Wartiva Security Controls

Endpoint Posture: 23 Checks

Wartiva's Endpoint Posture controls: the basics on every endpoint: host firewall, antivirus, security services, disk encryption, storage, network interfaces, vulnerabilities, logons, and location.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →

All 23 checks on this page

The host firewall

Ensure The Windows Host Firewall Is Enabled

High severity · Wartiva Security Controls · Endpoint Posture

Finding: The Windows host firewall is disabled.

This rule inspects a Windows endpoint's security posture. This rule fails when the firewall security-service health is POOR or a registered firewall product reports OFF.

Rationale: A disabled host firewall removes a key layer of defense against network-based attacks and lateral movement.

Impact: The host is more exposed to remote exploitation and unauthorized inbound connections.

Remediation

Turn on Microsoft Defender Firewall for the Domain, Private, and Public profiles (Windows Security > Firewall & network protection), or through Group Policy.

From the command line:

Set-NetFirewallProfile -Profile Domain,Private,Public -Enabled True
Framework mappings
  • CIS Controls v8: 4.4 Implement and Manage a Firewall on Servers; 4.5 Implement and Manage a Firewall on End-User Devices
  • NIST SP 800-53 Rev. 5: CA-9 Internal System Connections; SC-7 Boundary Protection
  • PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.4.1 Deploy NSCs where trusted networks meet untrusted ones
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure The macOS Application Firewall Is Enabled

High severity · Wartiva Security Controls · Endpoint Posture

Finding: The macOS application Firewall is disabled.

This rule inspects a macOS endpoint's security posture. This rule fails when the firewall security-service health is POOR or a registered firewall product reports OFF.

Rationale: A disabled host firewall removes a key layer of defense against network-based attacks and lateral movement.

Impact: The host is more exposed to remote exploitation and unauthorized inbound connections.

Remediation

Turn on the firewall in System Settings > Network > Firewall, or enforce it through your MDM.

From the command line:

/usr/bin/sudo /usr/libexec/ApplicationFirewall/socketfilterfw --setglobalstate on
Framework mappings
  • CIS Controls v8: 4.4 Implement and Manage a Firewall on Servers; 4.5 Implement and Manage a Firewall on End-User Devices
  • NIST SP 800-53 Rev. 5: CA-9 Internal System Connections; SC-7 Boundary Protection
  • PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.4.1 Deploy NSCs where trusted networks meet untrusted ones
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure The Linux Host Firewall Is Enabled

High severity · Wartiva Security Controls · Endpoint Posture

Finding: The Linux host Firewall is disabled.

This rule inspects a Linux endpoint's security posture. This rule fails when the firewall security-service health is POOR or a registered firewall product reports OFF.

Rationale: A disabled host firewall removes a key layer of defense against network-based attacks and lateral movement.

Impact: The host is more exposed to remote exploitation and unauthorized inbound connections.

Remediation

Turn on the host firewall and allow only the services the endpoint needs.

  • Ubuntu or Debian (ufw): run sudo ufw enable.
  • Red Hat, Fedora, or SUSE (firewalld): run sudo systemctl enable --now firewalld.
Framework mappings
  • CIS Controls v8: 4.4 Implement and Manage a Firewall on Servers; 4.5 Implement and Manage a Firewall on End-User Devices
  • NIST SP 800-53 Rev. 5: CA-9 Internal System Connections; SC-7 Boundary Protection
  • PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.4.1 Deploy NSCs where trusted networks meet untrusted ones
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Windows Endpoints With A Disabled Firewall Are Not On A Network With A Publicly Exposed Gateway

High severity · Wartiva Security Controls · Endpoint Posture

Finding: This Windows endpoint's firewall is off and its network's gateway exposes ports to the public internet.

This rule finds Windows endpoints whose host firewall is disabled or unhealthy while one of their network interfaces is connected to a network whose gateway has a port open to the public internet. A gateway is any device that has acted as the network's gateway in the last 30 days. This rule fails for each such endpoint.

Rationale: A gateway exposing ports to the internet may forward traffic into the network; an endpoint with no host firewall has no second line of defense.

Impact: Services on the endpoint may be reachable from the internet through the gateway, with nothing on the host to block them.

Remediation

Turn Microsoft Defender Firewall back on for every network profile (Windows Security > Firewall & network protection) and confirm it reports healthy. Then review the gateway's internet-exposed ports and close or restrict any that don't need to be public.

Framework mappings
  • CIS Controls v8: 4.4 Implement and Manage a Firewall on Servers; 4.5 Implement and Manage a Firewall on End-User Devices
  • NIST SP 800-53 Rev. 5: CA-9 Internal System Connections; SC-7 Boundary Protection
  • PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.4.1 Deploy NSCs where trusted networks meet untrusted ones
Risks
External Exposure, External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure macOS Endpoints With A Disabled Firewall Are Not On A Network With A Publicly Exposed Gateway

High severity · Wartiva Security Controls · Endpoint Posture

Finding: This macOS endpoint's firewall is off and its network's gateway exposes ports to the public internet.

This rule finds macOS endpoints whose host firewall is disabled or unhealthy while one of their network interfaces is connected to a network whose gateway has a port open to the public internet. A gateway is any device that has acted as the network's gateway in the last 30 days. This rule fails for each such endpoint.

Rationale: A gateway exposing ports to the internet may forward traffic into the network; an endpoint with no host firewall has no second line of defense.

Impact: Services on the endpoint may be reachable from the internet through the gateway, with nothing on the host to block them.

Remediation

Turn the firewall back on in System Settings > Network > Firewall. Then review the gateway's internet-exposed ports and close or restrict any that don't need to be public.

Framework mappings
  • CIS Controls v8: 4.4 Implement and Manage a Firewall on Servers; 4.5 Implement and Manage a Firewall on End-User Devices
  • NIST SP 800-53 Rev. 5: CA-9 Internal System Connections; SC-7 Boundary Protection
  • PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.4.1 Deploy NSCs where trusted networks meet untrusted ones
Risks
External Exposure, External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Linux Endpoints With A Disabled Firewall Are Not On A Network With A Publicly Exposed Gateway

High severity · Wartiva Security Controls · Endpoint Posture

Finding: This Linux endpoint's firewall is off and its network's gateway exposes ports to the public internet.

This rule finds Linux endpoints whose host firewall is disabled or unhealthy while one of their network interfaces is connected to a network whose gateway has a port open to the public internet. A gateway is any device that has acted as the network's gateway in the last 30 days. This rule fails for each such endpoint.

Rationale: A gateway exposing ports to the internet may forward traffic into the network; an endpoint with no host firewall has no second line of defense.

Impact: Services on the endpoint may be reachable from the internet through the gateway, with nothing on the host to block them.

Remediation

Turn the host firewall (ufw or firewalld) back on and confirm it's active. Then review the gateway's internet-exposed ports and close or restrict any that don't need to be public.

Framework mappings
  • CIS Controls v8: 4.4 Implement and Manage a Firewall on Servers; 4.5 Implement and Manage a Firewall on End-User Devices
  • NIST SP 800-53 Rev. 5: CA-9 Internal System Connections; SC-7 Boundary Protection
  • PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.4.1 Deploy NSCs where trusted networks meet untrusted ones
Risks
External Exposure, External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Anti-virus protection

Ensure Active Antivirus Protection Is Present

High severity · Wartiva Security Controls · Endpoint Posture

Finding: No active antivirus protection is present on the endpoint.

This rule inspects an endpoint's registered antivirus products (as reported by Windows Security Center). This rule fails when no antivirus product is in the ON state, or the antivirus security-service health is POOR.

Rationale: Without active antivirus/anti-malware protection, malicious code can run undetected.

Impact: The endpoint is exposed to malware infection and post-exploitation activity.

Remediation

Install and enable a supported antivirus/anti-malware product. On Windows, ensure Microsoft Defender Antivirus (or a third-party AV) is active and up to date in Windows Security.

