Check out our companion blog!
Sept. 21, 2026

Endpoint Hardening: Closing Windows Before Somebody Climbs In

Endpoint Hardening: Closing Windows Before Somebody Climbs In

Endpoint hardening is the unglamorous work of closing the windows and locking the doors before somebody comes along and jiggles the handle. Prasanna, Dr. Mike Saylor and I walk through what that actually looks like: secure builds and golden images, which services to shut off, which ones to uninstall so a bad guy can't just switch them back on, USB lockdown, full disk encryption, BIOS and UEFI, and the phone in your pocket that logs onto your corporate Wi-Fi every morning.

Mike opens with the analogy he uses in the book. Bad guys casing your organization are doing what a burglar does walking down your street — checking every door, every window, every garage. An unpatched box screaming its version number to the internet is a broken window with a sign on it.

Then we get practical. Your receptionist's computer is running a web server she will never use. Your new Dell shipped with Xbox Game Bar running by default. Mike's point is that turning those off isn't enough, because an attacker living off the land will just turn them back on. Uninstall the thing.

We also get into the argument nobody wins: locking down USB ports. Prasanna makes the end-user case, Mike makes the red team case, and we land on data leakage controls as the middle ground. Then Mike explains how he gets into a laptop that's suspended instead of logged off, and why your encrypted drive doesn't help you in that state.

If you've been told you should harden your endpoints and nobody ever handed you the list, this one's for you. Start with one image, the lowest common denominator, and build from there. Don't let perfect be the enemy of good.

CHAPTERS

00:00 Your receptionist's computer is running a web server

01:39 Welcome, with Prasanna and Dr. Mike Saylor

03:52 The house analogy: broken windows and unlocked doors

06:22 Do you just have to be safer than your neighbor?

08:49 Assume breach, and close the windows anyway

09:52 Secure builds and golden images

13:37 One image for everyone, or one per role?

14:39 Level one hardening: turning off what nobody uses

16:20 Xbox Game Bar, and why disabling isn't enough

19:07 The USB lockdown fight

22:46 BIOS, UEFI, and malware that survives a reimage

26:35 Full disk encryption only works if you log off

29:42 Physical access trumps everything

30:07 Port scans, Nmap, and banner grabbing

31:50 Building your hardening checklist

33:14 The endpoint in your pocket

Speaker:

Did you know your receptionist's computer is running a web server?

Speaker:

And an Xbox game bar?

Speaker:

Neither one of those helps them answer the phone, but both are doors that

Speaker:

a bad guy can walk right through.

Speaker:

Uh, today, Prasanna and Mike and I, uh, talk about hardening your endpoints.

Speaker:

In other words, we're talking about closing the windows, locking the doors,

Speaker:

before somebody else comes along and, you know, starts trying to jiggle the handle.

Speaker:

We talk about secure builds and golden images, as well as which services

Speaker:

to completely uninstall so the bad guys can't just switch them back on.

Speaker:

We talk about doing things like locking down USB ports, and why

Speaker:

full-disk encryption does nothing if you don't actually log off.

Speaker:

Mike also talks about malware that lives in UEFI and survives a complete re-image.

Speaker:

If this is your first time watching or listening to me, I'm

Speaker:

W. Curtis Preston, AKA Mr. Backup.

Speaker:

I've been obsessing over backup recovery and now cyber recovery for over 30 years.

Speaker:

If that's your bag, I'm your guy.

Speaker:

You're not gonna find anyone that cares about it more than me.

Speaker:

Ever since 1993 when I had to tell my boss that there were no backups

Speaker:

of the database that we just lost.

Speaker:

Now I've written five O'Reilly books, a blog, and a podcast.

Speaker:

Here we turn unappreciated admins into cyber recovery heroes.

Speaker:

This is the Backup Wrap-Up.

Speaker:

Welcome to the Backup Wrap Up.

Speaker:

I'm your host, W. Curtis Preston, AKA Mr. Backup, and I have with me my

Speaker:

anchor and my rock, Prasanna Malaiyandi.

Speaker:

How's it going, Prasanna?

Speaker:

I'm, flattered I guess you could say.

Speaker:

Your anchor and your rock

Speaker:

what else do I refer to you as?

Speaker:

What do I else do refer…

Speaker:

As long as you don't call me, your ball and chain or

Speaker:

something, I think we're good.

Speaker:

you're my work husband.

Speaker:

except we don't work at the same place anymore.

Speaker:

Isn't that kinda weird?

Speaker:

Although you and I do a lot of work with the same company, but

Speaker:

just in a very different way.

Speaker:

Yes, that is true

Speaker:

and, and once again, I have my, my book co-author and friend, Dr. Mike Saylor.

Speaker:

How's it going, Mike?

Speaker:

Hello everybody.

Speaker:

Doing good.

Speaker:

Doing good

Speaker:

we're of course talking about the book Learning Ransomware Response Recovery,

Speaker:

which you, if you are watching us on the YouTube, the Backup Wrap-Up channel,

Speaker:

you can see over my, left shoulder, it looks like the right shoulder in

Speaker:

the picture, but oh, and there he is.

Speaker:

He's

Speaker:

And Mike's holding the book.

Speaker:

So then you could see, the ginormous poster behind Curtis, and for everyone

Speaker:

else who wants to read the book, Mike's holding up a picture of the book

Speaker:

So Curtis, e-enhanced for detail, and then this is the actual size.

Speaker:

It's a good, it's a good, it's got a good weight to it

Speaker:

Yeah, and it's, yeah, and for those that, if you haven't heard me talk about this

Speaker:

before, that poster, in order to look okay on the camera, that thing is ginormous.

Speaker:

That's It's literally

Speaker:

sent

Speaker:

Hang on.

Speaker:

I'm j-

Speaker:

publisher sent us one, but

Speaker:

Yeah, send us a small one.

Speaker:

I'm gonna go back here.

Speaker:

than, it's not much bigger than

Speaker:

You see what I'm saying?

Speaker:

yeah.

Speaker:

Anyway,

Speaker:

Yeah, it's two shelves on your book tall.

Speaker:

Yeah, exactly.

Speaker:

All right.

Speaker:

So today, friends, we're gonna be talking about, hardening, endpoints, which, you

Speaker:

know, just basically that, that thing that people, that, bad guys like to attack.

Speaker:

And Mike, I thought you'd start, you would start us off with this idea that

Speaker:

used, that you used in the book about, comparing, cybersecurity to, to houses

Speaker:

Yeah, I do that a lot and it helps, I think, people, relate cyber to the

Speaker:

real world, things you see every day.

Speaker:

You don't see cyber, you just, you get hit over the head with it every now and then.

Speaker:

But, when you think about your house, and we've talked about this analogy in

Speaker:

a lot of different ways but, backing up just a little bit, bad guys, when they

Speaker:

do a, when they look for weaknesses in your home, they're gonna look at all of

Speaker:

the potential entry points or weaknesses.

Speaker:

is that a, is the door unlocked?

Speaker:

is it a, a lock I can pick easy?

Speaker:

Is it a double pane tempered glass, or is it, some, some

Speaker:

older different type of glass?

Speaker:

and so when we're doing a vulnerability assessment, we're looking for weaknesses,

Speaker:

when we find an endpoint where the window's already broken, we know it, it's

Speaker:

got a vulnerability that's widely known.

Speaker:

it calls out to the internet, "Please, somebody me." those are the obvious things

Speaker:

that bad guys can pick up on very quickly.

Speaker:

as an example, we all miss Windows XP.

Speaker:

Do we?

Speaker:

you connect

Speaker:

That no one ever

Speaker:

if you con- if you connect a Windows XP computer to the internet, the

Speaker:

meantime to compromise is, minutes, that is a broken window that,

Speaker:

that's just asking for trouble.

Speaker:

But yeah, bad guys, when they look at an organization, broken windows are

Speaker:

those things that are just, they're already cataloged as known entry points.

Speaker:

Does it

Speaker:

what the, the bad guys think when they drive by my house and for some reason my

Speaker:

garage is just sitting there hope open.

Speaker:

Which is like every other day.

Speaker:

which is what's funny is, I have a Tesla, right?

Speaker:

And Tesla will automatically open the garage when I come up, and it's

Speaker:

100% successful when coming up to the house, opening up the garage

Speaker:

door, and it's roughly 90% successful shutting the garage door when I leave.

Speaker:

But it's so successful that I often forget to, double-check that

Speaker:

it's going down as I'm leaving.

Speaker:

And, and then I come back after having been gone all day, and

Speaker:

I go, "Huh, look at that. My

Speaker:

is, open." And the… And I even have all these fail-safes where I have,

Speaker:

I actually have a if this then that thing that kicks off, and it basically

Speaker:

runs every half hour and cl- tries to close my garage door every half hour.

Speaker:

And that fixes that about 50% of the time.

Speaker:

But the other 50% of the time, the reason why it isn't closing

Speaker:

is because something's in the way.

Speaker:

And, software's not gonna fix that 'cause that's a hardware problem, yeah.

Speaker:

Anyway, Prasanna

Speaker:

no, I, Mike, I like your analogy.

Speaker:

Is there something similar to be said?

Speaker:

you know how they say, to avoid getting eaten by a bear, you don't need to be

Speaker:

the fastest person, you just need to be faster than the person next to you?

Speaker:

Does that also apply for your broken window analogy too?

Speaker:

That

Speaker:

It does.

Speaker:

to, to some degree.

Speaker:

a lot of times, in that analogy, and there's others similar, like

Speaker:

I don't have to have the best security on my house, I just needs

Speaker:

to be more secure than my neighbor.

Speaker:

Or if you're gonna buy new

Speaker:

Yeah.

Speaker:

and something, expensive and you've gotta throw the trash away, throw

Speaker:

it away in your neighbor's trash.

Speaker:

so it's all about obfuscation and perspective, but a lot of bad

Speaker:

guys don't target Prasanna, right?

Speaker:

They're- I'm not- they're not just waking up tomorrow and go, "I'm gonna attack

Speaker:

Prasanna. And then while I'm attacking Prasanna, I notice that Curtis has more

Speaker:

broken windows, and so I'm gonna go attack Curtis." it doesn't happen that way.

Speaker:

W- the way it works is usually if they're truly targeting and th- then

Speaker:

they're hands on the keyboard doing this type of or reconnaissance, sure,

Speaker:

they're gonna look at one thing, and if it's too much trouble, they're gonna

Speaker:

move on to the next one, for sure.

