Skip to content

Security: bad-antics/nullsec-win

Security

SECURITY.md

Windows Security Guide

Overview

Windows security testing and hardening techniques.

System Hardening

Group Policy

  • Security settings
  • Audit policies
  • Software restriction
  • AppLocker

Defender Configuration

  • Real-time protection
  • Cloud protection
  • Exclusion management
  • ASR rules

Credential Protection

  • Credential Guard
  • LSASS protection
  • Remote Guard
  • Virtualization security

Attack Surface Reduction

Feature Removal

  • Unnecessary services
  • Legacy protocols
  • Debug features
  • Remote access

Configuration

  • UAC settings
  • PowerShell policies
  • Script blocking
  • Macro settings

Security Testing

Local Privesc

  • Service misconfigurations
  • Unquoted paths
  • DLL hijacking
  • Token manipulation

Credential Access

  • SAM dumping
  • LSA secrets
  • Cached credentials
  • Kerberos attacks

Persistence

  • Registry keys
  • Scheduled tasks
  • Services
  • WMI subscriptions

Monitoring

  • Event logs
  • Sysmon
  • ETW tracing
  • WEF collection

Tools

  • Sysinternals
  • PowerShell
  • Windows Admin Center

Legal Notice

For authorized security work.

There aren’t any published security advisories