Hardcore Windows Hardening

Опубликовано: 16 Октябрь 2024
на канале: S4 Events
3,035
32

The team from OSIsoft gave this very practical presentation on the S4x18 Sponsor Stage, but after seeing it we should have put it on Stage 2. Asset owners and vendors should watch this.

It is how OSIsoft would optimally configure the OS that PI System components would be installed on. They also talk about the good, the bad and the ugly issues with the latest Windows security controls.

Github resources at: https://gist.github.com/hpaul-osi/d1d...

The session includes:

the highlighted the benefits of Server Core
what to disable after install
proper use and security of PowerShell
configuration as code ... Desired State Configuration
AppLocker and Device Guard
Windows Service Hardening (with a good example)
User Access Control (UAC)
Strong cipher suites (disable weak protocols)
Using Windows Integrated Security
Group Managed Service Accounts
Use of SYSMON

This is a lot of content covered quickly, but well.