Generic Windows Features
- Disable Windows Script Host.
- Disabling AutoRun and AutoPlay. D
- Disables powershell.exe, powershell_ise.exe and cmd.exe execution via Windows Explorer.
- Sets User Account Control (UAC) to always ask for permission (
- Disable file extensions mainly used for malicious purposes. Disables the ".hta", ".js", ".JSE", ".WSH", ".WSF", ".scf", ".scr", ".vbs", ".vbe" and ".pif" file extensions
Microsoft Office
- Disable Macros.
- Disable OLE object execution.
- Disabling ActiveX.
- Disable DDE.
Acrobat Reader
- Disable JavaScript in PDF documents.
- Disable execution of objects embedded in PDF documents.
- Switch on the Protected Mode
- Switch on Enhanced Security
https://github.com/securitywithoutborders/hardentools
No comments:
Post a Comment