sync: auto-sync from Mikes-MacBook-Air.local at 2026-06-06 11:32:15
Author: Mike Swanson Machine: Mikes-MacBook-Air.local Timestamp: 2026-06-06 11:32:15
This commit is contained in:
@@ -0,0 +1,873 @@
|
||||
{
|
||||
"host": "GTS-PEDRO-H",
|
||||
"collected_at_utc": "2026-06-06T18:10:36Z",
|
||||
"os": {
|
||||
"caption": "Microsoft Windows 11 Home",
|
||||
"version": "10.0.26200",
|
||||
"build": "26200",
|
||||
"install_date": "2025-02-15T22:25:45Z",
|
||||
"last_boot_utc": "2026-05-24T01:34:12Z",
|
||||
"architecture": "64-bit"
|
||||
},
|
||||
"facts": {
|
||||
"builtin_admin_enabled": false,
|
||||
"os_eol": {
|
||||
"eol_date": "2027-10-12",
|
||||
"release": "Win11 25H2"
|
||||
},
|
||||
"pending_updates": 2,
|
||||
"pending_reboot": true,
|
||||
"uptime_days": 13.7,
|
||||
"acg_managed_tools": "ScreenConnect / ConnectWise Control",
|
||||
"hardware": {
|
||||
"model": "90SM006QUS",
|
||||
"manufacturer": "LENOVO",
|
||||
"bios_date": "2023-01-03",
|
||||
"cpu_logical": 12,
|
||||
"bios_version": "M49KT21A",
|
||||
"cpu_cores": 6,
|
||||
"ram_gb": 15.7,
|
||||
"serial": "MJ0J9LD1",
|
||||
"cpu": "12th Gen Intel(R) Core(TM) i5-12400"
|
||||
},
|
||||
"third_party_av_active": false,
|
||||
"os_build": "26200",
|
||||
"secure_boot": true,
|
||||
"backup_agents": null,
|
||||
"autoruns_run_keys": [
|
||||
{
|
||||
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
|
||||
"name": "SecurityHealth",
|
||||
"value": "C:\\WINDOWS\\system32\\SecurityHealthSystray.exe"
|
||||
},
|
||||
{
|
||||
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
|
||||
"name": "RtkAudUService",
|
||||
"value": "\"C:\\WINDOWS\\System32\\DriverStore\\FileRepository\\realtekservice.inf_amd64_23392958033090bf\\RtkAudUService64.exe\" -background"
|
||||
},
|
||||
{
|
||||
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
|
||||
"name": "msedge_cleanup_{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}",
|
||||
"value": "\"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\149.0.4022.52\\Installer\\setup.exe\" --msedge --channel=stable --delete-old-versions --system-level --verbose-logging --on-logon"
|
||||
}
|
||||
],
|
||||
"physical_disks": [
|
||||
{
|
||||
"health": "Healthy",
|
||||
"model": "WDC PC SN540 SDDPNPF-1T00-1032",
|
||||
"media_type": "SSD"
|
||||
}
|
||||
],
|
||||
"local_users": [
|
||||
{
|
||||
"last_logon": "2022-08-26",
|
||||
"name": "Administrator",
|
||||
"password_never_expires": false,
|
||||
"enabled": false
|
||||
},
|
||||
{
|
||||
"last_logon": "",
|
||||
"name": "DefaultAccount",
|
||||
"password_never_expires": false,
|
||||
"enabled": false
|
||||
},
|
||||
{
|
||||
"last_logon": "",
|
||||
"name": "Guest",
|
||||
"password_never_expires": false,
|
||||
"enabled": false
|
||||
},
|
||||
{
|
||||
"last_logon": "",
|
||||
"name": "pgonz",
|
||||
"password_never_expires": false,
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"last_logon": "2026-05-23",
|
||||
"name": "QBDataServiceUser33",
|
||||
"password_never_expires": false,
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"last_logon": "",
|
||||
"name": "WDAGUtilityAccount",
|
||||
"password_never_expires": false,
|
||||
"enabled": false
|
||||
}
|
||||
],
|
||||
"scheduled_tasks_count": 35,
|
||||
"volumes": [
|
||||
{
|
||||
"drive": "[SYSTEM]",
|
||||
"size_gb": 0.2,
|
||||
"free_pct": 76.9,
|
||||
"free_gb": 0.2
|
||||
},
|
||||
{
|
||||
"drive": "C:",
|
||||
"size_gb": 951.6,
|
||||
"free_pct": 76.1,
|
||||
"free_gb": 723.7
|
||||
},
|
||||
{
|
||||
"drive": "[WinRE_DRV]",
|
||||
"size_gb": 2,
|
||||
"free_pct": 64.3,
|
||||
"free_gb": 1.3
|
||||
}
|
||||
],
|
||||
"network_adapters": [
|
||||
{
|
||||
"dhcp": false,
|
||||
"description": "ZeroTier Virtual Port",
|
||||
"gateway": [
|
||||
"25.255.255.254"
|
||||
],
|
||||
"mac": "7A:B3:7D:18:B8:91",
|
||||
"ip": [
|
||||
"10.244.10.231",
|
||||
"fe80::2bae:96e1:f136:d2d9",
|
||||
"fc2a:89c2:7b0d:1a52:bbed::1"
|
||||
],
|
||||
"dns": [
|
||||
"10.244.163.165"
|
||||
]
|
||||
},
|
||||
{
|
||||
"dhcp": true,
|
||||
"description": "Realtek RTL8852AE WiFi 6 802.11ax PCIe Adapter",
|
||||
"gateway": [
|
||||
"192.168.0.1",
|
||||
"fe80::b293:5bff:feb7:1fe4"
|
||||
],
|
||||
"mac": "E0:0A:F6:A5:E8:4F",
|
||||
"ip": [
|
||||
"192.168.0.146",
|
||||
"fe80::5f87:acec:b8fd:313f",
|
||||
"2600:8800:782c:5c00:ecc4:b8ee:f191:f8e9",
|
||||
"2600:8800:782c:5c00:94a1:fdd7:a658:a330",
|
||||
"2600:8800:782c:5c00:2abd:1cc9:5150:9bc7",
|
||||
"2600:8800:782c:5c00::bc77"
|
||||
],
|
||||
"dns": [
|
||||
"68.105.28.11",
|
||||
"68.105.29.11",
|
||||
"68.105.28.12"
|
||||
]
|
||||
}
|
||||
],
|
||||
"failed_autostart_services": [
|
||||
{
|
||||
"name": "gpsvc",
|
||||
"display": "Group Policy Client",
|
||||
"state": "Stopped"
|
||||
},
|
||||
{
|
||||
"name": "Intel(R) Platform License Manager Service",
|
||||
"display": "Intel(R) Platform License Manager Service",
|
||||
"state": "Stopped"
|
||||
},
|
||||
{
|
||||
"name": "QBVSS",
|
||||
"display": "QBIDPService",
|
||||
"state": "Stopped"
|
||||
},
|
||||
{
|
||||
"name": "GoogleUpdaterInternalService150.0.7863.0",
|
||||
"display": "Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)",
|
||||
"state": "Stopped"
|
||||
},
|
||||
{
|
||||
"name": "GoogleUpdaterService150.0.7863.0",
|
||||
"display": "Google Updater Service (GoogleUpdaterService150.0.7863.0)",
|
||||
"state": "Stopped"
|
||||
}
|
||||
],
|
||||
"stability_14d": {
|
||||
"unexpected_shutdowns": 0,
|
||||
"disk_errors": 1,
|
||||
"bugchecks": 0
|
||||
},
|
||||
"exposure": {
|
||||
"smb1_enabled": false,
|
||||
"laps_present": true,
|
||||
"rdp_enabled": false,
|
||||
"uac_enabled": true,
|
||||
"rdp_nla": true
|
||||
},
|
||||
"accounts_password_never_expires": [],
|
||||
"installed_software": [
|
||||
{
|
||||
"publisher": "Atlas Business Solutions, Inc.",
|
||||
"name": "ABS PDF Install",
|
||||
"version": "4.6.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Lenovo",
|
||||
"name": "Calliope_Keyboard",
|
||||
"version": "1.00.08"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Copilot",
|
||||
"version": "148.0.3967.96"
|
||||
},
|
||||
{
|
||||
"publisher": "Drake Software",
|
||||
"name": "Drake Accounting 2025",
|
||||
"version": "25.0.18"
|
||||
},
|
||||
{
|
||||
"publisher": "Intel Corporation",
|
||||
"name": "Dynamic Application Loader Host Interface Service",
|
||||
"version": "1.0.0.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Google LLC",
|
||||
"name": "Google Chrome",
|
||||
"version": "148.0.7778.217"
|
||||
},
|
||||
{
|
||||
"publisher": "Intel Corporation",
|
||||
"name": "Intel(R) Chipset Device Software",
|
||||
"version": "10.1.18836.8283"
|
||||
},
|
||||
{
|
||||
"publisher": "Intel Corporation",
|
||||
"name": "Intel(R) Icls",
|
||||
"version": "1.0.0.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Intel Corporation",
|
||||
"name": "Intel(R) Management Engine Components",
|
||||
"version": "1.0.0.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Intel Corporation",
|
||||
"name": "Intel(R) Management Engine Components",
|
||||
"version": "2307.4.12.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Intel Corporation",
|
||||
"name": "Intel(R) Management Engine Driver",
|
||||
"version": "1.0.0.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Intel Corporation",
|
||||
"name": "Intel(R) ME WMI Provider",
|
||||
"version": "1.0.0.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Lenovo Group Ltd.",
|
||||
"name": "Lenovo Vantage Service",
|
||||
"version": "4.1.22.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Host - 6.0.36 (x86)",
|
||||
"version": "48.144.23141"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Host - 8.0.27 (x86)",
|
||||
"version": "64.108.52182"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Host FX Resolver - 6.0.36 (x86)",
|
||||
"version": "48.144.23141"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Host FX Resolver - 8.0.27 (x86)",
|
||||
"version": "64.108.52182"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Runtime - 6.0.36 (x86)",
|
||||
"version": "48.144.23141"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Runtime - 8.0.27 (x86)",
|
||||
"version": "64.108.52182"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft 365 - en-us",
|
||||
"version": "16.0.20026.20112"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft ASP.NET Core 8.0.27 - Shared Framework (x86)",
|
||||
"version": "8.0.27.26230"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft ASP.NET Core 8.0.27 Shared Framework (x86)",
|
||||
"version": "8.0.27.26230"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Edge",
|
||||
"version": "149.0.4022.52"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Edge WebView2 Runtime",
|
||||
"version": "148.0.3967.96"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft OneNote - en-us",
|
||||
"version": "16.0.20026.20112"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft SQL Server Compact 4.0 SP1 x64 ENU",
|
||||
"version": "4.0.8876.1"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft",
|
||||
"name": "Microsoft Teams Meeting Add-in for Microsoft Office",
|
||||
"version": "1.25.28902"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Update Health Tools",
|
||||
"version": "5.72.0.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17",
|
||||
"version": "9.0.30729"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161",
|
||||
"version": "9.0.30729.6161"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501",
|
||||
"version": "12.0.30501.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501",
|
||||
"version": "12.0.30501.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005",
|
||||
"version": "12.0.21005"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005",
|
||||
"version": "12.0.21005"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005",
|
||||
"version": "12.0.21005"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005",
|
||||
"version": "12.0.21005"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.44.35211",
|
||||
"version": "14.44.35211.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.44.35211",
|
||||
"version": "14.44.35211.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2022 X64 Additional Runtime - 14.44.35211",
|
||||
"version": "14.44.35211"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.44.35211",
|
||||
"version": "14.44.35211"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2022 X86 Additional Runtime - 14.44.35211",
|
||||
"version": "14.44.35211"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.44.35211",
|
||||
"version": "14.44.35211"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Windows Desktop Runtime - 6.0.36 (x86)",
|
||||
"version": "48.144.23186"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Windows Desktop Runtime - 6.0.36 (x86)",
|
||||
"version": "6.0.36.34217"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Windows Desktop Runtime - 8.0.27 (x86)",
|
||||
"version": "64.108.52193"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Windows Desktop Runtime - 8.0.27 (x86)",
|
||||
"version": "8.0.27.36030"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Office 16 Click-to-Run Extensibility Component",
|
||||
"version": "16.0.20026.20076"
|
||||
},
|
||||
{
|
||||
"publisher": "Intuit Inc.",
|
||||
"name": "QuickBooks",
|
||||
"version": "33.0.4003.3302"
