---
title: Endpoint Posture Security Controls: 23 Checks | Wartiva
description: The 23 checks Wartiva runs for endpoint posture, beyond the CIS Benchmarks: what each one finds, why it matters, and how to fix it.
url: https://wartiva.com/policy-rules/wartiva/endpoint-posture.html
updated: 2026-10-07
---

Wartiva Security Controls

# Endpoint Posture: 23 Checks

Wartiva's Endpoint Posture controls: the basics on every endpoint: host firewall, antivirus, security services, disk encryption, storage, network interfaces, vulnerabilities, logons, and location.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. [How Wartiva works →](https://wartiva.com/platform.html)

## The host firewall

### [Ensure The Windows Host Firewall Is Enabled](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#the-windows-host-firewall-is-enabled)

High severity · Wartiva Security Controls · Endpoint Posture

**Finding:** The Windows host firewall is disabled.

This rule inspects a Windows endpoint's security posture. This rule fails when the firewall security-service health is `POOR` or a registered firewall product reports `OFF`.

**Rationale:** A disabled host firewall removes a key layer of defense against network-based attacks and lateral movement.

**Impact:** The host is more exposed to remote exploitation and unauthorized inbound connections.

#### Remediation

Turn on Microsoft Defender Firewall for the Domain, Private, and Public profiles (**Windows Security > Firewall & network protection**), or through Group Policy.

From the command line:

```
Set-NetFirewallProfile -Profile Domain,Private,Public -Enabled True
```

Framework mappings

- **CIS Controls v8**: 4.4 Implement and Manage a Firewall on Servers; 4.5 Implement and Manage a Firewall on End-User Devices
- **NIST SP 800-53 Rev. 5**: CA-9 Internal System Connections; SC-7 Boundary Protection
- **PCI DSS v4.0.1**: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.4.1 Deploy NSCs where trusted networks meet untrusted ones

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure The macOS Application Firewall Is Enabled](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#the-macos-application-firewall-is-enabled)

High severity · Wartiva Security Controls · Endpoint Posture

**Finding:** The macOS application Firewall is disabled.

This rule inspects a macOS endpoint's security posture. This rule fails when the firewall security-service health is `POOR` or a registered firewall product reports `OFF`.

**Rationale:** A disabled host firewall removes a key layer of defense against network-based attacks and lateral movement.

**Impact:** The host is more exposed to remote exploitation and unauthorized inbound connections.

#### Remediation

Turn on the firewall in **System Settings > Network > Firewall**, or enforce it through your MDM.

From the command line:

```
/usr/bin/sudo /usr/libexec/ApplicationFirewall/socketfilterfw --setglobalstate on
```

Framework mappings

- **CIS Controls v8**: 4.4 Implement and Manage a Firewall on Servers; 4.5 Implement and Manage a Firewall on End-User Devices
- **NIST SP 800-53 Rev. 5**: CA-9 Internal System Connections; SC-7 Boundary Protection
- **PCI DSS v4.0.1**: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.4.1 Deploy NSCs where trusted networks meet untrusted ones

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure The Linux Host Firewall Is Enabled](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#the-linux-host-firewall-is-enabled)

High severity · Wartiva Security Controls · Endpoint Posture

**Finding:** The Linux host Firewall is disabled.

This rule inspects a Linux endpoint's security posture. This rule fails when the firewall security-service health is `POOR` or a registered firewall product reports `OFF`.

**Rationale:** A disabled host firewall removes a key layer of defense against network-based attacks and lateral movement.

**Impact:** The host is more exposed to remote exploitation and unauthorized inbound connections.

#### Remediation

Turn on the host firewall and allow only the services the endpoint needs.

- **Ubuntu or Debian (ufw):** run `sudo ufw enable`.
- **Red Hat, Fedora, or SUSE (firewalld):** run `sudo systemctl enable --now firewalld`.

