Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →
All 14 checks on this page
- 9.2 Private Profile
- Ensure Windows Firewall Private Profile Blocked-Program Notifications Are Disabled
- Ensure Windows Firewall Private Profile Inbound Connections Are Blocked By Default
- Ensure Windows Firewall Private Profile Logging File Path Is Configured
- Ensure Windows Firewall Private Profile Logging Size Limit Is 16,384 KB Or Greater
- Ensure Windows Firewall Private Profile Logs Dropped Packets
- Ensure Windows Firewall Private Profile Logs Successful Connections
- Ensure Windows Firewall Private Profile State Is On
- 9.3 Public Profile
- Ensure Windows Firewall Public Profile Blocked-Program Notifications Are Disabled
- Ensure Windows Firewall Public Profile Inbound Connections Are Blocked By Default
- Ensure Windows Firewall Public Profile Logging File Path Is Configured
- Ensure Windows Firewall Public Profile Logging Size Limit Is 16,384 KB Or Greater
- Ensure Windows Firewall Public Profile Logs Dropped Packets
- Ensure Windows Firewall Public Profile Logs Successful Connections
- Ensure Windows Firewall Public Profile State Is On
9.2 Private Profile
Ensure Windows Firewall Private Profile Blocked-Program Notifications Are Disabled
Finding: Windows Firewall private profile displays a notification when a program is blocked.
Checks whether the firewall suppresses the pop-up shown to users when a program is blocked from accepting inbound connections on the private profile.
This rule fails when disableNotifications is false.
Rationale: Firewall pop-ups can confuse users, who typically cannot act on them, and may prompt them to weaken protection.
Impact: Users no longer see a notification when a program is blocked from receiving inbound connections.
Remediation
Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Private Profile > Settings Customize > Display a notification and set it to No.
From the command line:
netsh advfirewall set privateprofileprofile settings inboundusernotification disable
- Framework mappings
- CIS Controls v8: 4.5 Implement and Manage a Firewall on End-User Devices
- NIST SP 800-53 Rev. 5: SC-7 Boundary Protection
- PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets
- Risk
- External Exposure
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure Windows Firewall Private Profile Inbound Connections Are Blocked By Default
Finding: Windows Firewall private profile does not block inbound connections by default.
Checks the default action for inbound connections that match no firewall rule on the private profile.
This rule fails when defaultInboundAction is not BLOCK_TRAFFIC.
Rationale: If unmatched inbound traffic is allowed, a threat actor can more easily reach and exploit a network service.
Impact: None; this is the default behavior.
Remediation
Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Private Profile > Inbound connections and set it to Block (default).
From the command line:
netsh advfirewall set privateprofileprofile firewallpolicy blockinbound,allowoutbound
- Framework mappings
- CIS Controls v8: 4.5 Implement and Manage a Firewall on End-User Devices
- NIST SP 800-53 Rev. 5: SC-7 Boundary Protection
- PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Windows Firewall Private Profile Logging File Path Is Configured
Finding: Windows Firewall private profile logging file path is not configured.
Checks whether a dedicated log file is configured for the private firewall profile rather than the shared default.
This rule fails when logFilePath is empty or left at the shared default pfirewall.log.
Rationale: Without a dedicated firewall log, administrators may be unable to analyze system issues or trace the activity of a threat actor.
Impact: Firewall log entries for this profile are written to the configured file.
Remediation
Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Private Profile > Logging Customize > Name and set it to a dedicated log file path for this profile (for example %SystemRoot%\System32\logfiles\firewall\privatefw.log).
From the command line:
netsh advfirewall set privateprofileprofile logging filename %SystemRoot%\System32\logfiles\firewall\privatefw.log
- Framework mappings
- CIS Controls v8: 8.2 Collect Audit Logs
- NIST SP 800-53 Rev. 5: AU-2 Event Logging; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation
- PCI DSS v4.0.1: 5.3.4 Enable and retain anti-malware audit logs; 6.4.1 Assess or shield public-facing web applications against known attacks; 6.4.2 Deploy an automated solution that blocks attacks on public web apps; 10.2.1.1 Record every individual user's cardholder data access; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.3 Record any access made to audit records themselves; 10.2.1.4 Record failed logical access attempts; 10.2.1.5 Record account creation, privilege elevation, and other credential changes; 10.2.1.6 Record when audit logging is initialized, started, stopped, or paused; 10.2.1.7 Record the creation or removal of system-level objects; 10.2.2 Include user, event type, date, and time in each log entry
- Risk
- External Exposure
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure Windows Firewall Private Profile Logging Size Limit Is 16,384 KB Or Greater
Finding: Windows Firewall private profile logging size limit is below 16,384 KB.
Checks the maximum size, in kilobytes, of the private firewall log file.
This rule fails when logFileSize is less than 16384.
Rationale: A log that is too small overwrites older entries quickly, which can erase evidence needed to investigate an incident.
Impact: The firewall log grows to the configured size before older entries are overwritten.
Remediation
Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Private Profile > Logging Customize > Size limit (KB) and set it to 16,384 KB or greater.
