Configures Windows Group Policy Objects (GPO) to prevent ransomware
SKILL.md
Implementing Anti-Ransomware Group Policy
When to Use
Hardening a Windows Active Directory environment against ransomware execution and propagation
Implementing defense-in-depth by blocking ransomware execution paths via Group Policy
Configuring AppLocker or WDAC rules to prevent unauthorized executables from running in user-writable directories
Enabling Controlled Folder Access to protect critical directories from unauthorized file modifications
Restricting lateral movement vectors (RDP, SMB, WMI) that ransomware uses to spread across the domain
Do not use as a standalone ransomware defense. GPO settings complement but do not replace endpoint detection, backups, network segmentation, and user awareness training.
Prerequisites
Windows Server 2016+ Active Directory environment with Group Policy Management Console (GPMC)
Domain Admin or Group Policy Creator Owners privileges
Windows 10/11 Enterprise or Education (required for AppLocker and WDAC)
Microsoft Defender Antivirus enabled (required for Controlled Folder Access and ASR rules)
Python 3.8+ for audit script that validates GPO compliance
Test OU for validating GPO settings before domain-wide deployment
Workflow
Step 1: Block Ransomware Execution Paths with AppLocker
Configure AppLocker to prevent executables from running in common ransomware staging locations:
Enable ASR rules that target ransomware delivery mechanisms:
ASR Rules GPO Path:
Computer Configuration → Administrative Templates →
Windows Components → Microsoft Defender Antivirus →
Microsoft Defender Exploit Guard → Attack Surface Reduction
Critical ASR Rules for Ransomware Prevention:
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
GUID Rule
BE9BA2D9-53EA-4CDC-84E5-9B1EEEE46550 Block executable content from email
D4F940AB-401B-4EFC-AADC-AD5F3C50688A Block Office apps from creating child processes
3B576869-A4EC-4529-8536-B80A7769E899 Block Office apps from creating executable content
75668C1F-73B5-4CF0-BB93-3ECF5CB7CC84 Block Office apps from injecting into processes
D3E037E1-3EB8-44C8-A917-57927947596D Block JavaScript/VBScript from launching downloads
5BEB7EFE-FD9A-4556-801D-275E5FFC04CC Block execution of obfuscated scripts
92E97FA1-2EDF-4476-BDD6-9DD0B4DDDC7B Block Win32 API calls from Office macros
01443614-CD74-433A-B99E-2ECDC07BFC25 Block executable files unless they meet prevalence criteria
Set each rule to: Block (1) or Audit (2) for initial testing
Step 4: Restrict Lateral Movement Vectors
Lock down SMB, RDP, and WMI to limit ransomware propagation:
Network Restrictions:
━━━━━━━━━━━━━━━━━━━━
1. Disable SMBv1:
Computer Configuration → Administrative Templates →
Network → Lanman Workstation → Enable insecure guest logons: Disabled
Computer Configuration → Administrative Templates →
MS Security Guide → Configure SMBv1 server: Disabled
2. Restrict Remote Desktop:
Computer Configuration → Administrative Templates →
Windows Components → Remote Desktop Services →
Remote Desktop Session Host → Connections →
Allow users to connect remotely: Disabled (or restricted to specific groups)
3. Disable remote WMI:
Windows Firewall → Inbound Rules →
Block Windows Management Instrumentation (WMI) inbound
4. Disable AutoPlay/AutoRun:
Computer Configuration → Administrative Templates →
Windows Components → AutoPlay Policies →
Turn off AutoPlay: Enabled (All drives)
5. Disable PowerShell remoting for non-admin users:
Computer Configuration → Administrative Templates →
Windows Components → Windows PowerShell →
Turn on Script Execution: Allow only signed scripts
Step 5: Audit and Validate GPO Compliance
Verify that GPO settings are applied correctly across the domain: