This script fixes the windows CIS Benchmark check 18.9.5.2: "Ensure 'Turn On Virtualization Based Security: Select Platform Security Level' is set to 'Secure Boot' or higher."
This script fixes the windows CIS Benchmark check 18.9.5.3: "Ensure 'Turn On Virtualization Based Security: Virtualization Based Protection of Code Integrity' is set to 'Enabled with UEFI lock'."
This script fixes the windows CIS Benchmark check 18.9.5.4: "Ensure 'Turn On Virtualization Based Security: Require UEFI Memory Attributes Table' is set to 'True (checked)'."
This script fixes the windows CIS Benchmark check 18.9.5.5: "Ensure 'Turn On Virtualization Based Security: Credential Guard Configuration' is set to 'Enabled with UEFI lock'."
This script fixes the windows CIS Benchmark check 18.9.5.7: "Ensure 'Turn On Virtualization Based Security: Kernel-mode Hardware-enforced Stack Protection' is set to 'Enabled: Enabled in enforcement mode'."
This script fixes the windows CIS Benchmark check 18.9.7.1.1: "Ensure 'Prevent installation of devices that match any of these device IDs' is set to 'Enabled'."
This script fixes the windows CIS Benchmark check 18.9.7.2: "Ensure 'Prevent device metadata retrieval from the Internet' is set to 'Enabled'."
This script fixes the windows CIS Benchmark check 18.9.13.1: "Ensure 'Boot-Start Driver Initialization Policy' is set to 'Enabled: Good, unknown and bad but critical'."
This script fixes the windows CIS Benchmark check 18.9.19.2: "Ensure 'Configure registry policy processing: Do not apply during periodic background processing' is set to 'Enabled: FALSE'."
This script fixes the windows CIS Benchmark check 18.9.19.3: "Ensure 'Configure registry policy processing: Process even if the Group Policy objects have not changed' is set to 'Enabled: TRUE'."