19 KiB
19 KiB
PHASE 4: WINDOWS CONFIGURATION BY PROFILE
Operating System Hardening, Optimization & Profile-Specific Settings
Phase Start Date: 2026-09-09
Scope: Design reversible, logged, profile-specific Windows configuration
Outcomes: Windows configuration per profile with detection, planning, application, and rollback
4.1 CONFIGURATION PRINCIPLES
Design Requirements
- Detect: Identify current state before making changes
- Plan: Show what will change, expected impact
- Apply: Execute changes with logging
- Verify: Confirm changes took effect
- Rollback: Reverse changes if needed (where technically practical)
- Document: Log all changes with rationale and recovery info
- Safe: No changes that cannot be detected/recovered from
Implementation Pattern
function Set-WindowsConfiguration {
param(
[Parameter(Mandatory)][ValidateSet('Detect', 'Plan', 'Apply', 'Verify', 'Rollback')]
[string]$Mode
)
$current = Get-CurrentSetting
$desired = $DesiredConfiguration[$Profile]
if ($Mode -eq 'Detect') {
return $current
}
elseif ($Mode -eq 'Plan') {
return Compare-Configuration -Current $current -Desired $desired
}
elseif ($Mode -eq 'Apply') {
Set-SettingValue -Value $desired.Value
Verify-SettingChanged
}
elseif ($Mode -eq 'Verify') {
return Test-SettingValue -Expected $desired.Value
}
elseif ($Mode -eq 'Rollback') {
Set-SettingValue -Value $current.Value
Verify-SettingChanged
}
}
4.2 CONFIGURATION AREAS
4.2.1 Power Management
Rationale: Automotive diagnostics require consistent power. Sleeping/hibernating mid-operation causes failures.
Setting: Hibernation
- Detection:
powercfg.exe /query SCHEME_CURRENT SUB_SLEEP HIBERNATEFILE - DailyTech: Disabled (must stay powered for long tuning sessions)
- ODIS & XENTRY: Disabled (diagnostic sessions must not sleep)
- PIWIS & ISTA: Disabled (diagnostic sessions must not sleep)
- Application:
powercfg.exe /hibernate off - Rollback:
powercfg.exe /hibernate on - Status: ✅ Already implemented in current script
Setting: USB Selective Suspend
- Rationale: Prevents USB diagnostic interfaces from powering down mid-operation
- DailyTech: Disabled (critical for interfaces)
- ODIS & XENTRY: Disabled (critical for J2534)
- PIWIS & ISTA: Disabled (critical for J2534)
- Application:
powercfg.exe /setacvalueindex SCHEME_CURRENT SUB_USB USBSELECTIVE 0 # AC Power powercfg.exe /setdcvalueindex SCHEME_CURRENT SUB_USB USBSELECTIVE 0 # Battery powercfg.exe /setactive SCHEME_CURRENT - Detection:
$acValue = powercfg.exe /query SCHEME_CURRENT SUB_USB USBSELECTIVE | Select-String "AC Power Setting" - Status: ✅ Already implemented in current script
Setting: Power Plan
- DailyTech: High Performance
- Rationale: Full CPU/GPU for long-running analysis tasks
- ODIS & XENTRY: Balanced
- Rationale: Diagnostic tool requirements vary; balanced is safer
- PIWIS & ISTA: Balanced
- Rationale: Diagnostic tool requirements vary
- Application:
powercfg.exe /setactive SCHEME_GUID - Detection:
(Get-CimInstance -ClassName Win32_PowerPlan -Namespace root\cimv2\power | Where-Object IsActive -eq $true).ElementName - Rollback: Switch back to previous plan
Setting: Monitor Sleep
- DailyTech: Disable (no sleep during long tuning)
- ODIS & XENTRY: 30 minutes (reasonable for diagnostics)
- PIWIS & ISTA: 30 minutes
- Application:
powercfg.exe /change monitor-timeout-ac 0 # DailyTech powercfg.exe /change monitor-timeout-ac 30 # ODIS/PIWIS - Rollback: Restore previous timeout value
Setting: Disk Sleep
- All Profiles: Disable (avoid mid-operation failures)
- Application:
powercfg.exe /change disk-timeout-ac 0
Setting: System Sleep
- DailyTech: Disable
- ODIS & XENTRY: 60 minutes
- PIWIS & ISTA: 60 minutes
- Application:
powercfg.exe /change standby-timeout-ac 0 # or value in minutes
4.2.2 Windows Update
Setting: Active Hours
- All Profiles: Set to business hours to prevent mid-operation restarts
- Start: 08:00 (8 AM)
- End: 17:00 (5 PM)
- Application:
$path = "HKLM:\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" Set-ItemProperty -Path $path -Name ActiveHoursStart -Value 8 Set-ItemProperty -Path $path -Name ActiveHoursEnd -Value 17 - Detection:
Get-ItemProperty -Path $path -Name ActiveHoursStart, ActiveHoursEnd
Setting: Automatic Restart