Speaker:

but a lot of times today especially, there, a lot of the reconnaissance

Speaker:

is done through automation, whether that's AI or scripts.

Speaker:

And the bad guy doesn't even know, in a lot of cases, when

Speaker:

something's been compromised.

Speaker:

they've gotta go check their log or look at a dashboard or wait

Speaker:

till someone calls them and asks how much ransomware they owe.

Speaker:

but yeah, more secure than the next guy is, it's one of

Speaker:

those, zombie apocalypse rules

Speaker:

Yeah, a- again, going back to the house analogy, they're basically, they've got

Speaker:

a small army of, people that are just running up and checking every door,

Speaker:

every window at every house, right?

Speaker:

And if you happen to be the one with the back door open, your garage

Speaker:

door open, and your window open, you'll find yourself at my house.

Speaker:

Trunk open

Speaker:

the way, they're…

Speaker:

Go ahead

Speaker:

world, I use, I refer to as the kinetic world, they're hiring or

Speaker:

they're paying kids to do that.

Speaker:

They will pay a kid $5, $10, candy, whatever, "Hey, go see if that door is

Speaker:

unlocked." Because when you open the door and there's a kid there, it's a kid.

Speaker:

You're like, "What are you doing?

Speaker:

Get out of

Speaker:

What are you doing?

Speaker:

Yeah

Speaker:

stop being a nuisance," versus an adult who may have a different reaction

Speaker:

Interesting.

Speaker:

Yeah.

Speaker:

a good, that's a good way to get shot in some parts of the world.

Speaker:

maybe

Speaker:

What are we to-

Speaker:

Go ahead

Speaker:

So Curtis, so great analogy, Mike, but Curtis, what are we really

Speaker:

going to talk about on this episode?

Speaker:

the

Speaker:

how does it lead into what we wanted?

Speaker:

Yeah

Speaker:

Yeah, so the point of this is that the idea is that you do need to harden the,

Speaker:

the, the touchpoints, the endpoints where the cyber attacker, where the,

Speaker:

bad actor is going to try to attack you.

Speaker:

And, just to go back to the analogy, need to make sure that all the

Speaker:

windows are closed, that the doors are locked, that, all of these things,

Speaker:

and that we don't do anything stupid.

Speaker:

When we talk about it in the book, Mike, I remember, not… The book is not,

Speaker:

like, not to get ransomware, right?

Speaker:

We, we took an assume breach position, but that doesn't

Speaker:

mean that you can't try, right?

Speaker:

You can do the stupid stuff.

Speaker:

Make sure your windows are closed.

Speaker:

Make sure your doors are locked.

Speaker:

the stuff that you can do relatively easily, make sure you do those things, and

Speaker:

that's what we're gonna talk about today, is basically hardening, the endpoint.

Speaker:

And the first thing that we wanna talk about, and Prasanna, I know you've

Speaker:

talked about this with me before, so maybe you're gonna jump right on

Speaker:

in here, and that is this idea of a secure build and a golden image.

Speaker:

What are we talking about there?

Speaker:

Oh, yeah.

Speaker:

So you could do the sort of not necessarily a simple thing, but

Speaker:

take a pre-installed version, like a new laptop ships, from a vendor.

Speaker:

And you take it and you're like, "Okay, I'm just gonna install some software on it

Speaker:

and just hand it off to my users." There's probably a whole bunch of things running

Speaker:

on there that you don't necessarily need.

Speaker:

It's not something that makes it easy to repeat and have a consistent

Speaker:

view across your entire environment.

Speaker:

And so what you really want is a golden image that you can quickly install.

Speaker:

It isn't painful, but is consistent, and it only has what you need in

Speaker:

your environment and nothing more.

Speaker:

So if you don't need…

Speaker:

And Curtis, I know we will talk at some point about your favorite topic, but if

Speaker:

there are certain services you don't need to be running, then don't have them run.

Speaker:

Don't install it.

Speaker:

If there are certain programs you don't need, get rid of all the

Speaker:

bloatware, everything else as part of this golden image that you can

Speaker:

then replicate and install and reuse consistently throughout your environment

Speaker:

Yeah, and the whole point here is that you're essentially

Speaker:

restoring the laptop, right?

Speaker:

You're taking this image that you have backed up, and you're wiping the laptop.

Speaker:

and you're not just… you could do it in a different way.

Speaker:

You could say, "I'm buying a, this will work, but it- it's limit- limited

Speaker:

functionality, where you get a brand-new laptop, and then you have, like a scripted

Speaker:

installation of various pieces of software and the deactivation of certain features.

Speaker:

But, what we're really talking about here is the idea that you would have

Speaker:

this image that you're going to restore a complete drive, to that laptop

Speaker:

or to any other endpoints, right?

Speaker:

Servers and things like that, so that you're basically, in one

Speaker:

step, you get the baseline of everything you need to be functional.

Speaker:

And we normally think about this in the case of like virtualization, right?

Speaker:

Where you have a golden image that you spin up new VMs for, from.

Speaker:

But the same thing also applies, like you said, Curtis, for endpoints,

Speaker:

where you're just spinning up this golden image across your devices

Speaker:

Yeah.

Speaker:

Any thoughts on that, Mike?

Speaker:

so one of the things to think about too, and you need a strategy for that.

Speaker:

so you can't just… A- I did this a long time ago where I just went into

Speaker:

all my services and started turning things off, and yeah, maybe it worked

Speaker:

at the time, but then, tomorrow I need to something and it's not working

Speaker:

'cause I turned some services off that I needed for whatever that was.

Speaker:

so there, there needs to be a strategy for how you build your image.

Speaker:

and I think we're gonna touch on that a little bit more here in a second, but,

Speaker:

that, that approach, that image needs to be specific to the different hardware

Speaker:

that you deploy out into your environment.

Speaker:

So one of those strategies would be minimize the dif- the variety of

Speaker:

technology, 'cause that's just gonna help you as a, an IT department to…

Speaker:

you're maintaining less, variety, so the problem with this is the, the solution to

Speaker:

that problem's gonna be the same across And so now that golden image applies to,

Speaker:

the, the one, maybe two different types of, device models that you've got out.

Speaker:

one thing, real quick, one thing I will always hammer on is document that thing.

Speaker:

don't just build it.

Speaker:

Write down why you built it that way and how it was built, because

Speaker:

it's gonna take time to, to d- to troubleshoot why that image didn't

Speaker:

work or why that image isn't working with certain applications or whatever.

Speaker:

Now you've got a document, and we can refer to that, and then

Speaker:

you just, you update that, that image as, exceptions come in or

Speaker:

that build, is modified over time

Speaker:

Mike, I'm glad you touched on the point about sort of you might need a different

Speaker:

golden image per hardware, and so consolidate down hardware such that it

Speaker:

makes it easier and more streamlined.

Speaker:

What about in terms of, different roles within an organization?

Speaker:

So as an example, do you see typically, or like an engineer might need a different

Speaker:

golden image than, say, someone in finance or in HR, or do you also recommend trying

Speaker:

to consolidate down as much as possible to a single golden image that can be used

Speaker:

across many people in the organization or as many people as possible, and

Speaker:

then for things that an engineer might need, then there's additional scripts

Speaker:

you run on top of that golden image?

Speaker:

I'm gonna answer for Mike.

Speaker:

You ready?

Speaker:

wait, Mike, I know what your answer is.

Speaker:

it

Speaker:

It depends.

Speaker:

It depends.

Speaker:

Absolutely depends.

Speaker:

It depends on the environment because, for example, maybe your engineer needs

Speaker:

a different computer all together.

Speaker:

"I need better hardware.

Speaker:

I need more

Speaker:

RAM.

Speaker:

I need a different processor." that's a different image for

Speaker:

that different piece of hardware.

Speaker:

All right, but that's one approach.

Speaker:

But really, the, the approach you should take understanding the

Speaker:

different levels of hardening.

Speaker:

So level one hardening is just basic works- workspace type hardening.

Speaker:

do I need, Microsoft?

Speaker:

They, One of the services is a web server.

Speaker:

Why is a web server running on my receptionist's computer?

Speaker:

what a RDP, one of Curtis's favorite, or even remote procedure calls.

Speaker:

If, it depends on how your environment's built.

Speaker:

how do you support these devices?

Speaker:

If you're doing it remotely, you need some of that stuff.

Speaker:

If you're not, turn it off.

Speaker:

PowerShell.

Speaker:

Bluetooth.

Speaker:

Why is Bluetooth running on a server?

Speaker:

It depends.

Speaker:

Because I s- because… Yeah.

Speaker:

Oh, yeah.

Speaker:

maybe not.

Speaker:

Maybe you shouldn't.

Speaker:

'Cause I saw "Mr. Robot," and you can hack an entire, system via

Speaker:

Bluetooth from the police car.

Speaker:

Outside, yeah

Speaker:

but, w- I, also th- a s- a related idea would be a sort of a base image

Speaker:

everyone, and then scripted addition, yeah, yeah, the lowest common

Speaker:

denominator, and then scripted addition of certain software on top of that.

Speaker:

The exceptions, right?

Speaker:

we turn off, go back to RDP.

Speaker:

We turn off RDP for everybody.

Speaker:

No one needs RDP, right?

Speaker:

And then we go, we turn it on for the two people that need it.

Speaker:

And you

Speaker:

Coffee maker

Speaker:

can automate that, right?

Speaker:

What'd you say?

Speaker:

The coffee maker needs RDP

Speaker:

Yeah, the coffee maker needs RDP.

Speaker:

and we- and we touched on this a- a few times here, but one of the

Speaker:

other things is the whole idea behind hardening this, so is, w- or thing

Speaker:

that we're doing here is turning off things that don't need to be on, right?

Speaker:

Can you think of other things, you've mentioned Bluetooth on servers.

Speaker:

the… So I, I see on our list here Xbox services on workstations.

Speaker:

Is that actually a thing?

Speaker:

It is.

Speaker:

It is.

Speaker:

What?

Speaker:

especially Dell computers come with Xbox, the, the game bar and

Speaker:

other stuff, running by default.

Speaker:

only do you need to turn stuff off, you need to uninstall

Speaker:

the stuff that you turned off.

Speaker:

Because at some point, if that endpoint is compromised, bad

Speaker:

guy living off the land, right?

Speaker:

So bad guy finds out what's on this machine, it's turned off.

Speaker:

"Oh, I just need to turn it back on and I can use it." not

Speaker:

just turn it off, uninstall it

Speaker:

I remember when I was at a very large company, which everyone listening to

Speaker:

this podcast has done business with, they had… And these were Unix servers.

Speaker:

So there was this, there's this file, inetd.conf that would

Speaker:

define all of the ports that were on or off in a Unix system.

Speaker:

And their way of doing this was they had an inetd.conf that they pushed out every

Speaker:

day, to all the servers so that, What made me think about it, Mike, was, you're

Speaker:

talking about you wanna turn it off, so you'd wanna uninstall it so that if they

Speaker:

turn it on, it's not gonna work, right?

Speaker:

Their way of doing that was to push out this, this inetd.conf, every day.

Speaker:

And the way I found this out was I was installing backup software, enabling

Speaker:

backup ports, then my backups would stop working the next day, and I would go to

Speaker:

the inetd.conf and my ports would be gone.

Speaker:

And I would… It drove me batty for a couple of days until we found out that

Speaker:

they were actually pushing that out.

Speaker:

But that's the kind of thing of, having a standard, defining all of these, ports.

Speaker:

Can we think of any other types of services?

Speaker:

we talked about print services, SMB, NFS, any, anything else?

Speaker:

Anyone?

Speaker:

Anyone?

Speaker:

Bueller?

Speaker:

services that are often, turned on by default are workstation

Speaker:

and server, on a nor- on just any computer, laptop, workstation.

Speaker:

but those are… and so is, drive indexing.

Speaker:

all of those are resource hogs, m- but before you turn them off, you've

Speaker:

gotta understand what they do and how they are used in your environment.

Speaker:

but if you can, you'll free up, 5 to 8% of your resources.

Speaker:

anything web related by default could be turned off.

Speaker:

there's probably out of probably 60 or 70 services that are running by default,

Speaker:

probably 50 of those could be assessed to determine if they can be turned

Speaker:

off, at least not automatically started

Speaker:

Yeah, I know when you're putting together like a Linux image, with a lot of, with a

Speaker:

lot of the, packages that are available, they will say, "Do you want this hardened

Speaker:

or not?" And they do the opposite, where they by default turn off everything

Speaker:

except for the bare minimum that you need.

Speaker:

talk about USB locking down.

Speaker:

Prasanna, you've done a lot of work

Speaker:

I've…

Speaker:

some big companies

Speaker:

Yes, where they have disabled USB, and my gosh, is it a pain.

Speaker:

It, here, and here's why, right?

Speaker:

Here is my reasoning.

Speaker:

So I totally understand why, right?

Speaker:

You don't wanna just have a random person plug in a USB.

Speaker:

We see a whole bunch of cases.

Speaker:

I think there's a couple Apple cases going on right now where

Speaker:

people downloaded schematics onto a USB drive and then walked out to a

Speaker:

competitor, and there's a whole bunch of lawsuits pending around that, right?

Speaker:

As an end user, I have a very practical situation.

Speaker:

I might have, my W-2 or my other tax documents that are available

Speaker:

internally on the company website that I need to be able to transfer out.

Speaker:

I don't wanna send it over email, right?

Speaker:

Very rarely can you file share outside of a company to your own personal account.

Speaker:

And so you're only left with, USB.

Speaker:

And there are some companies I've worked in where they're like, "Yeah, you can't

Speaker:

plug in a USB drive because we do not allow that." Yeah, you can plug it in.

Speaker:

USB keyboards work great.

Speaker:

USB mice, totally fine.

Speaker:

USB drive, eh, sorry.

Speaker:

Oh,

Speaker:

And it was painful

Speaker:

they don't pour like, epoxy in the USB port

Speaker:

This co- this company did not.

Speaker:

school.

Speaker:

Yeah.

Speaker:

JB Weld

Speaker:

Yeah.

Speaker:

super glue

Speaker:

Yeah.

Speaker:

what, Mike, do you have any thoughts on the USB?

Speaker:

I,

Speaker:

I

Speaker:

is,

Speaker:

still, Prasanna,

Speaker:

this is gonna go back to the it depends thing, right?

Speaker:

I've been in companies where this is an absolute necessity because, we're,

Speaker:

because we're dealing with super secret stuff, and your W-2 problem

Speaker:

is the last I care about, right?

Speaker:

an analog solution for that, Prasanna.

Speaker:

Just it up on the screen and take a picture of it with your phone.

Speaker:

Yeah,

Speaker:

Not the same though, Mike

Speaker:

Yeah, I understand.

Speaker:

But-- and I've seen the USB lockdown policies, but every time

Speaker:

I see that, there's exceptions.

Speaker:

we only do that to the general population.

Speaker:

The executive team still needs to use their devices or somebody, definitely IT

Speaker:

in the build room, those types of things.

Speaker:

But with everything that you implement as a control, you've

Speaker:

also got to be able to monitor it.

Speaker:

is-- did somebody bypass our USB blocking?

Speaker:

And you're telling me that the USB port still allows me to u-use a USB

Speaker:

keyboard and a mouse, so now I just need to go buy a rubber ducky, which

Speaker:

is a USB that when you plug it in, it shows up as a USB or a mouse.

Speaker:

So there's way to circumvent controls.

Speaker:

how are you monitoring that?

Speaker:

and I can definitely see the value.

Speaker:

I've seen a lot of, environments where incidents could have been prevented

Speaker:

on the, the incoming, like someone brought something in that had a virus

Speaker:

on it, and it infected the endpoint.

Speaker:

so that… that's probably one of the key, reasons.

Speaker:

then on the intellectual property or data leakage side, you

Speaker:

don't want your data leaving.

Speaker:

And there's alternatives.

Speaker:

So you can block the USB, and that's just, that's the easy thing.

Speaker:

We're just gonna shut it off.

Speaker:

and there's, especially in today's Office 365 environment with Microsoft

Speaker:

Purview, you can implement data leakage that will tell you when someone copies

Speaker:

stuff to a, an external drive and how much and what was the file name and

Speaker:

when did it happen then who do I tell.

Speaker:

so there's alternatives to making it painful people,

Speaker:

for people to get their W-2s

Speaker:

The, and then the final thing that we talk about in terms of locking it

Speaker:

down is the BIOS or the UEFI layer.

Speaker:

We'll let Mike talk about that

Speaker:

Sure, I'll start.

Speaker:

and we've, we briefly mentioned lowest common denominator, and that, that is

Speaker:

a lot of ways how bad guys see targets.

Speaker:

they're gonna start at the simplest layer.

Speaker:

for example, whenever we red team an, a company, they attack us every

Speaker:

way you can or you can think of in order to achieve these objectives.

Speaker:

the first thing that we try to do is steal a computer that's got

Speaker:

all of the password hashes on it.

Speaker:

and if we can get into that computer, then does it… Does, is there some

Speaker:

kind of network trust with that?

Speaker:

and of the time that's been effective.

Speaker:

piggyback in a door, take the first laptop dump the passwords, and we've

Speaker:

got a local admin account in 30 minutes.

Speaker:

and then the rest of the project goes fairly quickly.

Speaker:

when you think of hardening your computer, your idea is not just to reduce the f-

Speaker:

the, the footprint of all the thing, not just from a security sh- perspective,

Speaker:

but also from a maintenance perspective.

Speaker:

If you're taking all this stuff off that you're not using and you're

Speaker:

turning off stuff you don't need, maintaining that machine is a lot easier.

Speaker:

creating less overhead across the network, so now the behavioral analysis

Speaker:

of your network and your trending and all that stuff is a lot simpler.

Speaker:

but all that's great, but if I can just walk up and touch this computer,

Speaker:

even if it's turned off, maybe I can get into the BIOS, I can reset

Speaker:

things, turn off passwords, what have you, accessing the computer that way.

Speaker:

So maybe the, the USB drives are turned off by policy in Windows, but I can boot

Speaker:

from a USB out of the BIOS, and now I can take advantage of this computer that way.

Speaker:

And then you have the UF, UEFI, or we also call that the baseboard controller.

Speaker:

so that's all the stuff that is hard-coded that tells c- the hardware how to

Speaker:

work together before the operating system, even before, back in the

Speaker:

day, DOS would run and then Windows.

Speaker:

the baseboard controller is firmware that and runs before all of that.

Speaker:

And so if I can compromise that, there, there's, there are ways of embedding

Speaker:

malware at that layer so that you come and y- log into your computer

Speaker:

like you usually do, not knowing that a lot of that fundamental hardware

Speaker:

layer, is compromised, and I'm… I've

Speaker:

and wasn't there a compromise recently, Mike, where people installed malware at

Speaker:

the UEFI layer such that it was persistent no matter what you did from trying to wipe

Speaker:

the drives and everything else like that?

Speaker:

Yeah, that was a nightmare because, you think you've, you understand the

Speaker:

compromise and you try to clean it.

Speaker:

In this case, they tried to clean it, and then they realized that it persisted.

Speaker:

They… And it was the, the persistent communication out of this device.

Speaker:

They weren't noticing anything on the device.

Speaker:

it was at the network layer they, that they determined that

Speaker:

the threat was still there.

Speaker:

So then they completely rebuilt the computer, and rebuilt meaning re-imaged

Speaker:

the drive, completely overwrote all the software, and it was still there.

Speaker:

And that's when they realized that it's not the, it's not on the drive,

Speaker:

it's in the, it's in the hardware

Speaker:

Just a final thing on the, the hardening of an endpoint.

Speaker:

Mike, you t- you talked about a, a really good, or made a really good point with

Speaker:

the stealing of the laptops, right?

Speaker:

Which are super easy to steal.

Speaker:

And I actually once… I don't know if I told you, Mike, but

Speaker:

I was in Houston once, right?

Speaker:

and on a seminar trip, and there were three of us, and we went inside to have

Speaker:

dinner, and just weren't thinking and left our laptop bags sitting in the car,

Speaker:

and then they did a smash and grab, and we lost all three laptops just like that.

Speaker:

thing with… And the real issue is if you have physical access to laptop, and

Speaker:

then again, the USB port, and, you can pretty easily boot into that, and then,

Speaker:

get access to the hard drive or the SSD, there's… What do we do to defeat that?

Speaker:

Anyone?

Speaker:

Anyone?

Speaker:

Encrypt, encrypt

Speaker:

Yeah.

Speaker:

Full disk encryption.

Speaker:

Yeah.

Speaker:

so you know, when you've got a laptop and it's closed in a bag in your car,

Speaker:

hopefully it is, it's not in standby mode or suspend, it's actually logged off.

Speaker:

Why do you always come up with these things, Mike?

Speaker:

You always come up with these things where it's of course you turn off

Speaker:

your laptop, you don't suspend it.

Speaker:

No one does that, Mike.

Speaker:

You do it, though.

Speaker:

So if you're already doing this hardening, your go- your golden image

Speaker:

setting for closing your laptop lid

Speaker:

Okay.

Speaker:

All right

Speaker:

you off and putting it in suspend.

Speaker:

Okay

Speaker:

if I took a laptop that was in that state and I'm able to boot and, there's

Speaker:

any number of tools out there that allow me to boot into a Linux environment

Speaker:

off of a USB through the BIOS.

Speaker:

And so now I'm an admin on this machine, and it, so it created

Speaker:

this little for me to run Linux.

Speaker:

If your drive is not encrypted, I can see everything.

Speaker:

can see all your Windows containers and objects and all of that stuff.

Speaker:

I can even reset your Windows password.

Speaker:

But if you're encrypted, if you're using BitLocker or something else,

Speaker:

then like Prasanna mentioned, I just see gobbledygook.

Speaker:

yeah,

Speaker:

encryption's key, but encryption only works when you're logged off

Speaker:

And this is where even for phones, right?

Speaker:

They talk about boot first use, where things are still encrypted versus

Speaker:

if you just have a lock screen where it's easy to, for law enforcement

Speaker:

to access your device as an example.

Speaker:

So Mike, let's continue to depress me.

Speaker:

so red team me a little bit, okay?

Speaker:

So I've left my laptop, suspended, not logged off.

Speaker:

So you open up my laptop and you see the login screen.

Speaker:

You're not me.

Speaker:

You don't have my password or my fingerprint.

Speaker:

What, how do you then… 'Cause I know how to get into a laptop regardless, right?

Speaker:

Booting it, and booting it off an alternate device, but how are you

Speaker:

gonna get into the laptop like that?

Speaker:

we're not gonna turn this into a how to hack 101, but

Speaker:

Okay.

Speaker:

are tools.

Speaker:

Okay

Speaker:

and at that point it just becomes a, a problem-solving, puzzle.

Speaker:

solve this puzzle.

Speaker:

it's suspended, it's not logged off.

Speaker:

Do the USB ports work?

Speaker:

Yes or no?

Speaker:

Is there Bluetooth enabled?

Speaker:

Yes or no?

Speaker:

Is wireless enabled?

Speaker:

Yes or no?

Speaker:

Does it have an ethernet jack?

Speaker:

Yes or no?

Speaker:

USB-C,

Speaker:

case, the answer is yes to all those things.

Speaker:

I'm gonna go down the list starting with the simplest thing first and working

Speaker:

Gotcha.

Speaker:

up to the most complex and

Speaker:

Okay

Speaker:

somewhere along the way I've got a, I'm a- I'm able to break a window or open a door

Speaker:

Yeah.

Speaker:

and one of the things that, that you should always understand, and hopefully

Speaker:

you hear this, you've heard this multiple times in other places, I know

Speaker:

we talk about that book, and that is physical access trumps everything, if

Speaker:

you've got physical access to a laptop or a phone or a server or whatever,

Speaker:

it, that just trumps everything.

Speaker:

At a minimum, I can wipe everything.

Speaker:

Even, even though we talk about the encryption, right?

Speaker:

At minimum, I can still wipe your hard drive, right?

Speaker:

but, anyway.

Speaker:

All right.

Speaker:

So let's ta- let's t- talk about a quick, We've been talking, once again,

Speaker:

we figured out how to talk about this way longer than I thought we were going to.

Speaker:

talk about running a port scan.

Speaker:

You wanna, Prasanna, you wanna talk about what Nmap is?

Speaker:

Yeah.

Speaker:

So it basically is a tool that you can run against a device, and it will scan and

Speaker:

try to look for whatever ports are open.

Speaker:

And this is important because, well-known services run on specific ports.

Speaker:

I think RDP is like 3359, I wanna say, and like SSH is 22, and so it's a list

Speaker:

of well-known ports for these services.

Speaker:

And so if something comes back and is like, "Hey, port 22 is open," or 3359,

Speaker:

then the attacker knows, "Oh, by the way, that means that RDP is running on that

Speaker:

machine or SSH is running on that machine.

Speaker:

Is there a way I can compromise that or connect to that to exploit it?"

Speaker:

Be even more worried if port 23 was open

Speaker:

Anyone?

Speaker:

Anyone?

Speaker:

too, so even if…

Speaker:

That's Telnet.

Speaker:

Yeah

Speaker:

Anyway

Speaker:

those, and FTP, Telnet, right?

Speaker:

and so those are services that shouldn't be running on a

Speaker:

desktop inside your environment.

Speaker:

But in the event that you do need those, making sure that when the bad

Speaker:

guy pings that and says, "Oh, that port's open. I wonder if it's RDP.

Speaker:

I wonder if it's Telnet." The next command he's gonna run is to try and

Speaker:

grab the banner of that service to see what version and type is running.

Speaker:

And so you can modify… So if you absolutely need these things running,

Speaker:

you can also absolutely change the information that's available.

Speaker:

w- and we call that en- the enumeration part of reconnaissance.

Speaker:

So I know that there's a port open, the next enumeration phase

Speaker:

is, what's running on that port?

Speaker:

And you can change what, what's provided to, to respond, that response

Speaker:

I actually didn't know that.

Speaker:

let's talk about, we talked about creating a, golden image.

