Attached is my CIS 2024 Beta config file, you can Import it at Settings / Configuration / Import Button. Don't forget to Activate it.
Particulars about this config:
. No Auto Containment Rule changes; all the default rules were kept; no additions.
. HIPS Rules were added:
... RuntimeBroker set to Custom Ruleset: Limited Application
... LogonUI set to Custom Ruleset: Limited Application. ( the reason: my red team guest attacked this, and made configration changes such that Logins are impossible. Restricting it to Limited Application protects LogonUI.
... TaskHostw. set to Custom Ruleset: Limited Application. My Xcitium CIS OpenEDR reported attacks against this. So setting it to Limited Application for protection.
. HIPS Settings
... Do not show popup alerts: Block Request ( no adverse effects noticed, so I am playing it safe )
... Block all unknown requests ... ( no adverse effects noticed, so I am playing it safe )
. HIPS Protected Objects
... Blocked Files
...... Powershell and Powershell_ise (these 2 are not frequently used by me. And attackers usually want to execute these 2 to perform fileless attacks.
...... cmd, blocked for the same reason as Powershell
...... mmc is the base application for Group Policy Editor, Local Security Policy, Device Manager and some others. If an attacker can reach this, they can disable a lot of defenses.
...... MoUsoCoreWorker is part of Windows Update. I don't run Windows Update, because last year 2023 I was attacked via Windows Update because a MS Certificate Leak allow hackers to sign malware posing as win updates. The leaked cert should be revoked by now, but I have gotten used to going to MS Update Catalog site to manually download and verify updates.
...... Drvinst is blocked for the same reason as Win Updates, drvinst installs drivers
...... wuauclt is part of Win Update
...... BitLocker, BitLockerToGo I do not encrypt the hard drive nor USB sticks. My 12 yr old Core i5 is already slow as is, and nobody is going steal a 5 lb laptop.
....... SSH is blocked because it is a known hacker TTP to setup a backdoor using this, source OSINT.
...... WerFault is blocked because I don't send error reports to MS
. Firewall
... Application Rules. Only contains a select few Windows exe's that are necessary for MS Account sign in , Outlook and smartscreen etc.
So because of the HIPS blocks, you will need to turn off HIPS protection if you want to use any of the above blocked exe's.
To download the config file, just click on the Play button inside the Spoiler.