Apotrope
Apotrope
Windows Security Tooling
Confidential
Endpoint Security Assessment

Security Posture Assessment

An independent, read-only evaluation of endpoint WORKSTATION-07 against 53 security controls aligned to the CIS Microsoft Windows Benchmarks, with a prioritized plan for remediation.

Host
WORKSTATION-07
Operating system
10.0.26200
Assessment date
13 July 2026
Controls evaluated
53 across 14 areas
Assessment mode
Read-only · non-invasive
Privileges
Administrator
Tool
Apotrope v0.1.12
Scan duration
21.7 seconds
C
75/100
Fair
1 high-priority finding should be addressed this week; 5 further items can be scheduled into routine maintenance.
1

Executive summary

Plain language

WORKSTATION-07 scored 75 out of 100 — “Fair” (C) on Apotrope's A–F scale. 6 findings are open for remediation across 4 areas.

On 13 July 2026, Apotrope attempted 53 security controls on WORKSTATION-07 (10.0.26200) against thresholds aligned to the CIS Microsoft Windows Benchmark v5.0.0. The assessment ran in read-only mode with administrator privileges and made no changes to the system. The device scored 75/100 (C — Fair).

Of the checks performed, 3 checks failed and 3 checks issued warnings. Of these, 1 is high priority: Password Policy — Minimum Length. The primary areas of concern are Accounts, Hardening and Encryption.

34 of 53 controls passed. Categories including Firewall, Patching, Remote Access passed all of their checks.

13 informational items were recorded for context; they do not affect the score.

Bottom line
Address the 1 Priority 1 item within the week; schedule the remaining 5 items into the next maintenance cycle.
2

Posture at a glance

Overall score
75/100
Grade C — Fair
Controls passed
34/53
64% compliant
Open findings
6
3 failed · 3 warnings
High-severity
1
Priority-1 item
Passed 34 (64%) Failed 3 (6%) Warnings 3 (6%) Informational 13 (25%)

13 informational items (system inventory and context) are recorded for reference and do not affect the score.

3

Prioritized remediation roadmap

6 actions
P1ImmediateThis week
AccountsPassword Policy — Minimum Length
Require a minimum password length of 14 characters.
HIGHCIS 1.1.4
P2Near-termThis maintenance cycle
AccountsPassword Policy — Complexity
Enable the password complexity requirement so passwords must mix character types.
MEDIUMCIS 1.1.5
EncryptionBitLocker — G:
Encrypt drive G: with BitLocker using the TPM protector.
MEDIUMCIS 18.10.10
HardeningAudit Policy
Enable audit logging for the key subcategories that currently have auditing disabled so security-relevant events are recorded. This can also be configured via Group Policy (secpol.msc → Advanced Audit Policy Configuration).
MEDIUMCIS 17.1.1
HardeningAutoPlay Disabled
Disable AutoPlay for all drive types so the remaining drive types can no longer auto-execute content.
MEDIUMCIS 18.10.8.3
P3Review & hygieneNext review
NetworkNetBIOS over TCP/IP
Explicitly disable NetBIOS on all adapters rather than relying on DHCP.
LOW
4

Detailed findings

Open items only
Failed HIGH Accounts CIS 1.1.4 Password Policy — Minimum Length
Finding

Minimum password length: 0 characters.

Business impact

Weak account and password settings make it easier for an attacker to guess or reuse credentials and take control of this machine.

Recommended action

Require a minimum password length of 14 characters.

Failed MEDIUM Accounts CIS 1.1.5 Password Policy — Complexity
Finding

Password complexity requirement: disabled.

Business impact

Weak account and password settings make it easier for an attacker to guess or reuse credentials and take control of this machine.

Recommended action

Enable the password complexity requirement so passwords must mix character types.

Failed MEDIUM Encryption CIS 18.10.10 BitLocker — G:
Finding

Drive: G: | Type: 1 | Status: Unknown | Encrypted: 0% | Protection: Off

Business impact

If this device is lost or stolen, data on an unencrypted or unprotected drive can be read by anyone with physical access.

