System Hardening
Definition
Configuration changes that reduce a system's attack surface by disabling unnecessary services, applying least-privilege access, enabling audit logging, and removing or restricting components that the attacker exploited. Hardening makes re-exploitation significantly harder.
- Actions
- Disable unnecessary services, apply least privilege, enable audit logging
- Goal
- Reduce attack surface after an incident
- Timing
- Part of long-term containment, after eradication
- Effect
- Makes re-exploitation of the same vector harder
Common questions
How does system hardening differ from the eradication step in incident response?+
Eradication removes the specific malware, backdoor, or attacker foothold found in the incident, while hardening is a broader, forward-looking step that closes the underlying weaknesses, such as unnecessary open services or excessive privileges, that made the exploitation possible in the first place, not just the artifacts of that one intrusion.
Why is hardening usually applied after containment and eradication rather than during the initial response?+
Making configuration changes mid-incident can alert an attacker still present in the environment, destroy evidence needed for the investigation, or disrupt systems before forensic imaging is complete, so hardening is sequenced after the environment is confirmed clean and evidence is preserved.
Does system hardening guarantee an environment cannot be re-compromised the same way?+
No; it significantly raises the difficulty of repeating the same attack path but does not eliminate risk, since new vulnerabilities, misconfigurations, or social-engineering vectors unrelated to the hardened controls can still provide a fresh route back in.
Related terms
- Access Revocation
- The removal of permissions, accounts, or trust relationships that the attacker exploited or could exploit. Distinct from credential rotation in that it...
- Attack Surface Reduction
- The systematic elimination of pathways an attacker could use to enter or move within a system. In incident response this includes closing...
- Compensating Control
- A security measure that reduces risk when the ideal control cannot be applied immediately. For example, routing traffic through a monitored proxy...
- Credential Rotation
- The process of invalidating and replacing passwords, API keys, certificates, and other authentication tokens that may have been exposed during an incident....
- Long-Term Containment
- The incident response phase in which emergency stabilisation measures are replaced with durable controls, such as patches, credential rotation, and firewall changes,...