Closed JavierBejMen closed 2 years ago
CIS ID | SCA ID | Status | Name |
---|---|---|---|
1.1.1 | 27000 | :green_circle: | (L1) Ensure 'Enforce password history' is set to '24 or more password(s)' (Automated) |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
1.1.2 | 27001 | :green_circle: | (L1) Ensure 'Maximum password age' is set to '365 or fewer days, but not 0' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
1.1.3 | 27002 | :green_circle: | (L1) Ensure 'Minimum password age' is set to '1 or more day |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
1.1.4 | 27003 | :green_circle: | (L1) Ensure 'Minimum password length' is set to '14 or morecharacter |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
1.1.5 | 27004 | :red_circle: | (L1) Ensure 'Password must meet complexity requirements' is set to'Enabled' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :red_circle: | Get-ADDefaultDomainPasswordPolicy not found |
dashboard | :green_circle: |
PS C:\Program Files (x86)\ossec-agent\ruleset\sca> Get-ADDefaultDomainPasswordPolicy -Current LoggedOnUser
Get-ADDefaultDomainPasswordPolicy : The term 'Get-ADDefaultDomainPasswordPolicy' is not recognized as the name of a cmdlet, function, script file, or operable program.
Check the spelling of the name, or if a path was included, verify that the path is correct and try again.
At line:1 char:1
+ Get-ADDefaultDomainPasswordPolicy -Current LoggedOnUser
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : ObjectNotFound: (Get-ADDefaultDomainPasswordPolicy:String) [], CommandNotFoundException
+ FullyQualifiedErrorId : CommandNotFoundException
CIS ID | SCA ID | Status | Name |
---|---|---|---|
1.1.6 | 27005 | :green_circle: | (L1) Ensure 'Relax minimum password length limits' is set to 'Enabled' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
1.1.7 | --- | :green_circle: | (L1) Ensure 'Store passwords using reversible encryption' is set to'Disabled' |
Can't be implemented
CIS ID | SCA ID | Status | Name |
---|---|---|---|
1.2.1 | 27006 | :green_circle: | (L1) Ensure 'Account lockout duration' is set to '15 or more minute(s)' (Automated) |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
1.2.2 | 27007 | :green_circle: | (L1) Ensure 'Account lockout threshold' is set to '5 or fewer invalidlogon attempt |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
1.2.3 | 27008 | :green_circle: | (L1) Ensure 'Reset account lockout counter after' is set to '15 or more minute(s) |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
The following CIS IDs were not found: ID | CIS ID |
---|---|
27229 | 18.8.34.6.6 |
27310 | 18.9.67.5 |
ID | CIS ID | Title | Description | Rationale | Remediation |
---|---|---|---|---|---|
27000 | 1.1.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27001 | 1.1.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27002 | 1.1.3 | :green_circle: | :red_circle: | :red_circle: | :green_circle: |
27003 | 1.1.4 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27004 | 1.1.5 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27005 | 1.1.6 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27006 | 1.2.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27007 | 1.2.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27008 | 1.2.3 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27009 | 2.3.1.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27010 | 2.3.1.2 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27011 | 2.3.1.3 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27012 | 2.3.1.4 | :green_circle: | :green_circle: | :red_circle: | :green_circle: |
27013 | 2.3.1.5 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27014 | 2.3.1.6 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27015 | 2.3.2.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27016 | 2.3.2.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27017 | 2.3.4.1 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27018 | 2.3.4.2 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27019 | 2.3.5.1 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27020 | 2.3.5.2 | :red_circle: | :red_circle: | :green_circle: | :green_circle: |
27021 | 2.3.5.3 | :red_circle: | :red_circle: | :red_circle: | :red_circle: |
27022 | 2.3.5.4 | :green_circle: | :red_circle: | :red_circle: | :green_circle: |
27023 | 2.3.5.5 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27024 | 2.3.6.1 | :green_circle: | :green_circle: | :red_circle: | :red_circle: |
27025 | 2.3.6.2 | :green_circle: | :green_circle: | :red_circle: | :red_circle: |
27026 | 2.3.6.3 | :green_circle: | :green_circle: | :red_circle: | :green_circle: |
27027 | 2.3.6.4 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27028 | 2.3.6.5 | :green_circle: | :red_circle: | :red_circle: | :green_circle: |
27029 | 2.3.6.6 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27030 | 2.3.7.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27031 | 2.3.7.2 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27033 | 2.3.7.4 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27034 | 2.3.7.6 | :red_circle: | :red_circle: | :red_circle: | :red_circle: |
27035 | 2.3.7.7 | :red_circle: | :red_circle: | :red_circle: | :red_circle: |
27037 | 2.3.7.8 | :green_circle: | :red_circle: | :green_circle: | :red_circle: |
27038 | 2.3.7.9 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27039 | 2.3.8.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27040 | 2.3.8.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27041 | 2.3.8.3 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27042 | 2.3.9.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27043 | 2.3.9.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27044 | 2.3.9.3 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27045 | 2.3.9.4 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27046 | 2.3.9.5 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27047 | 2.3.10.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27048 | 2.3.10.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27049 | 2.3.10.3 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27050 | 2.3.10.4 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27051 | 2.3.10.5 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27052 | 2.3.10.6 | :green_circle: | :red_circle: | :green_circle: | :red_circle: |
