Enable SMB signing to verify the integrity of SMB traffic and reduce the risk of man-in-the-middle attacks against Windows file sharing.
Windows Hardening
Secure Windows Server and Windows 11 with step-by-step hardening checklists, security baselines, GPO settings, and best practices.
Get notified when new items are published
Reduce the risk of the PrintNightmare vulnerability by securing the Windows Print Spooler service, applying security updates, and restricting printer driver installation to trusted administrators.
Disable NetBIOS name resolution to reduce legacy attack surfaces, prevent name spoofing attacks, and encourage secure DNS-based name resolution.
Mitigate PrintNightmare-class vulnerabilities by disabling the Print Spooler service on domain controllers, since DCs rarely need direct printing functionality.
Reduce the attack surface by disabling Internet Explorer and enforcing Microsoft Edge with Internet Explorer mode only for legacy applications when absolutely required.
Centrally enforce a secure Chrome baseline across your fleet by deploying Google's ADMX templates through Group Policy — lock down extensions, password saving, and risky flags instead of relying on user discretion.