Recommended action

Encrypt drive G: with BitLocker using the TPM protector.

Warning MEDIUM Hardening CIS 17.1.1 Audit Policy
Finding

The following subcategories have auditing disabled: Sensitive Privilege Use. Security-relevant events may not be recorded.

Business impact

Convenience features left enabled give attackers well-known shortcuts to run code or gather information on this machine.

Recommended action

Enable audit logging for the key subcategories that currently have auditing disabled so security-relevant events are recorded. This can also be configured via Group Policy (secpol.msc → Advanced Audit Policy Configuration).

Warning MEDIUM Hardening CIS 18.10.8.3 AutoPlay Disabled
Finding

AutoPlay is partially disabled (NoDriveTypeAutoRun = 158). Some drive types may still trigger AutoPlay.

Business impact

Convenience features left enabled give attackers well-known shortcuts to run code or gather information on this machine.

Recommended action

Disable AutoPlay for all drive types so the remaining drive types can no longer auto-execute content.

Warning LOW Network NetBIOS over TCP/IP
Finding

2 adapter(s) inherit NetBIOS setting from DHCP. If the DHCP server does not explicitly disable NetBIOS, it may be active.

Business impact

Insecure network protocols allow attackers on the local network to intercept traffic or impersonate services this machine trusts.

Recommended action

Explicitly disable NetBIOS on all adapters rather than relying on DHCP.

A

Attestation — controls passed

34 controls

The following controls were evaluated and passed. This record can serve as evidence of the endpoint's compliant configuration at the time of assessment.

ControlResultDetailBenchmark
Access Control
UAC Admin Consent BehaviorPassConsentPromptBehaviorAdmin = 5: Prompt for consent for non-Windows binaries (Windows default).CIS 2.3.17.2
UAC EnabledPassUAC (EnableLUA) is enabled.CIS 2.3.17.6
UAC Secure DesktopPassUAC prompts are displayed on the secure desktop (isolated from user input).CIS 2.3.17.7
Accounts
Built-in Administrator AccountPassBuilt-in Administrator account is disabled.CIS 2.3.1.3
Guest AccountPassBuilt-in Guest account is disabled.CIS 2.3.1.1
Local AdministratorsPass2 administrator(s): Administrator, jsmith
Password Policy — Account LockoutPassLockout threshold: 10 attempt(s) | Duration: 30 minute(s).CIS 1.2.1
Antivirus
Defender Real-Time ProtectionPassRealTimeProtectionEnabled: True | AMServiceEnabled: True | AntivirusEnabled: TrueCIS 18.10.42.10.3
Defender Signature AgePassAntivirus signature age: 0 day(s).CIS 18.10.42.14
Defender Tamper ProtectionPassIsTamperProtected: True
Encryption
BitLocker — C:PassDrive: C: | Type: Unknown | Status: 1 | Method: 6 | Encrypted: 100% | Protection: OnCIS 18.10.10
File Sharing
SMB Signing RequiredPassSMB signing is required on this server.CIS 2.3.9.2
SMBv1 DisabledPassSMBv1 protocol is disabled.CIS 18.4.2
Firewall
Firewall — Domain Default Inbound ActionPassProfile: Domain | DefaultInboundAction: NotConfigured | DefaultOutboundAction: NotConfiguredCIS 9.1.2
Firewall — Domain Profile EnabledPassProfile: Domain | Enabled: TrueCIS 9.1.1
Firewall — Private Default Inbound ActionPassProfile: Private | DefaultInboundAction: NotConfigured | DefaultOutboundAction: NotConfiguredCIS 9.2.2
Firewall — Private Profile EnabledPassProfile: Private | Enabled: TrueCIS 9.2.1
Firewall — Public Default Inbound ActionPassProfile: Public | DefaultInboundAction: NotConfigured | DefaultOutboundAction: NotConfiguredCIS 9.3.2
Firewall — Public Profile EnabledPassProfile: Public | Enabled: TrueCIS 9.3.1
Hardening
Screen Lock TimeoutPassScreen lock timeout: 10 minute(s).
WinRM StatusPassWinRM service is not running.CIS 18.10.90.2.2
Network
LLMNR DisabledPassLLMNR is disabled via Group Policy.CIS 18.6.4.4
Patching
Last Windows UpdatePassLast update installed 0 day(s) ago (2026-07-16).CIS 18.10.94.2.1
Pending Windows UpdatesPassNo pending Windows Updates were found; the system is up to date.CIS 18.10.94.2.1
Windows Update ServicePassWindows Update service start type is Automatic (current state: Stopped); it starts on demand when updates are needed.CIS 18.10.94.2.1
PowerShell
PowerShell Module LoggingPassModule Logging is enabled — module pipeline execution events are logged.
PowerShell Script Block LoggingPassScript Block Logging is enabled — PowerShell commands are logged to the event log.CIS 18.10.88.1
Remote Access
RDP EnabledPassRemote Desktop is disabled (fDenyTSConnections = 1).CIS 18.10.57.3.2.1
Services
Risky ServicesPassNo known-risky services are running.
Unquoted Service PathsPassNo services with unquoted paths containing spaces found.
System
OS End-of-Support StatusPassWindows 11 25H2 is supported until 2027-10-12 (452 days remaining).
Secure BootPassSecure Boot is enabled.CIS 18.10.10.2.2
System UptimePassSystem uptime is 7 day(s).
TPM StatusPassTPM present. Ready: True. Firmware version: 7.2.2.0.
B