27053 | 2.3.10.7 | :green_circle: | :red_circle: | :green_circle: | :red_circle: |
27054 | 2.3.10.8 | :green_circle: | :red_circle: | :green_circle: | :red_circle: |
27055 | 2.3.10.9 | :green_circle: | :red_circle: | :green_circle: | :red_circle: |
27056 | 2.3.10.10 | :green_circle: | :red_circle: | :green_circle: | :red_circle: |
27057 | 2.3.10.11 | :green_circle: | :red_circle: | :green_circle: | :red_circle: |
27058 | 2.3.10.12 | :green_circle: | :green_circle: | :red_circle: | :red_circle: |
27059 | 2.3.10.13 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27060 | 2.3.11.1 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27061 | 2.3.11.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27062 | 2.3.11.3 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27063 | 2.3.11.4 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27064 | 2.3.11.5 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27065 | 2.3.11.6 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27066 | 2.3.11.7 | :green_circle: | :red_circle: | :red_circle: | :green_circle: |
27067 | 2.3.11.8 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27068 | 2.3.11.9 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27069 | 2.3.11.10 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27070 | 2.3.13.1 | :green_circle: | :red_circle: | :green_circle: | :red_circle: |
27072 | 2.3.15.1 | :red_circle: | :green_circle: | :green_circle: | :red_circle: |
27073 | 2.3.15.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27074 | 2.3.17.1 | :green_circle: | :green_circle: | :red_circle: | :green_circle: |
27075 | 2.3.17.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27076 | 2.3.17.3 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27077 | 2.3.17.4 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27078 | 2.3.17.5 | :green_circle: | :red_circle: | :red_circle: | :green_circle: |
27079 | 2.3.17.6 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27080 | 2.3.17.7 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27081 | 2.3.17.8 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27082 | 5.1 | :green_circle: | :red_circle: | :red_circle: | :green_circle: |
27083 | 5.2 | :green_circle: | :red_circle: | :red_circle: | :green_circle: |
27084 | 9.2.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27085 | 9.2.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27086 | 9.2.3 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27087 | 9.2.4 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27088 | 9.2.5 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27089 | 9.2.6 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27090 | 9.2.7 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27091 | 9.2.8 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27092 | 9.3.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27093 | 9.3.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27094 | 9.3.3 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27095 | 9.3.4 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27096 | 9.3.5 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27097 | 9.3.6 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27098 | 9.3.7 | :red_circle: | :red_circle: | :green_circle: | :green_circle: |
27099 | 9.3.8 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27100 | 9.3.9 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27101 | 9.3.10 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27102 | 17.1.1 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27103 | 17.1.2 | :green_circle: | :red_circle: | :green_circle: | :red_circle: |
27104 | 17.1.3 | :green_circle: | :red_circle: | :green_circle: | :red_circle: |
27105 | 17.2.1 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27106 | 17.2.2 | :green_circle: | :red_circle: | :green_circle: | :red_circle: |
27107 | 17.2.3 | :green_circle: | :red_circle: | :red_circle: | :red_circle: |
27108 | 17.2.4 | :green_circle: | :red_circle: | :green_circle: | :red_circle: |
27109 | 17.2.5 | :green_circle: | :red_circle: | :red_circle: | :red_circle: |
27110 | 17.2.6 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27111 | 17.3.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27112 | 17.3.2 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27113 | 17.4.1 | :green_circle: | :red_circle: | :green_circle: | :red_circle: |
27114 | 17.4.2 | :green_circle: | :red_circle: | :green_circle: | :red_circle: |
27115 | 17.5.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27116 | 17.5.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27117 | 17.5.3 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27118 | 17.5.4 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27119 | 17.5.5 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27120 | 17.5.6 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27121 | 17.6.1 | :green_circle: | :red_circle: | :red_circle: | :green_circle: |
27122 | 17.6.2 | :green_circle: | :green_circle: | :red_circle: | :green_circle: |
27123 | 17.6.3 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27124 | 17.6.4 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27125 | 17.7.1 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27126 | 17.7.2 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27127 | 17.7.3 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27128 | 17.7.4 | :green_circle: | :red_circle: | :green_circle: | :red_circle: |
