Contenu non disponible dans la langue demandée. Affichage de la version anglaise.
HardeningKitty and Windows Hardening
Introduction
The project started as a simple hardening list for Windows 10. After some time, HardeningKitty was created to simplify the hardening of Windows. Now, HardeningKitty supports guidelines from Microsoft, CIS Benchmarks, DoD STIG and BSI SiSyPHuS Win10. And of course my own hardening list.
This is a hardening checklist that can be used in private and business environments for hardening Windows 10. The checklist can be used for all Windows versions, but in Windows 10 Home the Group Policy Editor is not integrated and the adjustment must be done directly in the registry. For this, there is the HailMary mode from HardeningKitty.
The settings should be seen as security and privacy recommendation and should be carefully checked whether they will affect the operation of your infrastructure or impact the usability of key functions. It is important to weigh security against usability.
The project started with the creation of a simple hardening checklist for Windows 10. The focus has shifted to the audit of various well-known frameworks / benchmarks with the development of HardeningKitty. Meanwhile, various CIS benchmarks and Microsoft Security Baselines are supported. With the development of the HailMary mode, it will also be possible to apply settings of any hardening checklist on a Windows system.
HardeningKitty
HardeningKitty supports hardening of a Windows system. The configuration of the system is retrieved and assessed using a finding list. In addition, the system can be hardened according to predefined values. HardeningKitty reads settings from the registry and uses other modules to read configurations outside the registry.
The script was developed for English systems. It is possible that in other languages the analysis is incorrect. Please create an issue if this occurs.
The development of HardeningKitty happens in this repository. In the repository of scip AG is a stable version of HardeningKitty that has been signed with the code signing certificate of scip AG. This means that HardeningKitty can also be run on systems that only allow signed scripts.
How To Run
Run the script with administrative privileges to access machine settings. For the user settings it is better to execute them with a normal user account. Ideally, the user account is used for daily work.
Download HardeningKitty and copy it to the target system (script and lists). Then HardeningKitty can be imported and executed:
root@kitploit:~
PS C:\tmp> Import-Module .\HardeningKitty.psm1
PS C:\tmp> Invoke-HardeningKitty -EmojiSupport
=^._.^=
_( )/ HardeningKitty 0.9.0-1662273740
[*] 9/4/2022 8:54:12 AM - Starting HardeningKitty
[*] 9/4/2022 8:54:12 AM - Getting user information
[*] Hostname: DESKTOP-DG83TOD
[*] Domain: WORKGROUP
...
[*] [*] 9/4/2022 8:54:12 AM - Starting Category Account Policies
[😺] ID 1103, Store passwords using reversible encryption, Result=0, Severity=Passed
[😺] ID 1100, Account lockout threshold, Result=10, Severity=Passed
[😺] ID 1101, Account lockout duration, Result=30, Severity=Passed
...
[*] 9/4/2022 8:54:12 AM - Starting Category User Rights Assignment
[😿] ID 1200, Access this computer from the network, Result=BUILTIN\Administrators;BUILTIN\Users, Recommended=BUILTIN\Administrators, Severity=Medium
...
[*] 9/4/2022 8:54:14 AM - Starting Category Administrative Templates: Printer
[🙀] ID 1764, Point and Print Restrictions: When installing drivers for a new connection (CVE-2021-34527), Result=1, Recommended=0, Severity=High
[🙀] ID 1765, Point and Print Restrictions: When updating drivers for an existing connection (CVE-2021-34527), Result=2, Recommended=0, Severity=High
...
[*] 9/4/2022 8:54:19 AM - Starting Category MS Security Guide
[😿] ID 2200, LSA Protection, Result=, Recommended=1, Severity=Medium
[😼] ID 2201, Lsass.exe audit mode, Result=, Recommended=8, Severity=Low
...
[*] 9/4/2022 8:54:25 AM - HardeningKitty is done
[*] 9/4/2022 8:54:25 AM - Your HardeningKitty score is: 4.82. HardeningKitty Statistics: Total checks: 325 - Passed: 213, Low: 33, Medium: 76, High: 3.
How To Install
First create the directory HardeningKitty and for every version a sub directory like 0.9.3 in a path listed in the PSModulePath environment variable.
Copy the module HardeningKitty.psm1, HardeningKitty.psd1, and the lists directory to this new directory.
The default mode is audit. HardeningKitty performs an audit, saves the results to a CSV file and creates a log file. The files are automatically named and receive a timestamp. Using the parameters ReportFile or LogFile, it is also possible to assign your own name and path.
The Filter parameter can be used to filter the hardening list. For this purpose the PowerShell ScriptBlock syntax must be used, for example { $_.ID -eq 4505 }. The following elements are useful for filtering: ID, Category, Name, Method, and Severity.
root@kitploit:~
Invoke-HardeningKitty -Mode Audit -Log -Report
HardeningKitty can be executed with a specific list defined by the parameter FileFindingList. If HardeningKitty is run several times on the same system, it may be useful to hide the machine information. The parameter SkipMachineInformation is used for this purpose.
The mode config retrives all current settings of a system. If a setting has not been configured, HardeningKitty will use a default value stored in the finding list. This mode can be combined with other functions, for example to create a backup.
HardeningKitty gets the current settings and stores them in a report:
Backups are important. Really important. Therefore, HardeningKitty also has a function to retrieve the current configuration and save it in a form that can be partially restored.
Disclaimer: HardeningKitty tries to restore the original configuration. This works quite well with registry keys and Hardening Kitty really tries its best. But the backup function is not a snapshot and does not replace a real system backup. It is not possible to restore the system 1:1 with HardeningKitty alone after HailMary. If this is a requirement, create an image or system backup and restore it.