Speaker:

The first thing, if we're going to create a golden image, we

Speaker:

have to first decide what's gonna be on that golden image, right?

Speaker:

So we're gonna have to get a

Speaker:

checklist,

Speaker:

RDP

Speaker:

yeah.

Speaker:

Get a checklist of the things that need to be on, the things that, you know…

Speaker:

And just as importantly, if not more importantly, the things

Speaker:

that need to be off, right?

Speaker:

and then that's how we work our way towards the, the golden image, right?

Speaker:

and I would say that a good starting point is to, we've mentioned it already,

Speaker:

but I'm just gonna reiterate it, is a good starting point is that if you can

Speaker:

come up with one image that's the least common denominator for everybody, right?

Speaker:

That's a good first step, right?

Speaker:

don't, don't let, the whole, don't let, perfect be the enemy of the good, right?

Speaker:

So start somewhere.

Speaker:

Do a single golden image.

Speaker:

Everybody's gonna run Windows XP with patch ABC, right?

Speaker:

and, Office… Wait, WordPerfect version 14, and Lotus 1-2-3.

Speaker:

that's what we're gonna run on there.

Speaker:

I'm just trying to just sound really old.

Speaker:

Anyway, yeah.

Speaker:

And so you do that, and then you can move forward from there.

Speaker:

and then finally, Mike, w- I wanna talk about just, again, the ultimate

Speaker:

endpoint is what's the endpoint that we always have with us?

Speaker:

What?

Speaker:

Your phone

Speaker:

Yeah.

Speaker:

So let's talk about, just talk about that a little bit, the, because that's

Speaker:

very, that's a very specific endpoint.

Speaker:

And for most companies, for most employees, that is a personal

Speaker:

device, but it's a personal device that is allowed, in most cases,

Speaker:

to log onto the corporate, Wi-Fi.

Speaker:

so what can we do to help secure this very not secure device that is,

Speaker:

logging into our corporate network?

Speaker:

So there's a couple things.

Speaker:

One, i-if you're not blocking USB ports, you can write a policy that says USB

Speaker:

ports work except for data transfer.

Speaker:

We won't-- We, we'll block data transfer.

Speaker:

So now we can at least charge our phone on a USB port, you're not able to transfer

Speaker:

data, which is important because bad guys are putting malware on people's

Speaker:

phones knowing that they're gonna go to work, plug it in to charge, and now

Speaker:

the mal-- That could be an entry point.

Speaker:

then most of the world is using Microsoft products, there are Microsoft products,

Speaker:

whether you're, you've got a, an on-premise domain or you're using Office

Speaker:

three sixty-five, on your licensing.

Speaker:

But, I think everything except the basic license for Microsoft

Speaker:

three sixty-five comes with Intune.

Speaker:

I it's called something else now.

Speaker:

But Intune is, has a mobile device management component that says, "All

Speaker:

right, Curtis, you can use your phone, but the moment you log in, the, the

Speaker:

day that you set up our email on your phone, you've got to agree the

Speaker:

company is gonna manage this data, this company data on your phone.

Speaker:

So when you leave, and we delete your account, it's also gonna reach into

Speaker:

your phone and delete our company data." and then there's ways of managing that

Speaker:

through Intune. So as an admin, I can go in, and I can see all the mobile

Speaker:

devices. I can also develop policy that says, "You've gotta have antivirus.

Speaker:

You've gotta have a pin code.

Speaker:

You've gotta have these things." And it'll tell me whether or not these devices are

Speaker:

compliant that list of, requirements.

Speaker:

Yeah.

Speaker:

At a minimum, make sure you're updating your device whenever patches come out

Speaker:

because the Apple, Android update process is a lot, a lot more strict than Windows.

Speaker:

Windows is gonna push out an update just because said the color scheme is off.

Speaker:

But Android and Apple are only gonna push updates out when there's critical

Speaker:

things to fix or a new feature.

Speaker:

but know too that whenever you apply one of those patches, it overwrites a

Speaker:

lot of the core firmware, the kernel.

Speaker:

And if you have malware on your phone that maybe rooted it or spyware,

Speaker:

a lot of times applying those patches will overwrite that malware

Speaker:

So it's a good thing to do is apply the patches.

Speaker:

thing to do.

Speaker:

do

Speaker:

All right, and with that, I wanna thank Prasanna once again

Speaker:

Thank you, Curtis.

Speaker:

I am your rock and your anchor.

Speaker:

it's funny, when I heard rock and anchor, I'm like, "Those are two

Speaker:

things that can really weigh you down."

Speaker:

and I am your paper.

Speaker:

I

Speaker:

and thanks again.

Speaker:

then

Speaker:

Thanks again, Mike.

Speaker:

Yeah, the scissors of this podcast.

Speaker:

And thanks again to our listeners.

Speaker:

you are why we do this.

Speaker:

That is a wrap.

Speaker:

The Backup Wrap Up is written, recorded, and produced by me, W. Curtis Preston.

Speaker:

If you need backup or DR consulting, content generation, or expert witness

Speaker:

work, check out backupcentral.com.

Speaker:

You can also find links for my O'Reilly books on the same website.

Speaker:

Remember, this is an independent podcast, and any opinions that

Speaker:

you hear are those of the speaker and not necessarily an employer.

Speaker:

Thanks for listening