Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →
All 23 checks on this page
- The host firewall
- Ensure The Windows Host Firewall Is Enabled
- Ensure The macOS Application Firewall Is Enabled
- Ensure The Linux Host Firewall Is Enabled
- Ensure Windows Endpoints With A Disabled Firewall Are Not On A Network With A Publicly Exposed Gateway
- Ensure macOS Endpoints With A Disabled Firewall Are Not On A Network With A Publicly Exposed Gateway
- Ensure Linux Endpoints With A Disabled Firewall Are Not On A Network With A Publicly Exposed Gateway
- Anti-virus protection
- Ensure Active Antivirus Protection Is Present
- Ensure Antivirus Is Reporting Its State
- The health of the operating system's security services
- Ensure Windows Security Services Are Healthy
- Ensure Endpoint Agents Are Up To Date
- Disk encryption coverage and cipher strength
- Ensure Windows Desktop System Drives Are Encrypted
- Ensure macOS Desktop System Drives Are Encrypted
- Ensure Linux Desktop System Drives Are Encrypted
- Ensure Disk Encryption Does Not Use A Weak Cipher
- Storage capacity and disk utilization
- Ensure Disk Mounts Are Not Critically Full
- Network interface health
- Ensure Network Interfaces Are Not Accumulating Errors
- Known vulnerabilities in the endpoint's operating system and software
- Ensure Endpoints Have No High-Severity Vulnerabilities
- Ensure Installed Applications Have No High-Severity Vulnerabilities
- Ensure Operating System Updates Are Installed Regularly
- Logons and account use, such as remote root logons and the built-in Administrator
- Ensure Root Does Not Log In From External Hosts
- Ensure The Built-In Administrator Account Is Not In Use
- Where the endpoint is, such as a sanctioned country
- Ensure Endpoints Are Not Located In A Sanctioned Country
- Ensure Endpoints Do Not Show Impossible Travel
The host firewall
Ensure The Windows Host Firewall Is Enabled
Finding: The Windows host firewall is disabled.
This rule inspects a Windows endpoint's security posture. This rule fails when the firewall security-service health is POOR or a registered firewall product reports OFF.
Rationale: A disabled host firewall removes a key layer of defense against network-based attacks and lateral movement.
Impact: The host is more exposed to remote exploitation and unauthorized inbound connections.
Remediation
Turn on Microsoft Defender Firewall for the Domain, Private, and Public profiles (Windows Security > Firewall & network protection), or through Group Policy.
From the command line:
Set-NetFirewallProfile -Profile Domain,Private,Public -Enabled True
- Framework mappings
- CIS Controls v8: 4.4 Implement and Manage a Firewall on Servers; 4.5 Implement and Manage a Firewall on End-User Devices
- NIST SP 800-53 Rev. 5: CA-9 Internal System Connections; SC-7 Boundary Protection
- PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.4.1 Deploy NSCs where trusted networks meet untrusted ones
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure The macOS Application Firewall Is Enabled
Finding: The macOS application Firewall is disabled.
This rule inspects a macOS endpoint's security posture. This rule fails when the firewall security-service health is POOR or a registered firewall product reports OFF.
Rationale: A disabled host firewall removes a key layer of defense against network-based attacks and lateral movement.
Impact: The host is more exposed to remote exploitation and unauthorized inbound connections.
Remediation
Turn on the firewall in System Settings > Network > Firewall, or enforce it through your MDM.
From the command line:
/usr/bin/sudo /usr/libexec/ApplicationFirewall/socketfilterfw --setglobalstate on
- Framework mappings
- CIS Controls v8: 4.4 Implement and Manage a Firewall on Servers; 4.5 Implement and Manage a Firewall on End-User Devices
- NIST SP 800-53 Rev. 5: CA-9 Internal System Connections; SC-7 Boundary Protection
- PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.4.1 Deploy NSCs where trusted networks meet untrusted ones
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure The Linux Host Firewall Is Enabled
Finding: The Linux host Firewall is disabled.
This rule inspects a Linux endpoint's security posture. This rule fails when the firewall security-service health is POOR or a registered firewall product reports OFF.
Rationale: A disabled host firewall removes a key layer of defense against network-based attacks and lateral movement.
Impact: The host is more exposed to remote exploitation and unauthorized inbound connections.
Remediation
Turn on the host firewall and allow only the services the endpoint needs.
- Ubuntu or Debian (ufw): run
sudo ufw enable. - Red Hat, Fedora, or SUSE (firewalld): run
sudo systemctl enable --now firewalld.
- Framework mappings
- CIS Controls v8: 4.4 Implement and Manage a Firewall on Servers; 4.5 Implement and Manage a Firewall on End-User Devices
- NIST SP 800-53 Rev. 5: CA-9 Internal System Connections; SC-7 Boundary Protection
- PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.4.1 Deploy NSCs where trusted networks meet untrusted ones
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Windows Endpoints With A Disabled Firewall Are Not On A Network With A Publicly Exposed Gateway
Finding: This Windows endpoint's firewall is off and its network's gateway exposes ports to the public internet.
This rule finds Windows endpoints whose host firewall is disabled or unhealthy while one of their network interfaces is connected to a network whose gateway has a port open to the public internet. A gateway is any device that has acted as the network's gateway in the last 30 days. This rule fails for each such endpoint.
Rationale: A gateway exposing ports to the internet may forward traffic into the network; an endpoint with no host firewall has no second line of defense.
Impact: Services on the endpoint may be reachable from the internet through the gateway, with nothing on the host to block them.
Remediation
Turn Microsoft Defender Firewall back on for every network profile (Windows Security > Firewall & network protection) and confirm it reports healthy. Then review the gateway's internet-exposed ports and close or restrict any that don't need to be public.
- Framework mappings
- CIS Controls v8: 4.4 Implement and Manage a Firewall on Servers; 4.5 Implement and Manage a Firewall on End-User Devices
- NIST SP 800-53 Rev. 5: CA-9 Internal System Connections; SC-7 Boundary Protection
- PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.4.1 Deploy NSCs where trusted networks meet untrusted ones
- Risks
- External Exposure, External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure macOS Endpoints With A Disabled Firewall Are Not On A Network With A Publicly Exposed Gateway
Finding: This macOS endpoint's firewall is off and its network's gateway exposes ports to the public internet.
This rule finds macOS endpoints whose host firewall is disabled or unhealthy while one of their network interfaces is connected to a network whose gateway has a port open to the public internet. A gateway is any device that has acted as the network's gateway in the last 30 days. This rule fails for each such endpoint.
Rationale: A gateway exposing ports to the internet may forward traffic into the network; an endpoint with no host firewall has no second line of defense.
Impact: Services on the endpoint may be reachable from the internet through the gateway, with nothing on the host to block them.
Remediation
Turn the firewall back on in System Settings > Network > Firewall. Then review the gateway's internet-exposed ports and close or restrict any that don't need to be public.
- Framework mappings
- CIS Controls v8: 4.4 Implement and Manage a Firewall on Servers; 4.5 Implement and Manage a Firewall on End-User Devices
- NIST SP 800-53 Rev. 5: CA-9 Internal System Connections; SC-7 Boundary Protection
- PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.4.1 Deploy NSCs where trusted networks meet untrusted ones
- Risks
- External Exposure, External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Linux Endpoints With A Disabled Firewall Are Not On A Network With A Publicly Exposed Gateway
Finding: This Linux endpoint's firewall is off and its network's gateway exposes ports to the public internet.
This rule finds Linux endpoints whose host firewall is disabled or unhealthy while one of their network interfaces is connected to a network whose gateway has a port open to the public internet. A gateway is any device that has acted as the network's gateway in the last 30 days. This rule fails for each such endpoint.
Rationale: A gateway exposing ports to the internet may forward traffic into the network; an endpoint with no host firewall has no second line of defense.
Impact: Services on the endpoint may be reachable from the internet through the gateway, with nothing on the host to block them.
Remediation
Turn the host firewall (ufw or firewalld) back on and confirm it's active. Then review the gateway's internet-exposed ports and close or restrict any that don't need to be public.
- Framework mappings
- CIS Controls v8: 4.4 Implement and Manage a Firewall on Servers; 4.5 Implement and Manage a Firewall on End-User Devices
- NIST SP 800-53 Rev. 5: CA-9 Internal System Connections; SC-7 Boundary Protection
- PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.4.1 Deploy NSCs where trusted networks meet untrusted ones
- Risks
- External Exposure, External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Anti-virus protection
Ensure Active Antivirus Protection Is Present
Finding: No active antivirus protection is present on the endpoint.
This rule inspects an endpoint's registered antivirus products (as reported by Windows Security Center). This rule fails when no antivirus product is in the ON state, or the antivirus security-service health is POOR.
Rationale: Without active antivirus/anti-malware protection, malicious code can run undetected.
Impact: The endpoint is exposed to malware infection and post-exploitation activity.
Remediation
Install and enable a supported antivirus/anti-malware product. On Windows, ensure Microsoft Defender Antivirus (or a third-party AV) is active and up to date in Windows Security.
- Framework mappings
- CIS Controls v8: 10.1 Deploy and Maintain Anti-Malware Software
- NIST SP 800-53 Rev. 5: MP-6 Media Sanitization
- NIST SP 800-171 Rev. 2: 3.14.2 Provide protection from malicious code at designated locations within organizational systems
- CMMC 2.0 Level 1: SI.L1-b.1.xiii Provide protection from malicious code at appropriate locations within organizational information systems
- CMMC 2.0 Level 2: SI.L2-3.14.2 Provide protection from malicious code at designated locations within organizational systems
- PCI DSS v4.0.1: 5.1.1 Malware protection policies and procedures kept documented, current, and applied; 5.2.1 Deploy anti-malware on all systems not evaluated as low risk; 5.2.2 Ensure anti-malware detects and removes or blocks all known malware; 5.3.2 Run periodic and real-time anti-malware scans or behavioral analysis
- Risk
- High Profile Threat
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure Antivirus Is Reporting Its State
Finding: This endpoint's antivirus hasn't reported its state within your reporting window.
This rule reads when each Windows endpoint's antivirus products last reported their state. This rule fails when none has reported within your deployment's reporting window (7 days by default).
Rationale: An antivirus product that stops reporting may have stopped running, stopped updating, or been disabled.
Impact: The endpoint may be unprotected while appearing covered.
Remediation
Open Windows Security > Virus & threat protection on the endpoint, confirm protection is on and definitions are current, and restart or reinstall the antivirus product if it isn't reporting.
- Framework mappings
- CIS Controls v8: 10.1 Deploy and Maintain Anti-Malware Software
- NIST SP 800-53 Rev. 5: MP-6 Media Sanitization
- NIST SP 800-171 Rev. 2: 3.14.2 Provide protection from malicious code at designated locations within organizational systems
- CMMC 2.0 Level 1: SI.L1-b.1.xiii Provide protection from malicious code at appropriate locations within organizational information systems
- CMMC 2.0 Level 2: SI.L2-3.14.2 Provide protection from malicious code at designated locations within organizational systems
- PCI DSS v4.0.1: 5.1.1 Malware protection policies and procedures kept documented, current, and applied; 5.2.1 Deploy anti-malware on all systems not evaluated as low risk; 5.2.2 Ensure anti-malware detects and removes or blocks all known malware; 5.3.2 Run periodic and real-time anti-malware scans or behavioral analysis
- Risk
- High Profile Threat
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
The health of the operating system's security services
Ensure Windows Security Services Are Healthy
Finding: A Windows security service (update, UAC, SmartScreen, etc.) is in an unhealthy state.
This rule inspects the Windows Security Center health of services other than the firewall, antivirus, and disk encryption (which each have dedicated rules). This rule fails when any of autoupdateSettings, antispyware, internetSettings, userAccountController, or securityService reports POOR.
Rationale: These services collectively maintain the endpoint's baseline security posture; an unhealthy state indicates a protection has been disabled or misconfigured.
Impact: Weakened update, UAC, browser, or anti-spyware settings increase the endpoint's exposure to compromise.
Remediation
Open Windows Security and resolve the flagged service: re-enable automatic updates, User Account Control, SmartScreen/Internet settings, anti-spyware, or disk encryption as indicated. Address any 'action needed' items.
- Framework mappings
- CIS Controls v8: 7.3 Perform Automated Operating System Patch Management; 10.1 Deploy and Maintain Anti-Malware Software
- NIST SP 800-53 Rev. 5: MP-6 Media Sanitization; RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
- NIST SP 800-171 Rev. 2: 3.14.2 Provide protection from malicious code at designated locations within organizational systems
- CMMC 2.0 Level 1: SI.L1-b.1.xiii Provide protection from malicious code at appropriate locations within organizational information systems
- CMMC 2.0 Level 2: SI.L2-3.14.2 Provide protection from malicious code at designated locations within organizational systems
- PCI DSS v4.0.1: 5.1.1 Malware protection policies and procedures kept documented, current, and applied; 5.2.1 Deploy anti-malware on all systems not evaluated as low risk; 5.2.2 Ensure anti-malware detects and removes or blocks all known malware; 5.3.2 Run periodic and real-time anti-malware scans or behavioral analysis
- Risk
- Insecure Application
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure Endpoint Agents Are Up To Date
Finding: This endpoint's agent is behind the latest release.
This rule compares each endpoint's agent version with the latest stable build for its platform. This rule fails for an endpoint still running an older agent after the newer build has been available longer than your deployment's grace period (14 days by default).
Rationale: Agent updates carry security fixes and new detections, and auto-update should reach an online endpoint within days.
Impact: An endpoint stuck on an old agent may be missing fixes and may report less than the rest of your fleet.
Remediation
Check why auto-update isn't reaching this endpoint: confirm it's online and can reach the update service, then restart the agent or reinstall the latest build.
- Framework mappings
- CIS Controls v8: 7.4 Perform Automated Application Patch Management
- NIST SP 800-53 Rev. 5: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Disk encryption coverage and cipher strength
Ensure Windows Desktop System Drives Are Encrypted
Finding: A Windows desktop's system drive is not encrypted.
This rule inspects the disk-encryption state of a Windows desktop. This rule fails when the system volume (C:) has an encryption state of OFF.
Rationale: Full-disk encryption protects data at rest if a drive or machine is stolen or improperly decommissioned.
Impact: Data on an unencrypted system drive can be read by anyone with physical access to the disk.
Remediation
Turn on BitLocker for the operating system drive (Control Panel > BitLocker Drive Encryption, or your MDM's disk-encryption policy) and escrow the recovery key to Active Directory or Microsoft Entra ID.
From the command line:
manage-bde -on C: -RecoveryPasswordRequires a restart to take effect.
- Framework mappings
- CIS Controls v8: 3.6 Encrypt Data on End-User Devices
- NIST SP 800-53 Rev. 5: SC-28 Protection of Information at Rest
- NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
- CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure macOS Desktop System Drives Are Encrypted
Finding: A macOS desktop's system drive is not encrypted.
This rule inspects the disk-encryption state of a macOS desktop. This rule fails when the system volume (/) has an encryption state of OFF.
Rationale: Full-disk encryption protects data at rest if a drive or machine is stolen or improperly decommissioned.
Impact: Data on an unencrypted system drive can be read by anyone with physical access to the disk.
Remediation
Turn on FileVault in System Settings > Privacy & Security > FileVault and escrow the recovery key through your MDM.
From the command line:
/usr/bin/sudo /usr/bin/fdesetup enableRequires a restart to take effect.
- Framework mappings
- CIS Controls v8: 3.6 Encrypt Data on End-User Devices
- NIST SP 800-53 Rev. 5: SC-28 Protection of Information at Rest
- NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
- CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure Linux Desktop System Drives Are Encrypted
Finding: A Linux desktop's system drive is not encrypted.
This rule inspects the disk-encryption state of a Linux desktop. This rule fails when the system volume (/) has an encryption state of OFF.
Rationale: Full-disk encryption protects data at rest if a drive or machine is stolen or improperly decommissioned.
Impact: Data on an unencrypted system drive can be read by anyone with physical access to the disk.
Remediation
Encrypt the root volume with LUKS. An existing root volume usually can't be encrypted in place, so this normally means reinstalling with full-disk encryption selected. Escrow the recovery passphrase securely.
- Framework mappings
- CIS Controls v8: 3.6 Encrypt Data on End-User Devices
- NIST SP 800-53 Rev. 5: SC-28 Protection of Information at Rest
- NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
- CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure Disk Encryption Does Not Use A Weak Cipher
Finding: An encrypted drive uses a weak or deprecated cipher.
This rule inspects the cipher used by encrypted volumes. This rule fails when an encrypted volume uses a weak or deprecated method (AES128, AES128_WITH_DIFFUSER, or AES256_WITH_DIFFUSER).
Rationale: 128-bit and legacy BitLocker diffuser modes are weaker than modern XTS-AES-256 and are deprecated.
Impact: Data at rest is protected by a weaker cipher than current standards recommend.
Remediation
Set the BitLocker encryption method to XTS-AES-256 through Group Policy, then decrypt and re-encrypt the drive so it uses the new method.
- Framework mappings
- CIS Controls v8: 3.6 Encrypt Data on End-User Devices
- NIST SP 800-53 Rev. 5: SC-28 Protection of Information at Rest
- NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
- CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Storage capacity and disk utilization
Ensure Disk Mounts Are Not Critically Full
Finding: A disk mount is more than 90% full.
This rule inspects a disk mount's usage. This rule fails when usage.usedPercent exceeds 90%.
Rationale: A nearly-full volume can halt logging, updates, and security tooling, and cause service outages.
Impact: Loss of audit logs, failed updates, and degraded or unavailable services.
Remediation
Free space on the affected volume (remove temporary files, rotate/archive logs, uninstall unused software) or expand the volume. Investigate the cause of rapid growth.
- Risk
- Reliability Impact
- MITRE ATT&CK tactic
- Impact (TA0040)
Network interface health
Ensure Network Interfaces Are Not Accumulating Errors
Finding: A network interface is accumulating input or output errors.
This rule inspects a network interface's error counters. This rule fails when inErrors or outErrors is greater than zero.
Rationale: Interface errors indicate faulty cabling, duplex mismatches, driver problems, or hardware failure, and can also accompany certain network attacks.
Impact: Packet loss and degraded connectivity that can affect availability and reliability of services on the host.
Remediation
Investigate the interface's physical layer: check cabling and connectors, confirm speed/duplex auto-negotiation, update NIC drivers/firmware, and replace faulty hardware. Clear counters and confirm errors do not recur.
- Risk
- Reliability Impact
- MITRE ATT&CK tactic
- Impact (TA0040)
Known vulnerabilities in the endpoint's operating system and software
Ensure Endpoints Have No High-Severity Vulnerabilities
Finding: This endpoint has one or more high or critical severity vulnerabilities.
This rule matches each endpoint's operating system and hardware against known vulnerabilities (CVEs). Installed applications are covered by the "Ensure Installed Applications Have No High-Severity Vulnerabilities" rule. This rule fails for an endpoint with one or more vulnerabilities rated high or critical, and records the most severe, with the total matched, in one finding.
Rationale: High and critical vulnerabilities are the ones attackers most often exploit, many with public exploit code.
Impact: An unpatched high-severity vulnerability can let an attacker run code, escalate privileges, or steal data.
Remediation
Apply the vendor updates that fix the listed CVEs, starting with any marked as known exploited. Where an update isn't available, apply the vendor's mitigation or restrict access to the affected software.
- Framework mappings
- CIS Controls v8: 7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets; 7.7 Remediate Detected Vulnerabilities
- NIST SP 800-53 Rev. 5: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
- NIST SP 800-171 Rev. 2: 3.11.2 Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified; 3.11.3 Remediate vulnerabilities in accordance with risk assessments; 3.14.1 Identify, report, and correct system flaws in a timely manner
- CMMC 2.0 Level 1: SI.L1-b.1.xii Identify, report, and correct information and information system flaws in a timely manner
- CMMC 2.0 Level 2: RA.L2-3.11.2 Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified; RA.L2-3.11.3 Remediate vulnerabilities in accordance with risk assessments; SI.L2-3.14.1 Identify, report, and correct system flaws in a timely manner
- PCI DSS v4.0.1: 11.3.1.1 Address lower-risk vulnerabilities as set by targeted risk analysis; 11.3.1.2 Run credentialed internal scans using adequate privileges; 11.3.1.3 Rescan internally after significant changes and resolve high-risk findings; 11.3.2.1 Run external scans after significant changes and fix CVSS 4.0+ findings
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Installed Applications Have No High-Severity Vulnerabilities
Finding: This installed application has one or more high or critical severity vulnerabilities.
This rule matches each application installed on an endpoint against known vulnerabilities (CVEs). This rule fails for an application with one or more vulnerabilities rated high or critical, and records the most severe, with the total matched, in one finding.
Rationale: Browsers, runtimes, and shared libraries are where attackers find most exploitable flaws, and every installed copy is its own exposure.
Impact: An unpatched high-severity vulnerability in an installed application can let an attacker run code, escalate privileges, or steal data.
Remediation
Update the application to a version that fixes the listed CVEs, starting with any marked as known exploited. Where no update is available, apply the vendor's mitigation or remove the application.
- Framework mappings
- CIS Controls v8: 7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets; 7.7 Remediate Detected Vulnerabilities
- NIST SP 800-53 Rev. 5: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
- NIST SP 800-171 Rev. 2: 3.11.2 Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified; 3.11.3 Remediate vulnerabilities in accordance with risk assessments; 3.14.1 Identify, report, and correct system flaws in a timely manner
- CMMC 2.0 Level 1: SI.L1-b.1.xii Identify, report, and correct information and information system flaws in a timely manner
- CMMC 2.0 Level 2: RA.L2-3.11.2 Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified; RA.L2-3.11.3 Remediate vulnerabilities in accordance with risk assessments; SI.L2-3.14.1 Identify, report, and correct system flaws in a timely manner
- PCI DSS v4.0.1: 11.3.1.1 Address lower-risk vulnerabilities as set by targeted risk analysis; 11.3.1.2 Run credentialed internal scans using adequate privileges; 11.3.1.3 Rescan internally after significant changes and resolve high-risk findings; 11.3.2.1 Run external scans after significant changes and fix CVSS 4.0+ findings
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Operating System Updates Are Installed Regularly
Finding: This endpoint hasn't installed an operating system update within your update window.
This rule reads when each Windows endpoint last installed operating system updates successfully. This rule fails when that was longer ago than your deployment's maximum update age (30 days by default).
Rationale: Operating system updates close actively exploited vulnerabilities, and a monthly patch cycle is the usual baseline.
Impact: An endpoint that stopped patching accumulates known vulnerabilities.
Remediation
Install pending updates in Settings > Windows Update. If updates keep failing, check free disk space and the Windows Update service.
- Framework mappings
- CIS Controls v8: 7.3 Perform Automated Operating System Patch Management; 7.4 Perform Automated Application Patch Management
- NIST SP 800-53 Rev. 5: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Logons and account use, such as remote root logons and the built-in Administrator
Ensure Root Does Not Log In From External Hosts
Finding: The root account logged in to a Linux endpoint from an external host.
This rule finds logon sessions of the root account on Linux endpoints that come from a public address or a hostname. This rule fails for each such session.
Rationale: Direct remote root logons bypass per-user accountability, and root logons from outside your networks are a strong sign of credential compromise or an exposed SSH service.
Impact: An attacker with remote root access has full control of the endpoint.
Note: A host recorded as a hostname counts as external even when it looks private, since reverse DNS is controlled by whoever owns the connecting address. IPv4-mapped IPv6 addresses are judged by their IPv4 address, and carrier-grade NAT addresses (100.64.0.0/10) count as external.
Remediation
Confirm whether this root logon was authorized. Disable direct root logons over SSH (PermitRootLogin no in sshd_config), require administrators to log in as themselves and elevate with sudo, and restrict SSH to trusted networks or a VPN. If the logon wasn't authorized, treat the endpoint as compromised and rotate its credentials.
- Framework mappings
- CIS Controls v8: 5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-6 Least Privilege
- NIST SP 800-171 Rev. 2: 3.1.6 Use non-privileged accounts or roles when accessing nonsecurity functions; 3.1.7 Prevent non-privileged users from executing privileged functions and audit the execution of such functions
- CMMC 2.0 Level 2: AC.L2-3.1.6 Use non-privileged accounts or roles when accessing nonsecurity functions; AC.L2-3.1.7 Prevent non-privileged users from executing privileged functions and audit the execution of such functions
- Risks
- High Profile Threat, External Exposure
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure The Built-In Administrator Account Is Not In Use
Finding: The built-in Windows Administrator account has been used to log on.
This rule finds the built-in Windows Administrator account (the account whose security identifier ends in -500) when it has logon sessions. This rule fails for each such account.
Rationale: The built-in Administrator can't be locked out and is a primary target for password guessing; using it hides which person acted.
Impact: Activity under a shared, well-known privileged account is hard to attribute and invites brute-force attacks.
Remediation
Give administrators individual accounts with administrative rights, then disable the built-in Administrator account (Local Security Policy > Security Options > "Accounts: Administrator account status") or rename it and set a long random password managed by Windows LAPS.
- Framework mappings
- CIS Controls v8: 4.7 Manage Default Accounts on Enterprise Assets and Software; 5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-6 Least Privilege; IA-5 Authenticator Management
- NIST SP 800-171 Rev. 2: 3.1.6 Use non-privileged accounts or roles when accessing nonsecurity functions; 3.1.7 Prevent non-privileged users from executing privileged functions and audit the execution of such functions
- CMMC 2.0 Level 2: AC.L2-3.1.6 Use non-privileged accounts or roles when accessing nonsecurity functions; AC.L2-3.1.7 Prevent non-privileged users from executing privileged functions and audit the execution of such functions
- PCI DSS v4.0.1: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 2.3.1 Replace or confirm default wireless settings when installing access points
- Risk
- High Profile Threat
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Where the endpoint is, such as a sanctioned country
Ensure Endpoints Are Not Located In A Sanctioned Country
Finding: This endpoint was last located in a country under comprehensive U.S. sanctions.
This rule finds endpoints whose last known location is in a country under comprehensive U.S. (OFAC) sanctions: Cuba, Iran, North Korea, or Syria. This rule fails for each such endpoint.
Rationale: Operating equipment or providing services in a comprehensively sanctioned country can violate U.S. export controls and sanctions law, and may indicate stolen or diverted equipment.
Impact: Regulatory exposure and possible loss of control of the endpoint.
Note: Sanctioned regions within other countries, such as Crimea, can't be identified by country code.
Remediation
Confirm the endpoint's location and who holds it. If it isn't authorized to be there, recover or remotely disable it and involve your legal and compliance teams.
Ensure Endpoints Do Not Show Impossible Travel
Finding: This endpoint's location changed faster than anyone could travel.
This rule reads each endpoint's recent precise positions (the last 7 days by default). This rule fails when two consecutive positions far enough apart to rule out location error (100 km by default) imply travel faster than your deployment's maximum speed (1,000 km/h by default).
Rationale: No one can move a laptop that fast, so the jump points to tampered location reports, a cloned or spoofed endpoint, or a shared device identity.
Impact: An endpoint whose identity or telemetry can't be trusted undermines every other finding about it.
Note: Positions too imprecise to compare reliably aren't judged.
Remediation
Confirm who holds the endpoint and where it is. If the locations can't both be right, check for a cloned or re-imaged device sharing its identity, and re-enroll it if needed.
- Risk
- High Profile Threat
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)