{"id":42266,"date":"2021-08-11T16:00:00","date_gmt":"2021-08-11T16:00:00","guid":{"rendered":"https:\/\/www.microsoft.com\/security\/blog\/?p=95229"},"modified":"2021-08-11T16:00:00","modified_gmt":"2021-08-11T16:00:00","slug":"7-ways-to-harden-your-environment-against-compromise","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/7-ways-to-harden-your-environment-against-compromise\/","title":{"rendered":"7 ways to harden your environment against compromise"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/08\/SEC20_Security_032.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>Here at the global <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/06\/09\/crsp-the-emergency-team-fighting-cyber-attacks-beside-customers\/\" target=\"_blank\" rel=\"noopener\">Microsoft Compromise Recovery Security Practice<\/a> (CRSP), we work with customers who have experienced disruptive security incidents to restore trust in identity systems and remove adversary control. During 2020, the team responded to many incidents involving ransomware and the deployment of crypto-mining tools. Ransomware is a growing threat to organizations and home users, as it is a low-cost, high-return business model. These attacks aren\u2019t complex, they rely on tools and software exploits that have existed for many years and are still not remediated. They\u2019re still sought out for a simple reason: they still work.<\/p>\n<p>In this post, we hope to share with you the most practical and cost-effective ways of never needing our services.<\/p>\n<h2>Update and maintain your basic security<\/h2>\n<p>There is an old story about two hikers in the wilderness who see a bear coming towards them. One reaches for his running shoes and his friend says, \u201cyou\u2019ll never outrun a bear.\u201d The first hiker replies, \u201cI don\u2019t have to, I just need to outrun you.\u201d<\/p>\n<p>The theme behind this story echoes in the current cybersecurity threat landscape. The news is full of stories of cyberattacks, most of which are described as \u201cextremely sophisticated.\u201d However, the truth is the bulk of cyber incidents aren\u2019t particularly sophisticated. Most attackers aren\u2019t well-funded nation-states; they are just criminals trying to make some money. Direct <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2016\/04\/22\/ransomware-understanding-the-risk\/\" target=\"_blank\" rel=\"noopener\">financial gain<\/a> is a key motivator behind cyberattacks in 2020. This is particularly true when the victims are small to medium enterprises and non-profit sectors, like schools and charities. An easy way in which you can improve your security posture is with quick and efficient patching.<\/p>\n<p>In early 2020, <a href=\"https:\/\/www.microsoft.com\/security\/blog\/microsoft-detection-and-response-team-dart-blog-series\/\" target=\"_blank\" rel=\"noopener\">Microsoft\u2019s Detection and Response Team<\/a> (DART) was engaged by a public sector organization in Australia to investigate a cyberattack. The DART investigation determined that an attacker was originating from a foreign IP address. The Incident Response (IR) investigation discovered that the adversary started their attack by scanning internet-facing infrastructure for exposed ports to attack. In this instance, a remote desktop connection was opened directly to the internet to enable a software vendor to provide support. A weak administrative password was quickly forced. With administrative access to the exposed server, they performed some reasonably noisy network reconnaissance, utilizing commonly available hacking tools. Attackers quickly moved laterally across the network, escalating to Domain Controllers.<\/p>\n<p>Following the DART investigation, the CRSP team worked to recover the environment through re-establishing trust in the identity systems, hardening defenses, and removing the adversary\u2019s control. Although high profile and well-resourced, the public sector organization was a small organization of around 500 staff and had unfortunately fallen behind in security measures in recent years.<\/p>\n<p>From the initial brute force attack, the attacker achieved domain dominance in a matter of hours. In this attack, the adversary showed its financial motivation by deploying crypto-mining tools across all servers and workstations. As it was at the weekend, the attack went undiscovered for a period.<\/p>\n<p>There was no indication that the attack was targeted specifically at the organization, the attacker\u2019s motivations appeared to be purely financial. Crypto-mining is a low-risk, low-return payload, it requires no explicit choice on the part of the victim to pay them. Rewards are less but they are instant, perfect for high volume low-value attacks.<\/p>\n<p>The lessons from this incident are: if you can make it more difficult than average, low-skill attackers often give up quickly and move to the next target. Basically outrunning your friend, not the bear. A focus on fixing up the basics will go a long way to protecting most small and medium-sized enterprises. Below are seven (entirely non-exhaustive) areas that can quickly make you a harder target to hit\u2014and are all things we implement when engaged with customers on reactive projects.