Skip to content

Instantly share code, notes, and snippets.

View lcpdn's full-sized avatar

lcpdn lcpdn

View GitHub Profile
@lcpdn
lcpdn / windows_hardening.cmd
Created May 10, 2020 08:47 — forked from mackwage/windows_hardening.cmd
Script to perform some hardening of Windows OS
:: Windows 10 Hardening Script
:: This is based mostly on my own personal research and testing. My objective is to secure/harden Windows 10 as much as possible while not impacting usability at all. (Think being able to run on this computer's of family members so secure them but not increase the chances of them having to call you to troubleshoot something related to it later on). References for virtually all settings can be found at the bottom. Just before the references section, you will always find several security settings commented out as they could lead to compatibility issues in common consumer setups but they're worth considering.
:: Thank you @jaredhaight for the Win Firewall config recommendations!
:: Thank you @ricardojba for the DLL Safe Order Search reg key!
:: Best script I've found for Debloating Windows 10: https://github.com/Sycnex/Windows10Debloater
::
::#######################################################################
::
:: Change file associations to protect against common ransomware
### Keybase proof
I hereby claim:
* I am lcpdn on github.
* I am lcpdn (https://keybase.io/lcpdn) on keybase.
* I have a public key ASCS8LSNDLg-VtXOMd0ydmMYzxztU_z3KB1oLjKE1mSqCwo
To claim this, I am signing this object:
# coding=utf-8
"""
LICENSE http://www.apache.org/licenses/LICENSE-2.0
"""
import datetime
import sys
import time
import threading
import traceback
import SocketServer
{"parsed":{"extensions": {"authority_info_access": {"issuer_urls": ["http://gv.symcb.com/gv.crt"], "ocsp_urls": ["http://gv.symcd.com"]}, "a
uthority_key_id": "c39cf3fcd3460834bbce467fa07c5bf3e208cb59", "basic_constraints": {"is_ca": false}, "certificate_policies": ["2.23.140.1.2.
1"], "crl_distribution_points": ["http://gv.symcb.com/gv.crl"], "extended_key_usage": [1, 2], "key_usage": {"digital_signature": true, "key_
encipherment": true, "value": 5}, "subject_alt_name": {"dns_names": ["*.wickrtech.co", "wickrtech.co"]}}, "fingerprint_md5": "4100fe4676c68e
cfb31530346df2c05a", "fingerprint_sha1": "251701185d1770c40f9023f20970a6b687dd1641", "fingerprint_sha256": "00000162526c53e967bb2b3cf70a602d
ab6f2ca3ca1eb1e424e860b55fb6976d", "issuer": {"common_name": ["RapidSSL SHA256 CA - G3"], "country": ["US"], "organization": ["GeoTrust Inc.
"]}, "issuer_dn": "C=US, O=GeoTrust Inc., CN=RapidSSL SHA256 CA - G3", "serial_number": "524860", "signature": {"self_signed": false, "signa
ture_algorithm": {"name": "SHA256With
ct.googleapis.com/pilot 0
AAAAAAE9pe0GcwAAAATWMIIE0jCCA7qgAwIBAgIDAPY6MA0GCSqGSIb3DQEBBQUAMEAxCzAJBgNVBAYTAlVTMRcwFQYDVQQKEw5HZW9UcnVzdCwgSW5jLjEYMBYGA1UEAxMPR2VvVHJ1c3QgU1NMIENBMB4XDTExMTAyMTExMDUwNloXDTEzMTEyMjA0MzI0N1owgc4xKTAnBgNVBAUTIFRqbGZoUTB0cXp3WmtNa0svNXFNdGZqbjJ6aWRVNzRoMQswCQYDVQQGEwJVUzEXMBUGA1UECBMOU291dGggQ2Fyb2xpbmExEzARBgNVBAcTCkNoYXJsZXN0b24xFzAVBgNVBAoTDkJsYWNrYmF1ZCBJbmMuMRAwDgYDVQQLEwdIb3N0aW5nMTswOQYDVQQDEzJ3d3cuc3RydWxlYXJ0c2NlbnRyZS5wdXJjaGFzZS10aWNrZXRzLW9ubGluZS5jby51azCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAJtkbcF8x3TtIARHC8BDRtoIAdh9HO9fo+5UUDtoc8f4xq7Rb2xbWOiEX29JqZOdsuucYTuYbbDf0uBYcJpkwhEg4Vg5skyfp0jAd6pXm1euQ+RiRShzEQYKJ8y4/IjZHttA/8HSzEKWJnuidsYrl/twFhlX5WIZq3BUVQ9GVqGe9n1r2eIFTs6FxYUpaVzTkc6OLh1qSz+cnDDPigLUoUOK/KqN7ybmJxSefJw9WpFW/pIn6M0gFAbu0egFgDybQ3JwUAEh8ddzpKRCqGq1mdZAKpKFHcqmi5nG5aFD4p1NFmPjDVQXohXLQvwtmwwKS2Zo+tnulPnEe9jjET/f+MUCAwEAAaOCAUQwggFAMB8GA1UdIwQYMBaAFEJ5VBthzVUrPmPVPEhX9Z/7Rc5KMA4GA1UdDwEB/wQEAwIEsDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwPQYDVR0RBDYwN
[800]
type=friend
secret=1234
username=800
fromuser=800
host=dynamic
canreinvite=yesdtmfmode=rfc2833
context=from-sip
[801]