Skip to content
FirstSIDocs

Hardening your Windows servers: persistence, SMBv1, patches, encryption, firewall

The points to check on a Windows fleet to close the most used doors (added services and tasks, local administrators, SMBv1, late patches, antivirus, BitLocker, firewall), with the commands to verify them

After an intrusion, the investigation often finds the same doors: an old protocol left open, a server without patches for months, an antivirus switched off, then a scheduled task or a service added to come back. This guide goes through these points, server by server, then explains how to keep the result over time.

The commands run in a PowerShell console opened as administrator. They only read, except those flagged as such.

1. What gets installed to last

An attacker who has gained a foothold on a server wants to come back after a restart or a password change. The most common means are a service, a scheduled task or an account added to the local administrators.

Services outside the Windows folder, tasks outside \Microsoft\, local administrators
Get-CimInstance Win32_Service | Where-Object { $_.PathName -notmatch '\\Windows\\' } | Select-Object Name, StartName, PathName
Get-ScheduledTask | Where-Object TaskPath -notlike '\Microsoft\*' | Select-Object TaskPath, TaskName, State
Get-LocalGroupMember -SID 'S-1-5-32-544'

Look first for:

  • an executable placed in a folder users can write to (C:\Users, C:\ProgramData, C:\Windows\Temp);
  • a task that starts PowerShell, cmd, mshta or rundll32 with arguments;
  • an executable without a digital signature;
  • an unknown account among the local administrators.

On a domain controller there is no local group: the domain Administrators group is what counts.

The Windows logs keep traces too. Event 7045 in the System log reports the installation of a service. Events 1102 (Security log) and 104 (System log) report that a log was cleared. A log cleared on a production server calls for an explanation.

This inventory is only worth something compared with the previous one. Keep a baseline per server: the difference matters more than the list.

2. SMBv1

SMBv1 is the first version of the Windows file-sharing protocol. Worms such as WannaCry exploited it in 2017. Recent versions of Windows no longer install it by default, but it remains on servers upgraded from older versions.

SMBv1 status on the server side
Get-SmbServerConfiguration | Select-Object EnableSMB1Protocol

Before turning it off, check that no old device (copier, NAS) still uses it. Set-SmbServerConfiguration -AuditSmb1Access $true records every SMBv1 access in the Microsoft-Windows-SMBServer/Audit log. After a few weeks without access, Set-SmbServerConfiguration -EnableSMB1Protocol $false turns it off. These two commands change the configuration.

3. Patches

A published security patch also tells attackers about the flaw it fixes. The delay between its release and its installation on your machines is their window. Check two things: the date of the last patch, and any pending restart, without which the patch is not active.

Latest installed patches, and pending restart
Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 5 HotFixID, InstalledOn
Test-Path 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\RebootRequired'

Get-HotFix does not see every update, and the date can be missing: the Windows Update history remains the reference. True on the second line means a restart is pending.

The operating system is not the only concern. Installed software (Java, browsers, compression tools, backup agents) has its own flaws. A software inventory matched against known vulnerabilities (CVEs) tells you which to update first.

4. Antivirus and EDR

Microsoft Defender status
Get-MpComputerStatus | Select-Object AMRunningMode, RealTimeProtectionEnabled, AntivirusSignatureLastUpdated, IsTamperProtected

AMRunningMode is Normal when Defender protects the machine, Passive Mode when another antivirus has taken over. Signatures 3 days old or more, or tamper protection turned off, need close attention: turning off the antivirus is often one of an attacker's first moves.

5. BitLocker on workstations

A stolen laptop whose disk is not encrypted gives up all its content to whoever removes the disk. On workstations, and laptops first, encryption of the system volume is expected.

Encryption status of the system volume
Get-BitLockerVolume -MountPoint 'C:' | Select-Object MountPoint, VolumeStatus, ProtectionStatus

Keep the recovery keys in Active Directory or in Entra ID, not on the workstation itself.

6. The Windows firewall

The firewall turned off "just for an installation" and then forgotten is a classic. The domain profile must stay on: it filters connections between machines on the internal network, the ones an attacker uses to move from one server to another.

Firewall profile status
Get-NetFirewallProfile | Select-Object Name, Enabled

What FirstSI follows

Two screens cover this guide, from the same agent:

Points in this guideScreenCollection frequency
Services, tasks, local administrators and accounts, cleared logsSI-Tracer → Persistence (#/sitracer/persistance)every 15 minutes
Antivirus, EDR, tamper protection, patches, SMBv1, BitLocker, firewall, LAPSAsset Monitor → Security status (#/am/securite)every 6 hours
Installed software and known flawsAssetMonitor: inventory, vulnerabilities, end of supportCVE matching every night

Persistence. A server's first collection becomes its baseline. After that, each service, task or administrator added opens an incident, with its indicators: outside Windows / Program Files, user-writable folder, unsigned, interpreter with arguments. A legitimate change is validated with Approve and joins the baseline. The module is not on by default: turn it on for each server, in FSI Agents. See Persistence on servers.

Security status. Each machine gets a mark out of 100. The fleet score is a weighted average in which a domain controller counts 3, a server 2 and a workstation 1. The thresholds used: signatures older than 3 days, last patch older than 45 days, restart pending for 7 days. Gaps of medium severity or higher open an incident in the SIEM.

For BitLocker, only physical workstations are assessed, and only the loss of encryption on a workstation already seen encrypted opens an incident. A fleet that has not encrypted its workstations therefore does not get one alert per workstation. See Machine security status.

The agent reads the state of Windows without changing it. Fixes are up to your teams.

Further reading

Overview: Windows server security and capacity

Source: · FirstSI Docs · updated 2026-10-11