<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security Baseline | Florian Stosse</title><link>https://me.harvester.fr/tags/security-baseline/</link><atom:link href="https://me.harvester.fr/tags/security-baseline/index.xml" rel="self" type="application/rss+xml"/><description>Security Baseline</description><generator>HugoBlox Kit (https://hugoblox.com)</generator><language>en-us</language><lastBuildDate>Wed, 22 May 2024 00:00:00 +0000</lastBuildDate><image><url>https://me.harvester.fr/media/icon_hu_59c72f5082cfcb9b.png</url><title>Security Baseline</title><link>https://me.harvester.fr/tags/security-baseline/</link></image><item><title>exploit-protection-policy</title><link>https://me.harvester.fr/project/exploit-protection-policy/</link><pubDate>Wed, 22 May 2024 00:00:00 +0000</pubDate><guid>https://me.harvester.fr/project/exploit-protection-policy/</guid><description>&lt;p&gt;&lt;strong&gt;Exploit-Protection-policy&lt;/strong&gt; provides a production-hardened Exploit Protection (EP) policy tailored for Windows 10 and Windows 11 systems. It combines multiple industry-standard security baselines with advanced restrictions to maximize security without breaking compatibility with everyday applications.&lt;/p&gt;
&lt;p&gt;This policy has been tested in air-gapped systems to protect endpoints from advanced threat vectors while maintaining productivity.&lt;/p&gt;
&lt;h3 id="merged-security-baselines"&gt;Merged Security Baselines&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;DISA STIG&lt;/strong&gt; Exploit Protection v3.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Microsoft Security Baseline&lt;/strong&gt; Exploit Protection policy (specifically aligned for enterprise systems).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;milgradesec&amp;rsquo;s&lt;/strong&gt; custom Exploit Protection rule configurations.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="key-protections-enforced"&gt;Key Protections Enforced&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;System-Wide Mitigations:&lt;/strong&gt; Enforces fundamental protections such as Control Flow Guard (CFG), Data Execution Prevention (DEP), Address Space Layout Randomization (ASLR), and Heap Protection by default.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Advanced Payload Controls:&lt;/strong&gt; Restricts execution vectors using Export Address Filtering (EAF/EAF+), Import Address Filtering (IAF), and Return-Oriented Programming (ROP) mitigations.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Image &amp;amp; Code Integrity Restrictions:&lt;/strong&gt; Blocks loading of low-integrity or remote images, preventing malicious library injection.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Application-Specific Tuning:&lt;/strong&gt; Includes pre-configured exceptions and application rules to balance high-security containment with software compatibility.&lt;/li&gt;
&lt;/ul&gt;</description></item></channel></rss>