> ## Documentation Index
> Fetch the complete documentation index at: https://docs.specterops.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Overview

| Codename                                                  | Description                                                                                                    | Admin Roles                              |
| --------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | ---------------------------------------- |
| [CANARY‑1](./CANARY/CANARY-1/canary-1_description)        | Configure an appropriately-privileged NAA with interactive logon restricted                                    | SCCM, domain                             |
| [DETECT‑1](./DETECT/DETECT-1/detect-1_description)        | Monitor site server domain computer accounts authenticating from another source                                | Security                                 |
| [DETECT‑2](./DETECT/DETECT-2/detect-2_description)        | Monitor read access to the System Management Active Directory container                                        | Security                                 |
| [DETECT‑3](./DETECT/DETECT-3/detect-3_description)        | Monitor client push installation accounts authenticating from anywhere other than the primary site server      | Security                                 |
| [DETECT‑4](./DETECT/DETECT-4/detect-4_description)        | Monitor application deployment logs in the site's Audit Status Messages                                        | SCCM, security                           |
| [DETECT‑5](./DETECT/DETECT-5/detect-5_description)        | Monitor group membership changes for SMS Admins                                                                | SCCM, server, security                   |
| [DETECT‑6](./DETECT/DETECT-6/detect-6_description)        | Monitor group membership changes for RBAC\_Admins table                                                        | SCCM, server, security                   |
| [DETECT‑7](./DETECT/DETECT-7/detect-7_description)        | Monitor read access to the SMSTemp directory                                                                   | SCCM, server, security                   |
| [DETECT‑8](./DETECT/DETECT-8/detect-8_description)        | Monitor connections to winreg named pipe                                                                       | SCCM, server, security                   |
| [DETECT‑9](./DETECT/DETECT-9/detect-9_description)        | Monitor local object access for local SCCM logs and settings                                                   | SCCM, server, security                   |
| [PREVENT‑1](./PREVENT/PREVENT-1/prevent-1_description)    | Patch site server with KB15599094                                                                              | SCCM, server                             |
| [PREVENT‑2](./PREVENT/PREVENT-2/prevent-2_description)    | Disable Fallback to NTLM                                                                                       | SCCM                                     |
| [PREVENT‑3](./PREVENT/PREVENT-3/prevent-3_description)    | Harden or disable network access accounts                                                                      | SCCM, domain, security                   |
| [PREVENT‑4](./PREVENT/PREVENT-4/prevent-4_description)    | Configure Enhanced HTTP                                                                                        | SCCM                                     |
| [PREVENT‑5](./PREVENT/PREVENT-5/prevent-5_description)    | Disable automatic side-wide client push installation                                                           | SCCM                                     |
| [PREVENT‑6](./PREVENT/PREVENT-6/prevent-6_description)    | Configure a strong PXE boot password                                                                           | SCCM                                     |
| [PREVENT‑7](./PREVENT/PREVENT-7/prevent-7_description)    | Disable command support in PXE boot configuration                                                              | SCCM                                     |
| [PREVENT‑8](./PREVENT/PREVENT-8/prevent-8_description)    | Require PKI certificates for client authentation                                                               | SCCM, network, security, server, domain  |
| [PREVENT‑9](./PREVENT/PREVENT-9/prevent-9_description)    | Enforce MFA for SMS Provider calls                                                                             | SCCM                                     |
| [PREVENT‑10](./PREVENT/PREVENT-10/prevent-10_description) | Enforce the principle of least privilege for accounts                                                          | SCCM, domain, server, security           |
| [PREVENT‑11](./PREVENT/PREVENT-11/prevent-11_description) | Disable and uninstall WebClient on site servers                                                                | SCCM, server                             |
| [PREVENT‑12](./PREVENT/PREVENT-12/prevent-12_description) | Require SMB signing on site systems                                                                            | Domain, server, SCCM                     |
| [PREVENT‑13](./PREVENT/PREVENT-13/prevent-13_description) | Require LDAP channel binding and signing                                                                       | Domain, server                           |
| [PREVENT‑14](./PREVENT/PREVENT-14/prevent-14_description) | Require EPA on AD CS and site databases                                                                        | Domain, security, SCCM, server, database |
| [PREVENT‑15](./PREVENT/PREVENT-15/prevent-15_description) | Disable and change passwords of legacy NAAs and collection variables/task sequence secrets in Active Directory | Domain, SCCM                             |
| [PREVENT‑16](./PREVENT/PREVENT-16/prevent-16_description) | Remove SeMachineAccountPrivilege and set MachineAccountQuota to 0 for non-admin accounts                       | Domain                                   |
| [PREVENT‑17](./PREVENT/PREVENT-17/prevent-17_description) | Remove Extended Rights assignment from accounts that do not require it                                         | Domain, desktop                          |
| [PREVENT‑18](./PREVENT/PREVENT-18/prevent-18_description) | Use strong passwords for DBA accounts                                                                          | Database, security, domain               |
| [PREVENT‑19](./PREVENT/PREVENT-19/prevent-19_description) | Remove unnecessary links to site databases                                                                     | SCCM, database                           |
| [PREVENT‑20](./PREVENT/PREVENT-20/prevent-20_description) | Block unnecessary connections to site systems                                                                  | Network, server                          |
| [PREVENT‑21](./PREVENT/PREVENT-21/prevent-21_description) | Restrict PXE boot to authorized VLANs                                                                          | SCCM, network                            |
| [PREVENT‑22](./PREVENT/PREVENT-22/prevent-22_description) | Do not manage assets in two or more segmented forests, domains, networks, or security tiers                    | SCCM, network, security, domain          |
