cmd /c reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters /v TcpMaxDataRetransmissions || echo TcpMaxDataRetransmissions notfound not config
TcpMaxDataRetransmissions notfound not config
cmd /c reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters /v TcpMaxConnectResponseRetransmissions || echo TcpMaxConnectResponseRetransmissions notfound not config
TcpMaxConnectResponseRetransmissions notfound not config
cmd /c reg query HKLM\SYSTEM\CurrentControlSet\Control\Lsa /v CrashOnAuditFail
CrashOnAuditFail REG_DWORD 0x0
cmd /c reg query HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters /v SynAttackProtect
SynAttackProtect notfound not config
cmd /c reg query HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v DisableCAD
DisableCAD notfound not config
cmd /c cscript %tmp%\NSF{nsf_tm}_checkfirewall.vbs //Nologo防火墙状态: 域配置文件 设置: 状态 启用 专用配置文件 设置: 状态 关闭 公用配置文件 设置: 状态 关闭
cmd /c reg query HKLM\SYSTEM\CurrentControlSet\Control\Lsa /v RestrictAnonymous
RestrictAnonymous REG_DWORD 0x0
cmd /c reg query HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Security /v RestrictGuestAccess
ERROR: 拒绝访问注册表项 HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Security\RestrictGuestAccess
cmd /c reg query HKLM\System\CurrentControlSet\Services\Tcpip\Parameters /v DisableIPSourceRouting || echo DisableIPSourceRouting notfound not config
DisableIPSourceRouting notfound not config
cmd /c reg query HKLM\System\CurrentControlSet\Services\Tcpip\Parameters /v EnablePMTUDiscovery || echo EnablePMTUDiscovery notfound not config
EnablePMTUDiscovery notfound not config
cmd /c reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters /v EnableDeadGWDetect || echo EnableDeadGWDetect notfound not config
EnableDeadGWDetect notfound not config
cmd /c reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters /v PerformRouterDiscovery || echo PerformRouterDiscovery notfound not config
PerformRouterDiscovery notfound not config
cmd /c reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters /v KeepAliveTime || echo KeepAliveTime notfound not config
KeepAliveTime notfound not config
cmd /c reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters /v EnableICMPRedirect || echo EnableICMPRedirect notfound not config
EnableICMPRedirect notfound not config
cmd /c secedit /export /cfg %temp%\secpol.cfg /quiet && findstr /i "PasswordComplexity" %temp%\secpol.cfg || echo secpol export failed
PasswordComplexity = notfound
cmd /c reg query HKLM\SYSTEM\CurrentControlSet\Control\Lsa /v FullPrivilegeAuditing
FullPrivilegeAuditing REG_TYPE_3 b'\x00'
cmd /c reg query HKLM\SYSTEM\CurrentControlSet\Control\Lsa /v AuditBaseObjects
AuditBaseObjects REG_DWORD 0x0
cmd /c reg query HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system /v DontDisplayLastUserName || echo DontDisplayLastUserName notfound not config
DontDisplayLastUserName REG_DWORD 0x0
cmd /c reg query HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters /v EnableSecurityFilters
EnableSecurityFilters notfound not config
cmd /c reg query HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system /v DontDisplayLockedUserId || echo DontDisplayLockedUserId notfound not config
DontDisplayLockedUserId notfound not config
cmd /c reg query HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management /v ClearPageFileAtShutdown
ClearPageFileAtShutdown REG_DWORD 0x0
cmd /c reg query HKLM\SYSTEM\CurrentControlSet\Control\Lsa /v DisableDomainCreds
DisableDomainCreds REG_DWORD 0x0
cmd /c reg query HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurePipeServers\Winreg\AllowedPaths /v Machine
ERROR: 拒绝访问注册表项 HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurePipeServers\Winreg\AllowedPaths\Machine
cmd /c reg query HKLM\SYSTEM\CurrentControlSet\Control\Lsa /v SubmitControl
