Hardening your Windows servers: persistence, SMBv1, patches, encryption, firewall
The points to check on a Windows fleet to close the most used doors (added services and tasks, local administrators, SMBv1, late patches, antivirus, BitLocker, firewall), with the commands to verify them
After an intrusion, the investigation often finds the same doors: an old protocol left open, a server without patches for months, an antivirus switched off, then a scheduled task or a service added to come back. This guide goes through these points, server by server, then explains how to keep the result over time.
The commands run in a PowerShell console opened as administrator. They only read, except those flagged as such.
1. What gets installed to last
An attacker who has gained a foothold on a server wants to come back after a restart or a password change. The most common means are a service, a scheduled task or an account added to the local administrators.
Get-CimInstance Win32_Service | Where-Object { $_.PathName -notmatch '\\Windows\\' } | Select-Object Name, StartName, PathName
Get-ScheduledTask | Where-Object TaskPath -notlike '\Microsoft\*' | Select-Object TaskPath, TaskName, State
Get-LocalGroupMember -SID 'S-1-5-32-544'Look first for:
- an executable placed in a folder users can write to (
C:\Users,C:\ProgramData,C:\Windows\Temp); - a task that starts PowerShell,
cmd,mshtaorrundll32with arguments; - an executable without a digital signature;
- an unknown account among the local administrators.
On a domain controller there is no local group: the domain Administrators group is what counts.
The Windows logs keep traces too. Event 7045 in the System log reports the installation of a service. Events 1102 (Security log) and 104 (System log) report that a log was cleared. A log cleared on a production server calls for an explanation.
This inventory is only worth something compared with the previous one. Keep a baseline per server: the difference matters more than the list.
2. SMBv1
SMBv1 is the first version of the Windows file-sharing protocol. Worms such as WannaCry exploited it in 2017. Recent versions of Windows no longer install it by default, but it remains on servers upgraded from older versions.
Get-SmbServerConfiguration | Select-Object EnableSMB1ProtocolBefore turning it off, check that no old device (copier, NAS) still uses it. Set-SmbServerConfiguration -AuditSmb1Access $true records every SMBv1 access in the Microsoft-Windows-SMBServer/Audit log. After a few weeks without access, Set-SmbServerConfiguration -EnableSMB1Protocol $false turns it off. These two commands change the configuration.
3. Patches
A published security patch also tells attackers about the flaw it fixes. The delay between its release and its installation on your machines is their window. Check two things: the date of the last patch, and any pending restart, without which the patch is not active.
Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 5 HotFixID, InstalledOn
Test-Path 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\RebootRequired'Get-HotFix does not see every update, and the date can be missing: the Windows Update history remains the reference. True on the second line means a restart is pending.
The operating system is not the only concern. Installed software (Java, browsers, compression tools, backup agents) has its own flaws. A software inventory matched against known vulnerabilities (CVEs) tells you which to update first.
4. Antivirus and EDR
Get-MpComputerStatus | Select-Object AMRunningMode, RealTimeProtectionEnabled, AntivirusSignatureLastUpdated, IsTamperProtectedAMRunningMode is Normal when Defender protects the machine, Passive Mode when another antivirus has taken over. Signatures 3 days old or more, or tamper protection turned off, need close attention: turning off the antivirus is often one of an attacker's first moves.
5. BitLocker on workstations
A stolen laptop whose disk is not encrypted gives up all its content to whoever removes the disk. On workstations, and laptops first, encryption of the system volume is expected.
Get-BitLockerVolume -MountPoint 'C:' | Select-Object MountPoint, VolumeStatus, ProtectionStatusKeep the recovery keys in Active Directory or in Entra ID, not on the workstation itself.
6. The Windows firewall
The firewall turned off "just for an installation" and then forgotten is a classic. The domain profile must stay on: it filters connections between machines on the internal network, the ones an attacker uses to move from one server to another.
Get-NetFirewallProfile | Select-Object Name, EnabledWhat FirstSI follows
Two screens cover this guide, from the same agent:
| Points in this guide | Screen | Collection frequency |
|---|---|---|
| Services, tasks, local administrators and accounts, cleared logs | SI-Tracer → Persistence (#/sitracer/persistance) | every 15 minutes |
| Antivirus, EDR, tamper protection, patches, SMBv1, BitLocker, firewall, LAPS | Asset Monitor → Security status (#/am/securite) | every 6 hours |
| Installed software and known flaws | AssetMonitor: inventory, vulnerabilities, end of support | CVE matching every night |
Persistence. A server's first collection becomes its baseline. After that, each service, task or administrator added opens an incident, with its indicators: outside Windows / Program Files, user-writable folder, unsigned, interpreter with arguments. A legitimate change is validated with Approve and joins the baseline. The module is not on by default: turn it on for each server, in FSI Agents. See Persistence on servers.
Security status. Each machine gets a mark out of 100. The fleet score is a weighted average in which a domain controller counts 3, a server 2 and a workstation 1. The thresholds used: signatures older than 3 days, last patch older than 45 days, restart pending for 7 days. Gaps of medium severity or higher open an incident in the SIEM.
For BitLocker, only physical workstations are assessed, and only the loss of encryption on a workstation already seen encrypted opens an incident. A fleet that has not encrypted its workstations therefore does not get one alert per workstation. See Machine security status.
The agent reads the state of Windows without changing it. Fixes are up to your teams.
Further reading
- Checking the security of your Active Directory: LAPS, privileged accounts and delegation.
- Anticipating a full disk and backups that fail silently: the other failure that builds up quietly.
- Exposure seen from the Internet: the ports of your servers visible from the Internet.
Overview: Windows server security and capacity
Source: · FirstSI Docs · updated 2026-10-11