- DailyTech: Manual (user decides when to restart)
- ODIS & XENTRY: Manual (during breaks)
- PIWIS & ISTA: Manual (during breaks)
- Application:
# Set to "Notify for scheduled restart" instead of auto-restart Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" ` -Name NoAutoRebootWithLoggedOnUsers -Value 1 - Detection:
Get-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" ` -Name NoAutoRebootWithLoggedOnUsers
4.2.3 Fast Startup
Setting: Enable Fast Startup
- DailyTech: Enabled (faster boot)
- ODIS & XENTRY: Enabled
- PIWIS & ISTA: Enabled
- Rationale: Faster access to diagnostic tools
- Application:
$path = "HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager\Power" Set-ItemProperty -Path $path -Name HibernationBootOptimization -Value 1 - Detection:
Get-ItemProperty -Path $path -Name HibernationBootOptimization
4.2.4 File System
Setting: Long Path Support (Windows 10 1607+)
- All Profiles: Enabled (ECU projects may have deep folder structures)
- Application:
# Registry key for long path support $path = "HKLM:\SYSTEM\CurrentControlSet\Control\FileSystem" Set-ItemProperty -Path $path -Name LongPathsEnabled -Value 1 - Detection:
(Get-ItemProperty -Path $path -Name LongPathsEnabled).LongPathsEnabled
Setting: File Extension Visibility
- All Profiles: Show all file extensions (critical for .hex, .bin, .eep)
- Application:
# HKCU: Hide extensions for known file types = 0 (show) $path = "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" Set-ItemProperty -Path $path -Name HideFileExt -Value 0 - Rollback: Set HideFileExt to 1
Setting: Hidden Files Visibility
- All Profiles: Show hidden files (for debugging/admin tools)
- Application:
Set-ItemProperty -Path $path -Name Hidden -Value 1 # 1 = show
Setting: Page File Management
- DailyTech: System Managed (default; allow automatic sizing)
- ODIS & XENTRY: System Managed
- PIWIS & ISTA: System Managed
- Rationale: Page file helps with large EEPROM/binary analysis
- Detection:
Get-CimInstance -ClassName Win32_PageFileUsage
4.2.5 Storage Health
Setting: Storage Sense
- All Profiles: Enabled (automatic cleanup)
- Application:
$path = "HKCU:\Software\Microsoft\Windows\CurrentVersion\StorageSense\Parameters\StoragePolicy" Set-ItemProperty -Path $path -Name `01` -Value 1 - Features to Enable:
- Delete temporary files when storage is low
- Delete OneDrive cloud files if not accessed > 30 days (disable for this workstation)
Setting: Free Space Threshold
- All Profiles: Alert if < 10% free space
- Application: Implement in HealthCheck function
- Detection: Compare
SizeRemaining / Sizeratio
Setting: Disk Defragmentation
- All Profiles: Automatic weekly (SSDs exempt via WinGet settings)
- Application:
$defragSchedule = "defrag C: /U /V" # Schedule weekly
4.2.6 Windows Defender & Security
Setting: Defender Status
- DailyTech: Enabled (monitor for threats)
- Note: May flag legitimate tools (binary analysis, reverse engineering)
- Recommendation: Exclude project folders as needed
- ODIS & XENTRY: Enabled
- PIWIS & ISTA: Enabled
- Detection:
Get-MpPreference | Select-Object DisableRealtimeMonitoring - Rationale: Do not disable antivirus globally (defeats security)
Setting: Controlled Folder Access
- DailyTech: Disabled (tools may access system folders)
- ODIS & XENTRY: Disabled
- PIWIS & ISTA: Disabled
- Rationale: Diagnostic/OEM tools need broad access; manually add exclusions only if required
- Application:
Set-MpPreference -EnableControlledFolderAccess Disabled
Setting: Firewall
- All Profiles: Enabled (monitor for unauthorized access)
- Custom Rules: Allow VPN, remote SSH if needed
- Detection:
Get-NetFirewallProfile | Select-Object Name, Enabled - Rationale: Firewall should remain on; add exceptions only for known services
Setting: Windows Defender Exclusions
- Pattern: Exclude project folders (if user opts in; NOT automatic)
- Rationale: Some binary analysis tools trigger false positives
- Manual Configuration: User should set
C:\Automotive\Projects\*exclusions after setup - Application: Provide PowerShell snippet for user to run manually
Setting: Device Driver Signature Policy
- All Profiles: Enforce (require signed drivers)
- Exception: Only for well-known automotive interfaces (PCAN, J2534, etc.)