SubmitControl notfound not config
cmd /c reg query HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA
EnableLUA REG_DWORD 0x1
cmd /c reg query HKLM\SYSTEM\CurrentControlSet\Control\Lsa /v LimitBlankPasswordUse
LimitBlankPasswordUse REG_DWORD 0x1
cmd /c reg query HKLM\SYSTEM\CurrentControlSet\Control\Lsa /v restrictanonymoussam
restrictanonymoussam REG_DWORD 0x1
cmd /c reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanManServer\Parameters /v enableforcedlogoff || echo enableforcedlogoff notfound not config
enableforcedlogoff REG_DWORD 0x1
cmd /c reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\w32time\Parameters /v NtpServer || echo NtpServer notfound not config
NtpServer REG_SZ time.windows.com,0x9
cmd /c secedit /export /cfg %temp%\secpol.cfg /quiet && findstr /i "MinimumPasswordLength" %temp%\secpol.cfg || echo secpol export failed
MinimumPasswordLength = 0
cmd /c secedit /export /cfg %temp%\secpol.cfg /quiet && findstr /i "MaximumPasswordAge" %temp%\secpol.cfg || echo secpol export failed
MaximumPasswordAge = 42
cmd /c secedit /export /cfg %temp%\secpol.cfg /quiet && findstr /i "MinimumPasswordAge" %temp%\secpol.cfg || echo secpol export failed
MinimumPasswordAge = 0
cmd /c secedit /export /cfg %temp%\secpol.cfg /quiet && findstr /i "PasswordHistorySize" %temp%\secpol.cfg || echo secpol export failed
PasswordHistorySize = notfound
cmd /c secedit /export /cfg %temp%\secpol.cfg /quiet && findstr /i "LockoutBadCount" %temp%\secpol.cfg || echo secpol export failed
LockoutBadCount = 10
cmd /c secedit /export /cfg %temp%\secpol.cfg /quiet && findstr /i "LockoutDuration" %temp%\secpol.cfg || echo secpol export failed
LockoutDuration = 10
cmd /c secedit /export /cfg %temp%\secpol.cfg /quiet && findstr /i "LockoutThreshold" %temp%\secpol.cfg || echo secpol export failed
LockoutThreshold = 10
cmd /c cscript %tmp%\NSF{nsf_tm}_fscheck.vbs //Nologo文件系统检查通过 C:\Windows: 存在 C:\: 存在 C:\Users\T\AppData\Local\Temp: 存在 -> Temp目录可读写 磁盘剩余空间: 71.56 GB
cmd /c "ver"
Microsoft Windows [版本 10.0.19045.6456]
cmd /c net start | find /i "Remote Desktop"
找不到文件 - REMOTE DESKTOP
cmd /c wmic service where "name='RemoteAccess' or name='RasAuto'" get name,state,startmode
Name StartMode State RasAuto Manual Stopped RemoteAccess Disabled Stopped
cmd /c wmic service where "name='W3SVC' or name='IISADMIN'" get name,state,startmode
(命令执行成功,无输出)
cmd /c wmic service where "name='TlntSvr' or name='Telnet'" get name,state,startmode
(命令执行成功,无输出)
cmd /c netstat -ano | findstr LISTEN
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING 392 TCP 0.0.0.0:445 0.0.0.0:0 LISTENING 4 TCP 0.0.0.0:5040 0.0.0.0:0 LISTENING 5292 TCP 0.0.0.0:7680 0.0.0.0:0 LISTENING 6324 TCP 0.0.0.0:49664 0.0.0.0:0 LISTENING 776 TCP 0.0.0.0:49665 0.0.0.0:0 LISTENING 624 TCP 0.0.0.0:49666 0.0.0.0:0 LISTENING 1132 TCP 0.0.0.0:49667 0.0.0.0:0 LISTENING 1596 TCP 0.0.0.0:49668 0.0.0.0:0 LISTENING 2624 TCP 0.0.0.0:49669 0.0.0.0:0 LISTENING 768 TCP 0.0.0.0:49670 0.0.0.0:0 LISTENING 2832 TCP 127.0.0.1:5283 0.0.0.0:0 LISTENING 4268 TCP 127.0.0.1:55500 0.0.0.0:0 LISTENING 5884 TCP 127.0.0.1:55501 0.0.0.0:0 LISTENING 5884 TCP 127.0.0.1:55506 0.0.0.0:0 LISTENING 9944 TCP 127.0.0.1:55507 0.0.0.0:0 LISTENING 5884 TCP 127.0.0.1:55511 0.0.0.0:0 LISTENING 11084 TCP 127.0.0.1:55524 0.0.0.0:0 LISTENING 10508 TCP 127.0.0.1:55527 0.0.0.0:0 LISTENING 6072 TCP 127.0.0.1:55539 0.0.0.0:0 LISTENING 9484 TCP 192.168.232.148:139 0.0.0.0:0 LISTENING 4 TCP [::]:135 [::]:0 LISTENING 392 TCP [::]:445 [::]:0 LISTENING 4 TCP [::]:7680 [::]:0 LISTENING 6324 TCP [::]:49664 [::]:0 LISTENING 776 TCP [::]:49665 [::]:0 LISTENING 624 TCP [::]:49666 [::]:0 LISTENING 1132 TCP [::]:49667 [::]:0 LISTENING 1596 TCP [::]:49668 [::]:0 LISTENING 2624 TCP [::]:49669 [::]:0 LISTENING 768 TCP [::]:49670 [::]:0 LISTENING 2832 TCP [::1]:42050 [::]:0 LISTENING 3456
cmd /c wmic service where "name='FTPSVC' or name='MSFTPSVC'" get name,state,startmode
(命令执行成功,无输出)
cmd /c wmic /namespace:\\root\SecurityCenter2 path AntiVirusProduct get displayName /format:csv || echo No AV found
Node,displayName DESKTOP-B22A83M,Windows Defender
cmd /c wmic service where "name='DNS' or name='Dhcp'" get name,state,startmode
Name StartMode State Dhcp Auto Running
cmd /c wmic service where "name='SNMP' or name='SNMPTRAP'" get name,state,startmode
Name StartMode State SNMPTRAP Manual Stopped
cmd /c powershell -Command "(Get-WmiObject Win32_ComputerSystem).DomainRole"
0
cmd /c wmic os get DataExecutionPrevention_SupportPolicy || echo NoDEPWindows
DataExecutionPrevention_SupportPolicy 2
cmd /c wmic service where "name='Spooler' or name='PrintNotify'" get name,state,startmode
Name StartMode State PrintNotify Manual Stopped Spooler Auto Running
cmd /c wmic service where "name='WMPNetworkSvc' or name='RemoteRegistry'" get name,state,startmode
Name StartMode State RemoteRegistry Disabled Stopped WMPNetworkSvc Manual Stopped
cmd /c powershell -Command "Get-WmiObject Win32_DiskPartition | Select-Object DeviceID,Size | ConvertTo-Csv -NoTypeInformation"
"DeviceID","Size" "Disk #0, Partition #0","104857600" "Disk #0, Partition #1","127870275584" "Disk #0, Partition #2","853540864"
cmd /c powershell -Command "(Get-WmiObject Win32_OperatingSystem).Caption"
Microsoft Windows 10 企业版
cmd /c wmic service get caption,pathname,startmode,state | find /i /v ""
找不到文件 - 找不到文件 -
cmd /c wmic useraccount get name,domain,status,disabled /format:csv
XSL 格式(或)文件名无效
cmd /c wmic startup get caption,command,location | find /i /v ""
找不到文件 - 找不到文件 -
cmd /c wmic timezone get caption,standardname | find /i /v ""
找不到文件 - 找不到文件 -
cmd /c wmic qfe get description,hotfixid,installedon,installedby | find /v /i ""
Description HotFixID InstalledBy InstalledOn Update KB5066130 NT AUTHORITY\SYSTEM 6/4/2026 Update KB5066135 10/11/2025 Update KB5011048 NT AUTHORITY\SYSTEM 6/3/2026 Update KB5011050 NT AUTHORITY\SYSTEM 6/4/2026 Update KB5015684 10/11/2025 Security Update KB5072653 NT AUTHORITY\SYSTEM 6/3/2026 Security Update KB5066791 10/11/2025 Security Update KB5014032 10/11/2025 Update KB5028380 10/11/2025 Security Update KB5066790 10/11/2025
cmd /c wmic group get name,domain,sid /format:csv
XSL 格式(或)文件名无效
cmd /c del /f/s/q %tmp%\NSF{nsf_tm}_sec.log && del /f/s/q %tmp%\NSF{nsf_tm}_domainrole.txt && del /f/s/q %tmp%\NSF{nsf_tm}_wmiav.vbs && del /f/s/q %tmp%\NSF{nsf_tm}_nameav.vbs && del /f/s/q %tmp%\NSF{nsf_tm}_processav.bat && del /f/s/q %tmp%\NSF{nsf_tm}_sharecheck.vbs && del /f/s/q %tmp%\NSF{nsf_tm}_checkfirewall.vbs && del /f/s/q %tmp%\NSF{nsf_tm}_fscheck.vbs && del /f/s/q %tmp%\NSF{nsf_tm}_morelines.vbs找不到 C:\Users\T\AppData\Local\Temp\NSF{nsf_tm}_sec.log
找不到 C:\Users\T\AppData\Local\Temp\NSF{nsf_tm}_domainrole.txt
找不到 C:\Users\T\AppData\Local\Temp\NSF{nsf_tm}_wmiav.vbs
找不到 C:\Users\T\AppData\Local\Temp\NSF{nsf_tm}_nameav.vbs
找不到 C:\Users\T\AppData\Local\Temp\NSF{nsf_tm}_processav.bat
找不到 C:\Users\T\AppData\Local\Temp\NSF{nsf_tm}_sharecheck.vbs
找不到 C:\Users\T\AppData\Local\Temp\NSF{nsf_tm}_checkfirewall.vbs
找不到 C:\Users\T\AppData\Local\Temp\NSF{nsf_tm}_fscheck.vbs
找不到 C:\Users\T\AppData\Local\Temp\NSF{nsf_tm}_morelines.vbscmd /c hostname
DESKTOP-B22A83M
cmd /c wmic share get description,name,path | find /v /i ""
Description Name Path 远程管理 ADMIN$ C:\Windows 默认共享 C$ C:\ 远程 IPC IPC$
本次扫描对 DESKTOP-B22A83M 主机进行了等级保护2.0三级 基线安全合规检查,共执行 62 项检查,其中 38 项通过、24 项未通过。
整体合规率为 61.3%(基于 62 项可判定检查),存在 24 项配置不符合等级保护2.0三级要求,需尽快整改。
⚠ 重点关注:未通过项中包含 8 项高风险、16 项中风险配置缺陷。
针对未通过项,建议按照以下优先级进行整改:
每项未通过检查均附有具体的修复步骤,点击对应检查项可展开查看详细修复方法。