PingSentry   |   Discord   |   System32   |   GitHub   |   Free tools
EventSentry
  • Features
    EventSentry v6.0New Features
    Event Log MonitoringSIEM to the core
    Validation Scripts
    Health Monitoring
    Compliance
    ADMonitor
    Reporting
    Log File Monitoring
    Network
    Environment
    Notifications
    Consolidation
    EventSentry

    Why EventSentry?
  • Solutions
    Finance & Banking
    Event Log Monitoring
    Government
    CMMC
    Healthcare
    On-premise SIEM
    Education
    IT Security
    File Integrity (FIM)
    Ransomware
    Account Lockouts
    Solutions Index
  • Downloads
    Download EventSentry
    Admin Assistant
    EventSentry Light
    SysAdmin Tools
    EventSentry Home Lab
    Compliance Validator
    Version History
    Roadmap
  • Support
    Knowledge Base
    How-to Guides
    Documentation
    Video Tutorials
    EventSentry Blog
    Request Support


    EventSentry v6.0.1 Documentation
  • Purchase


    Product Sheet
    Pricing
    Request a quote
    Schedule a demo
    Testimonials
LoginDownload

EventSentry

Validation Scripts

Tag

security-server

Scripts

121



Accounts: Administrator accounts must not be enumerated during elevation

Accounts: Built-in Administrator account must be renamed

Accounts: Built-in Guest account must be renamed

Accounts: Local Admin accounts must have their privileged token filtered to prevent elevated privileges used over the network

Accounts: Local Guest account should be disabled

Accounts: Local accounts with blank passwords must be restricted to prevent access from the network

Accounts: Must be configured to enable Remote host allows delegation of non-exportable credentials

Accounts: Must disable automatically signing in the last interactive user after a system-initiated restart

Accounts: Must have the built-in Windows password complexity policy enabled

Accounts: Must require passwords

Accounts: Passwords for the built-in Administrator account must be changed at least every 60 days

Accounts: Reversible password encryption must be disabled

Accounts: UIAccess applications must not be allowed to prompt for elevation without using the secure desktop

Accounts: User Account Control (UAC) approval mode for the built-in Administrator must be enabled

Accounts: User Account Control (UAC) must automatically deny standard user requests for elevation

Accounts: User Account Control (UAC) must be configured to detect application installations and prompt for elevation

Accounts: User Account Control (UAC) must run all administrators in Admin Approval Mode, enabling UAC

Accounts: Users must be prompted to authenticate when the system wakes from sleep (on battery)

Accounts: Users must be prompted to authenticate when the system wakes from sleep (plugged in)

Accounts: Users must be required to enter a password to access private keys stored on the computer

Auditing: Command line data must be included in process creation events

Auditing: Event Log / Viewer must be protected from unauthorized modification and deletion

Auditing: Event Log size for Application log must be at least 32768 KB

Auditing: Event Log size for Security log must be at least 196608 KB

Auditing: Event Log size for System log must be at least 32768 KB

Auditing: Must force audit policy subcategory settings to override audit policy category settings

Auditing: Permissions for the Security event log must prevent access by non-privileged accounts

Auditing: Permissions for the System event log must prevent access by non-privileged accounts

Auditing: System must be configured to audit DS Access - Directory Service Access failures

Auditing: System must be configured to audit DS Access - Directory Service Access successes

Auditing: System must be configured to audit DS Access - Directory Service Changes successes

Auditing: System must be configured to audit Object Access - Removable Storage successes

Auditing: System must be configured to audit Policy Change - Audit Policy Change failures

Auditing: System must be configured to audit Policy Change - Audit Policy Change successes

Auditing: System must be configured to audit Privilege Use - Sensitive Privilege Use failures

Auditing: System must be configured to audit Privilege Use - Sensitive Privilege Use successes

Auditing: System must be configured to audit System - Other System Events failures

Auditing: System must be configured to audit System - Other System Events successes

Auditing: System must be configured to audit System - Security State Change successes

Auditing: System must be configured to audit System - Security System Extension successes

Autoplay: Must be turned off for non-volume devices

Autoplay: Should be disabled for all drives

Autorun: behavior must be configured to prevent Autorun commands

Credentials: WDigest Authentication must be disabled

Domain Controller: Must be configured to allow reset of machine account passwords

Domain Controller: SYSVOL directory must have proper access control permissions

Domain Controller: System must be configured for certificate-based authentication for domain controllers

Domain Controller: The password for the krbtgt account on a domain must be reset at least every 180 days

Domain Member: Must be running Credential Guard on domain-joined members

Domain Member: Digitally encrypt or sign secure channel data (always) must be set to Enabled

Domain Member: Digitally encrypt secure channel data (when possible) must be set to Enabled

Domain Member: Digitally sign secure channel data (when possible) must be set to Enabled

Domain Member: Domain-joined systems must have a Trusted Platform Module (TPM) enabled and ready for use

Domain Member: Group policy objects must be reprocessed even if they have not changed

Domain Member: Hardened UNC paths must require mutual authentication & integrity for at least \\*\SYSVOL and \\*\NETLOGON shares

Domain Member: Local users on domain-joined member servers must not be enumerated

Domain Member: Maximum age for machine account passwords must be configured to 30 days or less

Domain Member: must be configured to at least negotiate signing for LDAP client signing

Domain Member: must limit the caching of logon credentials to four or less - Server

File System: File Explorer shell protocol must run in protected mode

File System: Windows must prevent Indexing of encrypted files

General: AntiVirus/Antimalware Status

General: Early Launch Antimalware, Boot-Start Driver Initialization Policy must prevent boot drivers identified as bad

General: Machine inactivity limit must be set to 15 minutes or less, locking the system with the screen saver

General: Windows Defender SmartScreen must be enabled (Server)

General: Windows firewall status

General: Windows must prevent the display of slide shows on the lock screen

Internet Browser: Attachments must be prevented from being downloaded from RSS feeds

Internet Browser: Basic authentication for RSS feeds over HTTP must not be used

Logon: Network selection UI must not be displayed

Network Access: Do not allow anonymous enumeration of Security Account Manager (SAM) accounts

Network Access: Do not allow anonymous enumeration of shares

Network Access: LAN Manager authentication level must be configured to send NTLMv2 response only and refuse LM and NTLM

Network Access: Microsoft network Client: Digitally sign communications (always) must be configured to Enabled

Network Access: Microsoft network Client: Digitally sign communications (if server agrees) must be configured to Enabled

Network Access: Microsoft network Server: Digitally sign communications (always) must be configured to Enabled

Network Access: Microsoft network Server: Digitally sign communications (if client agrees) must be configured to Enabled

Network Access: Must be configured to prevent anonymous users from having the same permissions as the Everyone group

Network Access: Must prevent NTLM from falling back to a Null session

Network Access: Restrict remote calls to the Security Account Manager [SAM] to Administrators

Network Access: Services using Local System when reverting to NTLM authentication must use computer identity

Network Access: Session security for NTLM SSP-based CLIENTS must require NTLMv2 session security and 128-bit encryption

Network Access: Session security for NTLM SSP-based SERVERS must require NTLMv2 session security and 128-bit encryption

Network Access: System must be configured to require a strong session key

Network Access: Unencrypted passwords must not be sent to third-party Server Message Block (SMB) servers

Passwords: Windows must be configured to prevent the storage of the LAN Manager hash of passwords

Passwords: must, at a minimum, be 14 characters

PowerShell: v2 should not be installed / enabled

Printing: Prevent users from installing printer drivers

Privacy: Application Compatibility Program Inventory must not collect and send data to Microsoft

Privacy: The location feature must be turned off

Privacy: Windows Telemetry must not be set to Full

Remote Desktop: Idle session time limit

Remote Desktop: Must always prompt a client for passwords upon connection

Remote Desktop: Must be configured to set a time limit for disconnected sessions

Remote Desktop: Must be configured with the client connection encryption set to High Level

Remote Desktop: Must not save passwords in the Remote Desktop Client

Remote Desktop: Must prevent drive redirection

Remote Desktop: Must require secure Remote Procedure Call (RPC) communications

Remote Management: Unauthenticated RPC clients must be restricted from connecting to the RPC server

Remote Management: Windows Remote Management (WinRM) client must not allow unencrypted traffic

Remote Management: Windows Remote Management (WinRM) client must not use Basic authentication

Remote Management: Windows Remote Management (WinRM) client must not use Digest authentication

Remote Management: Windows Remote Management (WinRM) service must not allow unencrypted traffic

