An independent, read-only evaluation of endpoint WORKSTATION-07 against 53 security controls aligned to the CIS Microsoft Windows Benchmarks, with a prioritized plan for remediation.
WORKSTATION-07 scored 75 out of 100 — “Fair” (C) on Apotrope's A–F scale. 6 findings are open for remediation across 4 areas.
On 13 July 2026, Apotrope attempted 53 security controls on WORKSTATION-07 (10.0.26200) against thresholds aligned to the CIS Microsoft Windows Benchmark v5.0.0. The assessment ran in read-only mode with administrator privileges and made no changes to the system. The device scored 75/100 (C — Fair).
Of the checks performed, 3 checks failed and 3 checks issued warnings. Of these, 1 is high priority: Password Policy — Minimum Length. The primary areas of concern are Accounts, Hardening and Encryption.
34 of 53 controls passed. Categories including Firewall, Patching, Remote Access passed all of their checks.
13 informational items were recorded for context; they do not affect the score.
13 informational items (system inventory and context) are recorded for reference and do not affect the score.
Minimum password length: 0 characters.
Weak account and password settings make it easier for an attacker to guess or reuse credentials and take control of this machine.
Require a minimum password length of 14 characters.
Password complexity requirement: disabled.
Weak account and password settings make it easier for an attacker to guess or reuse credentials and take control of this machine.
Enable the password complexity requirement so passwords must mix character types.
Drive: G: | Type: 1 | Status: Unknown | Encrypted: 0% | Protection: Off
If this device is lost or stolen, data on an unencrypted or unprotected drive can be read by anyone with physical access.
Encrypt drive G: with BitLocker using the TPM protector.
The following subcategories have auditing disabled: Sensitive Privilege Use. Security-relevant events may not be recorded.
Convenience features left enabled give attackers well-known shortcuts to run code or gather information on this machine.
Enable audit logging for the key subcategories that currently have auditing disabled so security-relevant events are recorded. This can also be configured via Group Policy (secpol.msc → Advanced Audit Policy Configuration).
AutoPlay is partially disabled (NoDriveTypeAutoRun = 158). Some drive types may still trigger AutoPlay.
Convenience features left enabled give attackers well-known shortcuts to run code or gather information on this machine.
Disable AutoPlay for all drive types so the remaining drive types can no longer auto-execute content.
2 adapter(s) inherit NetBIOS setting from DHCP. If the DHCP server does not explicitly disable NetBIOS, it may be active.
Insecure network protocols allow attackers on the local network to intercept traffic or impersonate services this machine trusts.
Explicitly disable NetBIOS on all adapters rather than relying on DHCP.
The following controls were evaluated and passed. This record can serve as evidence of the endpoint's compliant configuration at the time of assessment.
| Control | Result | Detail | Benchmark |
|---|---|---|---|
| Access Control | |||
| UAC Admin Consent Behavior | Pass | ConsentPromptBehaviorAdmin = 5: Prompt for consent for non-Windows binaries (Windows default). | CIS 2.3.17.2 |
| UAC Enabled | Pass | UAC (EnableLUA) is enabled. | CIS 2.3.17.6 |
| UAC Secure Desktop | Pass | UAC prompts are displayed on the secure desktop (isolated from user input). | CIS 2.3.17.7 |
| Accounts | |||
| Built-in Administrator Account | Pass | Built-in Administrator account is disabled. | CIS 2.3.1.3 |
| Guest Account | Pass | Built-in Guest account is disabled. | CIS 2.3.1.1 |
| Local Administrators | Pass | 2 administrator(s): Administrator, jsmith | — |
| Password Policy — Account Lockout | Pass | Lockout threshold: 10 attempt(s) | Duration: 30 minute(s). | CIS 1.2.1 |
| Antivirus | |||
| Defender Real-Time Protection | Pass | RealTimeProtectionEnabled: True | AMServiceEnabled: True | AntivirusEnabled: True | CIS 18.10.42.10.3 |
| Defender Signature Age | Pass | Antivirus signature age: 0 day(s). | CIS 18.10.42.14 |
| Defender Tamper Protection | Pass | IsTamperProtected: True | — |
| Encryption | |||
| BitLocker — C: | Pass | Drive: C: | Type: Unknown | Status: 1 | Method: 6 | Encrypted: 100% | Protection: On | CIS 18.10.10 |
| File Sharing | |||
| SMB Signing Required | Pass | SMB signing is required on this server. | CIS 2.3.9.2 |
| SMBv1 Disabled | Pass | SMBv1 protocol is disabled. | CIS 18.4.2 |
| Firewall | |||
| Firewall — Domain Default Inbound Action | Pass | Profile: Domain | DefaultInboundAction: NotConfigured | DefaultOutboundAction: NotConfigured | CIS 9.1.2 |
| Firewall — Domain Profile Enabled | Pass | Profile: Domain | Enabled: True | CIS 9.1.1 |
| Firewall — Private Default Inbound Action | Pass | Profile: Private | DefaultInboundAction: NotConfigured | DefaultOutboundAction: NotConfigured | CIS 9.2.2 |
| Firewall — Private Profile Enabled | Pass | Profile: Private | Enabled: True | CIS 9.2.1 |
| Firewall — Public Default Inbound Action | Pass | Profile: Public | DefaultInboundAction: NotConfigured | DefaultOutboundAction: NotConfigured | CIS 9.3.2 |
| Firewall — Public Profile Enabled | Pass | Profile: Public | Enabled: True | CIS 9.3.1 |
| Hardening | |||
| Screen Lock Timeout | Pass | Screen lock timeout: 10 minute(s). | — |
| WinRM Status | Pass | WinRM service is not running. | CIS 18.10.90.2.2 |
| Network | |||
| LLMNR Disabled | Pass | LLMNR is disabled via Group Policy. | CIS 18.6.4.4 |
| Patching | |||
| Last Windows Update | Pass | Last update installed 0 day(s) ago (2026-07-16). | CIS 18.10.94.2.1 |
| Pending Windows Updates | Pass | No pending Windows Updates were found; the system is up to date. | CIS 18.10.94.2.1 |
| Windows Update Service | Pass | Windows Update service start type is Automatic (current state: Stopped); it starts on demand when updates are needed. | CIS 18.10.94.2.1 |
| PowerShell | |||
| PowerShell Module Logging | Pass | Module Logging is enabled — module pipeline execution events are logged. | — |
| PowerShell Script Block Logging | Pass | Script Block Logging is enabled — PowerShell commands are logged to the event log. | CIS 18.10.88.1 |
| Remote Access | |||
| RDP Enabled | Pass | Remote Desktop is disabled (fDenyTSConnections = 1). | CIS 18.10.57.3.2.1 |
| Services | |||
| Risky Services | Pass | No known-risky services are running. | — |
| Unquoted Service Paths | Pass | No services with unquoted paths containing spaces found. | — |
| System | |||
| OS End-of-Support Status | Pass | Windows 11 25H2 is supported until 2027-10-12 (452 days remaining). | — |
| Secure Boot | Pass | Secure Boot is enabled. | CIS 18.10.10.2.2 |
| System Uptime | Pass | System uptime is 7 day(s). | — |
| TPM Status | Pass | TPM present. Ready: True. Firmware version: 7.2.2.0. | — |
net accounts /minpwlen:14
# Enable the password-complexity policy via secedit (no reboot needed).$inf = "$env:TEMP\pwcomplexity.inf"@'[Unicode]Unicode=yes[Version]signature="$CHICAGO$"[System Access]PasswordComplexity = 1'@ | Set-Content -Path $inf -Encoding Unicodesecedit /configure /db "$env:TEMP\pwcomplexity.sdb" /cfg $inf /areas SECURITYPOLICY
# BitLocker requires Windows Pro/Enterprise/Education (absent on Home).if (Get-Command Enable-BitLocker -ErrorAction SilentlyContinue) {Enable-BitLocker -MountPoint 'G:' -EncryptionMethod XtsAes256 -UsedSpaceOnly -RecoveryPasswordProtector -SkipHardwareTestif ('G:' -eq $env:SystemDrive) { Add-BitLockerKeyProtector -MountPoint 'G:' -TpmProtector } else { Enable-BitLockerAutoUnlock -MountPoint 'G:' }} else {Write-Warning 'BitLocker is unavailable on this Windows edition.'}
auditpol /set /subcategory:'Logon' /success:enable /failure:enable
Set-ItemProperty -Path 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer' -Name NoDriveTypeAutoRun -Value 255 -Type DWord -Force
Get-CimInstance Win32_NetworkAdapterConfiguration -Filter 'IPEnabled=True' | ForEach-Object { Invoke-CimMethod -InputObject $_ -MethodName SetTcpipNetbios -Arguments @{ TcpipNetbiosOptions = 2 } | Out-Null }
About this assessment — Apotrope performs a read-only, non-invasive scan of Windows security configuration, scoring against thresholds aligned to the CIS Microsoft Windows Benchmark v5.0.0. No changes are made to the system during assessment. Scores start at 100 and deduct weighted points per finding: failed controls deduct 15, 10, 5, or 2 points for critical, high, medium, or low severity respectively; warnings deduct 7, 5, 2, or 1. Informational items and checks that could not be evaluated do not affect the score. The scan completed in 21.7 seconds. When printing, disable the browser's own header and footer — this document supplies its own.