Framework mappings
  • CIS Controls v8: 10.1 Deploy and Maintain Anti-Malware Software
  • NIST SP 800-53 Rev. 5: MP-6 Media Sanitization
  • NIST SP 800-171 Rev. 2: 3.14.2 Provide protection from malicious code at designated locations within organizational systems
  • CMMC 2.0 Level 1: SI.L1-b.1.xiii Provide protection from malicious code at appropriate locations within organizational information systems
  • CMMC 2.0 Level 2: SI.L2-3.14.2 Provide protection from malicious code at designated locations within organizational systems
  • PCI DSS v4.0.1: 5.1.1 Malware protection policies and procedures kept documented, current, and applied; 5.2.1 Deploy anti-malware on all systems not evaluated as low risk; 5.2.2 Ensure anti-malware detects and removes or blocks all known malware; 5.3.2 Run periodic and real-time anti-malware scans or behavioral analysis
Risk
High Profile Threat
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Antivirus Is Reporting Its State

High severity · Wartiva Security Controls · Endpoint Posture

Finding: This endpoint's antivirus hasn't reported its state within your reporting window.

This rule reads when each Windows endpoint's antivirus products last reported their state. This rule fails when none has reported within your deployment's reporting window (7 days by default).

Rationale: An antivirus product that stops reporting may have stopped running, stopped updating, or been disabled.

Impact: The endpoint may be unprotected while appearing covered.

Remediation

Open Windows Security > Virus & threat protection on the endpoint, confirm protection is on and definitions are current, and restart or reinstall the antivirus product if it isn't reporting.

Framework mappings
  • CIS Controls v8: 10.1 Deploy and Maintain Anti-Malware Software
  • NIST SP 800-53 Rev. 5: MP-6 Media Sanitization
  • NIST SP 800-171 Rev. 2: 3.14.2 Provide protection from malicious code at designated locations within organizational systems
  • CMMC 2.0 Level 1: SI.L1-b.1.xiii Provide protection from malicious code at appropriate locations within organizational information systems
  • CMMC 2.0 Level 2: SI.L2-3.14.2 Provide protection from malicious code at designated locations within organizational systems
  • PCI DSS v4.0.1: 5.1.1 Malware protection policies and procedures kept documented, current, and applied; 5.2.1 Deploy anti-malware on all systems not evaluated as low risk; 5.2.2 Ensure anti-malware detects and removes or blocks all known malware; 5.3.2 Run periodic and real-time anti-malware scans or behavioral analysis
Risk
High Profile Threat
MITRE ATT&CK tactic
Defense Evasion (TA0005)

The health of the operating system's security services

Ensure Windows Security Services Are Healthy

Medium severity · Wartiva Security Controls · Endpoint Posture

Finding: A Windows security service (update, UAC, SmartScreen, etc.) is in an unhealthy state.

This rule inspects the Windows Security Center health of services other than the firewall, antivirus, and disk encryption (which each have dedicated rules). This rule fails when any of autoupdateSettings, antispyware, internetSettings, userAccountController, or securityService reports POOR.

Rationale: These services collectively maintain the endpoint's baseline security posture; an unhealthy state indicates a protection has been disabled or misconfigured.

Impact: Weakened update, UAC, browser, or anti-spyware settings increase the endpoint's exposure to compromise.

Remediation

Open Windows Security and resolve the flagged service: re-enable automatic updates, User Account Control, SmartScreen/Internet settings, anti-spyware, or disk encryption as indicated. Address any 'action needed' items.

Framework mappings
  • CIS Controls v8: 7.3 Perform Automated Operating System Patch Management; 10.1 Deploy and Maintain Anti-Malware Software
  • NIST SP 800-53 Rev. 5: MP-6 Media Sanitization; RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
  • NIST SP 800-171 Rev. 2: 3.14.2 Provide protection from malicious code at designated locations within organizational systems
  • CMMC 2.0 Level 1: SI.L1-b.1.xiii Provide protection from malicious code at appropriate locations within organizational information systems
  • CMMC 2.0 Level 2: SI.L2-3.14.2 Provide protection from malicious code at designated locations within organizational systems
  • PCI DSS v4.0.1: 5.1.1 Malware protection policies and procedures kept documented, current, and applied; 5.2.1 Deploy anti-malware on all systems not evaluated as low risk; 5.2.2 Ensure anti-malware detects and removes or blocks all known malware; 5.3.2 Run periodic and real-time anti-malware scans or behavioral analysis
Risk
Insecure Application
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure Endpoint Agents Are Up To Date

Medium severity · Wartiva Security Controls · Endpoint Posture

Finding: This endpoint's agent is behind the latest release.

