Windows Security

Start Here!
Auditing!!!
Last

Quick Security Change for Windows 10, Windows 2k8r2 Server, and ???

Open an administrator CMD window Watch Video
Export the old configuration: Watch Video

C:\Windows\System32\SecEdit.exe /export /cfg "C:\%COMPUTERNAME%-Config-Export.inf"
In the cmd terminal as ADMINISTRATOR:
Create file C:\newsecurity.inf with the following AND "SAVE AS" UNICODE!!!!:

[Unicode]
Unicode=yes
[System Access]
MinimumPasswordAge = 2
MaximumPasswordAge = 42
MinimumPasswordLength = 8
PasswordComplexity = 1
PasswordHistorySize = 5
LockoutBadCount = 5
RequireLogonToChangePassword = 0
ForceLogoffWhenHourExpire = 0
ClearTextPassword = 0
LSAAnonymousNameLookup = 0
EnableAdminAccount = 0
EnableGuestAccount = 0
[Event Audit]
AuditSystemEvents = 3
AuditLogonEvents = 3
AuditObjectAccess = 3
AuditPrivilegeUse = 3
AuditPolicyChange = 3
AuditAccountManage = 3
AuditProcessTracking = 3
AuditDSAccess = 3
AuditAccountLogon = 3
[Version]
signature="$CHICAGO$"
Revision=1

Run C:\Windows\System32\secedit.exe /configure /db C:\Windows\security\new.sdb /cfg C:\newsecurity.inf /areas SECURITYPOLICY

Stuff to Check

Hidden Files

Find Hidden Files

Passwords

Recommeded Password Settings

Windows 10 Services

Windows 10

Win2k16

Windows Win2k16

GodMode

GodMode

Windows 7 Update

Download File IIS - Internet Information Server (HTTP or FTP) - Turn on or off in Control Panel (Turn Windows Features on or off)
Local Policy - Audit Policy
1Audit account logon eventsSuccess, Failure
2Audit logon eventsSuccess, Failure
3Audit policy changeSuccess, Failure
Local Policy - Security Options
4Accounts: Guest account statusDisabled
Account Policies - Password Policy
5Enforce password historyAny value from 3 to 24
6Maximum password ageAny value from 30 to 90
7Minimum password ageAny value from 1 to 1
8Minimum password lengthAny value from 8 to 14
9Password must meet complexity requirementsEnabled
10Automatic UpdatesInstall updates automatically
Firewall Profiles
11Domain ProfileFirewall State: On
12Domain ProfileInbound connections: Block
13Private ProfileFirewall State: On
14Private ProfileInbound connections: Block
15Public ProfileFirewall State: On
16Public ProfileInbound connections: Block all connections
Firewall - Inbound Rules
17Apache HTTP ServerProfile:Domain Enabled:True Protocol: UDP Action:Block the connection LocalAddress:Any RemoteAddress:Any LocalPort:Any RemotePort:Any
18Apache HTTP ServerProfile:Domain Enabled:True Protocol: TCP Action:Block the connection LocalAddress:Any RemoteAddress:Any LocalPort:Any RemotePort:Any
19Apache HTTP ServerProfile:Public,Private Enabled:True Protocol: UDP Action:Block the connection LocalAddress:Any RemoteAddress:Any LocalPort:Any RemotePort:Any
20Apache HTTP ServerProfile:Public,Private Enabled:True Protocol: TCP Action:Block the connection LocalAddress:Any RemoteAddress:Any LocalPort:Any RemotePort:Any
21BranchCache Content Retrieval (HTTP-In)Profile:Public,Private,Domain Enabled:False Protocol: TCP Action:Block the connection LocalAddress:Any RemoteAddress:Any LocalPort:80 RemotePort:Any
22BranchCache Hosted Cache Server (HTTP-In)Profile:Public,Private,Domain Enabled:False Protocol: TCP Action:Block the connection LocalAddress:Any RemoteAddress:Any LocalPort:80,443 RemotePort:Any
23Core Networking - IPv8 MasterProfile:Public,Private,Domain Enabled:True Protocol: TCP Action:Block the connection LocalAddress:Any RemoteAddress:Any LocalPort:80,8080,8888 RemotePort:Any
Services
24Apache2.2Stopped - Disabled
Roles and Features
25FTP ServerItemDisabled
Other
26Remote DesktopDon't allow connections to this computer
27Files to be removed from the systemC:\Users\Elliot\Downloads\httpd-2.2.25-win32-x86-no_ssl.msi