Menu
CCMEXEC.COM – Enterprise Mobility
  • General
  • Configuration Manager
  • Windows 10
  • Windows 11
  • Intune
  • GitHub
  • About
CCMEXEC.COM – Enterprise Mobility

Block SSH using Windows Firewall

Posted on October 9, 2026October 9, 2026 by Jörgen Nilsson

Windows 11, Microsoft Edge and many other products are increasingly secure. One big challenge that is not handled by Windows 11 Secure by default is LOLBins – Living On the Land Binaries.

LOLBins (Living Off The Land Binaries) are legitimate Microsoft-signed executables that are built into Windows. While these tools are designed for administrative and system management tasks, threat actors can abuse them to perform malicious activities without deploying traditional malware.
Because LOLBins are trusted components of the operating system, their use often appears normal to security controls, making them an attractive option for attackers who want to evade detection and blend into everyday system activity.
Why do attackers use LOLBins?

Attackers leverage LOLBins because they can:
• Evade traditional antivirus and malware detection
• Bypass application control and allow-listing policies
• Blend in with legitimate administrator activity
• Reduce the need to introduce custom tools or malware
• Abuse trusted Windows functionality to execute code, download content, or move laterally within an environment
LOLBins should be blocked by using App Control for business or AppLocker for example. Many organizations do not block these binaries because the do not have any tool deployed to do it.

Microsoft posted a recommendation to block MSHta.exe in Defender

Why block SSH?

What we see is that ssh.exe is being used as a proxy and to download payloads and binaries on victim’s computers. So why not simply use Windows Firewall to block outgoing traffic from ssh.exe as well for example? How many normal office workers use the built-in ssh.exe in their day-to-day work?

Let’s block it!

Exactly like we block mshta.exe using Windows Firewall we block ssh.exe.
We create a new Windows Firewall rule in Intune with the following properties.

How can we verify it is blocked?

We can always test on a device and verify that we cannot connect anymore.

If we have defender for Endpoint P2 we can of course use Advanced hunting to verify that the Firewall rule works with a query like the one below.

Conclusion

We need to take the LOLBins seriously and block the use of them, SSH.exe can be used to launch other local applications and much more, we cannot block that with the Windows Firewall.
If a user needs to use SSH, make sure to open the Windows Firewall to the IP Adress that user should use it for an noting else.
Develop a way to block the LOLBins as part of your Windows Client hardening strategy.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

My name is Jörgen Nilsson and I work as a Senior Consultant at Onevinn in Malmö, Sweden. This is my blog where I will share tips and stuff for my own and everyone elses use on Enterprise Mobility and Windows related topics.
All code is provided "AS-IS" with no warranties.

Recent Posts

  • Block SSH using Windows Firewall
  • Windows 365 – Placing a Cloud PC Under Review
  • Edge management service – extension monitoring
  • Microsoft Intune Endpoint Privilege Management – Overview
  • MMUGSE – Summer 2026 meetup
©2026 CCMEXEC.COM – Enterprise Mobility | WordPress Theme by Superb Themes
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish.Accept Reject Read More
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT