Network restrictions for service hardening

(This is part 5 of our series of posts on service hardening.) Last but not least a service can be (and should be) configured to have network restrictions with what is called the “Windows Service Hardening” rules in the Windows SDK (we’ll call those WSH rules for short). As a service developer, it is your…

3

Write-restricted token

(This is part 4 of our series of posts on service hardening.) A service can be configured to be write-restricted, in addition to having a per-service SID. To do so, you specify a SID type of “Restricted” when configuring your service (see our previous post “Per-service SID”). In that case the process hosting your service…

1