The videos and the summary are AI generated. AI was also used for finding ways of remediating the STIGs

Date of completion: 01/2026

STIG Application (STIG-ID: WN11-CC-000315)
STIG Application (STIG-ID: WN11-AU-000050)
STIG Application (STIG-ID: WN11-CC-000090)
STIG Application (STIG-ID: WN11-EP-000310)
STIG Application (STIG-ID: WN11-CC-000110)
STIG Application (STIG-ID: WN11-CC-000197)
STIG Application (STIG-ID: WN11-CC-000285)

In brief

Explainer video

Project: DISA STIG Compliance Auditing & Hardening

Objective
To enforce Department of Defense (DoD) security standards by auditing a Windows 11 endpoint against the Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) and remediating non-compliant configurations.

Tools & Technologies

  • Cloud Platform: Microsoft Azure (Virtual Machines)
  • Compliance Scanner: Tenable Vulnerability Management (Policy Compliance Auditing)
  • Standard: DISA STIG
  • Remediation: PowerShell (ISE), Local Group Policy Editor, AI-Assisted Scripting

Methodology

1. Infrastructure & Scan Configuration

  • Deployed a Windows 11 Azure VM (StigHD1232) and prepared it for internal scanning by modifying the LocalAccountTokenFilterPolicy and temporarily disabling the Windows Defender Firewall to ensure full scanner visibility.
  • Configured a Policy Compliance Auditing scan in Tenable, selecting the strict DISA STIG benchmark to evaluate the system against military-grade security controls.

2. Baseline Audit

  • The initial compliance scan revealed significant hardening gaps, returning 152 Failed checks and only 102 Passed checks.
  • High-priority failures identified included insecure installer privileges, lack of DMA protection, and unsecure RPC communication.

3. Hybrid Remediation Strategy

  • Automated Scripting: Leveraged PowerShell and AI assistance (Google Gemini) to rapidly remediate registry-based vulnerabilities. Key controls fixed included:
  • WN11-CC-000315: Disabled “Always install with elevated privileges” to prevent privilege escalation.
  • WN11-EP-000310: Enabled Kernel Direct Memory Access (DMA) Protection.
  • WN11-CC-000110: Prevented printing over HTTP.
  • Manual Policy Configuration: Utilized the Local Group Policy Editor to enforce behavioral restrictions, such as turning off Microsoft consumer experiences (WN11-CC-000197) and requiring secure RPC communication (WN11-CC-000285).

4. Validation

  • Executed a post-remediation verification scan. The results confirmed the successful remediation of the targeted controls, raising the “Passed” count from 102 to 111 and reducing the overall risk profile of the machine.

Key Takeaway

This lab demonstrated the complexity of compliance management compared to standard vulnerability scanning. Unlike simple software patching, achieving STIG compliance requires a deep understanding of OS internals (Registry & GPO). It also highlighted the value of hybrid remediation—using PowerShell for scalable, registry-level fixes and Group Policy for nuanced, behavior-based controls.