首页 > 系统相关 >Windows server 2022 安全基线加固 安全加固 仅供参考

Windows server 2022 安全基线加固 安全加固 仅供参考

时间:2024-01-31 18:33:48浏览次数:26  
标签:Windows HKEY server MACHINE 00000001 加固 dword LOCAL Microsoft

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp]
"PortNumber"=dword:0000045a

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
"DisableIPSourceRouting"=dword:00000002

[HKEY_LOCAL_MACHINE\System Access]
"MaximumPasswordAge"=dword:0000005a
"MinimumPasswordLength"=dword:00000008
"PasswordComplexity"=dword:00000001
"PasswordHistorySize"=dword:00000002
"LockoutBadCount"=dword:00000001
"ResetLockoutCount"=dword:00000005
"LockoutDuration"=dword:00000005

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg\AllowedPaths]
"Machine"=""

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanServer\Parameters]
"NullSessionPipes"=""
"NullSessionShares"=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Restrictanonymous"=dword:00000001
"Restrictanonymoussam"=dword:00000001

[HKEY_LOCAL_MACHINE\Privilege Rights]
"SeShutdownPrivilege"="*S-1-5-32-544"
"SeRemoteShutdownPrivilege"="*S-1-5-32-544"
"SeProfileSingleProcessPrivilege"="*S-1-5-32-544"

[HKEY_LOCAL_MACHINE\Event Audit]
"AuditSystemEvents"=dword:00000003
"AuditLogonEvents"=dword:00000003
"AuditObjectAccess"=dword:00000003
"AuditProcessTracking"=dword:00000003
"AuditDSAccess"=dword:00000003
"AuditPrivilegeUse"=dword:00000003
"AuditAccountLogon"=dword:00000003
"AuditAccountManage"=dword:00000003

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\System]
"Retention"=dword:00000000
"MaxSize"=dword:00800000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application]
"Retention"=dword:00000000
"MaxSize"=dword:00800000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Security]
"Retention"=dword:00000000
"MaxSize"=dword:00800000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Tcpip\Parameters]
"SynAttackProtect"=dword:00000001
"TcpMaxPortsExhausted"=dword:00000005
"TcpMaxConnectResponseRetransmissions"=dword:00000002
"TcpMaxHalfOpen"=dword:000001f4
"TcpMaxHalfOpenRetried"=dword:00000190
"EnableICMPRedirect"=dword:00000000
"EnableDeadGWDetect"=dword:00000000
"TcpMaxDataRetransmissions"=dword:00000002
"PerformRouterDiscovery"=dword:00000000
"KeepAliveTime"=dword:000493e0
"EnablePMTUDiscovery"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System]
"Dontdisplaylastusername"=dword:00000001
"DontDisplayLockedUserId"=dword:00000003
"Disablecad"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"PasswordExpiryWarning"=dword:0000000e
"AutoAdminLogon"=dword:00000000
"CachedLogonsCount"=dword:00000005

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanServer\Parameters]
"AutoShareServer"=dword:00000000
"AutoShareWks"=dword:00000000

[HKEY_CURRENT_USER\Control Panel\Desktop]
"ScreenSaveActive"="1"
"ScreenSaveTimeOut"="300"
"ScreenSaverIsSecure"="1"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpServer]
"Enabled"=dword:00000000

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers]
"DisableAutoplay"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanServer\Parameters]
"Autodisconnect"=dword:0000000f
"Enableforcedlogoff"=dword:00000001

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Control Panel\International]
"RestrictLanguagePacksAndFeaturesInstall"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Printers]
"PointAndPrint!RestrictDriverInstallationToAdministrators"=dword:00000001
"EnableDeviceControl"=dword:00000001
"ApprovedUsbPrintDevices"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DNSClient]
"DoHPolicy"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Explorer]
"ShowOrHideMostUsedApps"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\PushNotifications]
"WnsEndpoint"=dword:00000001

[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Policies]
"NtfsForceNonPagedPoolAllocation"=dword:00000001
"NtfsDefaultTier"=dword:00000001
"NtfsParallelFlushThreshold"=dword:00000001
"NtfsParallelFlushWorkers"=dword:00000001

[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Policies\Microsoft\Windows NT\Printers]
"EnableDeviceControl"=dword:00000001
"ApprovedUsbPrintDevices"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos\Parameters]
"CloudKerberosTicketRetrievalEnabled"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Netlogon\Parameters]
"DnsSrvRecordUseLowerCaseHostNames"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\SAM]
"SamNGCKeyROCAValidation"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\StorageSense]
"AllowStorageSenseGlobal"=dword:00000001
"AllowStorageSenseTemporaryFilesCleanup"=dword:00000001
"ConfigStorageSenseGlobalCadence"=dword:00000001
"ConfigStorageSenseCloudContentDehydrationThreshold"=dword:00000001
"ConfigStorageSenseRecycleBinCleanupThreshold"=dword:00000001
"ConfigStorageSenseDownloadsCleanupThreshold"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Appx]
"AllowAutomaticAppArchiving"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\AppPrivacy]
"LetAppsAccessBackgroundSpatialPerception"=dword:00000001
"LetAppsAccessBackgroundSpatialPerception_UserInControlOfTheseApps"=dword:00000001
"LetAppsAccessBackgroundSpatialPerception_ForceAllowTheseApps"=""
"LetAppsAccessBackgroundSpatialPerception_ForceDenyTheseApps"=""
"LetAppsActivateWithVoice"=dword:00000001
"LetAppsActivateWithVoiceAboveLock"=dword:00000001
"LetAppsAccessGraphicsCaptureProgrammatic"=dword:00000001
"LetAppsAccessGraphicsCaptureProgrammatic_UserInControlOfTheseApps"=dword:00000001
"LetAppsAccessGraphicsCaptureProgrammatic_ForceAllowTheseApps"=""
"LetAppsAccessGraphicsCaptureProgrammatic_ForceDenyTheseApps"=""
"LetAppsAccessGraphicsCaptureWithoutBorder"=dword:00000001
"LetAppsAccessGraphicsCaptureWithoutBorder_UserInControlOfTheseApps"=dword:00000001
"LetAppsAccessGraphicsCaptureWithoutBorder_ForceAllowTheseApps"=""
"LetAppsAccessGraphicsCaptureWithoutBorder_ForceDenyTheseApps"=""

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\DataCollection]
"DisableOneSettingsDownloads"=dword:00000001
"EnableOneSettingsAuditing"=dword:00000001
"LimitDiagnosticLogCollection"=dword:00000001
"LimitDumpCollection"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\EnterpriseMode]
"AllowSaveTargetAsInIEMode"=dword:00000001
"EnableExtendedIEModeHotkeys"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows Defender]
"SupportLogLocation"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows Defender\Exclusions]
"Exclusions_IpAddresses"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\Network Protection]
"AllowNetworkProtectionOnWinServer"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows Defender\NIS]
"DisableDatagramProcessing"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows Defender\Real-Time Protection]
"DisableScriptScanning"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows Defender\Signature Updates]
"MeteredConnectionUpdates"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PassportForWork]
"UseCloudTrustForOnPremAuth"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Sandbox]
"AllowAudioInput"=dword:00000001
"AllowClipboardRedirection"=dword:00000001
"AllowNetworking"=dword:00000001
"AllowPrinterRedirection"=dword:00000001
"AllowVGPU"=dword:00000001
"AllowVideoInput"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services]
"AutoSubscription"=dword:00000001

[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows NT\Printers]
"EnableDeviceControl"=dword:00000001
"ApprovedUsbPrintDevices"=dword:00000001

[HKEY_CURRENT_USER\Software\Policies\Microsoft\Control Panel\International]
"RestrictLanguagePacksAndFeaturesInstall"=dword:00000001

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"HideSCAMeetNow"=dword:00000001

[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Explorer]
"ShowOrHideMostUsedApps"=dword:00000000

[HKEY_CURRENT_USER\Software\Policies\Microsoft\InputMethod\Settings\KOR]
"ConfigureImeVersion"=dword:00000001

[HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\EnterpriseMode]
"AllowSaveTargetAsInIEMode"=dword:00000001
"EnableExtendedIEModeHotkeys"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PassportForWork]
"UseCloudTrustForOnPremAuth"=dword:00000001

 

标签:Windows,HKEY,server,MACHINE,00000001,加固,dword,LOCAL,Microsoft
From: https://www.cnblogs.com/suv789/p/17999885

相关文章

  • SQL Server MERGE(合并)语句
    来源 https://www.cnblogs.com/yigegaozhongsheng/p/11941734.html如何使用SQLServerMERGE语句基于与另一个表匹配的值来更新表中的数据。  SQLServer MERGE语句 假设有两个表,分别称为源表和目标表,并且需要根据与源表匹配的值来更新目标表。有以下三种情况: 源表......
  • Socket.D v2.3.9 发布(增加 node.js server 实现)
    Socket.D是基于"事件"和"语义消息""流"的网络应用层传输协议。有用户说,“Socket.D之于Socket,尤如Vue之于Js、Mvc之于Http”。支持tcp,udp,ws,kcp传输。协议特点可参考《官网介绍》。pyton已开发完成,再在测试中;go,rust,c++正在开发中。forJava适配框架更新说......
  • Windows 下 cat 和 touch 的等价命令
    Linux系统下,常用cat命令查看文本文件内容、touch命令新建空白文件。Windows系统往往也有这些需求,具体的等价命令,如下:1. Linuxcat命令在WindowsCMD 中,Linuxcat命令的等价命令为type命令,具体示例,如下:echolinefromfile1>file1.txtecholinefromfile2>......
  • Windows Powershell 执行结束 返回状态码
    前言全局说明WindowsPowershell执行结束返回状态码一、1.源码用于将文件复制到文件夹的Powershell脚本$dest="C:est"New-Item$dest-typedirectory-force$source="c:samplefile.txt"Copy-Item$source$destexit$LASTEXITCODE$LASTEXITCODE保存Powershel......
  • 在Windows中设置开机启动项可以通过多种方式实现
    以下是两种常见的方法:方法1:使用“启动”文件夹打开启动文件夹:按Win+R打开运行对话框,输入shell:startup,然后按Enter。这将打开当前用户的“启动”文件夹。如果要为所有用户设置开机启动,请输入shell:commonstartup并按Enter。添加快捷方式:在“启动”文件......
  • AS-Windows 客户端不显示文件状态图标
    关键字状态图标、注册表适用产品AS5.0.xASEnterprise6.0.xASExpress6.0.xASCloud6.0.x问题描述打开AnyShareWindows客户端不显示文件状态图标。 问题影响AnyShareWindows客户端文件状态图标不显示,无法判断文件状态,影响用户使用体验。问题原因杀毒软件等原因导致文件状......
  • 如何在Windows上和Linux上配置自启动服务?
    我们以FastTunnel这个内网穿透工具为例,其中Server端的程序运行在Linux上,Client端的程序运行在Windows上。关于这个程序的配置请参考官方文档:快速上手:快速搭建服务。为了避免每次手动启动程序,我们把它们做成开启自启动的服务,这样你就可以无缝使用远程桌面了。Windows下载n......
  • Windows下安装Redis并配置自启服务
    推荐(免费):Redis使用教程1,下载地址:https://github.com/MicrosoftArchive/redis/releases2,解压缩后在文件夹中创建两个文件夹dbcache、logs。3,双击redis-server.exe,启动redis,如下图片表示启动成功。4,上面的启动一般用于检测redis是否可以成功启动,如果成功,接下来,要将redis注册为......
  • Windows10安装Hadoop3.1.3环境
    Windows10安装Hadoop3.1.3环境文章目录1.安装包下载1.1.hadoop官网下载1.2下载winutils1.3安装文件2.配置安装2.1安装配置JDK环境2.2解压hadoop压缩包2.3配置hadoop的环境变量2.3.1配置HADOOP_HOME2.3.2配置Path变量2.4配置hadoop2.4.1创建data和temp文件夹2.4.2配置hadoop......
  • Windows Server 2025 来了
    微软于2024年1月26日发布了WindowsServer2025的预览版更新,WindowsServer2025是由您的反馈和您希望拥抱混合、自适应云的愿望驱动的。这是2024年度的首个预览版,版本号为Build26040。在WindowsServer2025中,微软引入了多项新安全机制,旨在增强传统SMBoverTCP或RDMA的安全性。......