From the Field: Services

๐Ÿ”Ž ๐—™๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—™๐—ถ๐—ฒ๐—น๐—ฑ โ€” Real-World Findings from Security Assessments

๐Ÿ’ฅ ๐Ÿณ๐Ÿญ.๐Ÿฐ%ย of infrastructures Iโ€™ve assessedย ๐—ฑ๐—ผ ๐—ป๐—ผ๐˜ ๐—ฑ๐—ถ๐˜€๐—ฎ๐—ฏ๐—น๐—ฒ ๐˜‚๐—ป๐—ป๐—ฒ๐—ฐ๐—ฒ๐˜€๐˜€๐—ฎ๐—ฟ๐˜† ๐˜€๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฐ๐—ฒ๐˜€

And yes โ€” weโ€™re back in the 70% range, I skipped them by mistake.

๐—ง๐—ต๐—ถ๐˜€ ๐—ถ๐˜€ ๐—ฎ ๐—พ๐˜‚๐—ถ๐—ฐ๐—ธ ๐˜„๐—ถ๐—ปย in Windows infrastructure security. Microsoft even provides aย guideย showing which services are safe to disable and which ones are critical โ€” follow it, verify what you actually use, and push the configuration through aย GPOย for all Windows Servers.

๐—ฌ๐—ผ๐˜‚ ๐—ฐ๐—ฎ๐—ป ๐˜‚๐˜€๐—ฒ ๐—ณ๐—ผ๐—น๐—น๐—ผ๐˜„๐—ถ๐—ป๐—ด ๐—š๐—ฃ๐—ข๐˜€:

โ†’ ๐˜Š๐˜ฐ๐˜ฎ๐˜ฑ๐˜ถ๐˜ต๐˜ฆ๐˜ณ ๐˜Š๐˜ฐ๐˜ฏ๐˜ง๐˜ช๐˜จ๐˜ถ๐˜ณ๐˜ข๐˜ต๐˜ช๐˜ฐ๐˜ฏ\๐˜—๐˜ฐ๐˜ญ๐˜ช๐˜ค๐˜ช๐˜ฆ๐˜ด\๐˜ž๐˜ช๐˜ฏ๐˜ฅ๐˜ฐ๐˜ธ๐˜ด ๐˜š๐˜ฆ๐˜ต๐˜ต๐˜ช๐˜ฏ๐˜จ๐˜ด\๐˜š๐˜ฆ๐˜ค๐˜ถ๐˜ณ๐˜ช๐˜ต๐˜บ ๐˜š๐˜ฆ๐˜ต๐˜ต๐˜ช๐˜ฏ๐˜จ๐˜ด\๐˜š๐˜บ๐˜ด๐˜ต๐˜ฆ๐˜ฎ ๐˜š๐˜ฆ๐˜ณ๐˜ท๐˜ช๐˜ค๐˜ฆ๐˜ด

โ†’ ๐˜Š๐˜ฐ๐˜ฎ๐˜ฑ๐˜ถ๐˜ต๐˜ฆ๐˜ณ ๐˜Š๐˜ฐ๐˜ฏ๐˜ง๐˜ช๐˜จ๐˜ถ๐˜ณ๐˜ข๐˜ต๐˜ช๐˜ฐ๐˜ฏ\๐˜—๐˜ณ๐˜ฆ๐˜ง๐˜ฆ๐˜ณ๐˜ฆ๐˜ฏ๐˜ค๐˜ฆ๐˜ด\๐˜Š๐˜ฐ๐˜ฏ๐˜ต๐˜ณ๐˜ฐ๐˜ญ ๐˜—๐˜ข๐˜ฏ๐˜ฆ๐˜ญ ๐˜š๐˜ฆ๐˜ต๐˜ต๐˜ช๐˜ฏ๐˜จ๐˜ด\๐˜š๐˜ฆ๐˜ณ๐˜ท๐˜ช๐˜ค๐˜ฆ๐˜ด

But for this use case,ย the first option is just fine.

โš™๏ธย ๐—ฆ๐—ฝ๐—ฒ๐—ฐ๐—ถ๐—ฎ๐—น ๐—ป๐—ผ๐˜๐—ฒ:

The Print Spooler is a known risk โ€”ย ๐—ฒ๐˜€๐—ฝ๐—ฒ๐—ฐ๐—ถ๐—ฎ๐—น๐—น๐˜† ๐—ผ๐—ป ๐——๐—ผ๐—บ๐—ฎ๐—ถ๐—ป ๐—–๐—ผ๐—ป๐˜๐—ฟ๐—ผ๐—น๐—น๐—ฒ๐—ฟ๐˜€.ย Itโ€™s true that DCs use the spooler for print pruning (cleaning stale print queues in AD), but this is a trade-off not worth the exposure.

If you disable the spooler, just schedule regular pruning instead โ€” and enjoy a much smaller attack surface.

โœ… Thatโ€™s all it takes to improve your security today.