<\/p>\n<h3>1. Patch everything, faster<\/h3>\n<p>Aiming for full patch coverage within 48 hours will noticeably improve your security posture. <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows-server\/administration\/windows-server-update-services\/get-started\/windows-server-update-services-wsus\" target=\"_blank\" rel=\"noopener\">Patch your servers<\/a> as soon as you can, with a focus on Tier 0 systems such as Domain Controllers and Microsoft Azure Active Directory Connect.<\/p>\n<p>Application patching is equally important, particularly business productivity applications such as email clients, VPN clients, and web browsers. Enable automatic updating of your web browsers be it Edge, Chrome, Firefox, or others. Out of date browsers expose user data and the device to compromise. Using the cloud and Windows Update for Business can help to automate patching and remove some of the maintenance burdens when your organization\u2019s workforce is distributed, especially with a distributed pandemic style workforce.<\/p>\n<p>As part of a Compromise Recovery we work to make sure our customers can <a href=\"https:\/\/azure.microsoft.com\/en-gb\/blog\/azure-update-management-a-year-of-great-updates\/\" target=\"_blank\" rel=\"noopener\">patch their most important assets<\/a> within hours, this usually includes implementing rapid patch approval processes and test cycles for critical workloads. We see a great deal of benefit in keeping your patching systems separate for your key workloads, like implementing a dedicated update management tool just for Domain Controllers.<\/p>\n<h3>2. Actively protect your devices<\/h3>\n<p>A well-configured up-to-date Windows device running <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/threat-protection\/endpoint-defender\" target=\"_blank\" rel=\"noopener\">Microsoft Defender for Endpoint<\/a> or another extended detection and response (XDR) solution should be your first line of defense. Coupled with a <a href=\"https:\/\/azure.microsoft.com\/en-gb\/services\/azure-sentinel\/#overview\" target=\"_blank\" rel=\"noopener\">security incident event management<\/a> (SIEM) system for your critical and key business systems, this will help give you visibility over your important assets. Make sure people are looking at alerts and tracking activities.<\/p>\n<p>After we have spent time with our customers, we like to make sure that everything that happens within their important business systems is being well monitored and managed. Being able to react to anything which may occur in this environment is vital to maintain ongoing assurance in an environment.<\/p>\n<h3>3. Reduce your exposure<\/h3>\n<p>Opening any service to the internet comes with inherent risks. One risk is that anything connected to the internet is routinely and regularly scanned. As we saw with the recent <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/03\/02\/hafnium-targeting-exchange-servers\/\" target=\"_blank\" rel=\"noopener\">HAFNIUM exploit<\/a> anything that is found vulnerable will potentially be exploited within minutes of coming online.<\/p>\n<p>Additionally, there are publicly available resources of services available online. Not only are these results of interest to hackers looking to exploit resources but can be of use to those looking to enhance their security posture.<\/p>\n<p><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/firewall\/features\" target=\"_blank\" rel=\"noopener\">A firewall that restricts access<\/a> to defined source addresses will mitigate the risk somewhat, as will placing them behind a <a href=\"https:\/\/azure.microsoft.com\/en-gb\/services\/vpn-gateway\/\" target=\"_blank\" rel=\"noopener\">VPN connection<\/a>, especially one that requires <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/security\/identity-protection\/hello-for-business\/hello-overview\" target=\"_blank\" rel=\"noopener\">two-factor authentication<\/a>.<\/p>\n<p>If your servers are in Azure or another cloud, use a <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/virtual-network\/network-security-groups-overview\" target=\"_blank\" rel=\"noopener\">network security group<\/a> to restrict access to specific IPs, or even better use <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/security-center-just-in-time?tabs=jit-config-asc%2Cjit-request-asc\" target=\"_blank\" rel=\"noopener\">just-in-time access<\/a> and <a href=\"https:\/\/azure.microsoft.com\/en-us\/services\/azure-bastion\/\" target=\"_blank\" rel=\"noopener\">Microsoft Azure Bastion<\/a>.<\/p>\n<p>In our customer example, Remote Desktop Protocol was exposed directly to the internet, with no mitigating controls.<\/p>\n<p>We work with our customers to justify and reduce exposure of any internet-facing services within an environment. We work alongside administrative practices to make sure administrators can still fully maintain a system but doing so in a more secure way.<\/p>\n<h3>4. Reduce your privilege<\/h3>\n<p>Most attacks rely on the attacker obtaining administrative access. If we can limit exposure, we go a long way to blocking many attacks. Having a common local admin password makes lateral movement and elevation of privilege a trivial task for attackers.<\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=46899\" target=\"_blank\" rel=\"noopener\">Local Administrator Password Solution<\/a> (LAPS), which manages local administration accounts on systems, has been available for nearly six years and is free. Nonetheless, on many engagements, we see it has not been deployed. Deploy it on your network today.<\/p>\n<p>In our public-sector example, the attacker was able to extract highly privileged credentials from an application server. Deploying privilege management and just-in-time admin solutions add great value but can be complex and take time. Quick wins can be had by looking at the membership of your critical security groups, like Domain and Enterprise Administrators, and reducing to just those who really need it. In all but the largest of environments, you should be able to count the number of Domain Administrators on the fingers of one hand.<\/p>\n<p>Using a <a href=\"https:\/\/docs.microsoft.com\/en-us\/security\/compass\/privileged-access-devices\" target=\"_blank\" rel=\"noopener\">dedicated administrator workstation<\/a> for high-value tasks reduces the risk that administrator credentials will be stolen. Even the most careful of people sometimes click the wrong link. It\u2019s not a good idea to use your administrator account on the same PC that you read emails or surf the web due to the risks that it introduces to your privilege.<\/p>\n<p>Use <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows-server\/security\/group-managed-service-accounts\/group-managed-service-accounts-overview\" target=\"_blank\" rel=\"noopener\">Managed Service Accounts<\/a> with automatically rotating passwords, if an application vendor tells you that their service account needs to be an administrator, it\u2019s time to push back hard.<\/p>\n<p>Read more on our guidance surrounding <a href=\"https:\/\/aka.ms\/spa\" target=\"_blank\" rel=\"noopener\">securing privileged access<\/a>.<\/p>\n<p>Having dedicated hardened devices just for administrators is a great and cost-effective way to tactically increase your security. Having a standalone machine without email or web browsing greatly increases the difficulties attackers face.<\/p>\n<p>For our public sector customer, limits to the use of privilege would have made it much harder for the attacker to move from the initial beachhead on the exposed server to the rest of the environment.<\/p>\n<h3>5. Utilize the power of the cloud<\/h3>\n<p>Consider what services you still need to run on-premises. If you don\u2019t have a very explicit need to do it yourself, let someone else. The shared responsibility model in the cloud gives you the chance to reduce your exposure and delegate the security of the platform to a cloud provider. The <a href=\"https:\/\/azure.microsoft.com\/en-gb\/pricing\/details\/virtual-machine-scale-sets\/windows\/\" target=\"_blank\" rel=\"noopener\">cloud can scale automatically<\/a> where traditional IT cannot, and the same should be said for <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/connect-data-sources\" target=\"_blank\" rel=\"noopener\">security services in the cloud<\/a>.<\/p>\n<p>Look at what you are running and replace it with platform as a service (PaaS) or software as a service (SaaS) applications where you can.<\/p>\n<p>As an example, on-premises Exchange servers are a great product, but they require maintenance, patching, and configuration. Migration of mailboxes to <a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/exchange\/exchange-online\" target=\"_blank\" rel=\"noopener\">Exchange Online<\/a> removes a lot of work and decreases the attack surface by blocking most malicious and phishing links before they get to mailboxes.<\/p>\n<p>Running a secure <a href=\"https:\/\/azure.microsoft.com\/en-us\/services\/app-service\/\" target=\"_blank\" rel=\"noopener\">web server<\/a> in your environment can be hard if you can, in the longer term, move to a cloud-based solution in Azure or another cloud. This wouldn\u2019t have been relevant in this instance, but it\u2019s a common attack vector.<\/p>\n<p>Utilize modern cloud-powered security tools like <a href=\"https:\/\/azure.microsoft.com\/en-us\/services\/security-center\/\" target=\"_blank\" rel=\"noopener\">Azure Security Center<\/a> and <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/defender-for-servers-introduction\" target=\"_blank\" rel=\"noopener\">Azure Defender<\/a>. Even if your servers reside <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/security-center-powershell-onboarding#:~:text=%20Onboard%20Security%20Center%20using%20PowerShell%20%201,agent%20on%20your%20Azure%20VMs%3A%0APowerShell%0ASet-AzContext%20-Subscription...%20More%20\" target=\"_blank\" rel=\"noopener\">on-premises or in another cloud<\/a>, they can still be configured to report to the Security Center giving you a picture of your security posture. The use of a SIEM system such as <a href=\"https:\/\/azure.microsoft.com\/en-us\/blog\/introducing-microsoft-azure-sentinel-intelligent-security-analytics-for-your-entire-enterprise\/\" target=\"_blank\" rel=\"noopener\">Microsoft Azure Sentinel<\/a> can give increased visibility of potential attacks.<\/p>\n<p>Had our attacked customer been using cloud security solutions, they would have seen the attack happening.