Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 16 Current »


Product Name

CIS-CAT Pro Assessor v4

Product Version

all

Date



When CIS-CAT Pro connects to a remote Windows target for assessment, it requires an SMB connection in order to;

  • Create an "ephemeral" folder on that target system to hold scripts required for collection of necessary information

  • To allow CIS-CAT Pro to transfer the scripts from the machine executing CIS-CAT to that "ephemeral" folder.

Once the scripts are transferred from the CIS-CAT host to the "ephemeral" directory, WinRM commands are used to execute those scripts in order to collect the necessary information for assessment, such as password policies, account policies, registry keys, user rights assignments, etc.

Once the assessment is completed and the connection to the remote target is being closed, SMB is again used to remove the "ephemeral" directory and all those scripts from the target system.

To allow connection to the target host using SMB, ensure it is reachable on port 445

You can use a powershell command to test for that remote system SMB port connection;

Test-NetConnection -ComputerName <IP Address> -Port 445 -InformationLevel Detailed

Related Content


Copyright © 2020

Center for Internet Security®


  • No labels