← Back to Projects
Business Systems House 2025
Enterprise Endpoint Software Firewalls & Connection Rule Baselines
Windows Defender Firewall Group Policy (GPO) Connection Rules Network Isolation Endpoint Security
Enterprise Endpoint Software Firewalls & Connection Rule Baselines
Standardized host-based software firewall rules across all domain workstations to prevent lateral network movement during malware incidents.
Key Features & Implementation
- Inbound Default-Deny Baselines: Enforced default-deny inbound rules on all domain and private network firewall profiles.
- Management Port Restrictions: Restricted inbound WinRM, RDP, and SMB management ports exclusively to authorized Jump Host IP subnets.
- Outbound Application Whitelisting: Blocked unauthorized outbound connections from non-standard system directories to prevent reverse shell callbacks.