Securing and Checking Windows system’s security

Ensuring the security of Windows systems is equally important to protect them from threats and vulnerabilities. Regularly checking your system’s security can help identify potential risks and maintain a strong defense. Below are ten essential commands and tools that can assist you in auditing and securing your Windows system:

  1. Checking Open Ports:
   netstat -an
  • Description: Displays all active connections and listening ports.
  1. Checking Listening Services:
   netstat -ab
  • Description: Shows active listening ports along with the associated executables.
  1. Checking Firewall Status:
   netsh advfirewall show allprofiles
  • Description: Displays the status of the Windows Firewall for all profiles.
  1. Auditing System Security:
   secedit /analyze /db C:\Windows\security\local.sdb /log C:\Windows\security\logs\secanalysis.log
  • Description: Analyzes system security and generates a log file with the results.
  1. Listing User Accounts:
   net user
  • Description: Displays all user accounts on the system.
  1. Checking for Administrative Accounts:
   net localgroup administrators
  • Description: Lists all users in the local administrators group.
  1. Verifying Installed Updates:
   wmic qfe list
  • Description: Displays all installed updates on the system.
  1. Checking System Integrity:
   sfc /scannow
  • Description: Scans and repairs system files.
  1. Reviewing Event Logs:
   wevtutil qe Security "/q:*[System[(EventID=4625)]]" /f:text /rd:true /c:10
  • Description: Queries the Security event log for the last 10 failed login attempts.
  1. Checking for Malicious Software: cmd mrt
  2. Description: Launches the Microsoft Malicious Software Removal Tool to scan for and remove malicious software.

These commands and tools provide valuable insights into the security status of your Windows system, helping to identify potential vulnerabilities and unauthorized activities.

  1. Checking System Configuration:
msconfig
  1. Reviewing Security Policies: secpol.msc
  2. Checking Group Policy Settings: gpedit.msc
    • Description: Opens the Group Policy Editor, useful for managing user and computer configuration policies.
  3. Listing Scheduled Tasks: schtasks /query /fo LIST /v
    • Description: Lists all scheduled tasks with detailed information.
  4. Monitoring System Performance: perfmon
    • Description: Opens the Performance Monitor, which can be used to track system performance and detect unusual activity.
  5. Checking for Installed Software: wmic product get name,version
    • Description: Lists all installed software and their versions.
  6. Verifying Driver Integrity: sigverif
    • Description: Opens the File Signature Verification tool to verify the integrity of drivers and system files.
  7. Checking Disk Integrity: chkdsk C: /f
    • Description: Checks the file system and file system metadata of the specified volume for logical and physical errors.
  8. Network Diagnostics: ipconfig /all
    • Description: Displays detailed information about network configuration, useful for troubleshooting network issues.
  9. Checking System Information: systeminfo
    • Description: Displays detailed configuration information about the computer and its operating system.
  10. Checking User Login History: Get-EventLog -LogName Security -InstanceId 4624 | Select-Object -First 10
    • Description: Lists the last 10 successful login events from the Security log.
  11. Auditing File Access: auditpol /get /category:*
    • Description: Displays the current audit policy settings.
  12. Identifying Services Running as SYSTEM: Get-WmiObject win32_service | Where-Object { $_.StartName -eq 'LocalSystem' }
    • Description: Lists all services running under the LocalSystem account.
  13. Checking for System Vulnerabilities: Install-Module -Name SpeculationControl Get-SpeculationControlSettings
    • Description: Checks for vulnerabilities related to speculative execution, such as Meltdown and Spectre.
  14. Scanning for Open Shares: Get-WmiObject -Query "SELECT * FROM Win32_Share" | Format-Table Name,Path,Description
    • Description: Lists all shared resources on the system.
  15. Verifying System Uptime: net statistics workstation
    • Description: Displays statistics about the workstation, including system uptime.
  16. Checking DNS Cache: ipconfig /displaydns
    • Description: Displays the contents of the DNS resolver cache.
  17. Verifying Remote Desktop Configuration: Get-WmiObject -Class Win32_TerminalServiceSetting -Namespace root\CIMV2\TerminalServices | Select-Object -Property AllowTSConnections
    • Description: Checks if Remote Desktop is enabled.
  18. Listing Active Network Connections: netstat -anob
    • Description: Lists active network connections along with the associated processes.
  19. Checking Windows Defender Status:
    powershell Get-MpComputerStatus
    • Description: Displays the status of Windows Defender, including antivirus definitions and real-time protection status.
  20. Description: Opens the System Configuration utility, where you can manage startup programs, services, and boot settings.
  21. Description: Opens the Local Security Policy editor, allowing you to review and manage security policies.

These commands and tools provide a comprehensive set of utilities for monitoring, auditing, and securing your Windows system.

368

One thought on “Securing and Checking Windows system’s security”

Leave a Reply