From the command line:
netsh advfirewall set privateprofileprofile logging maxfilesize 16384
- Framework mappings
- CIS Controls v8: 8.3 Ensure Adequate Audit Log Storage
- NIST SP 800-53 Rev. 5: AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures
- Risk
- External Exposure
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure Windows Firewall Private Profile Logs Dropped Packets
Finding: Windows Firewall private profile does not log dropped packets.
Checks whether the private firewall records inbound packets that it discards.
This rule fails when logDroppedPackets is false.
Rationale: Without a record of dropped packets it is harder to detect scanning or intrusion attempts and to diagnose connectivity problems.
Impact: Dropped packets are recorded in the firewall log file.
Remediation
Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Private Profile > Logging Customize > Log dropped packets and set it to Yes.
From the command line:
netsh advfirewall set privateprofileprofile logging droppedconnections enable
- Framework mappings
- CIS Controls v8: 4.5 Implement and Manage a Firewall on End-User Devices; 8.5 Collect Detailed Audit Logs
- NIST SP 800-53 Rev. 5: AU-3 Content of Audit Records; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation; SC-7 Boundary Protection; SI-4 System Monitoring
- PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 9.4.5 Keep a log-based inventory of electronic media holding cardholder data; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.5 Record account creation, privilege elevation, and other credential changes
- Risk
- External Exposure
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure Windows Firewall Private Profile Logs Successful Connections
Finding: Windows Firewall private profile does not log successful connections.
Checks whether the private firewall records inbound connections that it allows.
This rule fails when logSuccessfulConnections is false.
Rationale: Without a record of allowed connections, investigators lack the context needed to reconstruct activity during an incident.
Impact: Successful connections are recorded in the firewall log file.
Remediation
Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Private Profile > Logging Customize > Log successful connections and set it to Yes.
From the command line:
netsh advfirewall set privateprofileprofile logging allowedconnections enable
- Framework mappings
- CIS Controls v8: 4.5 Implement and Manage a Firewall on End-User Devices; 8.5 Collect Detailed Audit Logs
- NIST SP 800-53 Rev. 5: AU-3 Content of Audit Records; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation; SC-7 Boundary Protection; SI-4 System Monitoring
- PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 9.4.5 Keep a log-based inventory of electronic media holding cardholder data; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.5 Record account creation, privilege elevation, and other credential changes
- Risk
- External Exposure
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure Windows Firewall Private Profile State Is On
Finding: Windows Firewall private profile is turned off.
Checks whether Windows Defender Firewall is turned on for the private network profile.
This rule fails when enableFirewall is false.
Rationale: With the firewall off, all traffic can reach the host and a threat actor can more easily exploit an exposed network service.
Impact: None; this is the default state.
Remediation
Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Private Profile > Firewall state and set it to On (recommended).
From the command line:
netsh advfirewall set privateprofileprofile state on
- Framework mappings
- CIS Controls v8: 4.5 Implement and Manage a Firewall on End-User Devices
- NIST SP 800-53 Rev. 5: SC-7 Boundary Protection
- PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
9.3 Public Profile
Ensure Windows Firewall Public Profile Blocked-Program Notifications Are Disabled
Finding: Windows Firewall public profile displays a notification when a program is blocked.
Checks whether the firewall suppresses the pop-up shown to users when a program is blocked from accepting inbound connections on the public profile.
This rule fails when disableNotifications is false.
Rationale: Firewall pop-ups can confuse users, who typically cannot act on them, and may prompt them to weaken protection.
Impact: Users no longer see a notification when a program is blocked from receiving inbound connections.
Remediation
Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Public Profile > Settings Customize > Display a notification and set it to No.
From the command line:
netsh advfirewall set publicprofileprofile settings inboundusernotification disable
- Framework mappings
- CIS Controls v8: 4.5 Implement and Manage a Firewall on End-User Devices
- NIST SP 800-53 Rev. 5: SC-7 Boundary Protection
- PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets
- Risk
- External Exposure
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure Windows Firewall Public Profile Inbound Connections Are Blocked By Default
Finding: Windows Firewall public profile does not block inbound connections by default.
Checks the default action for inbound connections that match no firewall rule on the public profile.
This rule fails when defaultInboundAction is not BLOCK_TRAFFIC.
Rationale: If unmatched inbound traffic is allowed, a threat actor can more easily reach and exploit a network service.
Impact: None; this is the default behavior.
Remediation
Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Public Profile > Inbound connections and set it to Block (default).
From the command line:
netsh advfirewall set publicprofileprofile firewallpolicy blockinbound,allowoutbound
- Framework mappings
- CIS Controls v8: 4.5 Implement and Manage a Firewall on End-User Devices
- NIST SP 800-53 Rev. 5: SC-7 Boundary Protection
- PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Windows Firewall Public Profile Logging File Path Is Configured
Finding: Windows Firewall public profile logging file path is not configured.
Checks whether a dedicated log file is configured for the public firewall profile rather than the shared default.
