Windows Server Hardening for D3 Agent

last updated: feb 01, 2024

att_50_for_15007789.png

The Proxy Agent does not need incoming TCP connections. It always initiates TCP connections to vSOC server and RestfulAPI targets. So we can block all incoming connections to the Windows server where D3 Proxy Agent is running on. Just run the powershell scripts to disable all the default enabled incoming firewall rules on Windows Server.

att_9_for_15007789.png
att_22_for_15007789.png