Check out our companion blog!

Endpoint Hardening

Endpoint hardening means closing the windows before a bad guy jiggles the handle: golden images, USB lockdown, BIOS/UEFI, and full disk encryption.

Your receptionist's computer is running a web server. Your new Dell shipped with Xbox Game Bar turned on. Neither one helps anybody do their job, and both of them are doors somebody can walk through.

In this episode, Prasanna Malaiyandi, Dr. Mike Saylor and I go through endpoint hardening the way an admin actually has to do it — not the vendor slide version.

Mike starts with the analogy he uses in our book. Attackers casing your organization are doing what a burglar does walking down your street: checking every door, every window, every garage. An unpatched box announcing its version number to the internet is a broken window with a sign hanging on it.

Then we get into the work itself. Secure builds and golden images, and why one image for everybody beats a perfect image you never finish. Which services to shut off, and Mike's point that shutting them off isn't enough — an attacker living off the land will just switch them back on, so uninstall the thing.

We have the USB argument too. Prasanna makes the end-user case, having lived under a full lockdown. Mike makes the red team case and brings up the rubber ducky that shows up as a keyboard. We land somewhere reasonable, with data leakage monitoring instead of a blanket block.

Mike also walks through BIOS and UEFI attacks, including the compromise where a company reimaged the drive, overwrote everything, and the malware was still calling home. That's the part that should worry you.

And then the one that catches good admins: full disk encryption does nothing for you when the laptop is suspended instead of logged off. Mike explains what he does with a laptop in that state.

We wrap with port scanning, banner grabbing, the hardening checklist, and the endpoint everybody forgets — the phone in your pocket that joins your corporate Wi-Fi every morning.

If somebody told you to harden your endpoints and never handed you the list, start here.

CHAPTERS

00:00 Your receptionist's computer is running a web server

01:39 Welcome, with Prasanna and Dr. Mike Saylor

03:52 The house analogy: broken windows and unlocked doors

05:23 The Tesla that keeps leaving the garage open

06:22 Do you just have to be safer than your neighbor?

08:49 Assume breach, and close the windows anyway

09:52 Secure builds and golden images

12:47 Write down why you built the image that way

13:37 One image for everyone, or one per role?

14:39 Level one hardening: turning off what nobody uses

16:20 Xbox Game Bar, and why disabling isn't enough

17:09 The inetd.conf story that drove me batty

19:07 The USB lockdown fight

20:38 Rubber duckies and monitoring your own controls

22:46 BIOS, UEFI, and malware that survives a reimage

26:35 Full disk encryption only works if you log off

28:34 Red teaming a suspended laptop

29:42 Physical access trumps everything

30:07 Port scans, Nmap, and banner grabbing

31:50 Building your hardening checklist

33:14 The endpoint in your pocket: phones and Intune

35:20 Patching your phone can overwrite the malware on it

36:39 That's a wrap

LINKS

Read the blog post: https://www.backupcentral.com

See what Mike and I are building: https://www.stopransomware.com

Get the book from O'Reilly: https://www.oreilly.com/library/view/learning-ransomware-response/9781098169572/

Get the book from Amazon: https://www.amazon.com/Learning-Ransomware-Response-Recovery-Stopping/dp/1098169581