Registry Security Configuration Ensure that all administrators take the time to thoroughly understand how the registry functions and the purpose of each of its various keys. Many of the vulnerabilities in the Windows operating system can be fixed by changing specific keys, as detailed below. Configure registry permissions. Protect the registry from anonymous access. Disallow remote registry access if not required. Set MaxCachedSockets (REG_DWORD) to 0. Set SmbDeviceEnabled (REG_DWORD) to 0. Set AutoShareServer to 0. Set AutoShareWks to 0. Delete all value data INSIDE the NullSessionPipes key. Delete all value data INSIDE the NullSessionShares key. 6
Windows Server Hardening Checklist Page 5 Page 7