- Rationale: Prevent malicious unsigned drivers; approve needed ones
- Detection:
bcdedit /enum | Select-String "nointegritychecks"
4.2.7 Network Configuration
Setting: Network Profile
- All Profiles: Private network (more permissive firewall rules)
- Rationale: These are isolated workstations, not on corporate networks
- Application:
Set-NetConnectionProfile -NetworkCategory Private - Detection:
Get-NetConnectionProfile | Select-Object Name, NetworkCategory
Setting: Time Synchronization
- All Profiles: Enabled (critical for logs/diagnostics timestamps)
- Application:
# Ensure time sync service is running Start-Service -Name W32Time Set-Service -Name W32Time -StartupType Automatic
Setting: Timezone
- Detection:
Get-TimeZone - Note: User should set timezone manually during Windows install
- Rationale: Timezone affects EEPROM dates, logs, diagnostic records
4.2.8 Optional Features
Feature: Hyper-V
- DailyTech: Optional (for VM testing)
- Installation:
Enable-WindowsOptionalFeature -FeatureName Microsoft-Hyper-V -Online -NoRestart
- Installation:
- ODIS & XENTRY: Not recommended (conflicts with other virtualization)
- PIWIS & ISTA: Not recommended
- Rationale: Hyper-V conflicts with VirtualBox; choose one
Feature: Windows Sandbox
- DailyTech: Optional (for sandboxed app testing)
- Installation:
Enable-WindowsOptionalFeature -FeatureName Containers-DisposableContainers -Online
- Installation:
- ODIS & XENTRY: Optional
- PIWIS & ISTA: Optional
- Rationale: Useful for safe testing; adds minimal overhead
Feature: Windows Subsystem for Linux (WSL)
- DailyTech: Optional (for Linux tool support)
- ODIS & XENTRY: Not recommended
- PIWIS & ISTA: Not recommended
- Rationale: Adds complexity; not necessary for automotive diagnostics
Feature: VirtualBox Support
- All Profiles: Keep VirtualBox as WinGet optional package (user chooses)
- Note: Cannot use Hyper-V and VirtualBox together
- Recommendation: If user enables Hyper-V, warn about VirtualBox incompatibility
4.2.9 Services
Core Services (Always Running)
TermService— Remote Desktop (optional; disable if not needed)Bits— Background Intelligent Transfer Service (keep for updates)WinDefend— Windows Defender (keep enabled for security)W32Time— Time sync (critical for logs)AudioSrv— Audio (needed for some diagnostic tools)
Services to Disable (Reduce Attack Surface)
DiagTrack— Connected User Experiences and Telemetrydmwappushservice— Update Orchestrator Service (handle via Group Policy)AppVClient— App-V client (if not using App-V)RemoteRegistry— Remote Registry (disable if not doing remote management)
Configuration per Profile
- DailyTech: Minimal restrictions (user may need various services)
- Disable: DiagTrack, dmwappushservice
- ODIS & XENTRY: Minimal restrictions
- Disable: DiagTrack, dmwappushservice
- PIWIS & ISTA: Minimal restrictions
- Disable: DiagTrack, dmwappushservice
Application:
$servicesToDisable = @('DiagTrack', 'dmwappushservice')
foreach ($service in $servicesToDisable) {
Set-Service -Name $service -StartupType Disabled -ErrorAction SilentlyContinue
Stop-Service -Name $service -Force -ErrorAction SilentlyContinue
}
Detection:
Get-Service -Name $servicesToDisable | Select-Object Name, StartType, Status
4.2.10 Event Logging & Crash Dumps
Setting: System Event Log
- All Profiles: Enabled (critical for troubleshooting)
- Size: 20MB minimum (allow system to keep 30 days of logs)
- Application:
$eventLog = Get-WmiObject Win32_NTEventLogFile -Filter "LogFileName='System'" $eventLog.MaxFileSize = 20971520 # 20 MB $eventLog.Put()
Setting: Application Event Log
- All Profiles: Enabled
- Size: 20MB minimum
Setting: Crash Dumps
- All Profiles: Enabled (system memory dump)
- Rationale: Helps diagnose system crashes/BSODs
- Application:
$path = "HKLM:\SYSTEM\CurrentControlSet\Control\CrashControl" Set-ItemProperty -Path $path -Name CrashDumpEnabled -Value 1 # Full dump
Setting: PowerShell Script Logging
- All Profiles: Enable for security + debugging
- Application:
$path = "HKLM:\Software\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging" New-Item -Path $path -Force Set-ItemProperty -Path $path -Name EnableScriptBlockLogging -Value 1
