Services Methodology Why Us About Us Blog Get in Touch
← Back to Device Configuration Reviews
// 07A - WINDOWS HARDENING

Windows Build
Review

Baseline hardening assessment of Windows Server and client builds (Win 10/11) against best security practices including CIS benchmarks, Microsoft Security Baselines, and DISA STIGs - covering Group Policy, local security policy, services, and attack surface reduction.

CIS benchmarksMicrosoft Security BaselineDISA STIGGroup PolicyASR RulesLAPSBitLockerWindows ServerWindows 11VDI
Overview

Windows remains the most widely deployed enterprise operating system - and the most heavily targeted. Default builds, inconsistent Group Policy, and unmanaged local administrator accounts routinely leave exploitable gaps that standard vulnerability scanning does not surface.

Our Windows build reviews assess Server and Client builds against CIS benchmarks (Level 1 and Level 2), the Microsoft Security Compliance Toolkit baselines, and DISA STIGs - covering password and audit policy, service hardening, network protocol configuration, and attack surface reduction rules.

We look beyond checkbox compliance to identify configurations attackers actually rely on for credential theft and lateral movement, such as NTLM fallback, weak LSA protection, and unconstrained delegation.

Testing Methodology
01

Scope & Baseline Selection

Agreement on device roles in scope - domain controller, member server, workstation, or VDI image.

02

Configuration Data Collection

Secure, read-only extraction of Group Policy results, local security policy, registry state, and service configuration via WinRM/PowerShell remoting. No persistent agent required.

03

Automated Benchmark Analysis

Systematic comparison and custom scripted checks spanning password policy, audit policy, user rights assignment, network protocol hardening, and service exposure.

04

Manual Review & Attack Surface Mapping

Expert review of Group Policy inheritance and exceptions, local administrator sprawl, LAPS/PAM coverage, credential caching behaviour, PowerShell logging, and availability of common living-off-the-land binaries.

05

Risk Prioritisation

Findings ranked by real-world exploitability for credential theft and lateral movement - not compliance severity alone - so remediation effort goes where an attacker would actually look first.

06

Remediation Guidance

Custom guidance (including where appropriate, PowerShell remediation scripts) delivered alongside a prioritised fix list.

What Makes Levantis Different

Our experienced operators treat every finding through an attacker's eyes - flagging the configurations most likely to enable credential theft or lateral movement first, rather than burying critical issues in a long compliance list.

// In Scope

  • Windows Server (2012 – 2025)
  • Windows Client (Windows XP - 11)
  • Windows Server Core
  • Remote Desktop / VDI golden images
  • Domain-joined & Azure AD-joined endpoints
  • Point of Sale Terminals
  • Required legacy production systems

// Standards

  • CIS benchmarks (L1 & L2)
  • Microsoft Security Compliance Toolkit
  • DISA STIGs
  • NCSC Windows guidance

// Typical Duration

  • Up to 2 builds: 3 days
  • 5+ builds: price on request

// Engage Us

Ready to scope an engagement? Get in touch for a no-obligation conversation.

Request Assessment

Know your Windows hardening gaps.

Default Windows builds carry more exploitable configuration than most teams realise. Get a clear, prioritised picture of your baseline.

Get in Touch