Skip to content
CyberSmithSECURE
Under Attack

Configuration Review

Configuration Review of Endpoints

Endpoints are where attackers land. They are also the estate's largest population, so the only sustainable control is the build and the policy that enforces it, not per-machine remediation. The review therefore assesses the gold image and the management policy together, and then samples real machines to find out how far reality has drifted from both.

Methodology

  1. 01

    Build and image review

    The standard operating environment assessed against the CIS benchmark for each platform: local accounts, services, protocols, audit policy and installed software.

  2. 02

    Management policy review

    Group Policy, Intune or the equivalent examined for what it actually enforces, what is set to 'not configured', and which policies conflict.

  3. 03

    Deployed-state sampling

    A representative sample of live machines assessed against the same baseline, because drift between image and estate is usually where the finding is.

  4. 04

    Endpoint protection review

    EDR or antivirus configuration assessed for coverage, exclusions, tamper protection, and whether it is set to block or merely to report.

  5. 05

    Privilege and application control

    Local administrator rights across the estate, LAPS deployment, application allowlisting posture, and the scripting engines available to a standard user.

  6. 06

    Patch and vulnerability posture

    Operating system and third-party patch currency, deployment cadence, and the tail of machines that never complete a cycle.

  7. 07

    Reporting and retest

    Technical report and executive summary together, with changes sequenced by user impact and deployment risk, then a retest confirming closure.

Approach to testing

  • Image and estate are assessed separately, because a correct image tells you nothing about a fleet that has drifted for three years.
  • EDR exclusions are enumerated and each is challenged. Broad path exclusions added to fix a performance complaint are a common and severe finding.
  • Local administrator rights are measured as a count, not as a policy. 'Users do not have local admin' is frequently untrue for a long tail of exceptions.
  • Recommendations state user impact and deployment risk. Application allowlisting is correct and will break something, and a report that omits that will be ignored.
  • Sampling is representative by role and location — a review of 30 head office laptops says nothing about 400 shop floor terminals.

Types of assessment

Build and policy review (default)

Gold image and management policy against the benchmark. The most leverage, because it fixes every future machine.

Estate drift assessment

Sampling live machines against the baseline to quantify how far the fleet has moved from the intended build.

Endpoint protection effectiveness

Focused review of EDR configuration, exclusions and response posture, with optional safe technique testing to confirm detection.

Privileged access on endpoints

Narrow scope on local administrator rights, LAPS coverage and privilege escalation paths available to a standard user.

Frameworks and standards

CIS Benchmarks
Windows 10/11, Windows Server, macOS and Linux distribution baselines, at Level 1 or Level 2 as agreed.
Microsoft Security Baselines
Group Policy and Intune baselines, which are often more current than the CIS equivalent.
NIST SP 800-53 / 800-171
Control mapping where the client has a compliance obligation.
MITRE ATT&CK
Used to assess whether the endpoint protection configuration covers the techniques that matter.
Essential Eight
Where the client wants a maturity-model view of application control, patching and administrative privilege.

Tools used

Tooling is where testing starts, not where it ends. Every automated result is reproduced by hand before it reaches a report.

CIS-CAT Pro

Automated benchmark assessment against Windows, macOS and Linux hosts.

Microsoft Security Compliance Toolkit

Comparing deployed Group Policy against Microsoft's published baselines.

Intune / Configuration Manager reporting

Read-only export of deployed policy and compliance state across the estate.

PingCastle

Where endpoints are domain-joined, for LAPS coverage and local administrator distribution.

Atomic Red Team

Safe, bounded technique execution to confirm EDR detection, where authorised.

Lynis

Linux endpoint hardening assessment.

Checklist approach

The checklist is the floor, not the ceiling. It guarantees coverage so nothing standard is missed; the findings that matter usually come from what a tester does after it is complete.

Operating system hardening

  • Benchmark compliance for the platform at the agreed level
  • Legacy protocols: SMBv1, LLMNR, NBT-NS, WDigest
  • PowerShell logging, constrained language mode and version 2 removal
  • Audit policy coverage for security-relevant events
  • Secure boot, disk encryption and TPM usage
  • Local account policy and built-in administrator handling

Privilege

  • Count of users with local administrator, by role
  • LAPS deployment coverage and password rotation
  • Privileged accounts used on standard endpoints
  • UAC configuration and prompt behaviour
  • Service account rights on endpoints

Endpoint protection

  • EDR coverage: machines with no agent or a stale agent
  • Detection posture: block versus report only
  • Exclusion list, with justification for each entry
  • Tamper protection enabled
  • Attack surface reduction rules and their mode
  • Alert routing and who responds outside business hours

Application control

  • Allowlisting posture and coverage
  • Macro policy for Office documents
  • Scripting engines available to standard users
  • Removable media policy and enforcement
  • Browser extension governance

Patch and currency

  • Operating system patch compliance and the unpatched tail
  • Third-party application patching coverage
  • End-of-life operating systems still deployed
  • Firmware and driver update handling
  • Reboot compliance, which is where patch cycles usually fail

Configuration management

  • Drift between gold image and deployed estate
  • Conflicting policies across management platforms
  • Machines unmanaged by any platform
  • Onboarding and decommissioning process
  • Backup and recovery for endpoint data

How findings are scored

Every finding is scored on CVSS 3.1 and placed in one of five levels. The executive summary adds a sixth band — Compliant — so components that passed appear on the same chart as those that did not.

Critical
Immediate measures must be taken. These vulnerabilities can allow an attacker to take complete control of the application or server — stealing user data, tricking users into supplying sensitive information, or defacing the site.
High
Maximum risk associated with a specific vulnerability instance. May enable an attacker to compromise the application and its data, partially or completely, or to modify application behaviour beyond its intended purpose. To be handled with utmost priority.
Medium
Considerable risk. May enable an attacker to exploit the application to a particular level, gaining low-level information that can be used to craft more specific attacks.
Low
Lowest risk. May allow an attacker to gain some information about the application that was not intended to be known, without an exploitation technique currently available at that instance.
Informational
A functionality or component is missing best-practice implementation. Not a risk today, but may become one as the application changes or as exploitation techniques, policy or legal requirements evolve.

Scan types selected

  • Safe Checks
  • Standard / OWASP Top 10
  • Destructive
  • SANS Top 25
  • Business Logic Vulnerability Testing

Standard toolset by stage

OSINT
Datasploit, Google Dorks, Shodan
Enumeration & Scanning
Nmap, Wfuzz, Unicornscan
Domain Enumeration
Nikto, DnsRecon, Knock
Crawling & Fuzzing
Burp Suite, Acunetix, Netsparker
Vulnerability Analysis
OpenSSL, sqlmap, CVE-Details
Exploitation
Metasploit, Netcat, Exploit-DB

How CSS tests

A unified swarm of agents, for blind spot detection

AI agents drive several testing tracks against the same target at once, then cross-check each other. A single tester works one hypothesis at a time; parallel agents cover the space a sequential pass leaves behind.

  • Benchmark evaluation across thousands of settings on hundreds of sampled machines is exhaustive comparison, and the setting that differs is rarely the one a reviewer would check by hand.

  • Policy conflict between Group Policy and Intune produces an effective setting neither administrator intended; resolving precedence across every setting is computation, not reading.

  • EDR exclusion lists grow quietly. Cross-referencing every exclusion against what an attacker could place there is enumeration work.

  • The unpatched tail hides in aggregate compliance figures — 97% compliant across 4,000 machines is 120 machines that never patch, and identifying which ones and why requires correlating several data sources.

Every agent finding is validated by a human reviewer. Assessment is read-only; where technique testing is used to confirm EDR detection it is bounded, authorised in writing, and run on nominated machines only.

Why this differs

What CSS does that most vendors do not

Every one of these is checkable. Ask any vendor for the same and compare the answers.

Image and estate, not one or the other

A correct gold image is worthless if the fleet drifted three years ago. CSS assesses both and reports the gap, which is usually the actual risk.

Exclusions are challenged

Most reviews confirm EDR is installed. CSS enumerates every exclusion and asks what an attacker could put there — broad path exclusions are among the most common ways a well-funded EDR deployment is neutralised.

