Read-only local campaign artifact
server-hardening-readonly-assessment.md
direct-local-ops-wave-6/server-hardening-readonly-assessment.md
# Server hardening -- local Windows read-only assessment ## Direct result The bounded Windows status and exposure checks completed without altering this PC. | Area | Observed result | Disposition | | --- | --- | --- | | Microsoft Defender | Normal mode with antivirus, antispyware, IOAV, and real-time protection enabled | Healthy observation | | Firewall baseline | Domain, Private, and Public profiles enabled; inbound defaults set to Block | Healthy observation | | Selected service posture | RemoteRegistry is disabled and stopped; WinRM is stopped and manual | No change made | | Network listeners | Inventory collected only | Requires owner-reviewed allowlist before any remediation | ## Why this is PARTIAL The skill requires explicit target selection and a hardened-change decision before firewall, service, account, or port remediation. A safe assessment is complete, but hardening was intentionally not applied. ## Next real run Name the Windows target and approve a change window plus a listener allowlist. Then produce a backup/rollback point before changing firewall, services, or SSH policy.