Threat Mitigation Strategies: Part 2 — Technical Recommendations and Info
ID: 1da00193-c2ae-5af5-bfdf-889eabfdc119
STIX ID: report--1da00193-c2ae-5af5-bfdf-889eabfdc119
Feed Name: SpecterOps Blog
A comprehensive Windows enterprise security hardening and detection playbook that compiles actionable guidance and references: account and password policy (NIST 800-63-3), KRBTGT resets, LAPS/MSA, LSASS protection, PowerShell module logging, Windows Event Forwarding, and disabling legacy risks (WPAD, LLMNR, WDigest, NTLMv1) and backporting KB2871997. It outlines remote access protections (RDP Restricted Admin and Remote Credential Guard), host firewalls and egress controls with enforced proxying, and application control via AppLocker/Software Restriction Policies. The report further delivers hands-on hunting/detection queries and workflows across PowerShell/WEF/Sysmon, Splunk, Zeek/Bro, PCAP/tshark, and Snort, enabling both prevention and rapid detection of common attacker techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