Framework mappings

- **CIS Controls v8**: 4.4 Implement and Manage a Firewall on Servers; 4.5 Implement and Manage a Firewall on End-User Devices
- **NIST SP 800-53 Rev. 5**: CA-9 Internal System Connections; SC-7 Boundary Protection
- **PCI DSS v4.0.1**: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.4.1 Deploy NSCs where trusted networks meet untrusted ones

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Windows Endpoints With A Disabled Firewall Are Not On A Network With A Publicly Exposed Gateway](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#windows-endpoints-with-a-disabled-firewall-are-not-on-a-network-with-a-publicly)

High severity · Wartiva Security Controls · Endpoint Posture

**Finding:** This Windows endpoint's firewall is off and its network's gateway exposes ports to the public internet.

This rule finds Windows endpoints whose host firewall is disabled or unhealthy while one of their network interfaces is connected to a network whose gateway has a port open to the public internet. A gateway is any device that has acted as the network's gateway in the last 30 days. This rule fails for each such endpoint.

**Rationale:** A gateway exposing ports to the internet may forward traffic into the network; an endpoint with no host firewall has no second line of defense.

**Impact:** Services on the endpoint may be reachable from the internet through the gateway, with nothing on the host to block them.

#### Remediation

Turn Microsoft Defender Firewall back on for every network profile (**Windows Security > Firewall & network protection**) and confirm it reports healthy. Then review the gateway's internet-exposed ports and close or restrict any that don't need to be public.

Framework mappings

- **CIS Controls v8**: 4.4 Implement and Manage a Firewall on Servers; 4.5 Implement and Manage a Firewall on End-User Devices
- **NIST SP 800-53 Rev. 5**: CA-9 Internal System Connections; SC-7 Boundary Protection
- **PCI DSS v4.0.1**: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.4.1 Deploy NSCs where trusted networks meet untrusted ones

Risks

External Exposure, External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure macOS Endpoints With A Disabled Firewall Are Not On A Network With A Publicly Exposed Gateway](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#macos-endpoints-with-a-disabled-firewall-are-not-on-a-network-with-a-publicly-ex)

High severity · Wartiva Security Controls · Endpoint Posture

**Finding:** This macOS endpoint's firewall is off and its network's gateway exposes ports to the public internet.

This rule finds macOS endpoints whose host firewall is disabled or unhealthy while one of their network interfaces is connected to a network whose gateway has a port open to the public internet. A gateway is any device that has acted as the network's gateway in the last 30 days. This rule fails for each such endpoint.

**Rationale:** A gateway exposing ports to the internet may forward traffic into the network; an endpoint with no host firewall has no second line of defense.

**Impact:** Services on the endpoint may be reachable from the internet through the gateway, with nothing on the host to block them.

#### Remediation

Turn the firewall back on in **System Settings > Network > Firewall**. Then review the gateway's internet-exposed ports and close or restrict any that don't need to be public.

Framework mappings

- **CIS Controls v8**: 4.4 Implement and Manage a Firewall on Servers; 4.5 Implement and Manage a Firewall on End-User Devices
- **NIST SP 800-53 Rev. 5**: CA-9 Internal System Connections; SC-7 Boundary Protection
- **PCI DSS v4.0.1**: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.4.1 Deploy NSCs where trusted networks meet untrusted ones

Risks

External Exposure, External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Linux Endpoints With A Disabled Firewall Are Not On A Network With A Publicly Exposed Gateway](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#linux-endpoints-with-a-disabled-firewall-are-not-on-a-network-with-a-publicly-ex)

High severity · Wartiva Security Controls · Endpoint Posture

**Finding:** This Linux endpoint's firewall is off and its network's gateway exposes ports to the public internet.

This rule finds Linux endpoints whose host firewall is disabled or unhealthy while one of their network interfaces is connected to a network whose gateway has a port open to the public internet. A gateway is any device that has acted as the network's gateway in the last 30 days. This rule fails for each such endpoint.

**Rationale:** A gateway exposing ports to the internet may forward traffic into the network; an endpoint with no host firewall has no second line of defense.

**Impact:** Services on the endpoint may be reachable from the internet through the gateway, with nothing on the host to block them.

#### Remediation

Turn the host firewall (ufw or firewalld) back on and confirm it's active. Then review the gateway's internet-exposed ports and close or restrict any that don't need to be public.

Framework mappings

- **CIS Controls v8**: 4.4 Implement and Manage a Firewall on Servers; 4.5 Implement and Manage a Firewall on End-User Devices
- **NIST SP 800-53 Rev. 5**: CA-9 Internal System Connections; SC-7 Boundary Protection
- **PCI DSS v4.0.1**: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.4.1 Deploy NSCs where trusted networks meet untrusted ones

Risks

External Exposure, External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## Anti-virus protection

### [Ensure Active Antivirus Protection Is Present](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#active-antivirus-protection-is-present)

High severity · Wartiva Security Controls · Endpoint Posture

**Finding:** No active antivirus protection is present on the endpoint.

This rule inspects an endpoint's registered antivirus products (as reported by Windows Security Center). This rule fails when no antivirus product is in the `ON` state, or the antivirus security-service health is `POOR`.

**Rationale:** Without active antivirus/anti-malware protection, malicious code can run undetected.

**Impact:** The endpoint is exposed to malware infection and post-exploitation activity.

#### Remediation

Install and enable a supported antivirus/anti-malware product. On Windows, ensure Microsoft Defender Antivirus (or a third-party AV) is active and up to date in Windows Security.

Framework mappings

- **CIS Controls v8**: 10.1 Deploy and Maintain Anti-Malware Software
- **NIST SP 800-53 Rev. 5**: MP-6 Media Sanitization
- **NIST SP 800-171 Rev. 2**: 3.14.2 Provide protection from malicious code at designated locations within organizational systems
- **CMMC 2.0 Level 1**: SI.L1-b.1.xiii Provide protection from malicious code at appropriate locations within organizational information systems
- **CMMC 2.0 Level 2**: SI.L2-3.14.2 Provide protection from malicious code at designated locations within organizational systems
- **PCI DSS v4.0.1**: 5.1.1 Malware protection policies and procedures kept documented, current, and applied; 5.2.1 Deploy anti-malware on all systems not evaluated as low risk; 5.2.2 Ensure anti-malware detects and removes or blocks all known malware; 5.3.2 Run periodic and real-time anti-malware scans or behavioral analysis

Risk

High Profile Threat

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure Antivirus Is Reporting Its State](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#antivirus-is-reporting-its-state)

High severity · Wartiva Security Controls · Endpoint Posture

**Finding:** This endpoint's antivirus hasn't reported its state within your reporting window.

This rule reads when each Windows endpoint's antivirus products last reported their state. This rule fails when none has reported within your deployment's reporting window (7 days by default).

**Rationale:** An antivirus product that stops reporting may have stopped running, stopped updating, or been disabled.

**Impact:** The endpoint may be unprotected while appearing covered.

#### Remediation

Open **Windows Security > Virus & threat protection** on the endpoint, confirm protection is on and definitions are current, and restart or reinstall the antivirus product if it isn't reporting.

Framework mappings

- **CIS Controls v8**: 10.1 Deploy and Maintain Anti-Malware Software
- **NIST SP 800-53 Rev. 5**: MP-6 Media Sanitization
- **NIST SP 800-171 Rev. 2**: 3.14.2 Provide protection from malicious code at designated locations within organizational systems
- **CMMC 2.0 Level 1**: SI.L1-b.1.xiii Provide protection from malicious code at appropriate locations within organizational information systems
- **CMMC 2.0 Level 2**: SI.L2-3.14.2 Provide protection from malicious code at designated locations within organizational systems
- **PCI DSS v4.0.1**: 5.1.1 Malware protection policies and procedures kept documented, current, and applied; 5.2.1 Deploy anti-malware on all systems not evaluated as low risk; 5.2.2 Ensure anti-malware detects and removes or blocks all known malware; 5.3.2 Run periodic and real-time anti-malware scans or behavioral analysis

Risk

High Profile Threat

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

## The health of the operating system's security services

### [Ensure Windows Security Services Are Healthy](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#windows-security-services-are-healthy)

Medium severity · Wartiva Security Controls · Endpoint Posture

**Finding:** A Windows security service (update, UAC, SmartScreen, etc.) is in an unhealthy state.

This rule inspects the Windows Security Center health of services other than the firewall, antivirus, and disk encryption (which each have dedicated rules). This rule fails when any of `autoupdateSettings`, `antispyware`, `internetSettings`, `userAccountController`, or `securityService` reports `POOR`.

**Rationale:** These services collectively maintain the endpoint's baseline security posture; an unhealthy state indicates a protection has been disabled or misconfigured.

**Impact:** Weakened update, UAC, browser, or anti-spyware settings increase the endpoint's exposure to compromise.

#### Remediation

Open Windows Security and resolve the flagged service: re-enable automatic updates, User Account Control, SmartScreen/Internet settings, anti-spyware, or disk encryption as indicated. Address any 'action needed' items.

Framework mappings

- **CIS Controls v8**: 7.3 Perform Automated Operating System Patch Management; 10.1 Deploy and Maintain Anti-Malware Software
- **NIST SP 800-53 Rev. 5**: MP-6 Media Sanitization; RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
- **NIST SP 800-171 Rev. 2**: 3.14.2 Provide protection from malicious code at designated locations within organizational systems
- **CMMC 2.0 Level 1**: SI.L1-b.1.xiii Provide protection from malicious code at appropriate locations within organizational information systems
- **CMMC 2.0 Level 2**: SI.L2-3.14.2 Provide protection from malicious code at designated locations within organizational systems
- **PCI DSS v4.0.1**: 5.1.1 Malware protection policies and procedures kept documented, current, and applied; 5.2.1 Deploy anti-malware on all systems not evaluated as low risk; 5.2.2 Ensure anti-malware detects and removes or blocks all known malware; 5.3.2 Run periodic and real-time anti-malware scans or behavioral analysis

Risk

Insecure Application

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

### [Ensure Endpoint Agents Are Up To Date](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#endpoint-agents-are-up-to-date)

Medium severity · Wartiva Security Controls · Endpoint Posture

**Finding:** This endpoint's agent is behind the latest release.

This rule compares each endpoint's agent version with the latest stable build for its platform. This rule fails for an endpoint still running an older agent after the newer build has been available longer than your deployment's grace period (14 days by default).

**Rationale:** Agent updates carry security fixes and new detections, and auto-update should reach an online endpoint within days.

**Impact:** An endpoint stuck on an old agent may be missing fixes and may report less than the rest of your fleet.

#### Remediation

Check why auto-update isn't reaching this endpoint: confirm it's online and can reach the update service, then restart the agent or reinstall the latest build.

Framework mappings

- **CIS Controls v8**: 7.4 Perform Automated Application Patch Management
- **NIST SP 800-53 Rev. 5**: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation

Risk

Vulnerability

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

## Disk encryption coverage and cipher strength

### [Ensure Windows Desktop System Drives Are Encrypted](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#windows-desktop-system-drives-are-encrypted)

High severity · Wartiva Security Controls · Endpoint Posture

**Finding:** A Windows desktop's system drive is not encrypted.

This rule inspects the disk-encryption state of a Windows desktop. This rule fails when the system volume (`C:`) has an encryption state of `OFF`.

**Rationale:** Full-disk encryption protects data at rest if a drive or machine is stolen or improperly decommissioned.

**Impact:** Data on an unencrypted system drive can be read by anyone with physical access to the disk.

#### Remediation

Turn on BitLocker for the operating system drive (**Control Panel > BitLocker Drive Encryption**, or your MDM's disk-encryption policy) and escrow the recovery key to Active Directory or Microsoft Entra ID.

