TechKnowSurge
VideoSecurityFree

Hardening - Remove Unnecessary Software

Every piece of installed software introduces a potential attack vector, making it essential to minimize unnecessary applications on any system. Reducing software exposure is a foundational step in hardening a machine against vulnerabilities.

Complete this video to capture a CTF flag worth 1 point.

About this video

Every piece of software installed on a system represents an additional attack surface. When a vulnerability exists in any one of those applications, it can potentially be leveraged to compromise other software on the machine or the entire system itself. Because vulnerabilities are discovered regularly and patches are released on an ongoing basis, maintaining a minimal software footprint is one of the most effective ways to reduce exposure. New machines frequently arrive with a substantial amount of preinstalled software that serves no operational purpose for the end user. Rather than attempting to identify and remove individual unnecessary applications — a process that can be incomplete or time-consuming — reimaging the machine and performing a clean operating system installation is often the more reliable approach. This eliminates unknown or unwanted software entirely and provides a controlled, minimal baseline from which a properly hardened system can be built.

What you'll learn

What's covered

Minimizing Software Attack Vectors

Key terms

Attack Surface
The total set of points in a system where an unauthorized user can attempt to enter or extract data.
Vulnerability
A weakness in a system, application, or process that can be exploited by a threat actor.
Patch Management
The process of acquiring, testing, and installing software updates to fix vulnerabilities and improve functionality.
Endpoint
Any device that connects to a network, including computers, smartphones, tablets, and IoT devices.
Attack Vector
The specific path or method a threat actor uses to gain unauthorized access to a system or network, such as a phishing email, an unpatched vulnerability, or a misconfigured network port.

Topics

System Hardening Attack Surface Reduction Endpoint Security Software Management Vulnerability Management Operating Systems

Transcript

For each piece of software that's installed on our computer, we open up another attack vector. We need to minimize how many attack vectors there are, and therefore we need to minimize how much software we have running on a computer.

Software is constantly being patched and updated for vulnerabilities. Let's imagine we have a vulnerable piece of software that's installed on this computer. That could open up other software to some sort of attack, or the whole computer to attack, if there is a vulnerability. So having just one piece of software can really expose the whole machine.

What we want to do is remove the possibility, or mitigate and lower the risk of this possibility, by not having unnecessary software.

Reimaging instead of uninstalling

What I've found is that a lot of machines, when you purchase them, will come with a lot of extra software that's unnecessary. So one of the things that I do, rather than trying to remove those, is I'll just actually wipe out the whole machine. I will reimage the machine or set up a new operating system on it. So I delete all the old stuff and reinstall the operating system.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →