not DISABLED.
Rationale: Network sharing of media libraries has no place in an enterprise-managed environment.
Impact: Media Player libraries will not be shared over the network to other devices.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Windows Media Player Network Sharing Service, and set its startup type to Disabled.
From the command line:
sc.exe config WMPNetworkSvc start= disabled
Set-Service -Name WMPNetworkSvc -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure Windows Mobile Hotspot Service Is Disabled
Finding: Windows Mobile Hotspot Service is not disabled.
Checks that the service that shares a cellular data connection with other devices is disabled.
This rule fails when the Windows Mobile Hotspot Service service is present and its startType is not DISABLED.
Rationale: Running a mobile hotspot from a managed computer can expose the internal network to wardrivers and other attackers.
Impact: The Windows Mobile Hotspot feature will be unavailable.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Windows Mobile Hotspot Service, and set its startup type to Disabled.
From the command line:
sc.exe config icssvc start= disabled
Set-Service -Name icssvc -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Windows Push Notifications System Service Is Disabled
Finding: Windows Push Notifications System Service is not disabled.
Checks that the service hosting the push-notification platform and its connection to the WNS server is disabled.
This rule fails when the Windows Push Notifications System Service service is present and its startType is not DISABLED.
Rationale: Push notifications receive third-party updates from the cloud; external systems should not be able to affect secure workstations.
Impact: Live Tiles and other features will not receive live updates.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Windows Push Notifications System Service, and set its startup type to Disabled.
From the command line:
sc.exe config WpnService start= disabled
Set-Service -Name WpnService -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure Windows PushToInstall Service Is Disabled
Finding: Windows PushToInstall Service is not disabled.
Checks that the service managing apps pushed to the device from the Microsoft Store on other devices or the web is disabled.
This rule fails when the Windows PushToInstall Service service is present and its startType is not DISABLED.
Rationale: Application installation should be managed centrally by IT staff, not initiated remotely by end users.
Impact: Users will be unable to push apps to this device from the Microsoft Store on other devices or the web.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Windows PushToInstall Service, and set its startup type to Disabled.
From the command line:
sc.exe config PushToInstall start= disabled
Set-Service -Name PushToInstall -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure Windows Remote Management (WS-Management) Is Disabled
Finding: Windows Remote Management (WS-Management) is not disabled.
Checks that the WinRM service, which listens on the network for WS-Management requests, is disabled.
This rule fails when the Windows Remote Management (WS-Management) service is present and its startType is not DISABLED.
Rationale: Services that accept inbound network connections expand the attack surface; secure workstations should be managed locally.
Impact: Remote management of the system through WinRM will be lost; some remote management tools depend on this service.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Windows Remote Management (WS-Management), and set its startup type to Disabled.
From the command line:
sc.exe config WinRM start= disabled
Set-Service -Name WinRM -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure World Wide Web Publishing Service Is Disabled
Finding: World Wide Web Publishing Service is not disabled.
Checks that the World Wide Web Publishing service, which provides IIS web connectivity, is disabled or not installed.
This rule fails when the World Wide Web Publishing Service service is present and its startType is not DISABLED.
Rationale: Hosting a website from a workstation greatly increases its attack surface and chance of successful remote attack.
Impact: IIS web services will not function.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select World Wide Web Publishing Service, and set its startup type to Disabled.
From the command line:
sc.exe config W3SVC start= disabled
Set-Service -Name W3SVC -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Xbox Accessory Management Service Is Disabled
Finding: Xbox Accessory Management Service is not disabled.
Checks that the service managing connected Xbox accessories is disabled.
This rule fails when the Xbox Accessory Management Service service is present and its startType is not DISABLED.
Rationale: Xbox Live is a gaming service with no place in an enterprise-managed environment.
Impact: Connected Xbox accessories may not function.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Xbox Accessory Management Service, and set its startup type to Disabled.
From the command line:
sc.exe config XboxGipSvc start= disabled
Set-Service -Name XboxGipSvc -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure Xbox Live Auth Manager Is Disabled
Finding: Xbox Live Auth Manager is not disabled.
Checks that the service providing authentication and authorization for Xbox Live is disabled.
This rule fails when the Xbox Live Auth Manager service is present and its startType is not DISABLED.
Rationale: Xbox Live is a gaming service with no place in an enterprise-managed environment.
Impact: Connections to Xbox Live may fail, along with applications that use the service.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Xbox Live Auth Manager, and set its startup type to Disabled.
From the command line:
sc.exe config XblAuthManager start= disabled
Set-Service -Name XblAuthManager -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure Xbox Live Game Save Is Disabled
Finding: Xbox Live Game Save is not disabled.
Checks that the service that syncs save data for Xbox Live save-enabled games is disabled.
This rule fails when the Xbox Live Game Save service is present and its startType is not DISABLED.
Rationale: Xbox Live is a gaming service with no place in an enterprise-managed environment.
Impact: Game save data will not upload to or download from Xbox Live.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Xbox Live Game Save, and set its startup type to Disabled.
From the command line:
sc.exe config XblGameSave start= disabled
Set-Service -Name XblGameSave -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure Xbox Live Networking Service Is Disabled
Finding: Xbox Live Networking Service is not disabled.
Checks that the service supporting the Windows.Networking.XboxLive API is disabled.
This rule fails when the Xbox Live Networking Service service is present and its startType is not DISABLED.
Rationale: Xbox Live is a gaming service with no place in an enterprise-managed environment.
Impact: Connections to Xbox Live may fail, along with applications that use the service.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Xbox Live Networking Service, and set its startup type to Disabled.
From the command line:
sc.exe config XboxNetApiSvc start= disabled
Set-Service -Name XboxNetApiSvc -StartupType Disabled
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Execution (TA0002)