This rule compares each endpoint's agent version with the latest stable build for its platform. This rule fails for an endpoint still running an older agent after the newer build has been available longer than your deployment's grace period (14 days by default).

Rationale: Agent updates carry security fixes and new detections, and auto-update should reach an online endpoint within days.

Impact: An endpoint stuck on an old agent may be missing fixes and may report less than the rest of your fleet.

Remediation

Check why auto-update isn't reaching this endpoint: confirm it's online and can reach the update service, then restart the agent or reinstall the latest build.

Framework mappings
  • CIS Controls v8: 7.4 Perform Automated Application Patch Management
  • NIST SP 800-53 Rev. 5: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
Risk
Vulnerability
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Disk encryption coverage and cipher strength

Ensure Windows Desktop System Drives Are Encrypted

High severity · Wartiva Security Controls · Endpoint Posture

Finding: A Windows desktop's system drive is not encrypted.

This rule inspects the disk-encryption state of a Windows desktop. This rule fails when the system volume (C:) has an encryption state of OFF.

Rationale: Full-disk encryption protects data at rest if a drive or machine is stolen or improperly decommissioned.

Impact: Data on an unencrypted system drive can be read by anyone with physical access to the disk.

Remediation

Turn on BitLocker for the operating system drive (Control Panel > BitLocker Drive Encryption, or your MDM's disk-encryption policy) and escrow the recovery key to Active Directory or Microsoft Entra ID.

From the command line:

manage-bde -on C: -RecoveryPassword

Requires a restart to take effect.

Framework mappings
  • CIS Controls v8: 3.6 Encrypt Data on End-User Devices
  • NIST SP 800-53 Rev. 5: SC-28 Protection of Information at Rest
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
Risk
Unprotected Data
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure macOS Desktop System Drives Are Encrypted

High severity · Wartiva Security Controls · Endpoint Posture

Finding: A macOS desktop's system drive is not encrypted.

This rule inspects the disk-encryption state of a macOS desktop. This rule fails when the system volume (/) has an encryption state of OFF.

Rationale: Full-disk encryption protects data at rest if a drive or machine is stolen or improperly decommissioned.

Impact: Data on an unencrypted system drive can be read by anyone with physical access to the disk.

Remediation

Turn on FileVault in System Settings > Privacy & Security > FileVault and escrow the recovery key through your MDM.

From the command line:

/usr/bin/sudo /usr/bin/fdesetup enable

Requires a restart to take effect.

Framework mappings
  • CIS Controls v8: 3.6 Encrypt Data on End-User Devices
  • NIST SP 800-53 Rev. 5: SC-28 Protection of Information at Rest
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
Risk
Unprotected Data
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure Linux Desktop System Drives Are Encrypted

High severity · Wartiva Security Controls · Endpoint Posture

Finding: A Linux desktop's system drive is not encrypted.

This rule inspects the disk-encryption state of a Linux desktop. This rule fails when the system volume (/) has an encryption state of OFF.

Rationale: Full-disk encryption protects data at rest if a drive or machine is stolen or improperly decommissioned.

Impact: Data on an unencrypted system drive can be read by anyone with physical access to the disk.

Remediation

Encrypt the root volume with LUKS. An existing root volume usually can't be encrypted in place, so this normally means reinstalling with full-disk encryption selected. Escrow the recovery passphrase securely.

Framework mappings
  • CIS Controls v8: 3.6 Encrypt Data on End-User Devices
  • NIST SP 800-53 Rev. 5: SC-28 Protection of Information at Rest
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
Risk
Unprotected Data
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure Disk Encryption Does Not Use A Weak Cipher

Medium severity · Wartiva Security Controls · Endpoint Posture

Finding: An encrypted drive uses a weak or deprecated cipher.