From the command line:

```
manage-bde -on C: -RecoveryPassword
```

Requires a restart to take effect.

Framework mappings

- **CIS Controls v8**: 3.6 Encrypt Data on End-User Devices
- **NIST SP 800-53 Rev. 5**: SC-28 Protection of Information at Rest
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital

Risk

Unprotected Data

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure macOS Desktop System Drives Are Encrypted](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#macos-desktop-system-drives-are-encrypted)

High severity · Wartiva Security Controls · Endpoint Posture

**Finding:** A macOS desktop's system drive is not encrypted.

This rule inspects the disk-encryption state of a macOS desktop. This rule fails when the system volume (`/`) has an encryption state of `OFF`.

**Rationale:** Full-disk encryption protects data at rest if a drive or machine is stolen or improperly decommissioned.

**Impact:** Data on an unencrypted system drive can be read by anyone with physical access to the disk.

#### Remediation

Turn on FileVault in **System Settings > Privacy & Security > FileVault** and escrow the recovery key through your MDM.

From the command line:

```
/usr/bin/sudo /usr/bin/fdesetup enable
```

Requires a restart to take effect.

Framework mappings

- **CIS Controls v8**: 3.6 Encrypt Data on End-User Devices
- **NIST SP 800-53 Rev. 5**: SC-28 Protection of Information at Rest
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital

Risk

Unprotected Data

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Linux Desktop System Drives Are Encrypted](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#linux-desktop-system-drives-are-encrypted)

High severity · Wartiva Security Controls · Endpoint Posture

**Finding:** A Linux desktop's system drive is not encrypted.

This rule inspects the disk-encryption state of a Linux desktop. This rule fails when the system volume (`/`) has an encryption state of `OFF`.

**Rationale:** Full-disk encryption protects data at rest if a drive or machine is stolen or improperly decommissioned.

**Impact:** Data on an unencrypted system drive can be read by anyone with physical access to the disk.

#### Remediation

Encrypt the root volume with LUKS. An existing root volume usually can't be encrypted in place, so this normally means reinstalling with full-disk encryption selected. Escrow the recovery passphrase securely.

Framework mappings

- **CIS Controls v8**: 3.6 Encrypt Data on End-User Devices
- **NIST SP 800-53 Rev. 5**: SC-28 Protection of Information at Rest
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital

Risk

Unprotected Data

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Disk Encryption Does Not Use A Weak Cipher](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#disk-encryption-does-not-use-a-weak-cipher)

Medium severity · Wartiva Security Controls · Endpoint Posture

**Finding:** An encrypted drive uses a weak or deprecated cipher.

This rule inspects the cipher used by encrypted volumes. This rule fails when an encrypted volume uses a weak or deprecated method (`AES128`, `AES128_WITH_DIFFUSER`, or `AES256_WITH_DIFFUSER`).

**Rationale:** 128-bit and legacy BitLocker diffuser modes are weaker than modern XTS-AES-256 and are deprecated.

**Impact:** Data at rest is protected by a weaker cipher than current standards recommend.

#### Remediation

Set the BitLocker encryption method to XTS-AES-256 through Group Policy, then decrypt and re-encrypt the drive so it uses the new method.

Framework mappings

- **CIS Controls v8**: 3.6 Encrypt Data on End-User Devices
- **NIST SP 800-53 Rev. 5**: SC-28 Protection of Information at Rest
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital

Risk

Unprotected Data

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

## Storage capacity and disk utilization

### [Ensure Disk Mounts Are Not Critically Full](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#disk-mounts-are-not-critically-full)

Medium severity · Wartiva Security Controls · Endpoint Posture

**Finding:** A disk mount is more than 90% full.

This rule inspects a disk mount's usage. This rule fails when `usage.usedPercent` exceeds 90%.

**Rationale:** A nearly-full volume can halt logging, updates, and security tooling, and cause service outages.

**Impact:** Loss of audit logs, failed updates, and degraded or unavailable services.

#### Remediation

Free space on the affected volume (remove temporary files, rotate/archive logs, uninstall unused software) or expand the volume. Investigate the cause of rapid growth.