|
||||
},
|
||||
{
|
||||
"publisher": "Intuit Inc.",
|
||||
"name": "QuickBooks Enterprise Solutions 23.0",
|
||||
"version": "33.0.4003.3302"
|
||||
},
|
||||
{
|
||||
"publisher": "Intuit Inc.",
|
||||
"name": "QuickBooks Runtime Redistributable",
|
||||
"version": "1.00.0000"
|
||||
},
|
||||
{
|
||||
"publisher": "Realtek Semiconductor Corp.",
|
||||
"name": "Realtek Audio Driver",
|
||||
"version": "6.0.9225.1"
|
||||
},
|
||||
{
|
||||
"publisher": "Realtek Semiconductor Corp.",
|
||||
"name": "Realtek Card Reader",
|
||||
"version": "10.0.22000.31269"
|
||||
},
|
||||
{
|
||||
"publisher": "ScreenConnect Software",
|
||||
"name": "ScreenConnect Client (1912bf3444b41a08)",
|
||||
"version": "26.1.24.9579"
|
||||
},
|
||||
{
|
||||
"publisher": "win.rar GmbH",
|
||||
"name": "WinRAR 7.00 beta 4 (64-bit)",
|
||||
"version": "7.00.4"
|
||||
},
|
||||
{
|
||||
"publisher": "ZeroTier, Inc.",
|
||||
"name": "ZeroTier One",
|
||||
"version": "1.12.2"
|
||||
}
|
||||
],
|
||||
"tpm": {
|
||||
"enabled": true,
|
||||
"ready": true,
|
||||
"present": true
|
||||
},
|
||||
"local_groups": [
|
||||
"Administrators",
|
||||
"Device Owners",
|
||||
"Distributed COM Users",
|
||||
"Event Log Readers",
|
||||
"Guests",
|
||||
"Hyper-V Administrators",
|
||||
"IIS_IUSRS",
|
||||
"OpenSSH Users",
|
||||
"Performance Log Users",
|
||||
"Performance Monitor Users",
|
||||
"Remote Management Users",
|
||||
"System Managed Accounts Group",
|
||||
"User Mode Hardware Operators",
|
||||
"Users"
|
||||
],
|
||||
"battery": {
|
||||
"present": false
|
||||
},
|
||||
"activation": {
|
||||
"edition": "Microsoft Windows 11 Home",
|
||||
"description": "Windows(R) Operating System, OEM_DM channel",
|
||||
"licensed": true,
|
||||
"license_status_code": 1
|
||||
},
|
||||
"time_source": "time.windows.com,0x9",
|
||||
"chassis_types": [
|
||||
3
|
||||
],
|
||||
"last_hotfix": {
|
||||
"hotfix_id": "KB5089549",
|
||||
"installed_on": "2026-05-21T07:00:00Z"
|
||||
},
|
||||
"scheduled_tasks": [
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "Calliope_Keyboard",
|
||||
"state": "Running"
|
||||
},
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "MicrosoftEdgeUpdateTaskMachineCore",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "MicrosoftEdgeUpdateTaskMachineUA",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "OneDrive Reporting Task-S-1-5-21-3052971633-1913791397-467572743-1001",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "OneDrive Standalone Update Task-S-1-5-21-3052971633-1913791397-467572743-1001",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "OneDrive Startup Task-S-1-5-21-3052971633-1913791397-467572743-1001",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\GoogleSystem\\GoogleUpdater\\",
|
||||
"name": "GoogleUpdaterTaskSystem150.0.7863.0{33CFAE4D-D353-44AD-948F-7D72E567628E}",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\GoogleUserPEH\\",
|
||||
"name": "RunPlatformExperienceHelperOnUnlock",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\GoogleUserPEH\\",
|
||||
"name": "RunPlatformExperienceHelper_Daily",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\GoogleUserPEH\\",
|
||||
"name": "RunPlatformExperienceHelper_Metrics",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\ImController\\",
|
||||
"name": "Lenovo iM Controller Monitor",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\ImController\\",
|
||||
"name": "Lenovo iM Controller Scheduled Maintenance",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\ImController\\Plugins\\",
|
||||
"name": "LenovoSystemUpdatePlugin_WeeklyTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\ImController\\TimeBasedEvents\\",
|
||||
"name": "48df2383-15fe-49ab-8f16-d4274103ead0",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\ImController\\TimeBasedEvents\\",
|
||||
"name": "66724497-f49c-4fc3-aa8a-4d373ddeea45",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\ImController\\TimeBasedEvents\\",
|
||||
"name": "aadd3f56-8002-4b8c-aec2-d0ff202832d3",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\UDC\\",
|
||||
"name": "Lenovo UDC Idle Monitor",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\UDC\\",
|
||||
"name": "Lenovo UDC Lazy Deployment",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\UDC\\",
|
||||
"name": "Lenovo UDC Maintainance Task",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\UDC\\",
|
||||
"name": "Lenovo UDC Monitor",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\",
|
||||
"name": "Lenovo.Vantage.ServiceMaintainance",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\",
|
||||
"name": "StartupFixPlan",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "BatteryGaugeAddinDailyScheduleTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "DailyTelemetryTransmission",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "GenericMessagingAddin",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "HeartbeatAddinDailyScheduleTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "Lenovo.Vantage.SmartPerformance.MonthlyReport",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "Lenovo.Vantage.SmartPerformance.SScan",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "LenovoBoostAddin.Prompt",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "LenovoCompanionAppAddinDailyScheduleTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "LenovoSystemUpdateAddin_WeeklyTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "SmartPerformance.ExpireReminder",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "VantageCoreAddinWeekScheduleTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\SoftLanding\\S-1-5-21-3052971633-1913791397-467572743-1001\\",
|
||||
"name": "SoftLandingCreativeManagementTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\SoftLanding\\S-1-5-21-3052971633-1913791397-467572743-1001\\",
|
||||
"name": "SoftLandingDeferralTask-{327badb4-08f8-4096-87f5-ffbafcb0a5d8}",
|
||||
"state": "Ready"
|
||||
}
|
||||
],
|
||||
"antivirus_products": [
|
||||
"Windows Defender"
|
||||
],
|
||||
"domain_joined": false,
|
||||
"defender": {
|
||||
"antispyware_signature_age": 0,
|
||||
"tamper_protected": true,
|
||||
"real_time_protection": true,
|
||||
"nis_enabled": true,
|
||||
"available": true,
|
||||
"antivirus_enabled": true,
|
||||
"am_service_enabled": true
|
||||
},
|
||||
"bitlocker": {
|
||||
"os_volume": "C:",
|
||||
"key_protectors": [],
|
||||
"recovery_key_present": false,
|
||||
"available": true,
|
||||
"encryption_percent": 0,
|
||||
"protection_status": "Off"
|
||||
},
|
||||
"is_laptop": false,
|
||||
"installed_software_count": 55,
|
||||
"local_administrators": [
|
||||
"GTS-PEDRO-H\\Administrator",
|
||||
"GTS-PEDRO-H\\pgonz"
|
||||
],
|
||||
"firewall_profiles": {
|
||||
"Private": true,
|
||||
"Domain": true,
|
||||
"Public": true
|
||||
},
|
||||
"domain": "WORKGROUP",
|
||||
"foreign_agents": null
|
||||
},
|
||||
"findings": [
|
||||
{
|
||||
"id": "sec.defender.ok",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Defender active and current",
|
||||
"detail": "Real-time protection on, service running, signatures current.",
|
||||
"evidence": "RealTimeProtectionEnabled=True; AMServiceEnabled=True; AntispywareSignatureAge=0 days; IsTamperProtected=True"
|
||||
},
|
||||
{
|
||||
"id": "sec.av_products.defender_only",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Defender is the only registered AV",
|
||||
"detail": "Only Microsoft/Windows Defender is registered in Security Center.",
|
||||
"evidence": "Windows Defender"
|
||||
},
|
||||
{
|
||||
"id": "sec.foreign_agents.none",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "No competitor/leftover management agents detected",
|
||||
"detail": "No known competitor RMM or unmanaged remote-access agents found in installed programs or services.",
|
||||
"evidence": "Scanned uninstall hives (HKLM + WOW6432Node) and Win32_Service"
|
||||
},
|
||||
{
|
||||
"id": "sec.foreign_agents.acg.screenconnect_connectwise_control",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Expected ACG management tooling present: ScreenConnect / ConnectWise Control",
|
||||
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
|
||||
"evidence": "program: ScreenConnect Client (1912bf3444b41a08) 26.1.24.9579\nservice: ScreenConnect Client (1912bf3444b41a08) (ScreenConnect Client (1912bf3444b41a08)) Running"
|
||||
},
|
||||
{
|
||||
"id": "sec.firewall.ok",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "All firewall profiles enabled",
|
||||
"detail": "Domain, Private, and Public firewall profiles are all enabled.",
|
||||
"evidence": "Private=True; Domain=True; Public=True"
|
||||
},
|
||||
{
|
||||
"id": "sec.bitlocker.unencrypted",
|
||||
"category": "security",
|
||||
"severity": "warning",
|
||||
"title": "OS volume is NOT encrypted with BitLocker",
|
||||
"detail": "The operating system volume is unencrypted. Data is exposed if the disk is removed or the device is lost. Enable BitLocker and escrow the recovery key.",
|
||||
"evidence": "Volume=C:; ProtectionStatus=Off; EncryptionPercentage=0; KeyProtectors="
|
||||
},
|
||||
{
|
||||
"id": "sec.local_admins.list",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Local administrators (2)",
|
||||
"detail": "Members of the local Administrators group. Review for unexpected or unknown accounts (especially leftover MSP/vendor accounts from a prior provider).",
|
||||
"evidence": "GTS-PEDRO-H\\Administrator\nGTS-PEDRO-H\\pgonz"
|
||||
},
|
||||
{
|
||||
"id": "sec.patch.os_supported",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "OS build supported: Win11 25H2",
|
||||
"detail": "Build 26200 (Win11 25H2) is in support until 2027-10-12.",
|
||||
"evidence": "Microsoft Windows 11 Home build 26200"
|
||||
},
|
||||
{
|
||||
"id": "sec.patch.pending",
|
||||
"category": "security",
|
||||
"severity": "warning",
|
||||
"title": "2 pending Windows updates",
|
||||
"detail": "Windows Update reports pending (not installed, not hidden) updates. Some may be security updates. Approve/install on the next maintenance window.",
|
||||
"evidence": "Microsoft.Update.Session search IsInstalled=0 and IsHidden=0 -> 2"
|
||||
},
|
||||
{
|
||||
"id": "sec.patch.last_hotfix",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Last hotfix: KB5089549",
|
||||
"detail": "Most recently installed update (from Get-HotFix; reflects CBS/MSU packages, not all cumulative metadata).",
|
||||
"evidence": "KB5089549 installed 2026-05-21T07:00:00Z"
|
||||
},
|
||||
{
|
||||
"id": "sec.exposure.smb1_off",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "SMBv1 disabled",
|
||||
"detail": "SMBv1 server protocol is disabled.",
|
||||
"evidence": "EnableSMB1Protocol=False"
|
||||
},
|
||||
{
|
||||
"id": "sec.exposure.laps_present",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "LAPS detected",
|
||||
"detail": "A LAPS mechanism is present.",
|
||||
"evidence": "Windows LAPS reg key"
|
||||
},
|
||||
{
|
||||
"id": "health.stability.some",
|
||||
"category": "health",
|
||||
"severity": "warning",
|
||||
"title": "Stability events present in the last 14 days",
|
||||
"detail": "One or more unexpected shutdowns, BSODs, or disk errors occurred recently. Monitor and correlate with user reports.",
|
||||
"evidence": "Unexpected shutdowns (id 41)=0; Bugchecks/BSOD (id 1001)=0; Disk errors (id 7/51/153)=1"
|
||||
},
|
||||
{
|
||||
"id": "health.reboot_uptime.pending",
|
||||
"category": "health",
|
||||
"severity": "warning",
|
||||
"title": "Reboot pending",
|
||||
"detail": "A reboot is pending. Pending reboots can block patches and leave the system in a half-updated state. Schedule a restart.",
|
||||
"evidence": "PendingFileRenameOperations"
|
||||
},
|
||||
{
|
||||
"id": "health.failed_services.stopped",
|
||||
"category": "health",
|
||||
"severity": "warning",
|
||||
"title": "5 auto-start service(s) not running",
|
||||
"detail": "These services are set to start automatically but are not running. Some may be benign; review for security agents, backup agents, or AV that should be running.",
|
||||
"evidence": "gpsvc (Group Policy Client) = Stopped\nIntel(R) Platform License Manager Service (Intel(R) Platform License Manager Service) = Stopped\nQBVSS (QBIDPService) = Stopped\nGoogleUpdaterInternalService150.0.7863.0 (Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)) = Stopped\nGoogleUpdaterService150.0.7863.0 (Google Updater Service (GoogleUpdaterService150.0.7863.0)) = Stopped"
|
||||
},
|
||||
{
|
||||
"id": "health.domain.workgroup",
|
||||
"category": "health",
|
||||
"severity": "info",
|
||||
"title": "Not domain-joined (workgroup)",
|
||||
"detail": "This machine is in workgroup/Azure AD only mode (Domain=WORKGROUP). No on-prem AD secure channel applies.",
|
||||
"evidence": "PartOfDomain=False; Domain=WORKGROUP"
|
||||
},
|
||||
{
|
||||
"id": "health.time.source",
|
||||
"category": "health",
|
||||
"severity": "info",
|
||||
"title": "Time service source",
|
||||
"detail": "Current Windows Time service source.",
|
||||
"evidence": "Source=time.windows.com,0x9"
|
||||
},
|
||||
{
|
||||
"id": "health.backup.none",
|
||||
"category": "health",
|
||||
"severity": "info",
|
||||
"title": "No backup agent detected",
|
||||
"detail": "No known backup agent service found. Backup expectation varies by endpoint; confirm whether this machine is supposed to have local/cloud backup and whether server-side or M365 backup covers it.",
|
||||
"evidence": "No matching backup service in Win32_Service"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,227 @@
|
||||
# Onboarding Diagnostic Baseline - GTS-PEDRO-H
|
||||
|
||||
- **Grade:** AMBER
|
||||
- **Host:** GTS-PEDRO-H
|
||||
- **Client:** Gonzvar Tax Services (`gonzvar-tax-services`)
|
||||
- **Collected (UTC):** 2026-06-06T18:10:36Z
|
||||
- **Agent ID:** 2f1499f8-2e04-44fa-89a8-ad93736e9787
|
||||
- **Command ID:** d7e48e75-c5ba-44df-85e5-63c463916854
|
||||
- **Findings:** 0 critical / 5 warning / 13 info / 0 unknown
|
||||
|
||||
- **OS:** Microsoft Windows 11 Home (build 26200)
|
||||
|
||||
---
|
||||
|
||||
## WARNING (5)
|
||||
|
||||
### OS volume is NOT encrypted with BitLocker
|
||||
- **Category:** security
|
||||
- **ID:** `sec.bitlocker.unencrypted`
|
||||
- The operating system volume is unencrypted. Data is exposed if the disk is removed or the device is lost. Enable BitLocker and escrow the recovery key.
|
||||
|
||||
```
|
||||
Volume=C:; ProtectionStatus=Off; EncryptionPercentage=0; KeyProtectors=
|
||||
```
|
||||
|
||||
### 2 pending Windows updates
|
||||
- **Category:** security
|
||||
- **ID:** `sec.patch.pending`
|
||||
- Windows Update reports pending (not installed, not hidden) updates. Some may be security updates. Approve/install on the next maintenance window.
|
||||
|
||||
```
|
||||
Microsoft.Update.Session search IsInstalled=0 and IsHidden=0 -> 2
|
||||
```
|
||||
|
||||
### Stability events present in the last 14 days
|
||||
- **Category:** health
|
||||
- **ID:** `health.stability.some`
|
||||
- One or more unexpected shutdowns, BSODs, or disk errors occurred recently. Monitor and correlate with user reports.
