; ============================================================ ; SKYFORT FORTRESS - WINDOWS SERVER 2022 ; Nivel 3 - Protecao Maxima (150+ controles) ; Versao: 1.0.0 | Data: 2026-03-01 ; ============================================================ [Unicode] Unicode=yes [Version] signature="$CHICAGO$" Revision=1 ProfileString=Skyfort Fortress - Windows Server 2022 [System Access] ; AUTENTICACAO MAXIMA MinimumPasswordLength = 16 PasswordComplexity = 1 PasswordHistorySize = 24 MinimumPasswordAge = 1 MaximumPasswordAge = 60 LockoutBadCount = 3 ResetLockoutCount = 30 LockoutDuration = 30 EnableGuestAccount = 0 NewAdministratorName = "Admin-Skyfort" NewGuestName = "Guest-Disabled" ForceLogoffWhenHourExpire = 1 RequireLogonToChangePassword = 1 [Event Audit] ; AUDITORIA COMPLETA AuditSystemEvents = 3 AuditLogonEvents = 3 AuditObjectAccess = 3 AuditPrivilegeUse = 3 AuditPolicyChange = 3 AuditAccountManage = 3 AuditProcessTracking = 3 AuditAccountLogon = 3 [Registry Values] ; ========== AUTENTICACAO ========== machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername=4,1 machine\software\microsoft\windows\currentversion\policies\system\legalnoticecaption=4,"Skyfort Fortress Security" machine\software\microsoft\windows\currentversion\policies\system\legalnoticetext=4,"Acesso autorizado apenas. Todas as atividades sao monitoradas." machine\software\microsoft\windows\currentversion\policies\system\DisableCAD=4,0 machine\system\currentcontrolset\control\terminal server\fSingleSessionPerUser=4,1 machine\system\currentcontrolset\control\lsa\LsaCfgFlags=4,1 machine\system\currentcontrolset\control\lsa\DisableRestrictedAdmin=4,0 ; ========== ARQUIVOS ========== machine\system\currentcontrolset\control\session manager\memory management\ClearPageFileAtShutdown=4,1 machine\software\policies\microsoft\windows\offlinefiles\Enabled=4,0 machine\system\currentcontrolset\control\filesystem\NtfsDisableLastAccessUpdate=4,1 machine\system\currentcontrolset\control\filesystem\NtfsDisable8dot3NameCreation=4,1 ; ========== REDE ========== machine\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\enablefirewall=4,1 machine\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\publicprofile\enablefirewall=4,1 machine\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\enablefirewall=4,1 machine\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\defaultinboundaction=4,1 machine\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\publicprofile\defaultinboundaction=4,1 machine\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\logging\EnableFileLogging=4,1 machine\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\logging\LogDroppedPackets=4,1 ; SMB machine\system\currentcontrolset\services\lanmanserver\parameters\smb1=4,0 machine\system\currentcontrolset\services\mrxsmb10\start=4,4 machine\system\currentcontrolset\services\lanmanserver\parameters\requiresecuritysignature=4,1 machine\system\currentcontrolset\services\lanmanworkstation\parameters\requiresecuritysignature=4,1 machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature=4,1 ; RDP machine\system\currentcontrolset\control\terminal server\winstations\rdp-tcp\UserAuthentication=4,1 machine\system\currentcontrolset\control\terminal server\winstations\rdp-tcp\MinEncryptionLevel=4,3 machine\software\policies\microsoft\windows nt\terminal services\DisablePasswordSaving=4,1 ; LSA machine\system\currentcontrolset\control\lsa\restrictanonymous=4,2 machine\system\currentcontrolset\control\lsa\restrictanonymoussam=4,1 machine\system\currentcontrolset\control\lsa\everyoneincludesanonymous=4,0 machine\system\currentcontrolset\control\lsa\RunAsPPL=4,1 machine\system\currentcontrolset\control\lsa\RunAsPPLBootKey=4,1 ; WinRM machine\software\policies\microsoft\windows\winrm\client\AllowUnencryptedTraffic=4,0 machine\software\policies\microsoft\windows\winrm\service\AllowUnencryptedTraffic=4,0 machine\software\policies\microsoft\windows\winrm\client\AllowBasic=4,0 ; TCP/IP machine\system\currentcontrolset\services\tcpip\parameters\DisableIPSourceRouting=4,1 machine\system\currentcontrolset\services\tcpip\parameters\EnableICMPRedirect=4,0 machine\system\currentcontrolset\services\tcpip\parameters\SynAttackProtect=4,1 ; ========== SERVICOS ========== machine\system\currentcontrolset\services\telnet\start=4,4 machine\system\currentcontrolset\services\remoteregistry\start=4,4 machine\system\currentcontrolset\services\ssdpsrv\start=4,4 machine\system\currentcontrolset\services\upnphost\start=4,4 machine\system\currentcontrolset\services\snmp\start=4,4 machine\system\currentcontrolset\services\simptcp\start=4,4 machine\system\currentcontrolset\services\fax\start=4,4 machine\system\currentcontrolset\services\browser\start=4,4 ; ========== SISTEMA ========== machine\software\policies\microsoft\windows\windowsupdate\au\AUOptions=4,4 machine\software\policies\microsoft\windows\windowsupdate\au\NoAutoUpdate=4,0 machine\software\policies\microsoft\windows\datacollection\AllowTelemetry=4,0 machine\software\policies\microsoft\windows\windows error reporting\Disabled=4,1 ; PowerShell machine\software\policies\microsoft\windows\powershell\modulelogging\enablemodulelogging=4,1 machine\software\policies\microsoft\windows\powershell\scriptblocklogging\enablescriptblocklogging=4,1 ; ========== DEFENDER ========== machine\software\policies\microsoft\windows defender\DisableAntiSpyware=4,0 machine\software\policies\microsoft\windows defender\real-time protection\DisableRealtimeMonitoring=4,0 machine\software\policies\microsoft\windows defender\real-time protection\DisableIOAVProtection=4,0 machine\software\policies\microsoft\windows defender\spynet\SpynetReporting=4,2 machine\software\policies\microsoft\windows defender\spynet\SubmitSamplesConsent=4,3 machine\software\policies\microsoft\windows defender\MpEngine\MpEnablePus=4,1 ; ========== APLICATIVOS ========== machine\software\microsoft\windows\currentversion\policies\system\EnableLUA=4,1 machine\software\microsoft\windows\currentversion\policies\system\ConsentPromptBehaviorAdmin=4,2 machine\software\policies\microsoft\windows\system\EnableSmartScreen=4,1 machine\software\microsoft\windows\currentversion\policies\explorer\NoDriveTypeAutoRun=4,255 machine\software\microsoft\windows script host\settings\TrustPolicy=4,2 ; Office machine\software\policies\microsoft\office\16.0\excel\security\VBAWarnings=4,4 machine\software\policies\microsoft\office\16.0\word\security\VBAWarnings=4,4 ; ========== CRIPTOGRAFIA ========== machine\system\currentcontrolset\control\lsa\fipsalgorithmpolicy\enabled=4,1 machine\system\currentcontrolset\control\securityproviders\schannel\protocols\ssl 2.0\client\enabled=4,0 machine\system\currentcontrolset\control\securityproviders\schannel\protocols\ssl 2.0\server\enabled=4,0 machine\system\currentcontrolset\control\securityproviders\schannel\protocols\tls 1.0\client\enabled=4,0 machine\system\currentcontrolset\control\securityproviders\schannel\protocols\tls 1.0\server\enabled=4,0 ; ========== SERVER ESPECIFICO ========== machine\software\microsoft\servermanager\DoNotOpenServerManagerAtLogon=4,1 machine\software\policies\microsoft\windows\credssp\AllowDefCredentials=4,0 ; PSS-001: Carimbo de identificacao da baseline aplicada MACHINE\Software\PSS\Baseline=1,"Skyfort Fortress v2.0.0 - Windows Server 2022" [Profile Description] Description=Skyfort Fortress - Windows Server 2022 Maximum Security (150+ controles)