This rule inspects the cipher used by encrypted volumes. This rule fails when an encrypted volume uses a weak or deprecated method (AES128, AES128_WITH_DIFFUSER, or AES256_WITH_DIFFUSER).

Rationale: 128-bit and legacy BitLocker diffuser modes are weaker than modern XTS-AES-256 and are deprecated.

Impact: Data at rest is protected by a weaker cipher than current standards recommend.

Remediation

Set the BitLocker encryption method to XTS-AES-256 through Group Policy, then decrypt and re-encrypt the drive so it uses the new method.

Framework mappings
  • CIS Controls v8: 3.6 Encrypt Data on End-User Devices
  • NIST SP 800-53 Rev. 5: SC-28 Protection of Information at Rest
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
Risk
Unprotected Data
MITRE ATT&CK tactic
Credential Access (TA0006)

Storage capacity and disk utilization

Ensure Disk Mounts Are Not Critically Full

Medium severity · Wartiva Security Controls · Endpoint Posture

Finding: A disk mount is more than 90% full.

This rule inspects a disk mount's usage. This rule fails when usage.usedPercent exceeds 90%.

Rationale: A nearly-full volume can halt logging, updates, and security tooling, and cause service outages.

Impact: Loss of audit logs, failed updates, and degraded or unavailable services.

Remediation

Free space on the affected volume (remove temporary files, rotate/archive logs, uninstall unused software) or expand the volume. Investigate the cause of rapid growth.

Risk
Reliability Impact
MITRE ATT&CK tactic
Impact (TA0040)

Network interface health

Ensure Network Interfaces Are Not Accumulating Errors

Low severity · Wartiva Security Controls · Endpoint Posture

Finding: A network interface is accumulating input or output errors.

This rule inspects a network interface's error counters. This rule fails when inErrors or outErrors is greater than zero.

Rationale: Interface errors indicate faulty cabling, duplex mismatches, driver problems, or hardware failure, and can also accompany certain network attacks.

Impact: Packet loss and degraded connectivity that can affect availability and reliability of services on the host.

Remediation

Investigate the interface's physical layer: check cabling and connectors, confirm speed/duplex auto-negotiation, update NIC drivers/firmware, and replace faulty hardware. Clear counters and confirm errors do not recur.

Risk
Reliability Impact
MITRE ATT&CK tactic
Impact (TA0040)

Known vulnerabilities in the endpoint's operating system and software

Ensure Endpoints Have No High-Severity Vulnerabilities

High severity · Wartiva Security Controls · Endpoint Posture

Finding: This endpoint has one or more high or critical severity vulnerabilities.

This rule matches each endpoint's operating system and hardware against known vulnerabilities (CVEs). Installed applications are covered by the "Ensure Installed Applications Have No High-Severity Vulnerabilities" rule. This rule fails for an endpoint with one or more vulnerabilities rated high or critical, and records the most severe, with the total matched, in one finding.

Rationale: High and critical vulnerabilities are the ones attackers most often exploit, many with public exploit code.

Impact: An unpatched high-severity vulnerability can let an attacker run code, escalate privileges, or steal data.

Remediation

Apply the vendor updates that fix the listed CVEs, starting with any marked as known exploited. Where an update isn't available, apply the vendor's mitigation or restrict access to the affected software.

Framework mappings
  • CIS Controls v8: 7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets; 7.7 Remediate Detected Vulnerabilities
  • NIST SP 800-53 Rev. 5: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
  • NIST SP 800-171 Rev. 2: 3.11.2 Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified; 3.11.3 Remediate vulnerabilities in accordance with risk assessments; 3.14.1 Identify, report, and correct system flaws in a timely manner
  • CMMC 2.0 Level 1: SI.L1-b.1.xii Identify, report, and correct information and information system flaws in a timely manner
  • CMMC 2.0 Level 2: RA.L2-3.11.2 Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified; RA.L2-3.11.3 Remediate vulnerabilities in accordance with risk assessments; SI.L2-3.14.1 Identify, report, and correct system flaws in a timely manner
  • PCI DSS v4.0.1: 11.3.1.1 Address lower-risk vulnerabilities as set by targeted risk analysis; 11.3.1.2 Run credentialed internal scans using adequate privileges; 11.3.1.3 Rescan internally after significant changes and resolve high-risk findings; 11.3.2.1 Run external scans after significant changes and fix CVSS 4.0+ findings
Risk
Vulnerability
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Installed Applications Have No High-Severity Vulnerabilities

High severity · Wartiva Security Controls · Endpoint Posture

Finding: This installed application has one or more high or critical severity vulnerabilities.

This rule matches each application installed on an endpoint against known vulnerabilities (CVEs). This rule fails for an application with one or more vulnerabilities rated high or critical, and records the most severe, with the total matched, in one finding.

Rationale: Browsers, runtimes, and shared libraries are where attackers find most exploitable flaws, and every installed copy is its own exposure.

Impact: An unpatched high-severity vulnerability in an installed application can let an attacker run code, escalate privileges, or steal data.

Remediation

Update the application to a version that fixes the listed CVEs, starting with any marked as known exploited. Where no update is available, apply the vendor's mitigation or remove the application.

Framework mappings
  • CIS Controls v8: 7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets; 7.7 Remediate Detected Vulnerabilities
  • NIST SP 800-53 Rev. 5: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
  • NIST SP 800-171 Rev. 2: 3.11.2 Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified; 3.11.3 Remediate vulnerabilities in accordance with risk assessments; 3.14.1 Identify, report, and correct system flaws in a timely manner
  • CMMC 2.0 Level 1: SI.L1-b.1.xii Identify, report, and correct information and information system flaws in a timely manner
  • CMMC 2.0 Level 2: RA.L2-3.11.2 Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified; RA.L2-3.11.3 Remediate vulnerabilities in accordance with risk assessments; SI.L2-3.14.1 Identify, report, and correct system flaws in a timely manner
  • PCI DSS v4.0.1: 11.3.1.1 Address lower-risk vulnerabilities as set by targeted risk analysis; 11.3.1.2 Run credentialed internal scans using adequate privileges; 11.3.1.3 Rescan internally after significant changes and resolve high-risk findings; 11.3.2.1 Run external scans after significant changes and fix CVSS 4.0+ findings
Risk
Vulnerability
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Operating System Updates Are Installed Regularly

High severity · Wartiva Security Controls · Endpoint Posture

Finding: This endpoint hasn't installed an operating system update within your update window.

This rule reads when each Windows endpoint last installed operating system updates successfully. This rule fails when that was longer ago than your deployment's maximum update age (30 days by default).

Rationale: Operating system updates close actively exploited vulnerabilities, and a monthly patch cycle is the usual baseline.

Impact: An endpoint that stopped patching accumulates known vulnerabilities.

Remediation

Install pending updates in Settings > Windows Update. If updates keep failing, check free disk space and the Windows Update service.

Framework mappings
  • CIS Controls v8: 7.3 Perform Automated Operating System Patch Management; 7.4 Perform Automated Application Patch Management
  • NIST SP 800-53 Rev. 5: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
Risk
Vulnerability
MITRE ATT&CK tactic
Initial Access (TA0001)

Logons and account use, such as remote root logons and the built-in Administrator

Ensure Root Does Not Log In From External Hosts

High severity · Wartiva Security Controls · Endpoint Posture

Finding: The root account logged in to a Linux endpoint from an external host.

This rule finds logon sessions of the root account on Linux endpoints that come from a public address or a hostname. This rule fails for each such session.

Rationale: Direct remote root logons bypass per-user accountability, and root logons from outside your networks are a strong sign of credential compromise or an exposed SSH service.

Impact: An attacker with remote root access has full control of the endpoint.

Note: A host recorded as a hostname counts as external even when it looks private, since reverse DNS is controlled by whoever owns the connecting address. IPv4-mapped IPv6 addresses are judged by their IPv4 address, and carrier-grade NAT addresses (100.64.0.0/10) count as external.

Remediation

Confirm whether this root logon was authorized. Disable direct root logons over SSH (PermitRootLogin no in sshd_config), require administrators to log in as themselves and elevate with sudo, and restrict SSH to trusted networks or a VPN. If the logon wasn't authorized, treat the endpoint as compromised and rotate its credentials.

