CyberPolice

An epic windows securing and hardening script
Log | Files | Refs | README

RegistyHardenData.txt (3927B)


      1 # auto update keys
      2 HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU:AutoInstallMinorUpdates:REG_DWORD:1
      3 HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU:NoAutoUpdate:REG_DWORD:0
      4 HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU:AUOptions:REG_DWORD:4
      5 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update:AUOptions:REG_DWORD:4
      6 HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate:DisableWindowsUpdateAccess:REG_DWORD:0
      7 HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate:ElevateNonAdmins:REG_DWORD:0
      8 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer:NoWindowsUpdate:REG_DWORD:0
      9 HKLM\SYSTEM\Internet Communication Management\Internet Communication:DisableWindowsUpdateAccess:REG_DWORD:0
     10 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\WindowsUpdate:DisableWindowsUpdateAccess:REG_DWORD:0
     11 # Restrict CD drive
     12 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon:AllocateCDRoms:REG_DWORD:1
     13 # No remote floppy
     14 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon:AutoAdminLogon:REG_DWORD:1
     15 # no auto admin login
     16 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon:AutoAdminLogon:REG_DWORD:0
     17 # clear page file on shut down (adds some slowdown to shut down)
     18 HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management:ClearPageFileAtShutdown:REG_DWORD:1
     19 # no printer drivers
     20 HKLM\SYSTEM\CurrentControlSet\Control\Print\Providers\LanMan Print Services\Servers:AddPrinterDrivers:REG_DWORD:1
     21 # enable LUA
     22 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System:EnableLUA:REG_DWORD:1
     23 # lsass.exe hardening
     24 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\LSASS.exe:AuditLevel:REG_DWORD:00000008
     25 # disable bad bad wDigest
     26 HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest:UseLogonCredential:REG_DWORD:0
     27 # No DNS
     28 HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient:EnableMulticast:REG_DWORD:1
     29 # No SMB1
     30 HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters:SMB1:REG_DWORD:0
     31 # UAC
     32 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System:ConsentPromptBehaviorAdmin:REG_DWORD:2
     33 # LSA protec
     34 HKLM\SYSTEM\CurrentControlSet\Control\Lsa:RunAsPPL:REG_DWORD:00000001
     35 # no blank passwords
     36 HKLM\SYSTEM\CurrentControlSet\Control\Lsa:LimitBlankPasswordUse:REG_DWORD:1
     37 # enable smartscreen old
     38 HKCU\Software\Microsoft\Internet Explorer\PhishingFilter:EnabledV8:REG_DWORD:1
     39 # enable smartscreen new
     40 HKCU\Software\Microsoft\Internet Explorer\PhishingFilter:EnabledV9:REG_DWORD:1
     41 # IE no cache passwords
     42 HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings:DisablePasswordCaching:REG_DWORD:1
     43 # check for bad certificate (warn)
     44 HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings:WarnonBadCertRecving:REG_DWORD:1
     45 # IE warn for redirect
     46 HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings:WarnOnPostRedirect:REG_DWORD:1
     47 # do not track me
     48 HKCU\Software\Microsoft\Internet Explorer\Main:DoNotTrack:REG_DWORD:1
     49 HKCU\Software\Microsoft\Internet Explorer\Download:RunInvalidSignatures:REG_DWORD:1
     50 HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\Settings:LOCALMACHINE_CD_UNLOCK:REG_DWORD:1
     51 HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings:WarnonZoneCrossing:REG_DWORD:1
     52 # show hidden files
     53 HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced:Hidden:REG_DWORD:1
     54 # disable sticky keys
     55 HKU\.DEFAULT\Control Panel\Accessibility\StickyKeys:Flags:REG_DWORD:506
     56 # show SUPER hidden files (epic)
     57 HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced:ShowSuperHidden:REG_DWORD:1
     58 # no dump files
     59 HKLM\SYSTEM\CurrentControlSet\Control\CrashControl:CrashDumpEnabled:REG_DWORD:0
     60 # disable autorun
     61 HKCU\SYSTEM\CurrentControlSet\Services\CDROM:AutoRun:REG_DWORD:1
     62 # clear null session pipes
     63 HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Parameters:NullSessionPipes:REG_MULTI_SZ: