API → UI component mappings · 90,813 documents
| ID | Document | Source |
|---|---|---|
| a500564314f3c0ee | SCA Check 16127: Ensure 'Audit Security System Extension' is set to include 'Success'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0005', 'TA0006', 'TA0007'] Techniques: ['T1562',… | wazuh-sca |
| 0d29ecee8fdfd967 | SCA Check 16128: Ensure 'Audit System Integrity' is set to 'Success and Failure'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0005', 'TA0006', 'TA0007'] Techniques: ['T1562',… | wazuh-sca |
| 99b3bfda932cf37e | SCA Check 16129: Ensure 'Prevent enabling lock screen camera' is set to 'Enabled'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0007'] Techniques: ['T1595', 'T1046', 'T1087']… | wazuh-sca |
| d5e497ea7bbbe9a3 | SCA Check 16130: Ensure 'Prevent enabling lock screen slide show' is set to 'Enabled'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0007'] Techniques: ['T1595', 'T1046', 'T1087']… | wazuh-sca |
| bfd64c24ac73c762 | SCA Check 16131: Ensure 'Allow users to enable online speech recognition services' is set to 'Disabled'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0005'] Techniques: ['T1036',… | wazuh-sca |
| dabf767665993913 | SCA Check 16132: Ensure 'Allow Online Tips' is set to 'Disabled'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0001', 'TA0011'] Techniques: ['T1133', 'T1200', 'T1046', 'T1571',… | wazuh-sca |
| 020a9537fde674d9 | SCA Check 16133: Ensure LAPS AdmPwd GPO Extension / CSE is installed (MS only). Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0006', 'TA0003'] Techniques: ['T1078', 'T1098', 'T1110',… | wazuh-sca |
| 27498cf52b7eb7d7 | SCA Check 16134: Ensure 'Do not allow password expiration time longer than required by policy' is set to 'Enabled' (MS only). Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0006',… | wazuh-sca |
| a40dd77ef31a3097 | SCA Check 16135: Ensure 'Enable Local Admin Password Management' is set to 'Enabled' (MS only). Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0006', 'TA0003'] Techniques: ['T1078',… | wazuh-sca |
| fb83c6562ec4b78c | SCA Check 16136: Ensure 'Password Settings: Password Complexity' is set to 'Enabled: Large letters + small letters + numbers + special characters' (MS only). Policy: CIS Microsoft Windows Server 2016… | wazuh-sca |
| f6660c4fe022d982 | SCA Check 16137: Ensure 'Password Settings: Password Length' is set to 'Enabled: 15 or more' (MS only). Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0006', 'TA0003'] Techniques:… | wazuh-sca |
| 31cffe4a145aa0a5 | SCA Check 16138: Ensure 'Password Settings: Password Age (Days)' is set to 'Enabled: 30 or fewer' (MS only). Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0006', 'TA0003'] Techniques:… | wazuh-sca |
| af7bff2fb9c7d89c | SCA Check 16139: Ensure 'Apply UAC restrictions to local accounts on network logons' is set to 'Enabled' (MS only). Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0006', 'TA0003']… | wazuh-sca |
| 6cf81fde173a75b7 | SCA Check 16140: Ensure 'Configure RPC packet level privacy setting for incoming connections' is set to 'Enabled'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0007'] Techniques:… | wazuh-sca |
| 994c6f0724393a08 | SCA Check 16141: Ensure 'Configure SMB v1 client driver' is set to 'Enabled: Disable driver (recommended)'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0005'] Techniques: ['T1036',… | wazuh-sca |
| ca36b6a1e7f44031 | SCA Check 16142: Ensure 'Configure SMB v1 server' is set to 'Disabled'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0005'] Techniques: ['T1036', 'T1564'] This setting configures the… | wazuh-sca |
| a81d2f1e46ae712a | SCA Check 16143: Ensure 'Enable Structured Exception Handling Overwrite Protection (SEHOP)' is set to 'Enabled'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0002', 'TA0005']… | wazuh-sca |
| 91363d9bf4672360 | SCA Check 16144: Ensure 'LSA Protection' is set to 'Enabled'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0007'] Techniques: ['T1595', 'T1046', 'T1087'] This policy setting controls… | wazuh-sca |
| b449e80419fc3a78 | SCA Check 16145: Ensure 'NetBT NodeType configuration' is set to 'Enabled: P-node (recommended)'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0005'] Techniques: ['T1036', 'T1564']… | wazuh-sca |
| f80bcb5849e843dd | SCA Check 16146: Ensure 'WDigest Authentication' is set to 'Disabled'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0009', 'TA0010'] Techniques: ['T1005', 'T1025', 'T1041', 'T1567',… | wazuh-sca |
| b081645bf9effacf | SCA Check 16147: Ensure 'MSS: (AutoAdminLogon) Enable Automatic Logon (not recommended)' is set to 'Disabled'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0009', 'TA0010']… | wazuh-sca |
| 1f81cb0bef7c5ba1 | SCA Check 16148: Ensure 'MSS: (DisableIPSourceRouting IPv6) IP source routing protection level (protects against packet spoofing)' is set to 'Enabled: Highest protection, source routing is completely… | wazuh-sca |
| 9deeb710bfcbad70 | SCA Check 16149: Ensure 'MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing)' is set to 'Enabled: Highest protection, source routing is completely… | wazuh-sca |
| 2ba9c53867f22138 | SCA Check 16150: Ensure 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is set to 'Disabled'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0005']… | wazuh-sca |
