Endpoint hardening is the unglamorous work of closing the windows and locking the doors before somebody comes along and jiggles the handle. Prasanna, Dr. Mike Saylor and I walk through what that actually looks like: secure builds and golden images, which services to shut off, which ones to uninstall so a bad guy can't just switch them back on, USB lockdown, full disk encryption, BIOS and UEFI, and the phone in your pocket that logs onto your corporate Wi-Fi every morning.
Mike opens with the analogy he uses in the book. Bad guys casing your organization are doing what a burglar does walking down your street — checking every door, every window, every garage. An unpatched box screaming its version number to the internet is a broken window with a sign on it.
Then we get practical. Your receptionist's computer is running a web server she will never use. Your new Dell shipped with Xbox Game Bar running by default. Mike's point is that turning those off isn't enough, because an attacker living off the land will just turn them back on. Uninstall the thing.
We also get into the argument nobody wins: locking down USB ports. Prasanna makes the end-user case, Mike makes the red team case, and we land on data leakage controls as the middle ground. Then Mike explains how he gets into a laptop that's suspended instead of logged off, and why your encrypted drive doesn't help you in that state.
If you've been told you should harden your endpoints and nobody ever handed you the list, this one's for you. Start with one image, the lowest common denominator, and build from there. Don't let perfect be the enemy of good.
CHAPTERS
00:00 Your receptionist's computer is running a web server
01:39 Welcome, with Prasanna and Dr. Mike Saylor
03:52 The house analogy: broken windows and unlocked doors
06:22 Do you just have to be safer than your neighbor?
08:49 Assume breach, and close the windows anyway
09:52 Secure builds and golden images
13:37 One image for everyone, or one per role?
14:39 Level one hardening: turning off what nobody uses
16:20 Xbox Game Bar, and why disabling isn't enough
19:07 The USB lockdown fight
22:46 BIOS, UEFI, and malware that survives a reimage
26:35 Full disk encryption only works if you log off
29:42 Physical access trumps everything
30:07 Port scans, Nmap, and banner grabbing
31:50 Building your hardening checklist
33:14 The endpoint in your pocket