Hardening Operations Playbook
RCCE students will learn endpoint hardening methodologies including operating system configuration lockdown, unnecessary service removal, registry hardening, group policy enforcement, application whitelisting, and CIS Benchmark implementation. RCCE students will learn to apply hardening baselines to Windows, Linux, and macOS systems, reduce the attack surface by disabling unused ports and protocols, configure host-based firewalls and intrusion prevention, implement secure boot and firmware protection, manage local administrator accounts, and validate hardening effectiveness through vulnerability scanning and compliance auditing. This operations-focused course delivers production-ready playbooks, checklists, and standard operating procedures. Starting from foundational concepts, RCCE students will learn to build repeatable day-to-day operational workflows that ensure consistency and quality. Students receive templates and frameworks they can customize and deploy immediately in their security operations, reducing time to operational effectiveness.
- Endpoint Security Engineers and EDR Analysts
- Windows and macOS Administrators managing privileges
- Identity and Access Management Engineers
- IT Security Operations Leads reducing attack surface
- Professionals implementing Hardening Operations Playbook
- Execute hands-on tasks for hardening operations
- Explain Course Overview fundamentals
- Execute hands-on tasks for what you will learn — covering Endpoint hardening methodologies, OS configuration lockdown techniques.
- Execute hands-on tasks for platforms covered — covering Windows Server and Desktop hardening, Linux (RHEL, Ubuntu, CentOS) lockdown.
- Execute hands-on tasks for windows server and desktop hardening — covering Linux (RHEL, Ubuntu, CentOS) lockdown.
- Execute hands-on tasks for operational outcomes — covering Production-ready hardening playbooks, Repeatable day-to-day workflows.
- Execute hands-on tasks for business impact — covering Least privilege for all accounts.
- Execute hands-on tasks for config management — covering Enforces desired state.
- Explain CIS Benchmarks Overview fundamentals
- Execute hands-on tasks for stig overlay — covering DoD-specific requirements, Maps to NIST 800-53.
- Execute hands-on tasks for implementation workflow — covering Select benchmark for target OS version, Run CIS-CAT assessment to establish baseline score.
- Execute hands-on tasks for select benchmark for target os version — covering Run CIS-CAT assessment to establish baseline score.
| Module 01 | Hardening Operations |
| Module 02 | Course Overview |
| Module 03 | What You Will Learn |
| Module 04 | Platforms Covered |
| Module 05 | Windows Server and Desktop hardening |
| Module 06 | Operational Outcomes |
| Module 07 | Business Impact |
| Module 08 | Config Management |
| Module 09 | CIS Benchmarks Overview |
| Module 10 | STIG Overlay |
| Module 11 | Implementation Workflow |
| Module 12 | Select benchmark for target OS version |
| Module 13 | CIS Benchmark Structure Deep Dive |
| Module 14 | Benchmark Sections |
All hands-on labs run on Rocheston Rose X OS. Students practice hardening operations playbook by implementing the controls discussed in class, with a focus on real-world deployment, monitoring, and validation.
- Lab 1: Execute hands-on tasks for hardening operations
- Lab 2: Explain Course Overview fundamentals
- Lab 3: Execute hands-on tasks for what you will learn
- Lab 4: Execute hands-on tasks for platforms covered
- Lab 5: Execute hands-on tasks for windows server and desktop hardening
Upon successful completion of this course, students will receive an official RCCE Course Completion Certificate for Hardening Operations Playbook, verifiable through the Rocheston certification portal.
- Full access to all course materials and slide decks
- Hands-on lab access on Rocheston Rose X OS environment
- Access to Rocheston CyberNotes
- Access to Rocheston Zelfire — EDR/XDR SIEM platform
- Access to Rocheston Raven — online cyber range exercise platform
- Access to Rocheston Vulnerability Vines AI