This rule fails when logFilePath is empty or left at the shared default pfirewall.log.
Rationale: Without a dedicated firewall log, administrators may be unable to analyze system issues or trace the activity of a threat actor.
Impact: Firewall log entries for this profile are written to the configured file.
Remediation
Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Public Profile > Logging Customize > Name and set it to a dedicated log file path for this profile (for example %SystemRoot%\System32\logfiles\firewall\publicfw.log).
From the command line:
netsh advfirewall set publicprofileprofile logging filename %SystemRoot%\System32\logfiles\firewall\publicfw.log
- Framework mappings
- CIS Controls v8: 8.2 Collect Audit Logs
- NIST SP 800-53 Rev. 5: AU-2 Event Logging; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation
- PCI DSS v4.0.1: 5.3.4 Enable and retain anti-malware audit logs; 6.4.1 Assess or shield public-facing web applications against known attacks; 6.4.2 Deploy an automated solution that blocks attacks on public web apps; 10.2.1.1 Record every individual user's cardholder data access; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.3 Record any access made to audit records themselves; 10.2.1.4 Record failed logical access attempts; 10.2.1.5 Record account creation, privilege elevation, and other credential changes; 10.2.1.6 Record when audit logging is initialized, started, stopped, or paused; 10.2.1.7 Record the creation or removal of system-level objects; 10.2.2 Include user, event type, date, and time in each log entry
- Risk
- External Exposure
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure Windows Firewall Public Profile Logging Size Limit Is 16,384 KB Or Greater
Finding: Windows Firewall public profile logging size limit is below 16,384 KB.
Checks the maximum size, in kilobytes, of the public firewall log file.
This rule fails when logFileSize is less than 16384.
Rationale: A log that is too small overwrites older entries quickly, which can erase evidence needed to investigate an incident.
Impact: The firewall log grows to the configured size before older entries are overwritten.
Remediation
Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Public Profile > Logging Customize > Size limit (KB) and set it to 16,384 KB or greater.
From the command line:
netsh advfirewall set publicprofileprofile logging maxfilesize 16384
- Framework mappings
- CIS Controls v8: 8.3 Ensure Adequate Audit Log Storage
- NIST SP 800-53 Rev. 5: AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures
- Risk
- External Exposure
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure Windows Firewall Public Profile Logs Dropped Packets
Finding: Windows Firewall public profile does not log dropped packets.
Checks whether the public firewall records inbound packets that it discards.
This rule fails when logDroppedPackets is false.
Rationale: Without a record of dropped packets it is harder to detect scanning or intrusion attempts and to diagnose connectivity problems.
Impact: Dropped packets are recorded in the firewall log file.
Remediation
Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Public Profile > Logging Customize > Log dropped packets and set it to Yes.
From the command line:
netsh advfirewall set publicprofileprofile logging droppedconnections enable
- Framework mappings
- CIS Controls v8: 4.5 Implement and Manage a Firewall on End-User Devices; 8.5 Collect Detailed Audit Logs
- NIST SP 800-53 Rev. 5: AU-3 Content of Audit Records; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation; SC-7 Boundary Protection; SI-4 System Monitoring
- PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 9.4.5 Keep a log-based inventory of electronic media holding cardholder data; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.5 Record account creation, privilege elevation, and other credential changes
- Risk
- External Exposure
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure Windows Firewall Public Profile Logs Successful Connections
Finding: Windows Firewall public profile does not log successful connections.
Checks whether the public firewall records inbound connections that it allows.
This rule fails when logSuccessfulConnections is false.
Rationale: Without a record of allowed connections, investigators lack the context needed to reconstruct activity during an incident.
Impact: Successful connections are recorded in the firewall log file.
Remediation
Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Public Profile > Logging Customize > Log successful connections and set it to Yes.
From the command line:
netsh advfirewall set publicprofileprofile logging allowedconnections enable
- Framework mappings
- CIS Controls v8: 4.5 Implement and Manage a Firewall on End-User Devices; 8.5 Collect Detailed Audit Logs
- NIST SP 800-53 Rev. 5: AU-3 Content of Audit Records; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation; SC-7 Boundary Protection; SI-4 System Monitoring
- PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 9.4.5 Keep a log-based inventory of electronic media holding cardholder data; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.5 Record account creation, privilege elevation, and other credential changes
- Risk
- External Exposure
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure Windows Firewall Public Profile State Is On
Finding: Windows Firewall public profile is turned off.
Checks whether Windows Defender Firewall is turned on for the public network profile.
This rule fails when enableFirewall is false.
Rationale: With the firewall off, all traffic can reach the host and a threat actor can more easily exploit an exposed network service.
Impact: None; this is the default state.
Remediation
Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Public Profile > Firewall state and set it to On (recommended).
From the command line:
netsh advfirewall set publicprofileprofile state on
- Framework mappings
- CIS Controls v8: 4.5 Implement and Manage a Firewall on End-User Devices
- NIST SP 800-53 Rev. 5: SC-7 Boundary Protection
- PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)