27129 | 17.7.5 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27130 | 17.8.1 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27131 | 17.9.1 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27132 | 17.9.2 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27133 | 17.9.3 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27134 | 17.9.4 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27135 | 17.9.5 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27136 | 18.1.1.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27137 | 18.1.1.2 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27138 | 18.1.2.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27139 | 18.1.3 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27140 | 18.2.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27141 | 18.2.2 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27142 | 18.2.3 | :red_circle: | :green_circle: | :green_circle: | :green_circle: |
27143 | 18.2.4 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27144 | 18.2.5 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27145 | 18.2.6 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27146 | 18.3.1 | :red_circle: | :red_circle: | :green_circle: | :red_circle: |
27147 | 18.3.2 | :red_circle: | :green_circle: | :red_circle: | :red_circle: |
27148 | 18.3.3 | :green_circle: | :green_circle: | :red_circle: | :red_circle: |
27149 | 18.3.4 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27150 | 18.3.5 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27151 | 18.3.6 | :red_circle: | :red_circle: | :green_circle: | :red_circle: |
27152 | 18.3.7 | :green_circle: | :red_circle: | :green_circle: | :red_circle: |
27153 | 18.4.1 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27154 | 18.4.2 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27155 | 18.4.3 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27156 | 18.4.4 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27157 | 18.4.5 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27158 | 18.4.6 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27159 | 18.4.7 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27160 | 18.4.8 | :green_circle: | :red_circle: | :green_circle: | :red_circle: |
27161 | 18.4.9 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27162 | 18.4.10 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27163 | 18.4.11 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27164 | 18.4.12 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27165 | 18.5.4.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27166 | 18.5.4.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27167 | 18.5.5.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27168 | 18.5.8.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27169 | 18.5.9.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27170 | 18.5.9.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27171 | 18.5.10.2 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27172 | 18.5.11.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27173 | 18.5.11.3 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27174 | 18.5.11.4 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27175 | 18.5.14.1 | :green_circle: | :red_circle: | :green_circle: | :red_circle: |
27176 | 18.5.19.2.1 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27177 | 18.5.20.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27178 | 18.5.20.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27179 | 18.5.21.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27180 | 18.5.21.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27181 | 18.6.1 | :green_circle: | :red_circle: | :green_circle: | :red_circle: |
27182 | 18.6.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27183 | 18.6.3 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27184 | 18.7.1.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27185 | 18.8.3.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27186 | 18.8.4.1 | :green_circle: | :green_circle: | :red_circle: | :green_circle: |
27187 | 18.8.4.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27188 | 18.8.5.1 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27189 | 18.8.5.2 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27190 | 18.8.5.3 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27191 | 18.8.5.4 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27192 | 18.8.5.5 | :red_circle: | :red_circle: | :green_circle: | :red_circle: |
27193 | 18.8.5.6 | :green_circle: | :red_circle: | :green_circle: | :red_circle: |
27194 | 18.8.5.7 | :green_circle: | :red_circle: | :red_circle: | :red_circle: |
27195 | 18.8.7.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27196 | 18.8.14.1 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27197 | 18.8.21.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27198 | 18.8.21.3 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27199 | 18.8.21.4 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27200 | 18.8.21.5 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27201 | 18.8.22.1.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27202 | 18.8.22.1.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27203 | 18.8.22.1.3 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27204 | 18.8.22.1.4 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27205 | 18.8.22.1.5 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27206 | 18.8.22.1.6 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27207 | 18.8.22.1.7 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27208 | 18.8.22.1.8 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27209 | 18.8.22.1.9 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27210 | 18.8.22.1.10 | :red_circle: | :red_circle: | :green_circle: | :green_circle: |
