More Info:
Ensure that no network security groups allow unrestricted inbound access on TCP port 139 and UDP ports 137 and 138 (NetBIOS).Risk Level
HighAddress
SecurityCompliance Standards
- APRA CPS 234 (Australia)
- BSI C5 (Germany)
- Brazil LGPD
- CCPA / CPRA (California)
- CIS Critical Security Controls v8
- CMMC 2.0
- CSA Cloud Controls Matrix v4
- DPDPA
- Digital Operational Resilience Act (EU)
- FedRAMP
- GDPR
- HIPAA
- HITRUST CSF
- ISO/IEC 27017
- ISO/IEC 27018
- ISO/IEC 27701
- KSA PDPL
- MAS Technology Risk Management (Singapore)
- MITRE ATT&CK (Cloud)
- NIS2 Directive
- NIST
- NIST CSF
- NIST SP 800-171
- NYDFS 23 NYCRR 500
- PCI
- Reserve Bank of India (RBI) Cyber Security Framework
- Reserve Bank of India (RBI) Master Direction – Information Technology Framework
- SOC2
- SWIFT Customer Security Controls Framework
- Sarbanes-Oxley IT General Controls
- UK NCSC Cyber Assessment Framework
Triage and Remediation
- Remediation
Remediation
Using Console
Using Console
Here are the step-by-step instructions to remediate the Unrestricted Netbios Access misconfiguration in Azure:
- Log in to the Azure portal.
- Go to the “Virtual networks” page.
- Select the virtual network that you want to remediate.
- Click on the “Subnets” option in the left-hand menu.
- Select the subnet that you want to remediate.
- Click on the “Network security group” option in the left-hand menu.
- Click on the “Edit” button to edit the network security group associated with the subnet.
- Click on the “Inbound security rules” option in the left-hand menu.
- Find the rule that allows unrestricted NetBIOS access.
- Click on the rule to select it.
- Click on the “Delete” button to delete the rule.
- Click on the “Save” button to save the changes.
Using CLI
Using CLI
To remediate Unrestricted NetBIOS Access in Azure using Azure CLI, follow the below steps:Step 1: Open Azure CLI and login to your Azure account.Step 2: Run the below command to list all the network security groups in your subscription:Step 3: Identify the NSG that is associated with your virtual machine or subnet that has Unrestricted NetBIOS Access.Step 4: Run the below command to get the details of the NSG:Step 5: Identify the security rule that allows Unrestricted NetBIOS Access.Step 6: Run the below command to delete the security rule:Note: Replace Step 8: Repeat the above steps for all the NSGs that have Unrestricted NetBIOS Access.By following the above steps, you can remediate Unrestricted NetBIOS Access in Azure using Azure CLI.
<rule-name>, <nsg-name> and <resource-group-name> with the actual values.Step 7: Verify that the security rule is deleted by running the below command:Using Python
Using Python
To remediate Unrestricted Netbios Access in Azure using Python, you can follow the below steps:Step 1: Install the Azure SDK for Python using pip.Step 2: Authenticate with Azure using the below code.Step 3: Get the Network Security Group (NSG) that has unrestricted Netbios access using the below code.Step 4: Remove the rule that allows unrestricted Netbios access using the below code.This code will remove the rule that allows unrestricted Netbios access from the NSG. You can replace the
your_nsg_name, your_resource_group_name, and your_rule_name with your own values.Using Terraform
Using Terraform
azurerm_resource_group.RGwith your actual resource group resource orresource_group_name = "YOUR_RESOURCE_GROUP_NAME"andlocation = "YOUR_REGION".azurerm_network_security_group.NETBIOS_SECURED_NSGwith your existing NSG if you already manage it in Terraform; in that case, remove the NSG resource above and reference the existing one.
terraform plan should show the creation of the new azurerm_network_security_rule.deny_netbios_tcp_139 and azurerm_network_security_rule.deny_netbios_udp_137_138 resources (or updates to existing rules if you changed them), with access = "Deny" on the specified ports.
