PingSentry   |   Discord   |   System32   |   GitHub   |   Free tools
EventSentry
  • Features
    EventSentry v6.0New Features
    Event Log MonitoringSIEM to the core
    Validation Scripts
    Health Monitoring
    Compliance
    ADMonitor
    Reporting
    Log File Monitoring
    Network
    Environment
    Notifications
    Consolidation
    EventSentry

    Why EventSentry?
  • Solutions
    Finance & Banking
    Event Log Monitoring
    Government
    CMMC
    Healthcare
    On-premise SIEM
    Education
    IT Security
    File Integrity (FIM)
    Ransomware
    Account Lockouts
    Solutions Index
  • Downloads
    Download EventSentry
    Admin Assistant
    EventSentry Light
    SysAdmin Tools
    EventSentry Home Lab
    Compliance Validator
    Version History
    Roadmap
  • Support
    Knowledge Base
    How-to Guides
    Documentation
    Video Tutorials
    EventSentry Blog
    Request Support


    EventSentry v6.0.1 Documentation
  • Purchase


    Product Sheet
    Pricing
    Request a quote
    Schedule a demo
    Testimonials
LoginDownload

EventSentry

Validation Scripts

Tag

stig-medium-desktop

Scripts

147



Accounts: Administrator accounts must not be enumerated during elevation

Accounts: Built-in Administrator account must be renamed

Accounts: Built-in Guest account must be renamed

Accounts: Deny log on locally user right must be configured to prevent access from highly privileged domain accounts

Accounts: Enable computer and user accounts delegation user right not be assigned to any groups or accounts

Accounts: Local Admin accounts must have their privileged token filtered to prevent elevated privileges used over the network

Accounts: Local Administrator account should be disabled

Accounts: Local Guest account should be disabled

Accounts: Local accounts with blank passwords must be restricted to prevent access from the network

Accounts: Lockout duration must be configured to 15 minutes or greater

Accounts: Must be configured to enable Remote host allows delegation of non-exportable credentials

Accounts: Must disable automatically signing in the last interactive user after a system-initiated restart

Accounts: Must have the period of time before the bad logon counter is reset configured to 15 minutes or greater

Accounts: Passwords for the built-in Administrator account must be changed at least every 60 days

Accounts: The number of allowed bad logon attempts must be configured to three or less

Accounts: User Account Control (UAC) approval mode for the built-in Administrator must be enabled

Accounts: User Account Control (UAC) must automatically deny standard user requests for elevation

Accounts: User Account Control (UAC) must be configured to detect application installations and prompt for elevation

Accounts: User Account Control (UAC) must run all administrators in Admin Approval Mode, enabling UAC

Accounts: User Account Control (UAC) must virtualize file and registry write failures to per-user locations

Accounts: User Account Control (UAC) must, at a minimum, prompt administrators for consent on the secure desktop

Accounts: User Account Control must only elevate UIAccess applications that are installed in secure locations

Accounts: Users must be prompted to authenticate when the system wakes from sleep (on battery)

Accounts: Users must be prompted to authenticate when the system wakes from sleep (plugged in)

Auditing: generate security audits user right must only be assigned to Local Service and Network Service

Auditing: Command line data must be included in process creation events

Auditing: Event Log size for Application log must be at least 32768 KB

Auditing: Event Log size for Security log must be at least 196608 KB

Auditing: Event Log size for System log must be at least 32768 KB

Auditing: Manage auditing and security log user right must only be assigned to the Administrators group

Auditing: Must force audit policy subcategory settings to override audit policy category settings

Auditing: Permissions for the Security event log must prevent access by non-privileged accounts

Auditing: Permissions for the System event log must prevent access by non-privileged accounts

Auditing: System must be configured to audit Account Logon - Credential Validation failures

Auditing: System must be configured to audit Account Logon - Credential Validation successes

Auditing: System must be configured to audit Account Management - Security Group Management successes

Auditing: System must be configured to audit Account Management - User Account Management failures

Auditing: System must be configured to audit Account Management - User Account Management successes

Auditing: System must be configured to audit Detailed Tracking - Process Creation successes

Auditing: System must be configured to audit Logon/Logoff - Group Membership successes

Auditing: System must be configured to audit Logon/Logoff - Special Logon successes

Auditing: System must be configured to audit Object Access - Other Object Access Events failures

Auditing: System must be configured to audit Object Access - Other Object Access Events successes

Auditing: System must be configured to audit Object Access - Removable Storage failures

Auditing: System must be configured to audit Object Access - Removable Storage successes

Auditing: System must be configured to audit Policy Change - Audit Policy Change successes

Auditing: System must be configured to audit Policy Change - Authentication Policy Change successes

Auditing: System must be configured to audit Policy Change - Authorization Policy Change successes

Auditing: System must be configured to audit Privilege Use - Sensitive Privilege Use failures

Auditing: System must be configured to audit Privilege Use - Sensitive Privilege Use successes

Auditing: System must be configured to audit System - Other System Events failures

Auditing: System must be configured to audit System - Other System Events successes

Auditing: System must be configured to audit System - Security State Change successes

Auditing: System must be configured to audit System - Security System Extension successes

Auditing: System must be configured to audit System - System Integrity failures

Auditing: System must be configured to audit System - System Integrity successes

Auditing: System must be configured to audit logoff successes

Auditing: System must be configured to audit logon failures

Auditing: System must be configured to audit logon successes

Auditing: Windows must be configured to audit Logon/Logoff - Account Lockout Failures

Compliance: System must be configured to use FIPS-compliant algorithms for encryption, hashing, and signing

Credentials: Access Credential Manager as a trusted caller user right must not be assigned to any groups or accounts

Credentials: WDigest Authentication must be disabled

Domain Member: Domain-joined systems must have a Trusted Platform Module (TPM) enabled and ready for use

Domain Member: Group policy objects must be reprocessed even if they have not changed

Domain Member: Hardened UNC paths must require mutual authentication & integrity for at least \\*\SYSVOL and \\*\NETLOGON shares

Domain Member: Local users on domain-joined member servers must not be enumerated

File System: Back up files and directories user right must only be assigned to the Administrators group

File System: File Explorer shell protocol must run in protected mode

File System: Turning off File Explorer heap termination on corruption must be disabled

File System: Windows must prevent Indexing of encrypted files

General: Downloading print driver packages over HTTP must be turned off

General: Early Launch Antimalware, Boot-Start Driver Initialization Policy must prevent boot drivers identified as bad

General: Machine inactivity limit must be set to 15 minutes or less, locking the system with the screen saver

General: Printing over HTTP must be turned off

General: The Microsoft Defender SmartScreen for Explorer must be enabled (Desktop)

General: Windows firewall status

Internet Browser: Attachments must be prevented from being downloaded from RSS feeds

Internet Browser: Basic authentication for RSS feeds over HTTP must not be used

Logon: Allow log on locally user right must only be assigned to the Administrators group

Logon: Network selection UI must not be displayed

Logon: Required legal notice must be configured to display before console logon

Logon: Smart Card removal option must be configured to Force Logoff or Lock Workstation

Microsoft Edge: The Windows Defender SmartScreen filter for Microsoft Edge must be enabled (Windows 10)

Microsoft Edge: Users must not be allowed to ignore SmartScreen filter warnings for unverified files (Windows 10)

Microsoft Edge: Users must not be allowed to ignore Windows Defender SmartScreen filter warnings (Windows 10)

Microsoft Edge: Windows 10 must be configured to prevent certificate error overrides in Microsoft Edge (Windows 10)

Network Access: Insecure logons to an SMB server must be disabled

Network Access: Kerberos encryption types must be configured to prevent the use of DES and RC4 encryption suites

Network Access: Must Have the Server Message Block (SMB) v1 protocol disabled on the SMB client

Network Access: Must be configured to prevent anonymous users from having the same permissions as the Everyone group

Network Access: Must have the Server Message Block (SMB) v1 protocol disabled on the SMB server

Network Access: Must prevent NTLM from falling back to a Null session

Network Access: Restrict remote calls to the Security Account Manager [SAM] to Administrators

Network Access: System must be configured to require a strong session key

Network Access: System must not allow anonymous SID/Name translation

Network Access: System must prevent PKU2U authentication using online identities

Network Access: Unencrypted passwords must not be sent to third-party Server Message Block (SMB) servers

Network: Internet Protocol version 6 (IPv6) source routing must use highest protection level to prevent IP source routing

Network: Simple TCP/IP Services must not be installed on the system

Network: System be configured to prevent ICMP redirects from overriding Open Shortest Path First (OSPF)-generated

Network: System must be configured to ignore NetBIOS name release requests except from WINS servers

Passwords: Maximum Password Age

Passwords: Minimum Password Age

Passwords: history must be configured to 24 passwords remembered

Passwords: must be configured to expire

Passwords: must, at a minimum, be 14 characters

PowerShell: Script block logging must be enabled

PowerShell: v2 should not be installed / enabled

Privacy: Windows Telemetry must not be set to Full

Remote Desktop: Access this computer from the network user right must only be assigned to the Admins and RD Users groups

Remote Desktop: Deny log RDP user on domain-joined servers be configured to prevent access highly privileged domain accountsn

Remote Desktop: Must always prompt a client for passwords upon connection

Remote Desktop: Must be configured with the client connection encryption set to High Level

Remote Desktop: Must not save passwords in the Remote Desktop Client

Remote Desktop: Must require secure Remote Procedure Call (RPC) communications

Remote Management: Unauthenticated RPC clients must be restricted from connecting to the RPC server

Remote Management: Windows Remote Management (WinRM) client must not allow unencrypted traffic

Remote Management: Windows Remote Management (WinRM) client must not use Digest authentication

Remote Management: Windows Remote Management (WinRM) service must not allow unencrypted traffic

Security: Act as part of the operating system user right must not be assigned to any groups or accounts

Security: Create a pagefile user right must only be assigned to the Administrators group

Security: Create a token object user right must not be assigned to any groups or accounts

Security: Create permanent shared objects user right must not be assigned to any groups or accounts

Security: Create symbolic links user right must only be assigned to the Administrators group

Security: Deny access to this computer from the network must include required accounts

Security: Deny log on as a batch job user right on Domain Joined members must be configured to prevent unauthenticated access

Security: Impersonate client after authentication user right only be assigned to Adminis,Service,Local Service,Network Service

Security: Kernel (Direct Memory Access) DMA Protection must be enabled

Security: Load and unload device drivers user right must only be assigned to the Administrators group

Security: Modify firmware environment values user right must only be assigned to the Administrators group

Security: Perform volume maintenance tasks user right must only be assigned to the Administrators group

Security: Profile single process user right must only be assigned to the Administrators group

Security: Restore files and directories user right must only be assigned to the Administrators group

Security: System default permissions of global system objects must be strengthened

Security: System must have orphaned security identifiers (SIDs) removed from user rights

Security: Systems must have UEFI firmware and be configured to run in UEFI mode, not Legacy BIOS

Security: Take ownership of files or other objects user right must only be assigned to the Administrators group

Security: The Force shutdown from a remote system user right must only be assigned to the Administrators group

Security: Virtualization-based security must be enabled with platform security level set to Secure Boot

Security: create global objects user right must only be assigned to Administrators, Service, Local Service, and Network Service

Windows Installer: Must prevent users from changing installation options

Windows Installer: Users must be notified if a web-based program attempts to install software

Windows OS: Explorer Data Execution Prevention must be enabled

Windows OS: Must have the DoD Root Certificate Authority (CA) certificates installed in the Trusted Root Store

Windows OS: Must not have the TFTP Client Installed

Windows OS: Must not have the Telnet Client Installed

Full tag list
nist800-53-server (204) stig-medium-server (199) nist800-171-server (177) nist800-53-desktop (169) cmmc2-l2-server (162) stig-medium-desktop (147) pci-dss-v4-server (131) nist800-171-desktop (128) security-server (121) cmmc2-l2-desktop (119) hipaa-server (96) security-desktop (95) pci-dss-v4-desktop (89) hipaa-desktop (65) bestpractice-desktop (39) cis-csc-server (38) bestpractice-server (35) cis-csc-desktop (34) mitre-att-server (32) mitre-att-desktop (30) cmmc2-l1-server (24) stig-high-desktop (23) stig-high-server (22) cmmc2-l1-desktop (21) pci-dss-v3.2-server (20) bestpractice-domaincontroller (16) tisax (16) cmmc2-l3-server (16) pci-dss-v3.2-desktop (15) threat-intel-server (13) cmmc2-l3-desktop (12) threat-intel-desktop (12) sec-hardening-desktop (10) sec-hardening-server (10) nist-privacy-server (10) sig-server (9) stig-low-desktop (8) health (8) csa-cmm-server (7) nist-privacy-desktop (7) stig-low-server (6) privacy-server (6) privacy-desktop (6) owasptop-server (6) owasptop-desktop (5) desktop (4) cce-server (4) cce-desktop (4) stig-medium-ie (4) sig-desktop (3) niap-desktop (3) fips140-2 (3) niap-server (3) msoffice (2) vm-guest-host (2) compliance-desktop (2) info-desktop (1) csa-cmm-desktop (1) server (1) domaincontroller-health (1) bitlocker-security-desktop (1) iis-stig-high (1) hyper-v (1) exchange-security (1)
  • Knowledge Base
  • Documentation
  • Tutorials
  • Screencasts
  • Validation Scripts
  • Support Center

CMMC v2.0ComplianceSTIGCISNIST 800-171ServersDesktops
Resources
  • Tutorials
  • Screencasts
  • Knowledge Base
  • Blog
  • Solutions
  • Support Center
  • MyEventlog
  • System32
About
  • About Us
  • Live Demo
  • In the Press
  • Testimonials
  • Our Customers
  • Our SysAdmin Promise
  • NETIKUS.NET ltd
Contact Us
  • 1-877-NETIKUS
  • 1-312-624-7698
  • sales@netikus.net
  • support@netikus.net
33 N Dearborn St, Suite 1000
Chicago, IL 60602

MON-FRI, 8AM-5PM CDT


Social
  • EventSentry FacebookEventSentry LinkedInEventSentry TwitterEventSentry GithubEventSentry DiscordEventSentry YouTube
Copyright (c) 2002-2026 NETIKUS.NET ltd | Server Monitoring | Event Log Monitoring | Network Monitoring

NETIKUS.NET ltd is a software development company based in Chicago, IL
All rights reserved. This website www.eventsentry.com is part of the www.netikus.net network

XHTML   |   Privacy Policy   |   Your Privacy Choices



Your Privacy Choices

Manage your cookie preferences below:

Helps us improve website performance and understand how visitors use our site.

Allows us to collect feedback about our products and improve them based on your input.

To learn more about our use of cookies, please see our
Privacy Policy.