Endpoint hardening means closing the windows before a bad guy jiggles the handle: golden images, USB lockdown, BIOS/UEFI, and full disk encryption.
Your receptionist's computer is running a web server. Your new Dell shipped with Xbox Game Bar turned on. Neither one helps anybody do their job, and both of them are doors somebody can walk through.
In this episode, Prasanna Malaiyandi, Dr. Mike Saylor and I go through endpoint hardening the way an admin actually has to do it — not the vendor slide version.
Mike starts with the analogy he uses in our book. Attackers casing your organization are doing what a burglar does walking down your street: checking every door, every window, every garage. An unpatched box announcing its version number to the internet is a broken window with a sign hanging on it.
Then we get into the work itself. Secure builds and golden images, and why one image for everybody beats a perfect image you never finish. Which services to shut off, and Mike's point that shutting them off isn't enough — an attacker living off the land will just switch them back on, so uninstall the thing.
We have the USB argument too. Prasanna makes the end-user case, having lived under a full lockdown. Mike makes the red team case and brings up the rubber ducky that shows up as a keyboard. We land somewhere reasonable, with data leakage monitoring instead of a blanket block.
Mike also walks through BIOS and UEFI attacks, including the compromise where a company reimaged the drive, overwrote everything, and the malware was still calling home. That's the part that should worry you.
And then the one that catches good admins: full disk encryption does nothing for you when the laptop is suspended instead of logged off. Mike explains what he does with a laptop in that state.
We wrap with port scanning, banner grabbing, the hardening checklist, and the endpoint everybody forgets — the phone in your pocket that joins your corporate Wi-Fi every morning.
If somebody told you to harden your endpoints and never handed you the list, start here.
CHAPTERS
00:00 Your receptionist's computer is running a web server
01:39 Welcome, with Prasanna and Dr. Mike Saylor
03:52 The house analogy: broken windows and unlocked doors
05:23 The Tesla that keeps leaving the garage open
06:22 Do you just have to be safer than your neighbor?
08:49 Assume breach, and close the windows anyway
09:52 Secure builds and golden images
12:47 Write down why you built the image that way
13:37 One image for everyone, or one per role?
14:39 Level one hardening: turning off what nobody uses
16:20 Xbox Game Bar, and why disabling isn't enough
17:09 The inetd.conf story that drove me batty
19:07 The USB lockdown fight
20:38 Rubber duckies and monitoring your own controls
22:46 BIOS, UEFI, and malware that survives a reimage
26:35 Full disk encryption only works if you log off
28:34 Red teaming a suspended laptop
29:42 Physical access trumps everything
30:07 Port scans, Nmap, and banner grabbing
31:50 Building your hardening checklist
33:14 The endpoint in your pocket: phones and Intune
35:20 Patching your phone can overwrite the malware on it
36:39 That's a wrap
LINKS
Read the blog post: https://www.backupcentral.com
See what Mike and I are building: https://www.stopransomware.com
Get the book from O'Reilly: https://www.oreilly.com/library/view/learning-ransomware-response/9781098169572/
Get the book from Amazon: https://www.amazon.com/Learning-Ransomware-Response-Recovery-Stopping/dp/1098169581