Skip to content

Add CIS Level 2 Windows 11 Defender Firewall policies (Testing & QA) - #54531

Open
kilo-code-bot[bot] wants to merge 1 commit into
mainfrom
mitch/cis-windows-firewall-policies
Open

kilo-code-bot[bot] wants to merge 1 commit into
mainfrom
mitch/cis-windows-firewall-policies

Conversation

@kilo-code-bot

@kilo-code-bot kilo-code-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Related issue: N/A

Checklist for submitter

  • Input data is properly validated, SELECT * is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters.

Summary

Adds three Windows policies enforcing CIS Microsoft Windows 11 Enterprise Benchmark Level 2 settings for Windows Defender Firewall, one per profile (Domain 9.1.x, Private 9.2.x, Public 9.3.x), under it-and-security/lib/windows/policies/:

  • cis-windows-11-firewall-domain-profile.yml
  • cis-windows-11-firewall-private-profile.yml
  • cis-windows-11-firewall-public-profile.yml

Each policy uses a registry-based query against HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\<Profile>Profile and its \Logging subkey, passing only when all settings match: firewall state On, inbound Block (default), outbound Allow (default), notifications disabled, log file name, log size >= 16384 KB, log dropped packets, and log successful connections. The Public profile additionally requires AllowLocalPolicyMerge = 0 and AllowLocalIPsecPolicyMerge = 0. CIS reference numbers are in each description, with a resolution.

The policies are referenced only in it-and-security/fleets/testing-and-qa.yml (new "Windows policies" section), same as the Apple Intelligence policy PR (#51976).

Testing

  • Added/updated automated tests
  • QA'd all new/changed functionality manually (queries not yet run on a Windows 11 host; CIS values and section numbers should be verified against the benchmark version in use)

AI

AI: Kilo (kilo/kilo-auto/frontier)


Built for Mitch Francese by Kilo for Slack

@kilo-code-bot
kilo-code-bot Bot requested a review from allenhouchins as a code owner October 1, 2026 14:31
@kilo-code-bot
kilo-code-bot Bot deployed to Docker Hub October 1, 2026 14:31 Active
@tux234 tux234 added the :sc-demo Used for issues and pull requests to showcase GitOps and agentic workflows for prospeects label Oct 1, 2026

This branch was successfully deployed

1 active deployment
Docker Hub — f0c72dcf Deployed Oct 1, 2026 by kilo-code-bot[bot] via publish #107098
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

:sc-demo Used for issues and pull requests to showcase GitOps and agentic workflows for prospeects

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant