Published on September 3, 2026 · 12 min read
Windows ships with a decent set of security features. Most people don't realize how much is already there. If you're wondering how much of a ransomware attack Windows can stop without third-party tools, the answer depends entirely on which switches you flip.
Ransomware attacks follow a predictable pattern. Not because attackers lack imagination — because there are only so many ways in. From initial access to encryption, they just need one path that works.
Phishing attachments, RDP brute force, and compromised websites are the main entry points. Zero-days make the news, but in practice most attacks use known vulnerabilities — systems that weren't patched, or users who clicked something they shouldn't have.
Defender's real-time scanning and SmartScreen are enabled by default. They catch most known malware and phishing links. But if a user clicks "Run anyway," or if the attacker uses fileless execution (running directly in memory without writing to disk), the default Defender setup doesn't always stop it.
MSHTA is a common one. A malicious URL triggers MSHTA to execute script in memory — no file ever touches the disk. Regsvr32 can do the same with remote scripts. Both bypass traditional file scanning.
That's where Controlled Folder Access comes in. It doesn't rely on signatures. It looks at process behavior and blocks unauthorized programs from modifying files in protected folders. Out of the box it's disabled, because it generates false positives and requires admin maintenance.
Set-MpPreference -EnableControlledFolderAccess Enabled
Once inside, attackers need to survive a reboot. The usual places: scheduled tasks, Registry Run keys, and the Startup folder.
Run keys live at:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run (all users)HKCU\Software\Microsoft\Windows\CurrentVersion\Run (current user)
By default, standard users can write to HKCU Run keys. No admin rights needed. Attackers can drop a malicious entry that runs every time the user logs in.
You can restrict this via Group Policy, but it's not on by default.
WDAC (Windows Defender Application Control) can block untrusted binaries from running at all — even if a scheduled task points to them. It's also off by default, because it requires planning and testing. In audit mode, it logs events without blocking, which is useful for testing before enforcement.
Common attacker command for scheduled tasks:
schtasks /create /tn "Updater" /tr C:\path\to\malware.exe /sc daily
Any user can create scheduled tasks unless you restrict it. Group Policy can limit who can create them, but the default is wide open.
Attackers want to know where they are. whoami, ipconfig, net view /all, systeminfo — these are the first things they run.
net view /all lists every machine in the domain or workgroup. If the current user is a domain user, it shows every registered machine in the domain. Attackers build their target list from that output.
The commands themselves are legitimate. The problem is attackers can run them. Windows can log these actions, but it's not enabled by default.
You can turn on process creation auditing (Event ID 4688) and PowerShell Script Block Logging through Group Policy. But logs only help if you actually review them or forward them to a SIEM. Without that, they're just entries in a file.
One compromised machine is rarely the end goal. Attackers move sideways using SMB and stolen credentials.
A single command can execute a payload on a remote machine:
schtasks /create /s 192.168.1.10 /ru SYSTEM /tr "C:\malware.exe" /tn "Update"
If the current account has admin rights on the target machine, no exploit is needed. Just credentials.
Port 445 is open by default on Windows because file sharing is enabled by default. If you don't need network shares, blocking 445 is the simplest fix.
On newer Windows 11 builds (22H2+), SMB signing and encryption are enabled by default. On older Windows 10 builds, you may need to configure them manually. Cross-version sharing may require client-side adjustments. Either way, signing prevents relay attacks.
You can also restrict 445 access to specific subnets via Windows Firewall, but most people never touch this.
Standard user accounts can only do so much. Attackers need admin or SYSTEM. UAC is the default control here, but it doesn't block admin accounts — it just asks.
UAC has four levels:
At the default level, many UAC bypasses work because Windows trusts child processes spawned from the current user context. Attackers use tools like wmic calling mshta, or built-in utilities like CMSTP, to bypass the prompt.
LSA protection (RunAsPPL) prevents credential dumping from lsass.exe. On domain-joined Windows 11 22H2 and later, it's enabled by default. On standalone or older Windows 10 systems, you need to set HKLM\SYSTEM\CurrentControlSet\Control\Lsa\RunAsPPL = 1 manually.
If you log in daily with an admin account, you're handing attackers a head start. Use a standard account for daily work and elevate only when needed.
Final stage. Files get encrypted, and shadow copies get deleted with:
vssadmin delete shadows /all /quiet
Any admin can run this. /quiet means no confirmation prompt.
Controlled Folder Access blocks unauthorized processes from modifying files in Desktop, Documents, Pictures, and other default folders. It's behavior-based, not signature-based. It works by maintaining an allowlist — admins must add legitimate apps to the list, otherwise they get blocked.
Attackers can still work around it by using processes already on the allowlist, like wmic.exe calling cscript.exe. CFA protects default system folders and allows admins to add custom folders, but default protected folders can't be removed.
It's a layer, not a silver bullet. You can further restrict vssadmin delete shadows via Group Policy or registry tweaks around vssvc.exe — but none of this is configured by default.
Windows can block a lot. Most of it just isn't turned on.
Controlled Folder Access, UAC at max level, LSA protection, SMB signing, PowerShell logging, WDAC — none of these are new. Together they cover most of the attack chain. They're off by default because compatibility takes priority over security. Turning them on might break legitimate software, so Microsoft leaves the choice to the admin. Most admins don't know these options exist.
Attackers don't exploit design flaws. They exploit default configurations. You don't need to reinvent security. You just need to turn on the right switches, close the right ports, and lock down the right permissions.
Digging through Group Policy and the registry takes time. Testing takes more. If you don't have the cycles for that, hardening tools exist to package these configurations into something repeatable and reversible. Running without third-party EDR doesn't mean running without protection. It just means you're choosing a path that depends more on configuration and maintenance than on a vendor's cloud backend.
Try WinRansomProtect free for 14 days.
⬇️ Download Free Trial