Deterministic Low-Latency Systems Engineering & Zero-Trust Device Foundation
Table of Contents (Click to Expand)
- 1. Architectural Overview
- 2. Systems Architecture Blueprint
- 3. Workload Compatibility & Boundary Matrix
- 4. CIS Benchmark & NIST Compliance Posture
- 5. Staging & Unattended Deployment Topology
- 6. Parameter Reference
- 7. Subsystem Implementations
- 8. Verification & Diagnostic Auditing
- 9. Community & Technical Support
- 10. License
Aegis Win11 is an automated, unattended provisioning pipeline engineered to replace arbitrary optimization and debloating scripts with verifiable systems engineering. It establishes a defense-in-depth posture while preventing runtime conflicts within high-performance workstations.
Standard OS stripping scripts regularly induce system failures by severing mandatory networking components (such as unbinding IPv6), degrading process boundaries (grouping svchost.exe instances to claim trivial memory reductions), disabling system memory paging mechanisms, or injecting unvalidated storage driver overrides. Aegis Win11 isolates telemetry, minimizes persistence vectors, and enforces Microsoft Defender Application Control (WDAC) driver blocklists while explicitly maintaining hardware abstraction layers, low-latency audio pipelines, and enterprise identity integration.
Every policy within Aegis Win11 is evaluated against four non-negotiable operational workstation targets:
- Digital Audio Workstations (DAWs): Preserves native ASIO hardware driver abstraction layers (Focusrite, Universal Audio, RME, Behringer, MOTU). Disables Audio Processing Objects (APOs) via
DisableAllSoundEffectsto eliminate DPC latency spikes while keeping DRM protected media pipelines (Widevine, PlayReady) operational. MMCSS Audio task thread priorities are locked to real-time (Priority = 8). - Computer-Aided Design (CAD) & Rendering Suites: Maintains nested directory depths via NTFS Long Paths (
LongPathsEnabled = 1), disables NTFS timestamp write operations (NtfsDisableLastAccessUpdate = 1), disables 8.3 short filename generation (NtfsDisable8dot3NameCreation = 1), and enforces Hardware-Accelerated GPU Scheduling (HAGS) for applications including Autodesk Revit, AutoCAD, Blender, and Adobe Creative Cloud. - Competitive Gaming & Anti-Cheat Runtimes: Omits strict kernel-mode code integrity policies (
CodeIntegrityPolicy = 1) and system-wide Mandatory ASLR, ensuring compatibility with kernel-level anti-cheat platforms (Riot Vanguard, Easy Anti-Cheat, BattlEye) and local gaming clients (Steam, Epic Games). - Enterprise Suites & Identity Management: Supports both standalone workstation topologies and enterprise domains via Microsoft Entra ID / Local Administrator Password Solution (LAPS) integration toggles, preserving Windows Remote Management (WinRM) and modern Kerberos/NTLMv2 authentication pathways.
Aegis Win11 aligns with technical controls from the Center for Internet Security (CIS) Microsoft Windows 11 Enterprise Benchmark (v3.0.0) and NIST SP 800-53 Rev 5 / NIST SP 800-171 Rev 2.
- CIS Level 1 Profile (Enterprise Baseline): ~24% direct implementation (~60 active configuration directives).
- CIS Level 2 Profile (High Security / Defense-in-Depth): ~11% selective implementation.
- Standalone Implementation (Non-Domain Applicable): 63.0% of CIS Level 1 and 75.9% of NIST SP 800-53 workstation controls.
- Network & Protocol Fortress: 100% compliance across all applicable standalone network boundaries.
To maintain credibility during external audits and peer review, the framework documents intentional deviations from the CIS Level 2 benchmark:
- Process Mitigation (CIS 18.10.14.2.1): Bottom-Up ASLR, DEP, and SEHOP are enforced system-wide. Mandatory ASLR (
MandatoryASLR) is intentionally omitted; enforcing Mandatory ASLR globally causes immediate load termination for binaries and third-party audio/graphics DLLs not compiled with/DYNAMICBASE. - PowerShell Constrained Language Mode (CIS 18.10.43.1): Not enforced globally via system policies. Constrained Language Mode completely halts automation scripts, CI/CD runners, and un-cataloged DAW package installation logic.
- Controlled Folder Access (CIS 18.10.43.4.2): Defaulted to
AuditMode. Enforcing CFA inBlockmode stops creative software (FL Studio, Ableton, Autodesk) and game runtimes from writing legitimate save states, scratch files, and presets to%USERPROFILE%\Documents. - Network Protocol Binding (IPv6): IPv6 adapter bindings remain active. Microsoft core networking identifies IPv6 as a mandatory OS component; disabling IPv6 breaks Teredo gaming discovery, Entra ID hybrid join state sync, and WinRM listeners.
