Host and OS Hardening

Host and OS hardening is the process of reducing the attack surface of computers, servers, and other endpoints by applying secure configurations, removing unnecessary services, controlling access, monitoring activity, and managing vulnerabilities.

This topic has four major areas:

  • Windows security baselines.

  • Linux security baselines.

  • EPP and EDR solutions.

  • Vulnerability management.

A hardened system is not automatically secure forever. It must be continuously monitored, updated, tested, and reviewed.

1. Host and OS Hardening

Concept

A host is any endpoint or system connected to a network, such as:

  • Desktop computer.

  • Laptop.

  • Server.

  • Virtual machine.

  • Cloud workload.

  • Network appliance.

  • IoT device.

Operating system hardening configures the host to make unauthorized access and exploitation more difficult.

The basic goal is:

Reduce unnecessary exposure, enforce secure settings, limit privileges, and continuously detect weaknesses.

Common hardening activities
  • Remove unnecessary software.

  • Disable unused services and ports.

  • Apply security patches.

  • Use strong authentication.

  • Enforce least privilege.

  • Restrict administrative access.

  • Enable host-based firewalls.

  • Configure secure logging.

  • Encrypt storage and sensitive communications.

  • Install endpoint protection.

  • Disable insecure protocols.

  • Apply configuration baselines.

  • Back up important data.

  • Regularly scan for vulnerabilities.

Example

A newly installed Linux server may have multiple services enabled by default. Hardening could involve:

  1. Removing unnecessary packages.

  2. Disabling unused services.

  3. Allowing SSH only from the management network.

  4. Disabling direct root login.

  5. Requiring SSH keys and multifactor authentication.

  6. Enabling a host firewall.

  7. Applying security updates.

  8. Monitoring authentication and system logs.

2. Security Baselines

Concept

A security baseline is a documented set of recommended configuration settings for an operating system, application, device, or service.

Baselines provide a consistent standard for determining whether systems are securely configured. Microsoft describes a security baseline as a group of recommended configuration settings that also explains their security implications.

A baseline may specify:

  • Password requirements.

  • Account lockout settings.

  • Audit policies.

  • Firewall configuration.

  • Encryption settings.

  • Access-control rules.

  • Logging requirements.

  • Application restrictions.

  • Network protocol settings.

  • User privilege assignments.

  • Automatic update behavior.

Why baselines are important

Without a baseline, administrators may configure systems inconsistently. One server may have strong security settings while another has weak or outdated configurations.

Baselines help organizations:

  • Standardize security.

  • Reduce configuration errors.

  • Support compliance.

  • Speed up system deployment.

  • Detect configuration drift.

  • Improve auditability.

  • Create measurable security requirements.

Baseline sources

Common sources include:

  • Microsoft Security Baselines.

  • CIS Benchmarks.

  • DISA STIGs.

  • NIST guidance.

  • Vendor hardening guides.

  • Organizational security policies.

A baseline should not be applied blindly. It should be tested because overly restrictive settings can break applications, affect performance, or prevent legitimate administrative work.

3. Windows Hardening

Common Windows controls
Account security
  • Disable or rename unnecessary local administrator accounts.

  • Use separate standard and administrative accounts.

  • Enforce strong passwords.

  • Enable account lockout policies.

  • Use multifactor authentication.

  • Restrict interactive logon rights.

  • Remove inactive accounts.

Group Policy

Group Policy allows administrators to centrally configure Windows computers in a domain environment.

It can control:

  • Password policies.

  • Windows Defender settings.

  • Firewall rules.

  • Audit policies.

  • Application restrictions.

  • Device control.

  • User permissions.

  • Security options.

For example, an organization may use Group Policy to prevent standard users from installing unauthorized software.

Windows Defender Firewall

The host firewall should restrict unnecessary inbound connections. Outbound traffic may also be controlled where appropriate.

A server should allow only the ports required for its role. For example, a web server may need TCP port 443 for HTTPS but should not expose administrative services to the entire internet.

BitLocker

BitLocker encrypts Windows storage volumes. It helps protect data if a laptop or drive is stolen.

Encryption does not prevent malware from using a system while it is running. It mainly protects data at rest.

User Account Control

User Account Control, or UAC, helps prevent applications from silently performing administrative actions. It prompts the user when elevated privileges are requested.

PowerShell security

PowerShell is useful for administration but can also be abused by attackers. Organizations can improve security by:

  • Restricting unnecessary PowerShell access.

  • Enabling PowerShell logging.

  • Monitoring suspicious scripts.

  • Applying application-control policies.

  • Using constrained language mode where appropriate.

  • Blocking unauthorized macros and script interpreters.

Security auditing

Windows auditing can record:

  • Successful and failed logons.

  • Account changes.

  • Privilege use.

  • Process creation.

  • Policy changes.

  • Object access.

  • PowerShell activity.

These events can be forwarded to a central logging or SIEM system.

Windows baseline workflow
  1. Identify the Windows edition and role.

  2. Select an appropriate baseline.

  3. Test the baseline in a lab or pilot group.

  4. Compare current settings with the baseline.

  5. Document approved exceptions.

  6. Deploy settings through Group Policy, Intune, or another management platform.

  7. Validate the result.

  8. Monitor for configuration drift.

  9. Review the baseline when the operating system or business requirements change.

Microsoft provides the Security Compliance Toolkit to help administrators download, analyze, test, edit, and store recommended security configurations.

4. Linux Hardening

Linux hardening varies between distributions such as Ubuntu, Debian, Fedora, Rocky Linux, and other enterprise systems. The exact commands and configuration files may differ, but the security principles are similar.

Common Linux controls
User and privilege management
  • Disable unnecessary accounts.

  • Use sudo instead of direct root login.

  • Require strong authentication.

  • Use SSH keys where appropriate.

  • Restrict administrative commands.

  • Review membership in privileged groups.

  • Remove inactive users.

SSH security

SSH is commonly used for remote administration. Recommended controls may include:

  • Disable direct root login.

  • Disable password authentication when key-based access is practical.

  • Restrict SSH to management networks.

  • Use multifactor authentication.

  • Apply connection rate limits.

  • Monitor failed login attempts.

  • Use modern cryptographic algorithms.

Example configuration concepts:

PermitRootLogin no
PasswordAuthentication no
AllowGroups administrators

These settings must be tested carefully because an incorrect SSH configuration can lock out administrators.

Services and ports

Administrators should identify listening services and disable those that are not required.

Useful activities include:

  • Listing active services.

  • Reviewing listening ports.

  • Removing unused packages.

  • Disabling legacy protocols.

  • Restricting services with firewall rules.

For example, a database server should not expose its database port to the public internet unless there is a specific, justified requirement.

File permissions

Linux permissions should follow least privilege. Sensitive files should not be writable by everyone.

Important areas include:

  • System configuration files.

  • SSH keys.

  • Application secrets.

  • Log files.

  • User home directories.

  • Backup files.

  • Database files.

Special permissions such as SUID and SGID should be reviewed because they can allow programs to run with elevated privileges.

Mandatory access control

Linux systems may use:

  • SELinux.

  • AppArmor.

These systems add policy-based restrictions that limit what applications can access, even when a process is compromised.

Logging

Important Linux logs may record:

  • Authentication attempts.

  • Privilege escalation.

  • Service activity.

  • Kernel events.

  • Firewall events.

  • Application errors.

Logs should be protected from unauthorized modification and forwarded to a central system when possible.

Updates

Linux systems should receive:

  • Kernel updates.

  • Security patches.

  • Package updates.

  • Application updates.

  • Firmware updates where applicable.

Updates should be tested and tracked, especially on production servers.

Linux baseline workflow
  1. Identify the Linux distribution and version.

  2. Determine the system’s role.

  3. Select a suitable CIS Benchmark, STIG, or organizational baseline.

  4. Scan the system.

  5. Review failed controls.

  6. Test remediation.

  7. Apply approved changes.

  8. Rescan the system.

  9. Document exceptions.

  10. Repeat the assessment periodically.

OpenSCAP and SCAP Security Guide profiles can be used to assess and remediate Linux systems against selected security profiles.

5. EPP and EDR Solutions

Endpoint Protection Platform

An Endpoint Protection Platform, or EPP, protects endpoints from known and common threats. It usually combines traditional antivirus capabilities with additional prevention features.

EPP functions may include:

  • Malware detection.

  • Real-time file scanning.

  • Web protection.

  • Email protection.

  • Exploit prevention.

  • Ransomware protection.

  • Device control.

  • Application control.

  • Quarantine.

  • Signature and reputation checks.

EPP mainly focuses on preventing malicious activity before or during execution.

Endpoint Detection and Response

Endpoint Detection and Response, or EDR, continuously monitors endpoint activity and helps security teams investigate and respond to suspicious behavior. CISA describes EDR as providing monitoring and control of endpoint devices across detection, response, recovery, and follow-up analysis.

EDR may collect:

  • Process activity.

  • Command-line arguments.

  • File creation and modification.

  • Registry changes.

  • Network connections.

  • User logons.

  • PowerShell activity.

  • Persistence mechanisms.

  • Security alerts.

  • Parent-child process relationships.

EPP versus EDR

Feature

EPP

EDR

Main purpose

Prevent common threats

Detect, investigate, and respond to threats

Primary focus

Prevention

Visibility and response

Typical detection

Malware signatures, reputation, behavior

Suspicious activity chains and attacker behavior

Data collection

Usually focused on security events

Detailed endpoint telemetry

Response

Quarantine or block files

Isolate host, terminate process, remove persistence

Best example

Blocking a known malware file

Investigating an attacker using PowerShell and stolen credentials

Many modern products combine EPP and EDR capabilities.

EDR example

An attacker sends a malicious document to an employee. The sequence may be:

  1. The user opens the document.

  2. The document launches an unusual script.

  3. The script starts PowerShell.

  4. PowerShell downloads a payload.

  5. The payload creates a scheduled task.

  6. The system connects to an unfamiliar external address.

An EDR platform can correlate these events into a single suspicious activity chain. Security personnel may then:

  • Isolate the endpoint.

  • Stop malicious processes.

  • Remove persistence.

  • Block the external address.

  • Identify other affected systems.

  • Review stolen credentials.

  • Preserve evidence for investigation.

EPP and EDR limitations
  • They may produce too many alerts.

  • Encrypted or fileless attacks can be difficult to detect.

  • Attackers may attempt to disable the agent.

  • Poorly configured exclusions can create blind spots.

  • Detection does not guarantee successful response.

  • Endpoint telemetry may raise privacy and data-retention concerns.

  • Unsupported operating systems may have limited protection.

EDR is most effective when combined with trained analysts, incident-response procedures, identity security, patching, and centralized logging.

6. Vulnerability Management

Concept

Vulnerability management is a continuous process for identifying, assessing, prioritizing, remediating, and verifying security weaknesses.

A vulnerability may exist in:

  • Operating systems.

  • Applications.

  • Libraries.

  • Firmware.

  • Network devices.

  • Cloud services.

  • Configurations.

  • User accounts.

  • Exposed services.

Vulnerability management lifecycle

1. Discover assets

Create and maintain an inventory of:

  • Workstations.

  • Servers.

  • Virtual machines.

  • Applications.

  • Network devices.

  • Cloud resources.

  • IoT devices.

  • Software versions.

  • System owners.

You cannot reliably secure assets that are unknown or unmanaged.

2. Scan for vulnerabilities

Scanning tools compare systems against vulnerability databases, software versions, configuration rules, and security checks.

Scanning types include:

  • Authenticated scanning.

  • Unauthenticated scanning.

  • Network scanning.

  • Web application scanning.

  • Cloud configuration assessment.

  • Container image scanning.

  • Dependency scanning.

Authenticated scanning generally provides better visibility because the scanner can inspect installed software and local configuration.

3. Validate findings

Not every scanner result is equally reliable. Security teams should confirm:

  • Whether the affected software is actually installed.

  • Whether the vulnerability applies to the system.

  • Whether compensating controls exist.

  • Whether the finding is a false positive.

  • Whether exploitation is possible in the environment.

4. Prioritize risk

Vulnerabilities should not be prioritized only by severity score. Risk also depends on:

  • Whether the asset is internet-facing.

  • Whether exploitation is active.

  • Whether exploit code is publicly available.

  • Business importance.

  • Data sensitivity.

  • Exposure to attackers.

  • Availability of a patch.

  • Existing compensating controls.

A medium-severity flaw on an internet-facing payment server may deserve faster action than a critical flaw on an isolated test machine.

5. Remediate

Remediation may involve:

  • Applying a patch.

  • Upgrading software.

  • Removing vulnerable software.

  • Changing configuration.

  • Disabling an exposed service.

  • Restricting network access.

  • Replacing unsupported systems.

  • Applying a temporary workaround.

6. Verify

After remediation, rescan or test the system. A ticket should not be closed merely because someone reports that a patch was installed.

7. Report and improve

Track:

  • Number of open vulnerabilities.

  • Age of vulnerabilities.

  • Mean time to remediate.

  • Recurring vulnerabilities.

  • Unmanaged devices.

  • Patch compliance.

  • Exceptions and their expiration dates.

Vulnerability versus threat versus risk

Term

Meaning

Example

Vulnerability

A weakness that can be exploited

An unpatched web server

Threat

A potential cause of harm

A cybercriminal group

Exploit

A method or code used to abuse a weakness

Malicious request targeting the server

Risk

The possibility and impact of harm

Data theft caused by exploiting the server

Control

A measure that reduces risk

Patch, firewall rule, or segmentation

Vulnerability management example

Suppose a vulnerability scanner identifies an outdated web framework on an internet-facing server.

A security team may:

  1. Confirm the framework version.

  2. Determine whether the server handles sensitive data.

  3. Check whether the vulnerability is actively exploited.

  4. Apply the vendor patch in a test environment.

  5. Schedule production deployment.

  6. Temporarily restrict access if patching is delayed.

  7. Rescan the server.

  8. Document the result and close the ticket only after verification.

7. How the Controls Work Together

Host hardening, endpoint protection, and vulnerability management support one another.

text

Secure Baseline
      |
Hardening and Configuration Control
      |
EPP Prevention
      |
EDR Monitoring and Response
      |
Vulnerability Scanning
      |
Patch and Remediation
      |
Continuous Verification
Example scenario

An organization runs a Linux application server and Windows employee laptops.

  • The Linux server is configured according to a CIS or STIG-based baseline.

  • SSH is restricted to the management network.

  • Unused services are disabled.

  • The server is scanned for vulnerabilities.

  • EDR monitors process and network behavior.

  • Windows laptops use Microsoft security baselines and host firewalls.

  • EPP blocks malware.

  • EDR detects suspicious PowerShell activity.

  • A vulnerability management platform identifies missing patches.

  • Critical internet-facing vulnerabilities receive priority.

  • Management receives reports about patch compliance and exceptions.

Hardening reduces the number of possible attack paths. EPP attempts to prevent malicious activity. EDR identifies suspicious behavior and supports response. Vulnerability management finds weaknesses before attackers exploit them.\

8. Common Implementation Mistakes

  • Applying a baseline without testing business applications.

  • Giving users permanent local administrator rights.

  • Leaving unused services enabled.

  • Using unsupported operating systems.

  • Installing endpoint protection but ignoring its alerts.

  • Creating excessive antivirus exclusions.

  • Scanning only the external network.

  • Failing to inventory cloud and IoT assets.

  • Treating every vulnerability as equally urgent.

  • Closing remediation tickets without verification.

  • Allowing exceptions to remain permanently.

  • Collecting EDR data without defining retention and privacy rules.

  • Failing to monitor whether security agents are running.

  • Relying only on antivirus signatures.

  • Neglecting backup and recovery testing.