<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hardening | Florian Stosse</title><link>https://me.harvester.fr/tags/hardening/</link><atom:link href="https://me.harvester.fr/tags/hardening/index.xml" rel="self" type="application/rss+xml"/><description>Hardening</description><generator>HugoBlox Kit (https://hugoblox.com)</generator><language>en-us</language><lastBuildDate>Mon, 20 May 2024 00:00:00 +0000</lastBuildDate><image><url>https://me.harvester.fr/media/icon_hu_59c72f5082cfcb9b.png</url><title>Hardening</title><link>https://me.harvester.fr/tags/hardening/</link></image><item><title>ad-hardening</title><link>https://me.harvester.fr/project/ad-hardening/</link><pubDate>Mon, 20 May 2024 00:00:00 +0000</pubDate><guid>https://me.harvester.fr/project/ad-hardening/</guid><description>&lt;p&gt;&lt;strong&gt;ad-hardening&lt;/strong&gt; is a comprehensive guidebook and reference repository dedicated to securing and hardening Active Directory (AD) environments in air-gapped, isolated networks. While physical isolation eliminates many remote threats, it places a heavier security premium on internal access control, endpoint hygiene, and physical media management.&lt;/p&gt;
&lt;p&gt;This project outlines step-by-step guidance, configurations, and templates to establish a resilient security posture inside sensitive, non-internet-connected directory environments.&lt;/p&gt;
&lt;h3 id="core-hardening-pillars"&gt;Core Hardening Pillars&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Tiered Administrative Model:&lt;/strong&gt; Isolating Tier 0 (Domain Controllers/Admins) credentials from Tier 1 (Servers) and Tier 2 (Workstations) to eliminate lateral escalation risks.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Offline Authentication &amp;amp; MFA:&lt;/strong&gt; Strategies for deploying local, offline-capable multi-factor authentication without internet-based validation services.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Service Account Securing:&lt;/strong&gt; transitioning legacy service accounts to Group Managed Service Accounts (gMSAs) to enforce automatic password rotation.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Audit &amp;amp; Event Analysis:&lt;/strong&gt; Configuration templates for offline Windows Event Forwarding (WEF) and local security log auditing.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Removable Media Control:&lt;/strong&gt; Hardening USB and other removable hardware access policies via Group Policy Objects (GPOs) to combat sneakernet malware propagation vectors.&lt;/li&gt;
&lt;/ul&gt;</description></item></channel></rss>