Remote Management: Windows Remote Management (WinRM) service must not use Basic authentication

Security: System must preserve zone information when saving attachments

Security: TLS/SSL Insecure Ciphers (SCHANNEL)

Security: Virtualization-based security must be enabled with platform security level set to Secure Boot

Services: List services containing a space in service path not enclosed in quotes

Threat Intel: Attack Vector: Credential dumping protections using LSA Protection

Threat Intel: Attack Vector: Disable Windows Event Logging

Threat Intel: Attack Vector: Utilizing Image File Execution Options (IFEO) For Stealthy Persistence

Threat Intel: Attack Vector: Vulnerable Fan Driver (WinRing0x64 sys)

Threat Intel: Attack Vector: Windows downgrade attacks

Threat Intel: Persistence - AppInit DLLs

Windows Installer: Disable -Always install with elevated privileges- option

Windows Installer: Must prevent users from changing installation options

Windows Installer: Users must be notified if a web-based program attempts to install software

Windows OS: Build Version Check (End Of Life)

Windows OS: Build Version Check (OS Updated)

Windows OS: Secure Boot must be enabled

Full tag list
nist800-53-server (204) stig-medium-server (199) nist800-171-server (177) nist800-53-desktop (169) cmmc2-l2-server (162) stig-medium-desktop (147) pci-dss-v4-server (131) nist800-171-desktop (128) security-server (121) cmmc2-l2-desktop (119) hipaa-server (96) security-desktop (95) pci-dss-v4-desktop (89) hipaa-desktop (65) bestpractice-desktop (39) cis-csc-server (38) bestpractice-server (35) cis-csc-desktop (34) mitre-att-server (32) mitre-att-desktop (30) cmmc2-l1-server (24) stig-high-desktop (23) stig-high-server (22) cmmc2-l1-desktop (21) pci-dss-v3.2-server (20) bestpractice-domaincontroller (16) tisax (16) cmmc2-l3-server (16) pci-dss-v3.2-desktop (15) threat-intel-server (13) cmmc2-l3-desktop (12) threat-intel-desktop (12) sec-hardening-desktop (10) sec-hardening-server (10) nist-privacy-server (10) sig-server (9) stig-low-desktop (8) health (8) csa-cmm-server (7) nist-privacy-desktop (7) stig-low-server (6) privacy-server (6) privacy-desktop (6) owasptop-server (6) owasptop-desktop (5) desktop (4) cce-server (4) cce-desktop (4) stig-medium-ie (4) sig-desktop (3) niap-desktop (3) fips140-2 (3) niap-server (3) msoffice (2) vm-guest-host (2) compliance-desktop (2) info-desktop (1) csa-cmm-desktop (1) server (1) domaincontroller-health (1) bitlocker-security-desktop (1) iis-stig-high (1) hyper-v (1) exchange-security (1)
  • Knowledge Base
  • Documentation
  • Tutorials
  • Screencasts
  • Validation Scripts
  • Support Center

CMMC v2.0ComplianceSTIGCISNIST 800-171ServersDesktops
Resources
  • Tutorials
  • Screencasts
  • Knowledge Base
  • Blog
  • Solutions
  • Support Center
  • MyEventlog
  • System32
About
  • About Us
  • Live Demo
  • In the Press
  • Testimonials
  • Our Customers
  • Our SysAdmin Promise
  • NETIKUS.NET ltd
Contact Us
  • 1-877-NETIKUS
  • 1-312-624-7698
  • sales@netikus.net
  • support@netikus.net
33 N Dearborn St, Suite 1000
Chicago, IL 60602

MON-FRI, 8AM-5PM CDT


Social
  • EventSentry FacebookEventSentry LinkedInEventSentry TwitterEventSentry GithubEventSentry DiscordEventSentry YouTube
Copyright (c) 2002-2026 NETIKUS.NET ltd | Server Monitoring | Event Log Monitoring | Network Monitoring

NETIKUS.NET ltd is a software development company based in Chicago, IL
All rights reserved. This website www.eventsentry.com is part of the www.netikus.net network

XHTML   |   Privacy Policy   |   Your Privacy Choices



Your Privacy Choices

Manage your cookie preferences below:

Helps us improve website performance and understand how visitors use our site.

Allows us to collect feedback about our products and improve them based on your input.

To learn more about our use of cookies, please see our
Privacy Policy.