Framework mappings
  • CIS Controls v8: 5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts
  • NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-6 Least Privilege
  • NIST SP 800-171 Rev. 2: 3.1.6 Use non-privileged accounts or roles when accessing nonsecurity functions; 3.1.7 Prevent non-privileged users from executing privileged functions and audit the execution of such functions
  • CMMC 2.0 Level 2: AC.L2-3.1.6 Use non-privileged accounts or roles when accessing nonsecurity functions; AC.L2-3.1.7 Prevent non-privileged users from executing privileged functions and audit the execution of such functions
Risks
High Profile Threat, External Exposure
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure The Built-In Administrator Account Is Not In Use

Medium severity · Wartiva Security Controls · Endpoint Posture

Finding: The built-in Windows Administrator account has been used to log on.

This rule finds the built-in Windows Administrator account (the account whose security identifier ends in -500) when it has logon sessions. This rule fails for each such account.

Rationale: The built-in Administrator can't be locked out and is a primary target for password guessing; using it hides which person acted.

Impact: Activity under a shared, well-known privileged account is hard to attribute and invites brute-force attacks.

Remediation

Give administrators individual accounts with administrative rights, then disable the built-in Administrator account (Local Security Policy > Security Options > "Accounts: Administrator account status") or rename it and set a long random password managed by Windows LAPS.

Framework mappings
  • CIS Controls v8: 4.7 Manage Default Accounts on Enterprise Assets and Software; 5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts
  • NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-6 Least Privilege; IA-5 Authenticator Management
  • NIST SP 800-171 Rev. 2: 3.1.6 Use non-privileged accounts or roles when accessing nonsecurity functions; 3.1.7 Prevent non-privileged users from executing privileged functions and audit the execution of such functions
  • CMMC 2.0 Level 2: AC.L2-3.1.6 Use non-privileged accounts or roles when accessing nonsecurity functions; AC.L2-3.1.7 Prevent non-privileged users from executing privileged functions and audit the execution of such functions
  • PCI DSS v4.0.1: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 2.3.1 Replace or confirm default wireless settings when installing access points
Risk
High Profile Threat
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Where the endpoint is, such as a sanctioned country

Ensure Endpoints Are Not Located In A Sanctioned Country

High severity · Wartiva Security Controls · Endpoint Posture

Finding: This endpoint was last located in a country under comprehensive U.S. sanctions.

This rule finds endpoints whose last known location is in a country under comprehensive U.S. (OFAC) sanctions: Cuba, Iran, North Korea, or Syria. This rule fails for each such endpoint.

Rationale: Operating equipment or providing services in a comprehensively sanctioned country can violate U.S. export controls and sanctions law, and may indicate stolen or diverted equipment.

Impact: Regulatory exposure and possible loss of control of the endpoint.

Note: Sanctioned regions within other countries, such as Crimea, can't be identified by country code.

Remediation

Confirm the endpoint's location and who holds it. If it isn't authorized to be there, recover or remotely disable it and involve your legal and compliance teams.

Risk
High Profile Threat
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Endpoints Do Not Show Impossible Travel

High severity · Wartiva Security Controls · Endpoint Posture

Finding: This endpoint's location changed faster than anyone could travel.

This rule reads each endpoint's recent precise positions (the last 7 days by default). This rule fails when two consecutive positions far enough apart to rule out location error (100 km by default) imply travel faster than your deployment's maximum speed (1,000 km/h by default).

Rationale: No one can move a laptop that fast, so the jump points to tampered location reports, a cloned or spoofed endpoint, or a shared device identity.

Impact: An endpoint whose identity or telemetry can't be trusted undermines every other finding about it.

Note: Positions too imprecise to compare reliably aren't judged.

Remediation

Confirm who holds the endpoint and where it is. If the locations can't both be right, check for a cloned or re-imaged device sharing its identity, and re-enroll it if needed.

Risk
High Profile Threat
MITRE ATT&CK tactic
Defense Evasion (TA0005)