I was thinking about hardening options that I'd add to the Raccine menu. My first idea was to unhide known file extensions to make double exts like .doc.exe visible to the user. Then I found long scripts like this on: https://gist.github.com/sjas/2d7a9b9c976bb2aa410757044d4282c9 … What do you think? Add some of it?
-
Show this thread
-
Replying to @cyb3rops
I think the script you linked is a 3 years old fork. The original gist looks more complete and up to date:https://gist.github.com/mackwage/08604751462126599d7e52f233490efe …
1 reply 6 retweets 18 likes -
Replying to @decalage2
I'll use that one and remote everything that seems to be unsafe. I'd only add no-brainers and changes that don't cause problems in 99,9% of cases.
1 reply 0 retweets 3 likes -
Replying to @cyb3rops @decalage2
Generally speaking, you shouldn't really hit many problems with many things in that script. I think
@mackwage deliberately tried to make it low impact in terms of undesirable side effects.1 reply 0 retweets 1 like -
(Although there are one or two things that could case issues in certain corporate /domain-joined environments managed I certain ways. Like the WMI ASR rule.)
1 reply 0 retweets 2 likes -
@cyb3rops I did specifically target settings which have positive impact to risk reduction with hopefully no or negligible impact to standard user use. For the potentially dicey ones, I comment them out. And always welcome feedback!2 replies 0 retweets 5 likes -
I've already divided them into soft and hard changes. I don't recommend running that script in environments in which admins (can) use GPOs to make these settings. This is for the small office, home office, private users. https://github.com/Neo23x0/Raccine/blob/main/windows-hardening.bat …
2 replies 2 retweets 5 likes
Thanks! 100% agree GPO is always preferred. This was specifically meant for folks not deploying via GPO (home, homelab, smb, etc)
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.