Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →
1 check on this page
- 3.1 Configure Network Devices
- Ensure Bluetooth services are not in use
3.1 Configure Network Devices
Ensure Bluetooth services are not in use
Finding: Bluetooth service is in use.
Checks whether the Bluetooth (bluez) service is masked or stopped on the endpoint.
This rule fails when the service unit is loaded (not masked) and RUNNING.
Rationale: Bluetooth is a short-range wireless path an attacker can use for bluesnarfing or to spread malicious code; disabling it on systems with no operational need reduces the attack surface.
Impact: Bluetooth peripherals such as wireless keyboards and mice will no longer be able to connect to the system.
Remediation
From the command line:
systemctl stop bluetooth.service
systemctl mask bluetooth.service
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)