Risk

Reliability Impact

MITRE ATT&CK tactic

Impact ([TA0040](https://attack.mitre.org/tactics/TA0040/))

## Network interface health

### [Ensure Network Interfaces Are Not Accumulating Errors](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#network-interfaces-are-not-accumulating-errors)

Low severity · Wartiva Security Controls · Endpoint Posture

**Finding:** A network interface is accumulating input or output errors.

This rule inspects a network interface's error counters. This rule fails when `inErrors` or `outErrors` is greater than zero.

**Rationale:** Interface errors indicate faulty cabling, duplex mismatches, driver problems, or hardware failure, and can also accompany certain network attacks.

**Impact:** Packet loss and degraded connectivity that can affect availability and reliability of services on the host.

#### Remediation

Investigate the interface's physical layer: check cabling and connectors, confirm speed/duplex auto-negotiation, update NIC drivers/firmware, and replace faulty hardware. Clear counters and confirm errors do not recur.

Risk

Reliability Impact

MITRE ATT&CK tactic

Impact ([TA0040](https://attack.mitre.org/tactics/TA0040/))

## Known vulnerabilities in the endpoint's operating system and software

### [Ensure Endpoints Have No High-Severity Vulnerabilities](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#endpoints-have-no-high-severity-vulnerabilities)

High severity · Wartiva Security Controls · Endpoint Posture

**Finding:** This endpoint has one or more high or critical severity vulnerabilities.

This rule matches each endpoint's operating system and hardware against known vulnerabilities (CVEs). Installed applications are covered by the "Ensure Installed Applications Have No High-Severity Vulnerabilities" rule. This rule fails for an endpoint with one or more vulnerabilities rated high or critical, and records the most severe, with the total matched, in one finding.

**Rationale:** High and critical vulnerabilities are the ones attackers most often exploit, many with public exploit code.

**Impact:** An unpatched high-severity vulnerability can let an attacker run code, escalate privileges, or steal data.

#### Remediation

Apply the vendor updates that fix the listed CVEs, starting with any marked as known exploited. Where an update isn't available, apply the vendor's mitigation or restrict access to the affected software.

Framework mappings

- **CIS Controls v8**: 7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets; 7.7 Remediate Detected Vulnerabilities
- **NIST SP 800-53 Rev. 5**: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
- **NIST SP 800-171 Rev. 2**: 3.11.2 Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified; 3.11.3 Remediate vulnerabilities in accordance with risk assessments; 3.14.1 Identify, report, and correct system flaws in a timely manner
- **CMMC 2.0 Level 1**: SI.L1-b.1.xii Identify, report, and correct information and information system flaws in a timely manner
- **CMMC 2.0 Level 2**: RA.L2-3.11.2 Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified; RA.L2-3.11.3 Remediate vulnerabilities in accordance with risk assessments; SI.L2-3.14.1 Identify, report, and correct system flaws in a timely manner
- **PCI DSS v4.0.1**: 11.3.1.1 Address lower-risk vulnerabilities as set by targeted risk analysis; 11.3.1.2 Run credentialed internal scans using adequate privileges; 11.3.1.3 Rescan internally after significant changes and resolve high-risk findings; 11.3.2.1 Run external scans after significant changes and fix CVSS 4.0+ findings

Risk

Vulnerability

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Installed Applications Have No High-Severity Vulnerabilities](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#installed-applications-have-no-high-severity-vulnerabilities)

High severity · Wartiva Security Controls · Endpoint Posture

**Finding:** This installed application has one or more high or critical severity vulnerabilities.

This rule matches each application installed on an endpoint against known vulnerabilities (CVEs). This rule fails for an application with one or more vulnerabilities rated high or critical, and records the most severe, with the total matched, in one finding.

