Draft — pending lab results. Scores and fixes are not yet measured; this document shows the assessment plan and expected findings.
The assessment plan expects 11 findings in the baseline domain; 11 still open. 2 rated critical: each could lead to full control of the domain.
| Severity | Findings | Open |
|---|---|---|
| Critical | 2 | 2 |
| High | 6 | 6 |
| Medium | 3 | 3 |
| Low | 0 | 0 |
PingCastle risk points: lower is better. Maturity level: higher is better.
| Metric | Before | After | Change |
|---|---|---|---|
| Global score (lower is better) | Pending | Pending | Pending |
| Stale objects | Pending | Pending | Pending |
| Privileged accounts | Pending | Pending | Pending |
| Trusts | Pending | Pending | Pending |
| Anomalies | Pending | Pending | Pending |
| Maturity level (higher is better) | Pending | Pending | Pending |
Evidence: Expected: PingCastle privileged-group rules; BloodHound shows svc-app as a path to Domain Admins
Business impact: Anyone who compromises the application or its host controls the whole domain.
Remediation: Replace the account with a group-managed service account (gMSA) that holds only the rights the app needs.
Status: open
Evidence: Expected: BloodHound sessions of Domain Admins on ws01/ws02
Business impact: Compromising any workstation can expose domain-admin credentials.
Remediation: Tiered administration with separate admin accounts and logon restrictions per tier.
Status: open
Evidence: Expected: PingCastle stale/privileged rules for passwords that never expire
Business impact: A leaked or guessed password stays valid indefinitely.
Remediation: gMSA passwords are 120 characters and rotated automatically by the domain.
Status: open
Evidence: Expected: PingCastle LAPS rule; Policy Analyzer shows no LAPS policy
Business impact: One stolen local password gives administrator access to every workstation and server.
Remediation: Deploy Windows LAPS so each machine has a unique, rotated password stored in AD.
Status: open
Evidence: Expected: PingCastle SMBv1 rule for app01
Business impact: An obsolete protocol with known critical vulnerabilities and no modern protections.
Remediation: Disable SMBv1 and require SMB signing.
Status: open
Evidence: Expected: PingCastle NTLMv1 rule; Policy Analyzer LmCompatibilityLevel below 5
Business impact: Captured authentication exchanges can be cracked or relayed easily.
Remediation: Set LmCompatibilityLevel to 5 (NTLMv2 only, refuse LM and NTLM).
Status: open
Evidence: Expected: BloodHound shows GG-Helpdesk → ForceChangePassword → adm.app → AdminTo → app01
Business impact: A compromised helpdesk account takes over a Tier 1 admin account, and every server it administers, in one step.
Remediation: Remove the delegation from the Admin OU; delegate helpdesk rights only on user OUs.
Status: open
Evidence: Expected: PingCastle spooler-on-DC rule
Business impact: A service with a history of critical vulnerabilities, exposed on the most sensitive server.
Remediation: Stop and disable the Print Spooler on domain controllers.
Status: open
Evidence: Expected: PingCastle LDAP signing / channel binding rules
Business impact: LDAP traffic to the domain controller can be tampered with or relayed.
Remediation: Require LDAP server signing and always enforce channel binding.
Status: open
Evidence: Expected: PingCastle stale-objects rules (inactive > 90 days)
Business impact: Forgotten accounts are unmonitored entry points.
Remediation: Review, then disable accounts inactive for more than 90 days.
Status: open
Evidence: Expected: PingCastle password-policy rules; Policy Analyzer minimum length below baseline
Business impact: Short passwords and no lockout make guessing attacks practical.
Remediation: Minimum length 14, lockout after 10 attempts, stricter fine-grained policy for administrators.
Status: open
| Finding | Severity | Remediation | Automation | Status |
|---|---|---|---|---|
| F01 Service account is a member of Domain Admins | critical | Replace the account with a group-managed service account (gMSA) that holds only the rights the app needs. | scripts/harden/Convert-ServiceAccountToGmsa.ps1 | open |
| F09 Domain administrators log on to workstations (no tiering) | critical | Tiered administration with separate admin accounts and logon restrictions per tier. | scripts/harden/Set-TieredAdminModel.ps1 | open |
| F02 Service account password never expires and is years old | high | gMSA passwords are 120 characters and rotated automatically by the domain. | scripts/harden/Convert-ServiceAccountToGmsa.ps1 | open |
| F03 Same local Administrator password on every machine (no LAPS) | high | Deploy Windows LAPS so each machine has a unique, rotated password stored in AD. | scripts/harden/Enable-WindowsLaps.ps1 | open |
| F04 SMBv1 enabled on the file server | high | Disable SMBv1 and require SMB signing. | scripts/harden/Disable-LegacyProtocols.ps1 | open |
| F05 NTLMv1 and LM authentication allowed | high | Set LmCompatibilityLevel to 5 (NTLMv2 only, refuse LM and NTLM). | scripts/harden/Disable-LegacyProtocols.ps1 | open |
| F07 Helpdesk group can reset passwords of administrator accounts | high | Remove the delegation from the Admin OU; delegate helpdesk rights only on user OUs. | scripts/harden/Set-TieredAdminModel.ps1 | open |
| F11 Print Spooler running on the domain controller | high | Stop and disable the Print Spooler on domain controllers. | scripts/harden/Disable-SpoolerOnDC.ps1 | open |
| F06 LDAP signing and channel binding not required | medium | Require LDAP server signing and always enforce channel binding. | scripts/harden/Set-LdapSigning.ps1 | open |
| F08 Stale enabled user and computer accounts | medium | Review, then disable accounts inactive for more than 90 days. | scripts/harden/Get-StaleAccounts.ps1 | open |
| F10 Weak domain password and lockout policy | medium | Minimum length 14, lockout after 10 attempts, stricter fine-grained policy for administrators. | scripts/harden/Set-PasswordPolicy.ps1 | open |
All testing was performed in an isolated lab environment owned by the author. No real organization's data, hostnames or configurations are included.