<\/p>\n<h3>6. Pay down your technical debt<\/h3>\n<p>Running legacy operating systems increases your vulnerability to attacks that exploit long-standing vulnerabilities. Where possible, look to decommission or upgrade <a href=\"https:\/\/docs.microsoft.com\/en-us\/lifecycle\/\" target=\"_blank\" rel=\"noopener\">legacy Windows operating systems<\/a>. Legacy protocols can increase risk. Older file share technologies are a well-known attack vector for ransomware but are still in use in many environments.<\/p>\n<p>In this incident, there were many systems, including Domain Controllers, that hadn\u2019t been patched recently. This greatly aided the attacker in their movement across the environment. As part of helping customers, we look at the most important systems and make sure we are running the most up-to-date protocols that we can to further enhance an environment.<\/p>\n<h3>7. Look at your logs and act on alerts<\/h3>\n<p>As the saying goes, \u201ccollection is not detection.\u201d On many engagements, the attacker\u2019s actions are clear and obvious in event logs. The common problem is no one is looking at them on a day-to-day basis or understanding what normal looks like. Unexplained changes to event logs, such as deletion or retention changes, should be considered suspicious and investigated.<\/p>\n<p>In this incident, the attacker\u2019s actions could easily be traced through logs after the fact. A SIEM system, which collates logs from many sources, was traditionally a major investment and out of reach for all but large enterprises. With <a href=\"https:\/\/azure.microsoft.com\/en-us\/services\/azure-sentinel\/\" target=\"_blank\" rel=\"noopener\">Azure Sentinel<\/a>, it\u2019s now within reach for everyone\u2014with no requirements for on-premises infrastructure and requiring no upfront investment. Simply deploy agents to your systems (it doesn\u2019t matter if they are on-premises, Azure, or another cloud).<\/p>\n<h2>Learn more<\/h2>\n<p>There is no magical technology solution that is going to make you a harder target to hit. The <a href=\"https:\/\/www.microsoft.com\/security\/blog\/microsoft-detection-and-response-team-dart-blog-series\/\" target=\"_blank\" rel=\"noopener\">Microsoft DART<\/a> and <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/06\/09\/crsp-the-emergency-team-fighting-cyber-attacks-beside-customers\/\" target=\"_blank\" rel=\"noopener\">CSRP teams<\/a> are a great crowd of people, friendly and helpful, but you really don\u2019t have to meet us.<\/p>\n<p>A determined, well-resourced threat actor will, in time, breach the best cyber defenses. In summary, it\u2019s not possible to outrun the bear, but taking the first steps to make yourself a harder target will make it much more likely that attackers will move on to easier targets.<\/p>\n<p>To learn more about Microsoft Security solutions,&nbsp;<a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/solutions\" target=\"_blank\" rel=\"noopener\">visit our&nbsp;website<\/a>.&nbsp;Bookmark the&nbsp;<a href=\"https:\/\/www.microsoft.com\/security\/blog\/\" target=\"_blank\" rel=\"noopener\">Security blog<\/a>&nbsp;to keep up with our expert coverage on security matters. Also, follow us at&nbsp;<a href=\"https:\/\/twitter.com\/@MSFTSecurity\" target=\"_blank\" rel=\"noopener\">@MSFTSecurity<\/a>&nbsp;for the latest news and updates on cybersecurity.<\/p>\n<p> READ MORE <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/08\/11\/7-ways-to-harden-your-environment-against-compromise\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Here at the global Microsoft Compromise Recovery Security Practice (CRSP), we work with customers who have experienced disruptive security incidents to restore trust in identity systems and remove adversary control. During 2020, the team responded to many incidents involving ransomware and the deployment of crypto-mining tools.<br \/>\nThe post 7 ways to harden your environment against compromise appeared first on Microsoft Security Blog. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":42267,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[347],"class_list":["post-42266","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-secure","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>7 ways to harden your environment against compromise 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/7-ways-to-harden-your-environment-against-compromise\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"7 ways to harden your environment against compromise 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/7-ways-to-harden-your-environment-against-compromise\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-08-11T16:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/08\/7-ways-to-harden-your-environment-against-compromise.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"800\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/7-ways-to-harden-your-environment-against-compromise\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/7-ways-to-harden-your-environment-against-compromise\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"7 ways to harden your environment against compromise\",\"datePublished\":\"2021-08-11T16:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/7-ways-to-harden-your-environment-against-compromise\\\/\"},\"wordCount\":2129,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/7-ways-to-harden-your-environment-against-compromise\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/7-ways-to-harden-your-environment-against-compromise.