๐ย Secure Bits ๐ก
๐๐ป๐ณ๐ผ๐ฟ๐ฐ๐ถ๐ป๐ด ๐ฆ๐ ๐ ๐ฆ๐ถ๐ด๐ป๐ถ๐ป๐ด: ๐ฆ๐๐ถ๐น๐น ๐ฎ ๐๐ต๐ฎ๐น๐น๐ฒ๐ป๐ด๐ฒ ๐ถ๐ป ๐ฎ๐ฌ๐ฎ๐ฑ?
SMB Signing is one of those security controls thatย everyone shouldย have in place โ ๐๐ฒ๐, ๐บ๐ฎ๐ป๐ ๐ฝ๐ฟ๐ผ๐ฑ๐๐ฐ๐๐ถ๐ผ๐ป ๐ฒ๐ป๐๐ถ๐ฟ๐ผ๐ป๐บ๐ฒ๐ป๐๐ ๐๐๐ถ๐น๐น ๐ฑ๐ผ๐ปโ๐.
๐ก๐ช๐ต๐?
Until now, itโs been difficult to track which clients or applications would break once you enforce it.
While you could runย Get-SmbConnection | FL *ย from the client side to check signing/encryption status and SMB version, ๐๐ต๐ถ๐ ๐ฑ๐ผ๐ฒ๐๐ปโ๐ ๐๐ฐ๐ฎ๐น๐ฒ ๐๐ฒ๐น๐น.
But thatโs changing withย Windows Server 2025ย andย Windows 11 24H2.
๐ย ๐๐บ๐ฝ๐ฟ๐ผ๐๐ฒ๐ฑ ๐๐๐ฑ๐ถ๐๐ถ๐ป๐ด ๐ณ๐ผ๐ฟ ๐ฆ๐ ๐ ๐ฆ๐ถ๐ด๐ป๐ถ๐ป๐ด ๐ฎ๐ป๐ฑ ๐๐ป๐ฐ๐ฟ๐๐ฝ๐๐ถ๐ผ๐ป
You can now audit clients and servers that doย notย support SMB signing or encryption viaย Event Logs. Hereโs how:
๐ ๏ธย ๐๐ฃ๐ข ๐ฆ๐ฒ๐๐๐ถ๐ป๐ด๐
โช๏ธ Computer ConfigurationAdministrative TemplatesNetwork:
๐น Lanman WorkstationAudit server does not support encryption
๐น Lanman WorkstationAudit server does not support signing
๐น Lanman ServerAudit client does not support encryption
๐น Lanman ServerAudit client does not support signing
๐ย ๐๐๐ฒ๐ป๐ ๐๐ผ๐ด ๐ฃ๐ฎ๐๐ต๐ & ๐๐๐ฒ๐ป๐๐
โช๏ธ Applications and Services LogsMicrosoftWindows:
๐น SMBServerAudit
๐น SMBClientAudit
โก๏ธ Events:ย 3021โ3027
๐ ๐ง๐ต๐ฒ๐ฟ๐ฒโ๐ ๐ฎ๐น๐๐ผ ๐ฒ๐๐ฒ๐ป๐ ๐ฐ๐ฌ๐ฌ๐ฌ, ๐น๐ผ๐ฐ๐ฎ๐๐ฒ๐ฑ ๐ฎ๐:
โช๏ธ Applications and Services LogsMicrosoftWindows:
๐น SMBServerConnectivity
๐น SMBClientConnectivity
This seems to be enabled by default in WS2025 and is not controlled by the GPOs above.
โ ๏ธ There was also a Patch Tuesday update (๐๐ฉ๐-๐ฎ๐ฌ๐ฎ๐ฑ-๐ฑ๐ฑ๐ฎ๐ฏ๐ฐ) thatย shouldย backport these auditing features to older Windows versions โ but I havenโt been able to reproduce that yet (maybe I misunderstood this CVE). I also found out that registry values are different between WS 2025 and older versions of WS.
๐๐ ๐น๐ฎ๐๐, ๐๐ฒ ๐ฐ๐ฎ๐ป ๐ฎ๐๐ฑ๐ถ๐ ๐๐ต๐ถ๐ ๐ฎ๐ ๐๐ฐ๐ฎ๐น๐ฒ โ from theย server sideย โ and plan for aย safe SMB hardening rollout.
๐๐ฟ๐ฒ ๐๐ผ๐ ๐ถ๐ป๐๐ฒ๐ฟ๐ฒ๐๐๐ฒ๐ฑ ๐ถ๐ป ๐๐ฐ๐๐ถ๐๐ฒ ๐๐ถ๐ฟ๐ฒ๐ฐ๐๐ผ๐ฟ๐ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐?ย Check out my free resources:
๐ https://academy.horizon-secured.com/p/free-resources
