// RESOURCES · HARDENING GUIDES · HANS STUDY

Hardening guides

The hardening reference on the site, by layer: the domain, Windows hosts, switches, firewalls, VMS hosts, and OT networks. Each guide keeps its own URL; this page is the index.

Domain and Active Directory

Hardening with Group Policy →

GPO structure, password policy, Kerberos, NTLM restriction, Advanced Audit Policy, Defender, SMBv1 removal, and LAPS via Group Policy.

Audit logging →

Advanced Audit Policy, domain controller GPO, event log sizing, Windows Event Forwarding, Sysmon, key event IDs, and log retention for Windows Server.

Windows Event Forwarding for security systems →

Collector sizing, source-initiated subscriptions by Group Policy, the query XML that pulls the right events from VMS and access control hosts, and the checks that prove forwarding is alive.

Deploying Active Directory for Genetec Security Center →

AD prerequisites, OU structure, service accounts, Group Policy, Kerberos configuration, and common pitfalls for Genetec AD integration.

Windows

Getting started →

Baseline Windows Server hardening: update management, roles audit, local accounts, Windows Firewall, services, NTP, PowerShell logging, and TLS.

Other considerations →

TLS 1.2 enforcement, legacy exceptions, Remote Desktop hardening, SMB signing, LAPS, and certificate management for Windows Server.

Windows Server 2025: what changed →

SMB signing and NTLM blocking on by default, Credential Guard on new installs, LAPS built in, delegated managed service accounts, and what breaks on a VMS or access control host.

Hardening security operator workstations →

Guard desk and control room machines are the most exposed hosts on the security network and the least hardened: OS choice, local admin removal, allow-listing, and lock policy for 24/7 desks.

Study Windows Configuration Utility →

Wizard-driven PowerShell script generator for Windows workstation and server hardening, with 49 sourced controls plus debloat targets.

Study CryptoConfig →

A Windows SCHANNEL and TLS configuration utility, in development. Join the waitlist to test it.

Switches

Cisco Catalyst 9200 and 9300 base configuration →

VLANs, SSH, AAA, port security, DHCP snooping, DAI, QoS, and syslog for physical security networks.

Aruba CX 6200 and 6300 base configuration →

AOS-CX configuration template: VLANs, SSH, AAA, VSF, port security, BPDU guard, LACP LAG, QoS, and syslog.

ALE OmniSwitch 6360 and 6560 base configuration →

AOS 8 configuration template: VLANs, SSH, AAA, Virtual Chassis, port security, BPDU guard, link aggregation, QoS, and syslog.

Juniper EX base configuration →

Junos OS configuration template: VLANs, SSH, AAA, Virtual Chassis, port security, BPDU guard, aggregated Ethernet, QoS, and syslog.

Switch configuration audit checklist →

The checklist behind the switch config audit tool: management plane, control plane, edge protection, VLAN hygiene, PoE, multicast, QoS, and logging, with the show commands that prove each one.

Switch Configuration Generator →

Base configuration generator for Cisco Catalyst, Aruba CX, and ALE OmniSwitch switches on CCTV and physical security networks.

Firewalls

There's no standalone firewall hardening guide on the site yet. The FortiBleed piece above is the closest related reading; the independent review of an existing firewall's rule base and configuration is a separate paid engagement at the firewall review page. See the firewall review page.

The firewall did its job: what FortiBleed was really about →

FortiBleed wasn't a firewall flaw. It was a pile of reused, never-rotated credentials with a brand name attached.

VMS hosts

Hardening Genetec Security Center: the baseline I deploy →

Windows server baselines, Defender exclusions done right, service-account discipline, SQL, segmentation, certificates, and RBAC.

Antivirus and Defender exclusions for video management systems →

Why real-time scanning breaks video recording, the exclusion lists for Genetec, Milestone, Avigilon, and Axis Camera Station, and how to prove they took.

Security System Hardening Guide →

End-to-end hardening reference for physical security network infrastructure: switches, servers, workstations, cameras, access control panels, and RADIUS.

Genetec CVE-2025-43028: the ALPR hole you have to close yourself →

A vulnerability in Security Center's ALPR Manager role over the legacy Patroller protocol, and why the patch alone doesn't close it.

SQL Server for Genetec Security Center →

Express versus Standard, max server memory, recovery models, autogrowth, index maintenance, and the SQL failures that take Security Center down.

OT networks

Security controls for OT networks that hold up in production →

Zones and conduits, the iDMZ, protocol awareness, passive monitoring, secure remote access, and the patching reality of a plant network.

Looking for the how-tos instead?

Network builds, IP addressing, VLANs, multicast, PoE budgets, and the Genetec how-to articles live on their own index.