Securing Remote PS
Securing Remoting Sessions¶
Implement robust encryption, authentication, and audit logging to protect remote session integrity and confidentiality.
Encryption Requirements¶
Enforce strong encryption protocols to secure data in transit:
- TLS 1.2+ Enforcement:
# Enable TLS 1.2 and disable older protocols
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
- HTTPS Usage: Configure remoting endpoints (e.g., IIS, PowerShell remoting) to use HTTPS with valid SSL/TLS certificates.
Authentication Best Practices¶
Strengthen access control to prevent unauthorized session entry:
- Certificate-Based Authentication:
# Configure WinRM to require client certificates
Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\WinRM\Client" -Name "EnableCredSSP" -Value 1
Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\WinRM\Client" -Name "TrustedHosts" -Value "*"
- Multi-Factor Authentication (MFA): Integrate MFA via Azure AD, Microsoft Authenticator, or third-party solutions for administrative remoting.
- Session Timeouts:
# Set idle session timeout to 15 minutes
Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\WinRM\Service" -Name "IdleTimeoutSec" -Value 900
Audit Logging¶
Enable detailed logging to track remote session activity and detect suspicious behavior.
Enable WinRM Logging¶
Configure WinRM to log requests and responses:
# Set log directory and level (0 = None, 4 = Full)
Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\WinRM\Service" -Name "LogLevel" -Value 4
Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\WinRM\Service" -Name "LogPath" -Value "C:\Windows\System32\LogFiles\WinRM"
Monitor Logs¶
Use Event Viewer to review security events:
- Event ID 4104: Successful WinRM connection.
- Event ID 4105: Failed authentication attempt.
- Event ID 4106: Successful authentication.
Regularly analyze logs for anomalies, such as repeated failed attempts or unexpected client IPs.