**Rationale:** Browsers, runtimes, and shared libraries are where attackers find most exploitable flaws, and every installed copy is its own exposure.

**Impact:** An unpatched high-severity vulnerability in an installed application can let an attacker run code, escalate privileges, or steal data.

#### Remediation

Update the application to a version that fixes the listed CVEs, starting with any marked as known exploited. Where no update is available, apply the vendor's mitigation or remove the application.

Framework mappings

- **CIS Controls v8**: 7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets; 7.7 Remediate Detected Vulnerabilities
- **NIST SP 800-53 Rev. 5**: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
- **NIST SP 800-171 Rev. 2**: 3.11.2 Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified; 3.11.3 Remediate vulnerabilities in accordance with risk assessments; 3.14.1 Identify, report, and correct system flaws in a timely manner
- **CMMC 2.0 Level 1**: SI.L1-b.1.xii Identify, report, and correct information and information system flaws in a timely manner
- **CMMC 2.0 Level 2**: RA.L2-3.11.2 Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified; RA.L2-3.11.3 Remediate vulnerabilities in accordance with risk assessments; SI.L2-3.14.1 Identify, report, and correct system flaws in a timely manner
- **PCI DSS v4.0.1**: 11.3.1.1 Address lower-risk vulnerabilities as set by targeted risk analysis; 11.3.1.2 Run credentialed internal scans using adequate privileges; 11.3.1.3 Rescan internally after significant changes and resolve high-risk findings; 11.3.2.1 Run external scans after significant changes and fix CVSS 4.0+ findings

Risk

Vulnerability

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Operating System Updates Are Installed Regularly](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#operating-system-updates-are-installed-regularly)

High severity · Wartiva Security Controls · Endpoint Posture

**Finding:** This endpoint hasn't installed an operating system update within your update window.

This rule reads when each Windows endpoint last installed operating system updates successfully. This rule fails when that was longer ago than your deployment's maximum update age (30 days by default).

**Rationale:** Operating system updates close actively exploited vulnerabilities, and a monthly patch cycle is the usual baseline.

**Impact:** An endpoint that stopped patching accumulates known vulnerabilities.

#### Remediation

Install pending updates in **Settings > Windows Update**. If updates keep failing, check free disk space and the Windows Update service.

Framework mappings

- **CIS Controls v8**: 7.3 Perform Automated Operating System Patch Management; 7.4 Perform Automated Application Patch Management
- **NIST SP 800-53 Rev. 5**: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation

Risk

Vulnerability

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## Logons and account use, such as remote root logons and the built-in Administrator

### [Ensure Root Does Not Log In From External Hosts](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#root-does-not-log-in-from-external-hosts)

High severity · Wartiva Security Controls · Endpoint Posture

**Finding:** The root account logged in to a Linux endpoint from an external host.

This rule finds logon sessions of the root account on Linux endpoints that come from a public address or a hostname. This rule fails for each such session.

**Rationale:** Direct remote root logons bypass per-user accountability, and root logons from outside your networks are a strong sign of credential compromise or an exposed SSH service.

**Impact:** An attacker with remote root access has full control of the endpoint.

**Note:** A host recorded as a hostname counts as external even when it looks private, since reverse DNS is controlled by whoever owns the connecting address. IPv4-mapped IPv6 addresses are judged by their IPv4 address, and carrier-grade NAT addresses (100.64.0.0/10) count as external.

#### Remediation

Confirm whether this root logon was authorized. Disable direct root logons over SSH (`PermitRootLogin no` in sshd_config), require administrators to log in as themselves and elevate with sudo, and restrict SSH to trusted networks or a VPN. If the logon wasn't authorized, treat the endpoint as compromised and rotate its credentials.