Remediation commands

For IT
Before you run these
Run in an elevated PowerShell prompt. Commands mirror the findings above; review each against your environment and change-management process before applying to a production device.
01Password Policy — Minimum LengthAccounts · P1
net accounts /minpwlen:14
02Password Policy — ComplexityAccounts · P2
# Enable the password-complexity policy via secedit (no reboot needed).
$inf = "$env:TEMP\pwcomplexity.inf"
@'
[Unicode]
Unicode=yes
[Version]
signature="$CHICAGO$"
[System Access]
PasswordComplexity = 1
'@ | Set-Content -Path $inf -Encoding Unicode
secedit /configure /db "$env:TEMP\pwcomplexity.sdb" /cfg $inf /areas SECURITYPOLICY
03BitLocker — G:Encryption · P2
# BitLocker requires Windows Pro/Enterprise/Education (absent on Home).
if (Get-Command Enable-BitLocker -ErrorAction SilentlyContinue) {
Enable-BitLocker -MountPoint 'G:' -EncryptionMethod XtsAes256 -UsedSpaceOnly -RecoveryPasswordProtector -SkipHardwareTest
if ('G:' -eq $env:SystemDrive) { Add-BitLockerKeyProtector -MountPoint 'G:' -TpmProtector } else { Enable-BitLockerAutoUnlock -MountPoint 'G:' }
} else {
Write-Warning 'BitLocker is unavailable on this Windows edition.'
}
04Audit PolicyHardening · P2
auditpol /set /subcategory:'Logon' /success:enable /failure:enable
05AutoPlay DisabledHardening · P2
Set-ItemProperty -Path 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer' -Name NoDriveTypeAutoRun -Value 255 -Type DWord -Force
06NetBIOS over TCP/IPNetwork · P3
Get-CimInstance Win32_NetworkAdapterConfiguration -Filter 'IPEnabled=True' | ForEach-Object { Invoke-CimMethod -InputObject $_ -MethodName SetTcpipNetbios -Arguments @{ TcpipNetbiosOptions = 2 } | Out-Null }

About this assessment — Apotrope performs a read-only, non-invasive scan of Windows security configuration, scoring against thresholds aligned to the CIS Microsoft Windows Benchmark v5.0.0. No changes are made to the system during assessment. Scores start at 100 and deduct weighted points per finding: failed controls deduct 15, 10, 5, or 2 points for critical, high, medium, or low severity respectively; warnings deduct 7, 5, 2, or 1. Informational items and checks that could not be evaluated do not affect the score. The scan completed in 21.7 seconds. When printing, disable the browser's own header and footer — this document supplies its own.

Apotrope v0.1.12 · Security Posture Assessment WORKSTATION-07 Confidential