27211 | 18.8.22.1.11 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27212 | 18.8.22.1.12 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27213 | 18.8.22.1.13 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27214 | 18.8.25.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27215 | 18.8.26.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27216 | 18.8.27.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27217 | 18.8.28.1 | :red_circle: | :green_circle: | :red_circle: | :green_circle: |
27218 | 18.8.28.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27219 | 18.8.28.3 | :red_circle: | :green_circle: | :green_circle: | :green_circle: |
27220 | 18.8.28.4 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27221 | 18.8.28.5 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27222 | 18.8.28.6 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27223 | 18.8.28.7 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27224 | 18.8.31.1 | :green_circle: | :green_circle: | :red_circle: | :red_circle: |
27225 | 18.8.31.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27226 | 18.8.34.6.1 | :red_circle: | :green_circle: | :green_circle: | :green_circle: |
27227 | 18.8.34.6.2 | :red_circle: | :green_circle: | :green_circle: | :green_circle: |
27228 | 18.8.34.6.3 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27230 | 18.8.36.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27231 | 18.8.36.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27232 | 18.8.37.1 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27233 | 18.8.37.2 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27234 | 18.8.40.1 | :green_circle: | :red_circle: | :red_circle: | :red_circle: |
27235 | 18.8.48.5.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27236 | 18.8.48.11.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27237 | 18.8.50.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27238 | 18.8.53.1.1 | :green_circle: | :green_circle: | :red_circle: | :green_circle: |
27239 | 18.8.53.1.2 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27240 | 18.9.4.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27241 | 18.9.6.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27242 | 18.9.8.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27243 | 18.9.8.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27244 | 18.9.8.3 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27245 | 18.9.10.1.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27246 | 18.9.12.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27247 | 18.9.14.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27248 | 18.9.14.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27249 | 18.9.15.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27250 | 18.9.16.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27251 | 18.9.16.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27252 | 18.9.17.1 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27253 | 18.9.17.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27254 | 18.9.17.3 | :green_circle: | :green_circle: | :red_circle: | :green_circle: |
27255 | 18.9.17.4 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27256 | 18.9.17.5 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27257 | 18.9.17.6 | :green_circle: | :green_circle: | :red_circle: | :green_circle: |
27258 | 18.9.17.7 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27259 | 18.9.17.8 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27260 | 18.9.27.1.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27261 | 18.9.27.1.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27262 | 18.9.27.2.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27263 | 18.9.27.2.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27264 | 18.9.27.3.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27265 | 18.9.27.3.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27266 | 18.9.27.4.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27267 | 18.9.27.4.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27268 | 18.9.31.2 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27269 | 18.9.31.3 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27270 | 18.9.31.4 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27271 | 18.9.41.1 | :green_circle: | :green_circle: | :red_circle: | :green_circle: |
27272 | 18.9.45.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27273 | 18.9.46.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27274 | 18.9.47.4.1 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27275 | 18.9.47.4.2 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27276 | 18.9.47.5.1.1 | :green_circle: | :green_circle: | :red_circle: | :green_circle: |
27277 | 18.9.47.5.1.2 | :green_circle: | :green_circle: | :red_circle: | :green_circle: |
27278 | 18.9.47.5.3.1 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27279 | 18.9.47.6.1 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27280 | 18.9.47.9.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27281 | 18.9.47.9.2 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27282 | 18.9.47.9.3 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27283 | 18.9.47.9.4 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27284 | 18.9.47.11.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27285 | 18.9.47.12.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27286 | 18.9.47.12.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27287 | 18.9.47.15 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27288 | 18.9.47.16 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27289 | 18.9.58.1 | :green_circle: | :green_circle: | :red_circle: | :green_circle: |
27290 | 18.9.64.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27291 | 18.9.65.2.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27292 | 18.9.65.3.2.1 | :green_circle: | :red_circle: | :green_circle: | :red_circle: |