The Backup switch specifies that the file is written in form of a finding list and can thus be used for the HailMary mode. The name and path of the backup can be specified with the parameter BackupFile.
root@kitploit:~
Invoke-HardeningKitty -Mode Config -Backup
Please test this function to see if it really works properly on the target system before making any serious changes. A Schrödinger's backup is dangerous.
Non-Default Finding List
Note that if -FileFindingList is not specified, the backup is referred to the default finding list. Before deploying a specific list in HailMary mode, always create a backup referred to that specific list.
The HailMary method is very powerful. It can be used to deploy a finding list on a system. All findings are set on this system as recommended in the list. With power comes responsibility. Please use this mode only if you know what you are doing. Be sure to have a backup of the system.
For now, the filter function is only supported in Audit and Config mode. As the HailMary mode is a delicate matter, create your own file and remove all the lines you want to filter.
Before HailMary is run, a finding list must be picked. It is important to check whether the settings have an influence on the stability and functionality of the system. Before running HailMary, a backup should be made.
Create a Group Policy (experimental)
Thanks to @gderybel, HardeningKitty can convert a finding list into a group policy. As a basic requirement, the Group Policy Management PowerShell module must be installed. At the moment only registry settings can be converted and not everything has been tested yet. A new policy is created, as long as it is not assigned to an object, no change is made to the system. Use it with care.
In the write modes (HailMary and GPO) the finding list fully controls what is applied to the system. To ensure that a list has not been tampered with en route to the operator (e.g. poisoned repository, shared baseline, downloaded or emailed 'run this list'), HardeningKitty can verify that a list is the authentic and unaltered from that published by the maintainer.
The official lists are attested by a signed manifest shipped in the lists\ directory:
lists\hardeningkitty_lists_manifest.psd1 - a readable file mapping each official list to its SHA-256 hash
lists\hardeningkitty_lists_manifest.psd1.p7s - a detached signature over that manifest, created with the maintainer certificate
At runtime, HardeningKitty verifies the detached signature and checks that the signer's certificate matches the thumbprint pinned in the module ($HardeningKittyListSigningThumbprint). It also compares the hash of the loaded list against the manifest. A list whose hash is in the signed manifest is official / verified. Any other list is custom / unverified. This is provenance, not an allow-list - custom lists are fully supported.
Behaviour by mode:
Audit / Config (read-only): the verification result is shown as information only. Custom lists run without restriction
HailMary / GPO (write): a verified official list runs normally. A custom or modified list will be refused unless the risk is explicitly accepted with the -AllowCustomList switch
root@kitploit:~
# Apply your own (unverified) list in HailMary - accept the risk
Invoke-HardeningKitty -Mode HailMary -FileFindingList .\my_custom_list.csv -AllowCustomList
Note that verification only confirms that a list has not been altered by the publisher. It cannot guarantee that the settings in a list are safe. It also does not protect against a malicious administrator - someone with administrator privileges can change the system directly. However, it does protect the honest operator against running a tampered or incorrect list.
Running Your Own Lists
Building and running your own custom lists is fully supported. An unsigned custom list simply runs in Audit/Config and requires the -AllowCustomList switch in write mode. To get the same 'verified' experience for your own lists, sign your list content with your code-signing certificate and pin your thumbprint locally. HardeningKitty's trust anchor is a single thumbprint.
Why RSA and not ECC?
The manifest is signed and verified as a PKCS#7/CMS structure (System.Security.Cryptography.Pkcs.SignedCms). On Windows PowerShell 5.1 (.NET Framework 4.x, still the default on Windows) CMS signing/verification with ECDSA keys is unreliable, whereas RSA works across both Windows PowerShell 5.1 and PowerShell 7. Since HardeningKitty must run on both, RSA-4096 is the interoperable choice.
HardeningKitty Score
Each Passed finding gives 4 points, a Low finding gives 2 points, a Medium finding gives 1 point and a High Finding gives 0 points.
The formula for the HardeningKitty Score is (Points achieved / Maximum points) * 5 + 1.
Rating
Score
Rating Casual
Rating Professional
6
😹 Excellent
Excellent
5
😺 Well done
Good
4
😼 Sufficient
Sufficient
3
😿 You should do better
Insufficient
2
🙀 Weak
Insufficient
1
😾 Bogus
Insufficient
HardeningKitty Interface
@ataumo build a web based interface for HardeningKitty. The tool can be used to create your own lists and provides additional information on the hardening settings. The source code is under AGPL license and there is a demo site.
KittyPorter - Make Hardening Kitty Reports Great Again
Yair took care of presenting HardeningKitty results for sysadmins and even management in the form of a beautiful Excel spreadsheet containing Security Assessment Dashboards and a Dashboard with Dynamic Updates based on the status of findings, as well as an HTML Report Overview. He publishes his work in the KittyPorter repo.
Last Update
HardeningKitty can be used to audit systems against the following baselines / benchmarks:
Name
System Version
Version
0x6d69636b Windows 11 (Machine)
25H2
0x6d69636b Windows 11 (User)
25H2
BSI SiSyPHuS Windows 10 hoher Schutzbedarf Domänenmitglied (Machine)
1809
1.0
BSI SiSyPHuS Windows 10 hoher Schutzbedarf Domänenmitglied (User)
1809
1.0
BSI SiSyPHuS Windows 10 normaler Schutzbedarf Domänenmitglied (Machine)
1809
1.0
BSI SiSyPHuS Windows 10 normaler Schutzbedarf Domänenmitglied (User)
1809
1.0
BSI SiSyPHuS Windows 10 normaler Schutzbedarf Einzelrechner (Machine)
1809
1.0
BSI SiSyPHuS Windows 10 normaler Schutzbedarf Einzelrechner (User)