{"id":2475,"date":"2023-04-01T09:42:25","date_gmt":"2023-04-01T13:42:25","guid":{"rendered":"https:\/\/increasec.com\/?p=2475"},"modified":"2026-03-06T13:59:55","modified_gmt":"2026-03-06T18:59:55","slug":"domain-security-recommendations","status":"publish","type":"post","link":"https:\/\/increasec.com\/?p=2475","title":{"rendered":"Domain Security Recommendations"},"content":{"rendered":"\n<p>These come from <a href=\"https:\/\/7minsec.com\/\">7minsec<\/a>, Brian Johnson makes an entertaining podcast which is unusual in  the normally dry security space.  Highly recommend.   I love podcasts as i can listen while I do other less productive things like drive or try to get to sleep&#8230;. or watch CSI for the 4th time because it&#8217;s my wife&#8217;s turn to choose&#8230;. not that I&#8217;m bitter&#8230;<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>disable users adding pcs to the domain;  Default DOMAIN Controllers policy, replace Authenticated Users with a stricter group(s)<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"669\" height=\"268\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-6.png\" alt=\"\" class=\"wp-image-4104\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-6.png 669w, https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-6-300x120.png 300w\" sizes=\"auto, (max-width: 669px) 100vw, 669px\" \/><\/figure>\n\n\n\n<p><br>smb signing<br>strong unique passwords + LAPS<br>run ping castle<br>disable insecure protocols; netbios, llmnr, mdns, smbv1<br>power up sql, find sql servers, stored procedures,<br>turn off print sharing, esp on DCs, ping castle scanners print spool<\/p>\n\n\n\n<p>take local admin away from everyone<br>Pre-filter email (yes they are all a pain)<br>Use GPO to auto-install the chrome extension Ublock Origin    see <a href=\"https:\/\/support.google.com\/chrome\/a\/answer\/7532015?hl=en#zippy=\" data-type=\"link\" data-id=\"https:\/\/support.google.com\/chrome\/a\/answer\/7532015?hl=en#zippy=\">here<\/a><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>Change the KrbTgt password.  I have done this a dozen times and never had a problem.   Don&#8217;t change it 2x in rapid succession, leave 3 days before changing again.<\/p>\n\n\n\n<p>Starting Audit Policy.  These settings will not generate excessive logs.   There are other settings, i don&#8217;t recommend enabling them until you have a reason.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"522\" height=\"563\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-7.png\" alt=\"\" class=\"wp-image-4113\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-7.png 522w, https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-7-278x300.png 278w\" sizes=\"auto, (max-width: 522px) 100vw, 522px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"391\" height=\"256\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-8.png\" alt=\"\" class=\"wp-image-4115\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-8.png 391w, https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-8-300x196.png 300w\" sizes=\"auto, (max-width: 391px) 100vw, 391px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"168\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-9-1024x168.png\" alt=\"\" class=\"wp-image-4117\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-9-1024x168.png 1024w, https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-9-300x49.png 300w, https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-9-768x126.png 768w, https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-9.png 1088w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"640\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-10-1024x640.png\" alt=\"\" class=\"wp-image-4118\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-10-1024x640.png 1024w, https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-10-300x188.png 300w, https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-10-768x480.png 768w, https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-10.png 1152w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>These come from 7minsec, Brian Johnson makes an entertaining podcast which is unusual in the normally dry security space. Highly recommend. I love podcasts as i can listen while I&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-2475","post","type-post","status-publish","format-standard","hentry","category-uncategorised"],"_links":{"self":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/2475","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2475"}],"version-history":[{"count":10,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/2475\/revisions"}],"predecessor-version":[{"id":4120,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/2475\/revisions\/4120"}],"wp:attachment":[{"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2475"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2475"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2475"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}