27293 | 18.9.65.3.3.1 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27294 | 18.9.65.3.3.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27295 | 18.9.65.3.3.3 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27296 | 18.9.65.3.3.4 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27297 | 18.9.65.3.3.5 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27298 | 18.9.65.3.3.6 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27299 | 18.9.65.3.9.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27300 | 18.9.65.3.9.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27301 | 18.9.65.3.9.3 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27302 | 18.9.65.3.9.4 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27303 | 18.9.65.3.9.5 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27304 | 18.9.65.3.10.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27305 | 18.9.65.3.10.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27306 | 18.9.65.3.11.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27307 | 18.9.65.3.11.2 | :green_circle: | :green_circle: | :green_circle: | :red_circle: |
27308 | 18.9.66.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27309 | 18.9.67.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27311 | 18.9.72.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27312 | 18.9.85.1.1 | :green_circle: | :red_circle: | :red_circle: | :green_circle: |
27313 | 18.9.89.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27314 | 18.9.89.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27315 | 18.9.90.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27316 | 18.9.90.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27317 | 18.9.90.3 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27318 | 18.9.91.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27319 | 18.9.100.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27320 | 18.9.100.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27321 | 18.9.102.1.1 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27322 | 18.9.102.1.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27323 | 18.9.102.1.3 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27324 | 18.9.102.2.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27325 | 18.9.102.2.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27326 | 18.9.102.2.3 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27327 | 18.9.102.2.4 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27328 | 18.9.103.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27329 | 18.9.105.2.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27330 | 18.9.108.1.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27331 | 18.9.108.2.1 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27332 | 18.9.108.2.2 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27333 | 18.9.108.4.1 | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
27334 | 18.9.108.4.2 | :green_circle: | :red_circle: | :green_circle: | :green_circle: |
27335 | 18.9.108.4.3 | :green_circle: | :red_circle: | :green_circle: | :red_circle: |
Some of the found issues are minor typos, wont be fixing those
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.1.1 | 27009 | :green_circle: | (L1) Ensure 'Accounts: Administrator account status' is set to 'Disabled' (MS only) |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.1.2 | 27010 | :green_circle: | (L1) Ensure 'Accounts: Block Microsoft accounts' is set to 'Users can't add or log on with Microsoft accounts' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.1.3 | 27011 | :green_circle: | (L1) Ensure 'Accounts: Guest account status' is set to 'Disabled' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.1.4 | 27012 | :green_circle: | (L1) Ensure 'Accounts: Limit local account use of blank passwords toconsole logon only' is set to 'Enabled' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.1.5 | 27013 | :green_circle: | (L1) Configure 'Accounts: Rename administrator account' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.1.6 | 27014 | :green_circle: | (L1) Configure 'Accounts: Rename guest account' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.2.1 | 27015 | :green_circle: | (L1) Ensure 'Audit: Force audit policy subcategory settings |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
When policy is not Enabled
should fail, but when is Not Defined
it passes:
Edit: Default registry value is as specified in the CIS
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.2.2 | 27016 | :green_circle: | (L1) Ensure 'Audit: Shut down system immediately if unable to logsecurity audits' is set to 'Disabled' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.4.2 | 27018 | :green_circle: | (L1) Ensure 'Devices: Prevent users from installing printer drivers' isset to 'Enabled' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.5.2 | 27020 | :green_circle: | (L1) Ensure 'Domain controller: Allow vulnerable Netlogon securechannel connections' is set to 'Not Configured' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.5.4 | 27022 | :green_circle: | (L1) Ensure 'Domain controller: LDAP server signing requirements' isset to 'Require signing' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.6.1 | 27024 | :green_circle: | (L1) Ensure 'Domain member: Digitally encrypt or sign securechannel data |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.6.3 | 27026 | :green_circle: | (L1) Ensure 'Domain member: Digitally sign secure channel data |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.6.5 | 27028 | :yellow_circle: | (L1) Ensure 'Domain member: Maximum machine account passwordage' is set to '30 or fewer days, but not 0' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :yellow_circle: | |
dashboard | :green_circle: |
The GP Path is set as defined in the CIS, but the command to check shows other settings, maybe it's because I have not configured Active Directory, in this case, should it be Not Applicable?