Framework mappings

- **CIS Controls v8**: 5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-6 Least Privilege
- **NIST SP 800-171 Rev. 2**: 3.1.6 Use non-privileged accounts or roles when accessing nonsecurity functions; 3.1.7 Prevent non-privileged users from executing privileged functions and audit the execution of such functions
- **CMMC 2.0 Level 2**: AC.L2-3.1.6 Use non-privileged accounts or roles when accessing nonsecurity functions; AC.L2-3.1.7 Prevent non-privileged users from executing privileged functions and audit the execution of such functions

Risks

High Profile Threat, External Exposure

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure The Built-In Administrator Account Is Not In Use](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#the-built-in-administrator-account-is-not-in-use)

Medium severity · Wartiva Security Controls · Endpoint Posture

**Finding:** The built-in Windows Administrator account has been used to log on.

This rule finds the built-in Windows Administrator account (the account whose security identifier ends in -500) when it has logon sessions. This rule fails for each such account.

**Rationale:** The built-in Administrator can't be locked out and is a primary target for password guessing; using it hides which person acted.

**Impact:** Activity under a shared, well-known privileged account is hard to attribute and invites brute-force attacks.

#### Remediation

Give administrators individual accounts with administrative rights, then disable the built-in Administrator account (Local Security Policy > Security Options > "Accounts: Administrator account status") or rename it and set a long random password managed by Windows LAPS.

Framework mappings

- **CIS Controls v8**: 4.7 Manage Default Accounts on Enterprise Assets and Software; 5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-6 Least Privilege; IA-5 Authenticator Management
- **NIST SP 800-171 Rev. 2**: 3.1.6 Use non-privileged accounts or roles when accessing nonsecurity functions; 3.1.7 Prevent non-privileged users from executing privileged functions and audit the execution of such functions
- **CMMC 2.0 Level 2**: AC.L2-3.1.6 Use non-privileged accounts or roles when accessing nonsecurity functions; AC.L2-3.1.7 Prevent non-privileged users from executing privileged functions and audit the execution of such functions
- **PCI DSS v4.0.1**: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 2.3.1 Replace or confirm default wireless settings when installing access points

Risk

High Profile Threat

MITRE ATT&CK tactic

Privilege Escalation ([TA0004](https://attack.mitre.org/tactics/TA0004/))

## Where the endpoint is, such as a sanctioned country

### [Ensure Endpoints Are Not Located In A Sanctioned Country](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#endpoints-are-not-located-in-a-sanctioned-country)

High severity · Wartiva Security Controls · Endpoint Posture

**Finding:** This endpoint was last located in a country under comprehensive U.S. sanctions.

This rule finds endpoints whose last known location is in a country under comprehensive U.S. (OFAC) sanctions: Cuba, Iran, North Korea, or Syria. This rule fails for each such endpoint.

**Rationale:** Operating equipment or providing services in a comprehensively sanctioned country can violate U.S. export controls and sanctions law, and may indicate stolen or diverted equipment.

**Impact:** Regulatory exposure and possible loss of control of the endpoint.

**Note:** Sanctioned regions within other countries, such as Crimea, can't be identified by country code.

#### Remediation

Confirm the endpoint's location and who holds it. If it isn't authorized to be there, recover or remotely disable it and involve your legal and compliance teams.

Risk

High Profile Threat

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Endpoints Do Not Show Impossible Travel](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#endpoints-do-not-show-impossible-travel)

High severity · Wartiva Security Controls · Endpoint Posture

**Finding:** This endpoint's location changed faster than anyone could travel.

This rule reads each endpoint's recent precise positions (the last 7 days by default). This rule fails when two consecutive positions far enough apart to rule out location error (100 km by default) imply travel faster than your deployment's maximum speed (1,000 km/h by default).

**Rationale:** No one can move a laptop that fast, so the jump points to tampered location reports, a cloned or spoofed endpoint, or a shared device identity.

**Impact:** An endpoint whose identity or telemetry can't be trusted undermines every other finding about it.

**Note:** Positions too imprecise to compare reliably aren't judged.

#### Remediation

Confirm who holds the endpoint and where it is. If the locations can't both be right, check for a cloned or re-imaged device sharing its identity, and re-enroll it if needed.

Risk

High Profile Threat

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