4.2.11 BitLocker & Encryption
Setting: BitLocker Status
- All Profiles: Check status (do not auto-enable)
- Rationale: User's choice; may conflict with forensic recovery needs
- Detection:
manage-bde -status C: - Recommendation: User should configure if needed
4.2.12 System Restore & Recovery
Setting: System Protection
- All Profiles: Enabled (allow system restore points)
- Rationale: Allows rollback if OS-level changes break diagnostics
- Application:
Enable-ComputerRestore -Drive "C:\" - Detection:
Get-ComputerRestorePoint | Select-Object -Last 1
Setting: Shadow Copy (Volume Shadow Copy)
- All Profiles: Enabled (for file version history)
- Application:
# Enable on C: drive Get-WmiObject -List -Namespace root\cimv2 | Where-Object Name -eq Win32_ShadowCopy
4.3 WINDOWS CONFIGURATION JSON SCHEMA
{
"WindowsSettings": {
"DailyTech-Tuning": {
"PowerManagement": {
"Hibernation": {
"Value": "Disabled",
"Registry": "N/A",
"Command": "powercfg.exe /hibernate off",
"Detect": "powercfg /query",
"Rollback": "powercfg.exe /hibernate on",
"Critical": true
},
"USBSelectiveSuspend": {
"Value": "Disabled",
"ACValue": 0,
"DCValue": 0,
"Critical": true
},
"PowerPlan": {
"Value": "High Performance",
"Guid": "SCHEME_MIN",
"Rationale": "Full CPU for long analysis tasks",
"Critical": false
},
"MonitorSleep": {
"Value": "Never",
"Minutes": 0,
"Critical": true
},
"DiskSleep": {
"Value": "Never",
"Minutes": 0,
"Critical": true
},
"SystemSleep": {
"Value": "Never",
"Minutes": 0,
"Critical": true
}
},
"WindowsUpdate": {
"ActiveHoursStart": 8,
"ActiveHoursEnd": 17,
"AutomaticRestart": "Disabled",
"RestartNotification": "User Configurable"
},
"Security": {
"Defender": "Enabled",
"ControlledFolderAccess": "Disabled",
"Firewall": "Enabled",
"DriverSignaturePolicy": "Enforce"
},
"FileSystem": {
"LongPathSupport": "Enabled",
"ShowFileExtensions": "Enabled",
"ShowHiddenFiles": "Enabled"
},
"Services": {
"Disable": ["DiagTrack", "dmwappushservice"],
"Enable": ["W32Time", "AudioSrv"]
}
},
"ODIS-XENTRY": {
// Similar structure, but:
"PowerManagement": {
"PowerPlan": {
"Value": "Balanced",
"Rationale": "OEM diagnostic tool requirements"
},
"MonitorSleep": {
"Minutes": 30
}
}
},
"PIWIS-ISTA": {
// Similar structure to ODIS-XENTRY
}
}
}
4.4 CONFIGURATION IMPLEMENTATION FUNCTIONS
New PowerShell Functions to Create
Detect-WindowsConfiguration— Scan current OS statePlan-WindowsConfiguration— Show proposed changesSet-WindowsConfiguration— Apply settings per profileVerify-WindowsConfiguration— Confirm changes took effectRollback-WindowsConfiguration— Revert to pre-setup stateGet-PowerPlanGUID— Resolve power plan names to GUIDsDetect-PendingRestart— Check for pending restartTest-PowerPlan— Verify active power planTest-USBSelectiveSuspend— Verify USB policyTest-RegistrySetting— Generic registry test
4.5 SAFETY GATES
Before Applying Configuration
- ✅ Admin check: Must be elevated
- ✅ Backup state: Save current config to JSON
- ✅ Conflict check: Warn if Hyper-V + VirtualBox selected
- ✅ System impact: Warn about pending restart scenarios
- ✅ Manual override: Allow
-SkipWindowsConfigurationflag
After Applying Configuration
- ✅ Verification: Run Verify functions
- ✅ Report: Export configuration state to CSV/JSON
- ✅ Recovery: Save rollback instructions
4.6 CONFIGURATION MATRIX SUMMARY
| Setting | DailyTech | ODIS/XENTRY | PIWIS/ISTA | Reason |
|---|---|---|---|---|
| Hibernation | Off | Off | Off | Critical for diagnostics |
| USB Suspend | Off | Off | Off | Critical for interfaces |
| Power Plan | High Perf | Balanced | Balanced | Workload optimization |
| Defender | On | On | On | Security |
| CFA | Off | Off | Off | Tool flexibility |
| Fast Startup | On | On | On | Boot speed |
| Long Paths | On | On | On | Project depth |
| Show Extensions | On | On | On | Critical for .hex, .bin |
| Services | Min removal | Min removal | Min removal | Reduce telemetry |
NEXT STEPS
Phase 5 will build on this foundation to create Workspace Templates for each profile, including automated folder structures and project initialization.