Important: SMB is often essential, so the objective is controlled use rather than indiscriminate blocking.
Network reachability
Use firewall policy to limit SMB to legitimate client and server relationships. Avoid broad TCP/445 access between user and server networks.
Permissions
Review share and file-system permissions, remove stale access and avoid broad write permissions where read-only access is sufficient.
Administrative access
Separate ordinary users from administrative accounts and restrict administrative shares and management paths.
Monitoring
- One workstation contacting many servers.
- Unusual authentication failures.
- Unexpected administrative-share access.
- Large increases in file modifications.
Containment
Document which network or firewall control can restrict SMB during a security incident and test that recovery operations remain possible.
This guide is particularly relevant to ransomware containment and lateral-movement reduction.