Both reports, always

Technical report and executive summary together, plus a change list sequenced by user impact and deployment risk.

Fixation, not a backlog

CSS works the deployment sequence with the endpoint team, including pilot groups and rollback plans, and retests to evidence closure.

Reporting

Two documents, two audiences

Both are produced for every engagement. They are not the same document at two lengths — they answer different questions and are written separately. The structure below is the one CSS actually issues.

Technical assessment report

For the engineers who will fix it

  • Disclaimer, and Limitations on Disclosure and Use
  • Risk Level & Description — the five levels above, scored on CVSS 3.1
  • Scan Type — which of the five assessment types were selected
  • Assessment Scope — the control areas covered
  • Assessment Date — the exact testing window
  • Objective of the Assessment — objectives listed against completion status
  • Tools Utilization — manual and automated tooling by stage
  • Summary of the Assessment
  • Overall Recommendations, split into Must Have and Should Have
  • Vulnerability Overall Classifications as per Organization
  • Security Issues Highlighted
  • The Key Findings — each with evidence and detailed recommendation
  • Summary of Findings & Conclusion

For this assessment specifically

  • Scope: platforms, image versions, management platforms and the sample composition
  • Benchmark findings with CIS control references, for both image and sampled estate
  • Drift analysis: where the fleet differs from the intended build and by how much
  • EDR configuration review including every exclusion and its assessed risk
  • Local administrator and LAPS coverage figures
  • Patch compliance with the unpatched tail identified
  • Prioritised change list with user impact and deployment risk
  • Retest results appended against each original finding

Executive summary

For the people who will fund the fix

  • Objectives, each against a completion status
  • Overall Finding of the Assessment — total threats identified, broken down by component and severity
  • Summary of the Assessment
  • Artefacts of the Assessment — the key findings as a numbered register with severity
  • Observation of the Assessment — the major attacks the organisation should be prepared for, given what was found
  • Overall Recommendation, including a Business Enabling Recommendation sequence
  • Must Have and Should Have actions

For this assessment specifically

  • What happens on the estate today when a user opens a malicious attachment
  • Benchmark compliance for image and estate as two separate figures
  • The three changes that most reduce exposure, with user impact stated
  • Regulatory or insurance position where endpoint controls are in scope
  • Remediation timeline and retest date
  • One page

Case studies

What this finds in practice

Representative engagement patterns. Sector and scale only — no client is named, and no detail is included that could identify one.

A manufacturer with roughly 2,300 endpoints across corporate offices and four plants.

Finding
The gold image was well hardened and scored 87% against CIS Level 1. Sampling the estate returned 54%: plant terminals had been imaged in 2019 and never rebuilt, still ran SMBv1, and had no EDR agent because the original rollout excluded the plant VLAN.
Recommendation
Bring plant terminals under the same management platform, deploy EDR to the excluded VLAN, and add a compliance report that reports by location rather than as a single estate figure.
Outcome
EDR deployed to the plant estate over two maintenance windows. Reporting by location is what made the gap visible to management, and it had been invisible in the aggregate figure for three years.

A financial services firm with a mature EDR deployment.

Finding
EDR was correctly deployed with tamper protection and blocking mode. The exclusion list had grown to 61 entries, including a wildcard on a temporary directory writable by all users, added during a 2023 performance investigation and never removed.
Recommendation
Remove the wildcard exclusion, require a ticket reference and expiry for any new exclusion, and review the list quarterly.
Outcome
The wildcard was removed the same day. The review reduced the list to 18 justified entries, and the expiry requirement has prevented it growing back.

A professional services firm of around 500 staff, largely macOS.

Finding
217 users held local administrator rights, granted individually over several years to allow software installation. There was no LAPS equivalent, and the local administrator password was identical on every machine imaged before 2024.
Recommendation
Remove standing local administrator in favour of a privilege elevation tool for approved installations, and rotate the shared local credential with per-machine unique passwords.
Outcome
Rights removed for 190 of 217 users over a quarter, with the remainder moved to time-bound elevation. The shared password rotation closed lateral movement between every machine of that era.

Next

Scope this assessment

Most scopes are settled in one call. Tell us what the application does and who uses it, and we will tell you what testing it properly involves.