1) AV enabled
2) Patches
3) Account Policies
4) Logging
4.1) Audit Policy
4.2) A remote logging software. E.g. Splunk Forwarder
4.3) Sysmon
4.4) A FIM Agent
E.g. https://docs.rapid7.com/insightidr/file-integrity-monitoring/
4.5) NTP
5) Turn off unnecessary Windows Features & Services
5.1) Server service?
No comments:
Post a Comment