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/7-ways-to-harden-your-environment-against-compromise\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/7-ways-to-harden-your-environment-against-compromise\\\/\",\"name\":\"7 ways to harden your environment against compromise 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/7-ways-to-harden-your-environment-against-compromise\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/7-ways-to-harden-your-environment-against-compromise\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/7-ways-to-harden-your-environment-against-compromise.jpg\",\"datePublished\":\"2021-08-11T16:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/7-ways-to-harden-your-environment-against-compromise\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/7-ways-to-harden-your-environment-against-compromise\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/7-ways-to-harden-your-environment-against-compromise\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/7-ways-to-harden-your-environment-against-compromise.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/7-ways-to-harden-your-environment-against-compromise.jpg\",\"width\":1200,\"height\":800},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/7-ways-to-harden-your-environment-against-compromise\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cybersecurity\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/cybersecurity\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"7 ways to harden your environment against compromise\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"7 ways to harden your environment against compromise 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/7-ways-to-harden-your-environment-against-compromise\/","og_locale":"en_US","og_type":"article","og_title":"7 ways to harden your environment against compromise 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/7-ways-to-harden-your-environment-against-compromise\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-08-11T16:00:00+00:00","og_image":[{"width":1200,"height":800,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/08\/7-ways-to-harden-your-environment-against-compromise.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/7-ways-to-harden-your-environment-against-compromise\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/7-ways-to-harden-your-environment-against-compromise\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"7 ways to harden your environment against compromise","datePublished":"2021-08-11T16:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/7-ways-to-harden-your-environment-against-compromise\/"},"wordCount":2129,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/7-ways-to-harden-your-environment-against-compromise\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/08\/7-ways-to-harden-your-environment-against-compromise.jpg","keywords":["Cybersecurity"],"articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/7-ways-to-harden-your-environment-against-compromise\/","url":"https:\/\/www.threatshub.org\/blog\/7-ways-to-harden-your-environment-against-compromise\/","name":"7 ways to harden your environment against compromise 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/7-ways-to-harden-your-environment-against-compromise\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/7-ways-to-harden-your-environment-against-compromise\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/08\/7-ways-to-harden-your-environment-against-compromise.jpg","datePublished":"2021-08-11T16:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/7-ways-to-harden-your-environment-against-compromise\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/7-ways-to-harden-your-environment-against-compromise\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/7-ways-to-harden-your-environment-against-compromise\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/08\/7-ways-to-harden-your-environment-against-compromise.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/08\/7-ways-to-harden-your-environment-against-compromise.jpg","width":1200,"height":800},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/7-ways-to-harden-your-environment-against-compromise\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Cybersecurity","item":"https:\/\/www.threatshub.org\/blog\/tag\/cybersecurity\/"},{"@type":"ListItem","position":3,"name":"7 ways to harden your environment against compromise"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/42266","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=42266"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/42266\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/42267"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=42266"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=42266"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=42266"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}