| b1632d069de400ca | SCA Check 16151: Ensure 'MSS: (KeepAliveTime) How often keep-alive packets are sent in milliseconds' is set to 'Enabled: 300,000 or 5 minutes (recommended)'. Policy: CIS Microsoft Windows Server 2016… | wazuh-sca |
| 1943aaba85a7a078 | SCA Check 16152: Ensure 'MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers' is set to 'Enabled'. Policy: CIS Microsoft Windows Server… | wazuh-sca |
| 7daebf8b4c805ca8 | SCA Check 16153: Ensure 'MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses (could lead to DoS)' is set to 'Disabled'. Policy: CIS Microsoft Windows Server… | wazuh-sca |
| c240360754b3a06c | SCA Check 16154: Ensure 'MSS: (SafeDllSearchMode) Enable Safe DLL search mode (recommended)' is set to 'Enabled'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0002', 'TA0005']… | wazuh-sca |
| 8b45cc28d304354e | SCA Check 16155: Ensure 'MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires (0 recommended)' is set to 'Enabled: 5 or fewer seconds'. Policy: CIS Microsoft… | wazuh-sca |
| 2d3da20d243cd83b | SCA Check 16156: Ensure 'MSS: (TcpMaxDataRetransmissions IPv6) How many times unacknowledged data is retransmitted' is set to 'Enabled: 3'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics:… | wazuh-sca |
| 0baa6fc386a9e5c8 | SCA Check 16157: Ensure 'MSS: (TcpMaxDataRetransmissions) How many times unacknowledged data is retransmitted' is set to 'Enabled: 3'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics:… | wazuh-sca |
| 0a575b34f28d26d1 | SCA Check 16158: Ensure 'MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning' is set to 'Enabled: 90% or less'. Policy: CIS Microsoft… | wazuh-sca |
| 779cecf7e1658f99 | SCA Check 16159: Ensure 'Configure NetBIOS settings' is set to 'Enabled: Disable NetBIOS name resolution on public networks'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0007']… | wazuh-sca |
| a372b88fa54c8133 | SCA Check 16160: Ensure 'Turn off multicast name resolution' is set to 'Enabled'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0005'] Techniques: ['T1036', 'T1564'] LLMNR is a… | wazuh-sca |
| fa22ab5ae8d3680e | SCA Check 16161: Ensure 'Enable Font Providers' is set to 'Disabled'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0001', 'TA0002'] Techniques: ['T1190', 'T1059', 'T1204'] This… | wazuh-sca |
| cb07742b11895ece | SCA Check 16162: Ensure 'Enable insecure guest logons' is set to 'Disabled'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0001', 'TA0011'] Techniques: ['T1133', 'T1200', 'T1046',… | wazuh-sca |
| f8dc213a0c64a5ed | SCA Check 16163: Ensure 'Turn on Mapper I/O (LLTDIO) driver' is set to 'Disabled'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0005'] Techniques: ['T1036', 'T1564'] This policy… | wazuh-sca |
| d861ea100dbb91ef | SCA Check 16164: Ensure 'Turn on Responder (RSPNDR) driver' is set to 'Disabled'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0005'] Techniques: ['T1036', 'T1564'] This policy… | wazuh-sca |
| 8d712706352d39c6 | SCA Check 16165: Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0005'] Techniques: ['T1036', 'T1564']… | wazuh-sca |
| cdcce03ce15ebc03 | SCA Check 16166: Ensure 'Prohibit installation and configuration of Network Bridge on your DNS domain network' is set to 'Enabled'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics:… | wazuh-sca |
| 4fe4d9b85a9fe142 | SCA Check 16167: Ensure 'Prohibit use of Internet Connection Sharing on your DNS domain network' is set to 'Enabled'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0005'] Techniques:… | wazuh-sca |
| 22897c3b77f0b72a | SCA Check 16168: Ensure 'Require domain users to elevate when setting a network's location' is set to 'Enabled'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0007'] Techniques:… | wazuh-sca |
| d71458d977b77161 | SCA Check 16169: Ensure 'Hardened UNC Paths' is set to 'Enabled, with "Require Mutual Authentication" and "Require Integrity" set for all NETLOGON and SYSVOL shares'. Policy: CIS Microsoft Windows… | wazuh-sca |
| 599851dcab37ac89 | SCA Check 16170: Disable IPv6 (Ensure TCPIP6 Parameter 'DisabledComponents' is set to '0xff (255)'). Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0005'] Techniques: ['T1036',… | wazuh-sca |
| b3ebc29d58fe7f42 | SCA Check 16171: Ensure 'Configuration of wireless settings using Windows Connect Now' is set to 'Disabled'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0005'] Techniques: ['T1036',… | wazuh-sca |
| c6ffcc0c50070991 | SCA Check 16172: Ensure 'Prohibit access of the Windows Connect Now wizards' is set to 'Enabled'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0005'] Techniques: ['T1036', 'T1564']… | wazuh-sca |
| a83c800cdab6f4fe | SCA Check 16173: Ensure 'Minimize the number of simultaneous connections to the Internet or a Windows Domain' is set to 'Enabled: 1 = Minimize simultaneous connections'. Policy: CIS Microsoft Windows… | wazuh-sca |
| 86647eac4dd8ab59 | SCA Check 16174: Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled' (MS only). Policy: CIS Microsoft Windows Server 2016 v2.0.0… | wazuh-sca |
| 7a84805859a9901e | SCA Check 16175: Ensure 'Allow Print Spooler to accept client connections' is set to 'Disabled'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0007'] Techniques: ['T1595', 'T1046',… | wazuh-sca |
| 1035124aa45a5b25 | SCA Check 16176: Ensure 'Configure Redirection Guard' is set to 'Enabled: Redirection Guard Enabled'. Policy: CIS Microsoft Windows Server 2016 v2.0.0 Tactics: ['TA0007'] Techniques: ['T1595',… | wazuh-sca |