- SMB3 Payload Encryption (CIS 2.3.8.3): Mandatory SMB payload encryption (
EncryptData = 1) is omitted. Packet signing (RequireSecuritySignature = 1) is enforced to stop NTLM relay attacks, but payload encryption is withheld to avoid saturating workstation CPU cores during multi-gigabit media transfers across local NAS devices.
5. Staging & Unattended Deployment Topology
Deployment occurs across three discrete execution boundaries coordinated through autounattend.xml and staged PowerShell logic.
INSTALLER_USB:
└───autounattend.xml
└───sources
└───$OEM$
└───$1
└───Aegis
└───AegisWin11_Deploy.ps1
Warning
Deploying autounattend.xml with automated disk partitioning (WipeDisk=true) destroys all existing volume data on Disk 0. Ensure target machine data is backed up and BitLocker recovery keys are escrowed before boot media execution.
Ensure the target installation drive enumerates as Disk 0 in the UEFI BIOS prior to boot, or disconnect/disable secondary SATA/AHCI drives upon initial staging.
6. Parameter Reference (`AegisWin11_Deploy.ps1`)
| Parameter | Type | Default | Operational Impact |
|---|---|---|---|
-EnableAntiForensicMode |
Switch / Boolean | $false |
When $false, configures 64MB event logs and enables Event ID 4688 command-line process auditing. When $true, caps logs at 1024KB, disables process auditing, purges Prefetch, and clears the USN journal. |
-EnforceDeviceEncryption |
Switch / Boolean | $true |
When $true, verifies 4KB allocation unit size and provisions BitLocker XTS-AES-256 with TPM protection. |
-EnableLAPS_EntraIDSupport |
Switch / Boolean | $false |
When $true, enables LocalAccountTokenFilterPolicy and drops RestrictAnonymousSAM once the dynamic anchor user is verified. Bypasses local plaintext key export in favor of cloud escrow. |
-ServiceTagIDEnableHardware |
Switch / Boolean | $true |
Generates the administrative identity anchor from the BIOS serial number. Falls back to UUID/MAC SHA-256 hash if unavailable. |
-EnableEdgeTweaks |
Switch / Boolean | $true |
Applies 33 enterprise security GPOs to Edge and Brave, including DNS-over-HTTPS, ECH, and tracking blocks. |
-EnableTelemetryPurge |
Switch / Boolean | $true |
Strips consumer diagnostic tracking, Cortana, Windows Feeds, and advertising identifiers. |
-DeployWingetPackages |
Switch / Boolean | $true |
Executes automated, unattended Winget package installations for baseline development and runtime tools. |
-EvacuateLegacyCapabilities |
Switch / Boolean | $true |
Removes deprecated attack surfaces: WordPad, VBScript, WMIC, and PowerShell v2. |
-PurgeShellUI |
Switch / Boolean | $true |
Executes Option A targeted bloatware removal and wipes pinned items via Policy Manager. |
-PurgeOneDrive |
Switch / Boolean | $false |
When $true, uninstalls consumer OneDrive and removes explorer sidebar namespace CLSIDs. |
-AICreativeKernelTuning |
Switch / Boolean | $false |
When $true, extends GPU Timeout Detection and Recovery (TDR) limits to 60 seconds. |
-ChangeDefaultWin11Name |
Switch / Boolean | $true |
Updates the BCD bootloader description to Win11_Aegis_OS-$StickerID. |
-EnableVBS |
Switch / Boolean | $true |
Enforces Virtualization-Based Security via group policy. |
-EnableHVCI |
Switch / Boolean | $true |
Enforces Hypervisor-Enforced Code Integrity for kernel execution. |
-Unattended |
Switch / Boolean | $true |
Suppresses interactive GUI modal dialogues, routing credentials to the transcript file. |
-AutoReboot |
Switch / Boolean | $true |
Executes an automated reboot upon pipeline completion. If $false, pauses for operator interaction. |
-ControlledFolderAccessMode |
String (Disabled, Enabled, AuditMode) |
"AuditMode" |
Configures Microsoft Defender Controlled Folder Access. Defaulted to AuditMode to prevent DAW/CAD save failures. |
-DefaultSearchProvider |
String | "duckduckgo" |
Sets the default search engine configuration across enterprise browsers. |
7. Subsystem Implementations
The framework dynamically provisions a unique, hardware-bound administrative anchor during installation:
- Queries
Win32_Bios.SerialNumber. If non-standard, queriesWin32_ComputerSystemProduct.UUIDand hashes the output via SHA-256 to create a 6-character identifier ($StickerID). - Provisions
MHS-$StickerID-Adminwith a 24-character cryptographic password generated at runtime viaSystem.Security.Cryptography.RandomNumberGenerator. - Enforces an immediate credential reset upon first interactive console login (
net user ... /logonpasswordchg:yes). - Exports the secret to
C:\Windows\Panther\Aegis_Bootstrap_Secret.txtunder strict ACL permissions restricted toSYSTEMandAdministrators, then disables the built-inAdministratoraccount (SID S-1-5-500).
- Unified 4096-Byte File Allocation: The
autounattend.xmlschema forcesBlockAllocationSize = 4096on volumeC:during the clean WinPE format pass. Matching NTFS cluster sizes to physical 4KB NAND pages eliminates Read-Modify-Write (RMW) amplification loops, extending flash endurance and reducing I/O write latency. - Metadata & Index Suppression: Sets
NtfsDisableLastAccessUpdate = 1andNtfsDisable8dot3NameCreation = 1during OOBE setup. This stops Master File Table (MFT) write thrashing and eliminates 8.3 short filename generation overhead across directories containing massive file counts. - Continuous Controller Readiness: Configures
IdleTimeout = 0andEnableD3 = 0understornvme\Parameters\Device, keeping NVMe links in active power state D0 and eliminating controller wake-up latency during real-time I/O processing. - Storage Sense Automation: Injects native policies (
AllowStorageSenseGlobal = 1,ConfigStorageSenseCloudContentCleanThreshold = 30) to purge unreferenced temporary files automatically. - Push-Button Reset (PBR) 4KB Mirroring: Stages a bare-metal recovery engine via
C:\Recovery\OEM\ResetConfig.xml. If a full wipe reset is executed, WinRE formats the system partition using an exact 4096-byte quick format (format quick fs=ntfs unit=4096), guaranteeing that factory recovery operations maintain physical NAND page alignment. - Silent Hardware BitLocker Pipeline: Validates that TPM 2.0 is ready and that volume
C:possesses an allocation unit size of exactly 4096 bytes before silently enabling XTS-AES-256 BitLocker encryption with a TPM protector. If-EnableLAPS_EntraIDSupportis false, it archives the recovery password toC:\Aegis_BitLocker_Recovery.txt; otherwise, local export is bypassed in favor of cloud escrow.
Aegis Win11 rejects blanket wildcard AppX removal scripts (Get-AppxPackage | Remove-AppxPackage). Indiscriminate package uninstallation destroys versioned Windows 11 system runtimes (Microsoft.UI.Xaml.2.8), the Windows Security Center interface (Microsoft.SecHealthUI), and Microsoft Store infrastructure required for Winget package management.
The framework enforces an explicit, non-destructive consumer blacklist targeting third-party and non-essential consumer stubs (BingNews, BingWeather, Clipchamp, Solitaire, Zune Video, Todos). Both installed instances and online provisioned stubs (Get-AppxProvisionedPackage) are uninstalled, preventing re-provisioning on secondary local user profiles while keeping system dependencies intact.
The deployment report (Aegis_Deployment_Report.txt) and a direct shortcut to C:\Windows\Panther (Deployment_Logs.lnk) are generated during finalization and staged in the Panther vault. A post-install first-logon dispatcher (Aegis_PostLogon_Cleanup.ps1) transfers these files directly onto the created administrator's desktop (MHS-$StickerID-Admin), ensuring full visibility while keeping public and unprivileged desktops clean.
8. Verification & Diagnostic Auditing
Post-installation validation can be executed using elevated PowerShell diagnostic commands:
# 1. Verify 4KB Allocation Unit Size
Get-Volume -DriveLetter C | Select-Object DriveLetter, AllocationUnitSize, FileSystemLabel
# 2. Verify BitLocker Encryption Status and Algorithm (XtsAes256)
Get-BitLockerVolume -MountPoint "C:" | Select-Object MountPoint, ProtectionStatus, EncryptionMethod, VolumeType
# 3. Verify Attack Surface Reduction Rules (14 Rules in Block Mode)
Get-MpPreference | Select-Object -ExpandProperty AttackSurfaceReductionRules_Ids
Get-MpPreference | Select-Object -ExpandProperty AttackSurfaceReductionRules_Actions
# 4. Verify Exploit Guard System Mitigations
Get-ProcessMitigation -System
# 5. Verify User Rights Assignment for Network Logons
secedit.exe /export /cfg "$env:TEMP\secpol_verify.inf" /areas USER_RIGHTS /quiet
Select-String -Path "$env:TEMP\secpol_verify.inf" -Pattern "SeNetworkLogonRight"
Remove-Item -Path "$env:TEMP\secpol_verify.inf" -Force- Wiki Documentation: Aegis-Win11 Wiki
- Technical Reference Manual: 44-Item Policy Matrix
- Security Architecture Report: Formal Compliance Audit
- Community Discussions: GitHub Discussions
Released by Moosehead Studio under the MIT License. See LICENSE for details.