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.7.1 | 27030 | :green_circle: | (L1) Ensure 'Interactive logon: Do not require CTRL+ALT+DEL' is setto 'Disabled' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.7.3 | 27032 | :green_circle: | (L1) Ensure 'Interactive logon: Machine inactivity limit' is set to '900 or fewer second(s), but not 0' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.7.5 | 27034 | :green_circle: | (L1) Configure 'Interactive logon: Message title for users attemptingto log on' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.7.7 | 27036 | :red_circle: | (L1) Ensure 'Interactive logon: Prompt user to change passwordbefore expiration' is set to 'between 5 and 14 days' |
Item | Check | Notes |
---|---|---|
id | :red_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS id is wrong, is settled as 2.3.7.8
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.7.9 | 27038 | :green_circle: | (L1) Ensure 'Interactive logon: Smart card removal behavior' is set to'Lock Workstation' or higher |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.8.2 | 27040 | :green_circle: | (L1) Ensure 'Microsoft network client: Digitally sign communications |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.9.1 | 27042 | :green_circle: | (L1) Ensure 'Microsoft network server: Amount of idle time requiredbefore suspending session' is set to '15 or fewer minute |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.9.3 | 27044 | :green_circle: | (L1) Ensure 'Microsoft network server: Digitally sign communications |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.9.5 | 27046 | :green_circle: | (L1) Ensure 'Microsoft network server: Server SPN target namevalidation level' is set to 'Accept if provided by client' or higher |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.10.2 | 27048 | :green_circle: | (L1) Ensure 'Network access: Do not allow anonymous enumerationof SAM accounts' is set to 'Enabled' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.10.4 | 27050 | :green_circle: | (L2) Ensure 'Network access: Do not allow storage of passwords andcredentials for network authentication' is set to 'Enabled' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.10.6 | 27052 | :green_circle: | (L1) Configure 'Network access: Named Pipes that can be accessedanonymously' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.10.8 | 27054 | :green_circle: | (L1) Configure 'Network access: Remotely accessible registry paths'is configured |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.10.10 | 27056 | :green_circle: | (L1) Ensure 'Network access: Restrict anonymous access to NamedPipes and Shares' is set to 'Enabled' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.10.12 | 27058 | :red_circle: | (L1) Ensure 'Network access: Shares that can be accessedanonymously' is set to 'None' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :red_circle: | |
dashboard | :green_circle: |
It passes after setting some value to the GP/Registry
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.11.1 | 27060 | :green_circle: | (L1) Ensure 'Network security: Allow Local System to use computeridentity for NTLM' is set to 'Enabled' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.11.3 | 27062 | :green_circle: | (L1) Ensure 'Network Security: Allow PKU2U authenticationrequests to this computer to use online identities' is set to 'Disabled' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.11.5 | 27064 | :green_circle: | (L1) Ensure 'Network security: Do not store LAN Manager hashvalue on next password change' is set to 'Enabled' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.11.7 | 27066 | :red_circle: | (L1) Ensure 'Network security: LAN Manager authentication level' is set to 'Send NTLMv2 response only. Refuse LM & NTLM' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :red_circle: | |
dashboard | :green_circle: |
Fails when compatibility level is settled to 5:
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.11.9 | 27068 | :red_circle: | (L1) Ensure 'Network security: Minimum session security for NTLMSSP based |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :red_circle: | |
dashboard | :green_circle: |
Reg number is different from specified in rule, and capitalization is incorrect too:
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.13.1 | 27070 | :green_circle: | (L1) Ensure 'Shutdown: Allow system to be shut down withouthaving to log on' is set to 'Disabled' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.15.2 | 27072 | :green_circle: | (L1) Ensure 'System objects: Strengthen default permissions ofinternal system objects |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
CIS ID | SCA ID | Status | Name |
---|---|---|---|
2.3.17.2 | 27074 | :green_circle: | (L1) Ensure 'User Account Control: Behavior of the elevation promptfor administrators in Admin Approval Mode' is set to 'Prompt for consent onthe secure desktop' |
Item | Check | Notes |
---|---|---|
id | :green_circle: | |
condition/rule | :green_circle: | |
dashboard | :green_circle: |
Description
This issue aims to manually test the new Windows server 2022 SCA checks.
Tests
For each check in the SCA policy checks:
yml
file.https://github.com/wazuh/wazuh/blob/f53ba8fa1ad5accede84703fe348cd75d56cfa6b/ruleset/sca/windows/cis_win2022.yml#L1-L5632
The installers must also be tested:
Test report procedure
Individual comments shows rule/condition test. Text checking is semi-automated:
Any failing test must be properly addressed with a new issue, detailing the error and the possible cause.
Please attach any documents, screenshots, or tables to the issue update with the results. This report can be used by the auditors to dig deeper into any possible failures and details.