Item Search

NameAudit NamePluginCategory
WN11-00-000190 - Orphaned security identifiers (SIDs) must be removed from user rights on Windows 11.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-00-000260 - The Windows 11 time service must synchronize with an appropriate DoW time source.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY

WN11-AU-000050 - The system must be configured to audit Detailed Tracking - Process Creation successes.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

WN11-AU-000082 - Windows 11 must be configured to audit Object Access - File Share successes.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY

WN11-AU-000084 - Windows 11 must be configured to audit Object Access - Other Object Access Events failures.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY

WN11-AU-000140 - The system must be configured to audit System - Security State Change successes.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY

WN11-AU-000555 - Windows 11 must be configured to audit Other Policy Change Events Failures.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY

WN11-AU-000570 - Windows 11 must be configured to audit Detailed File Share Failures.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY

WN11-CC-000025 - The system must be configured to prevent IP source routing.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000035 - The system must be configured to ignore NetBIOS name release requests except from WINS servers.DISA Microsoft Windows 11 STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN11-CC-000038 - WDigest Authentication must be disabled.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000040 - Insecure logons to an SMB server must be disabled.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000063 - Windows 11 systems must use either Group Policy or an approved Mobile Device Management (MDM) product to enforce STIG compliance.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000066 - Command line data must be included in process creation events.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY

WN11-CC-000070 - Virtualization-Based Security (VBS) must be enabled on Windows 11 with the platform security level configured to Secure Boot or Secure Boot with DMA Protection.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000080 - Virtualization-based protection of code integrity must be enabled.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000130 - Local users on domain-joined computers must not be enumerated.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000165 - Unauthenticated RPC clients must be restricted from connecting to the RPC server.DISA Microsoft Windows 11 STIG v2r9Windows

IDENTIFICATION AND AUTHENTICATION

WN11-CC-000170 - The setting to allow Microsoft accounts to be optional for modern style apps must be enabled.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000175 - The Application Compatibility Program Inventory must be prevented from collecting data and sending the information to Microsoft.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000180 - Autoplay must be turned off for non-volume devices.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000195 - Enhanced anti-spoofing for facial recognition must be enabled on Windows 11.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000200 - Administrator accounts must not be enumerated during elevation.DISA Microsoft Windows 11 STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN11-CC-000205 - Windows Telemetry must not be configured to Full.DISA Microsoft Windows 11 STIG v2r9Windows

SYSTEM AND INFORMATION INTEGRITY

WN11-CC-000260 - Windows 11 must be configured to require a minimum PIN length of six characters or greater.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000290 - Remote Desktop Services must be configured with the client connection encryption set to the required level.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WN11-CC-000325 - Automatically signing in the last interactive user after a system-initiated restart must be disabled.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000390 - Windows 11 must be configured to prevent users from receiving suggestions for third-party or additional applications.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-EP-000310 - Windows 11 Kernel (Direct Memory Access) DMA Protection must be enabled.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY

WN11-PK-000015 - The DoW Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems.DISA Microsoft Windows 11 STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN11-PK-000020 - The US DoW CCEB Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems.DISA Microsoft Windows 11 STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN11-RG-000005 - Default permissions for the HKEY_LOCAL_MACHINE registry hive must be maintained.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WN11-SO-000010 - The built-in guest account must be disabled.DISA Microsoft Windows 11 STIG v2r9Windows

IDENTIFICATION AND AUTHENTICATION

WN11-SO-000045 - Outgoing secure channel traffic must be signed.DISA Microsoft Windows 11 STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN11-SO-000120 - The Windows SMB server must be configured to always perform SMB packet signing.DISA Microsoft Windows 11 STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN11-SO-000167 - Remote calls to the Security Account Manager (SAM) must be restricted to Administrators.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WN11-SO-000180 - NTLM must be prevented from falling back to a Null session.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-SO-000195 - The system must be configured to prevent the storage of the LAN Manager hash of passwords.DISA Microsoft Windows 11 STIG v2r9Windows

IDENTIFICATION AND AUTHENTICATION

WN11-SO-000250 - User Account Control must prompt administrators for consent on the secure desktop.DISA Microsoft Windows 11 STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN11-SO-000255 - User Account Control must automatically deny elevation requests for standard users.DISA Microsoft Windows 11 STIG v2r9Windows

IDENTIFICATION AND AUTHENTICATION

WN11-SO-000275 - User Account Control must virtualize file and registry write failures to per-user locations.DISA Microsoft Windows 11 STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN11-SO-000280 - Passwords for enabled local Administrator accounts must be changed at least every 60 days.DISA Microsoft Windows 11 STIG v2r9Windows

IDENTIFICATION AND AUTHENTICATION

WN11-UR-000005 - The 'Access Credential Manager as a trusted caller' user right must not be assigned to any groups or accounts.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WN11-UR-000025 - The 'Allow log on locally' user right must only be assigned to the Administrators and Users groups.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WN11-UR-000035 - The 'Change the system time' user right must only be assigned to Administrators and Local Service.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WN11-UR-000050 - The 'Create global objects' user right must only be assigned to Administrators, Service, Local Service, and Network Service.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WNDF-AV-000071 - Microsoft Defender AV must report Dynamic Signature dropped events.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000075 - Microsoft Defender AV must enable asynchronous inspection.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000077 - Microsoft Defender AV must enable heuristics.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND INFORMATION INTEGRITY

WNDF-AV-000100 - Microsoft Defender AV must control whether exclusions are visible to Local Admins.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION