Item Search

NameAudit NamePluginCategory
2.3.5.4 Ensure 'Domain controller: LDAP server signing requirements Enforcement' is set to 'Enabled' (DC only)CIS Microsoft Windows Server 2025 v2.1.0 L1 DCWindows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.1 Ensure the Apache Web Server Runs As a Non-Root User - 'apache account is configured'CIS Apache HTTP Server 2.2 L1 v3.6.0Unix

ACCESS CONTROL

3.1 Ensure the Apache Web Server Runs As a Non-Root User - 'apache account is configured'CIS Apache HTTP Server 2.2 L1 v3.6.0 MiddlewareUnix

ACCESS CONTROL

3.1 Ensure the Apache Web Server Runs As a Non-Root User - 'httpd services are running as apache user'CIS Apache HTTP Server 2.2 L2 v3.6.0Unix

ACCESS CONTROL

3.1 Ensure the Apache Web Server Runs As a Non-Root User - 'httpd.conf User = apache'CIS Apache HTTP Server 2.2 L2 v3.6.0Unix

ACCESS CONTROL

3.2.7 Ensure unneeded network protocol kernel modules are not availableCIS Ubuntu Linux 26.04 LTS v1.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

5.131 - Windows is prevented from using Windows Update to search for drivers.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

18.9.11.1.8 Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Configure storage of BitLocker recovery information to AD DS' is set to 'Enabled: Backup recovery passwords and key packages'CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0Windows

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

18.9.11.1.8 Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Configure storage of BitLocker recovery information to AD DS' is set to 'Enabled: Backup recovery passwords and key packages'CIS Windows 7 Workstation Level 2 + Bitlocker v3.2.0Windows

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

18.9.11.3.8 Ensure 'Choose how BitLocker-protected removable drives can be recovered: Configure storage of BitLocker recovery information to AD DS:' is set to 'Enabled: Backup recovery passwords and key packages'CIS Windows 7 Workstation Level 2 + Bitlocker v3.2.0Windows

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

18.9.27.1 Ensure 'Configures LSASS to run as a protected process' is set to 'Enabled: Enabled with UEFI Lock'CIS Microsoft Windows Server 2025 Stand-alone v2.0.0 NG MSWindows

SYSTEM AND INFORMATION INTEGRITY

18.9.27.2 Ensure 'Configures LSASS to run as a protected process' is set to 'Enabled: Enabled with UEFI Lock'CIS Microsoft Windows Server 2022 v5.1.0 NG DCWindows

SYSTEM AND INFORMATION INTEGRITY

18.9.27.2 Ensure 'Configures LSASS to run as a protected process' is set to 'Enabled: Enabled with UEFI Lock'CIS Microsoft Windows Server 2022 v5.1.0 NG MSWindows

SYSTEM AND INFORMATION INTEGRITY

18.9.27.2 Ensure 'Configures LSASS to run as a protected process' is set to 'Enabled: Enabled with UEFI Lock'CIS Microsoft Windows 10 Enterprise v5.0.0 L2 NGWindows

SYSTEM AND INFORMATION INTEGRITY

18.9.27.2 Ensure 'Configures LSASS to run as a protected process' is set to 'Enabled: Enabled with UEFI Lock'CIS Microsoft Windows 10 Stand-alone v5.0.0 L1 NGWindows

SYSTEM AND INFORMATION INTEGRITY

18.9.27.2 Ensure 'Configures LSASS to run as a protected process' is set to 'Enabled: Enabled with UEFI Lock'CIS Microsoft Windows 10 Enterprise v5.0.0 L2 BL NGWindows

SYSTEM AND INFORMATION INTEGRITY

18.9.27.2 Ensure 'Configures LSASS to run as a protected process' is set to 'Enabled: Enabled with UEFI Lock'CIS Microsoft Windows 11 Enterprise v5.1.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

18.9.27.2 Ensure 'Configures LSASS to run as a protected process' is set to 'Enabled: Enabled with UEFI Lock'CIS Microsoft Windows 10 Stand-alone v5.0.0 L1 BL NGWindows

SYSTEM AND INFORMATION INTEGRITY

18.9.27.2 Ensure 'Configures LSASS to run as a protected process' is set to 'Enabled: Enabled with UEFI Lock'CIS Microsoft Windows 10 Stand-alone v5.0.0 L2 BL NGWindows

SYSTEM AND INFORMATION INTEGRITY

18.9.27.2 Ensure 'Configures LSASS to run as a protected process' is set to 'Enabled: Enabled with UEFI Lock'CIS Microsoft Windows Server 2025 v2.1.0 NG DCWindows

SYSTEM AND INFORMATION INTEGRITY

18.9.27.2 Ensure 'Configures LSASS to run as a protected process' is set to 'Enabled: Enabled with UEFI Lock'CIS Microsoft Windows 11 Enterprise v5.1.0 L1 BLWindows

SYSTEM AND INFORMATION INTEGRITY

18.9.27.2 Ensure 'Configures LSASS to run as a protected process' is set to 'Enabled: Enabled with UEFI Lock'CIS Microsoft Windows 10 Stand-alone v5.0.0 L2 NGWindows

SYSTEM AND INFORMATION INTEGRITY

18.9.27.2 Ensure 'Configures LSASS to run as a protected process' is set to 'Enabled: Enabled with UEFI Lock'CIS Microsoft Windows 10 Stand-alone v5.0.0 NGWindows

SYSTEM AND INFORMATION INTEGRITY

18.9.27.2 Ensure 'Configures LSASS to run as a protected process' is set to 'Enabled: Enabled with UEFI Lock'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BL NGWindows

SYSTEM AND INFORMATION INTEGRITY

18.9.27.2 Ensure 'Configures LSASS to run as a protected process' is set to 'Enabled: Enabled with UEFI Lock'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 NGWindows

SYSTEM AND INFORMATION INTEGRITY

18.9.27.2 Ensure 'Configures LSASS to run as a protected process' is set to 'Enabled: Enabled with UEFI Lock'CIS Microsoft Windows 10 Enterprise v5.0.0 NGWindows

SYSTEM AND INFORMATION INTEGRITY

18.9.59.3.10.1 (L2) Ensure 'Set time limit for active but idle Remote Desktop Services sessions' is set to 'Enabled: 15 minutes or less'CIS Microsoft Windows 8.1 v2.4.1 L2Windows

ACCESS CONTROL

18.9.59.3.10.1 Ensure 'Set time limit for active but idle Remote Desktop Services sessions' is set to 'Enabled: 15 minutes or less'CIS Windows 7 Workstation Level 2 v3.2.0Windows

ACCESS CONTROL

Allow Windows Ink WorkspaceMSCT Windows 11 v1.0.0Windows

CONFIGURATION MANAGEMENT

Allow Windows Ink WorkspaceMSCT Windows 10 1809 v1.0.0Windows

CONFIGURATION MANAGEMENT

Allow Windows Ink WorkspaceMSCT Windows 10 1909 v1.0.0Windows

CONFIGURATION MANAGEMENT

Allow Windows Ink WorkspaceMSCT Windows 10 v21H2 v1.0.0Windows

CONFIGURATION MANAGEMENT

Allow Windows Ink WorkspaceMSCT Windows Server 1903 DC v1.19.9Windows

CONFIGURATION MANAGEMENT

Allow Windows Ink WorkspaceMSCT Windows Server v1909 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Allow Windows Ink WorkspaceMSCT Windows Server v1909 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Allow Windows Ink WorkspaceMSCT Windows Server v2004 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Allow Windows Ink WorkspaceMSCT Windows Server 2019 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Allow Windows Ink WorkspaceMSCT Windows 10 v22H2 v1.0.0Windows

CONFIGURATION MANAGEMENT

Allow Windows Ink WorkspaceMSCT Windows 11 v23H2 v1.0.0Windows

CONFIGURATION MANAGEMENT

Allow Windows Ink WorkspaceMSCT Windows 10 v2004 v1.0.0Windows

CONFIGURATION MANAGEMENT

Allow Windows Ink WorkspaceMSCT MSCT Windows Server 2022 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Allow Windows Ink WorkspaceMSCT Windows Server v20H2 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Configure Windows Defender SmartScreenMSCT Windows 10 1809 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Turn off Windows DefenderMSCT Windows Server 2016 MS v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Windows Device Configuration - AccountsTenable Best Practices for Microsoft Intune Windows v1.0microsoft_azure

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Windows Device Configuration - SystemTenable Best Practices for Microsoft Intune Windows v1.0microsoft_azure

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Windows Firewall: Prohibit notificationsMSCT Windows 10 v1507 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Windows Firewall: Prohibit notificationsMSCT Windows Server 2012 R2 DC v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Windows Firewall: Prohibit notificationsMSCT Windows Server 2012 R2 MS v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

WN19-CC-000300 - Windows Server 2019 Windows Defender SmartScreen must be enabled.DISA Microsoft Windows Server 2019 STIG v3r9Windows

CONFIGURATION MANAGEMENT