|
||||
|
||||
```
|
||||
Unexpected shutdowns (id 41)=0; Bugchecks/BSOD (id 1001)=0; Disk errors (id 7/51/153)=1
|
||||
```
|
||||
|
||||
### Reboot pending
|
||||
- **Category:** health
|
||||
- **ID:** `health.reboot_uptime.pending`
|
||||
- A reboot is pending. Pending reboots can block patches and leave the system in a half-updated state. Schedule a restart.
|
||||
|
||||
```
|
||||
PendingFileRenameOperations
|
||||
```
|
||||
|
||||
### 5 auto-start service(s) not running
|
||||
- **Category:** health
|
||||
- **ID:** `health.failed_services.stopped`
|
||||
- These services are set to start automatically but are not running. Some may be benign; review for security agents, backup agents, or AV that should be running.
|
||||
|
||||
```
|
||||
gpsvc (Group Policy Client) = Stopped
|
||||
Intel(R) Platform License Manager Service (Intel(R) Platform License Manager Service) = Stopped
|
||||
QBVSS (QBIDPService) = Stopped
|
||||
GoogleUpdaterInternalService150.0.7863.0 (Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)) = Stopped
|
||||
GoogleUpdaterService150.0.7863.0 (Google Updater Service (GoogleUpdaterService150.0.7863.0)) = Stopped
|
||||
```
|
||||
|
||||
|
||||
## INFO (13)
|
||||
|
||||
### Defender active and current
|
||||
- **Category:** security
|
||||
- **ID:** `sec.defender.ok`
|
||||
- Real-time protection on, service running, signatures current.
|
||||
|
||||
```
|
||||
RealTimeProtectionEnabled=True; AMServiceEnabled=True; AntispywareSignatureAge=0 days; IsTamperProtected=True
|
||||
```
|
||||
|
||||
### Defender is the only registered AV
|
||||
- **Category:** security
|
||||
- **ID:** `sec.av_products.defender_only`
|
||||
- Only Microsoft/Windows Defender is registered in Security Center.
|
||||
|
||||
```
|
||||
Windows Defender
|
||||
```
|
||||
|
||||
### No competitor/leftover management agents detected
|
||||
- **Category:** security
|
||||
- **ID:** `sec.foreign_agents.none`
|
||||
- No known competitor RMM or unmanaged remote-access agents found in installed programs or services.
|
||||
|
||||
```
|
||||
Scanned uninstall hives (HKLM + WOW6432Node) and Win32_Service
|
||||
```
|
||||
|
||||
### Expected ACG management tooling present: ScreenConnect / ConnectWise Control
|
||||
- **Category:** security
|
||||
- **ID:** `sec.foreign_agents.acg.screenconnect_connectwise_control`
|
||||
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
|
||||
|
||||
```
|
||||
program: ScreenConnect Client (1912bf3444b41a08) 26.1.24.9579
|
||||
service: ScreenConnect Client (1912bf3444b41a08) (ScreenConnect Client (1912bf3444b41a08)) Running
|
||||
```
|
||||
|
||||
### All firewall profiles enabled
|
||||
- **Category:** security
|
||||
- **ID:** `sec.firewall.ok`
|
||||
- Domain, Private, and Public firewall profiles are all enabled.
|
||||
|
||||
```
|
||||
Private=True; Domain=True; Public=True
|
||||
```
|
||||
|
||||
### Local administrators (2)
|
||||
- **Category:** security
|
||||
- **ID:** `sec.local_admins.list`
|
||||
- Members of the local Administrators group. Review for unexpected or unknown accounts (especially leftover MSP/vendor accounts from a prior provider).
|
||||
|
||||
```
|
||||
GTS-PEDRO-H\Administrator
|
||||
GTS-PEDRO-H\pgonz
|
||||
```
|
||||
|
||||
### OS build supported: Win11 25H2
|
||||
- **Category:** security
|
||||
- **ID:** `sec.patch.os_supported`
|
||||
- Build 26200 (Win11 25H2) is in support until 2027-10-12.
|
||||
|
||||
```
|
||||
Microsoft Windows 11 Home build 26200
|
||||
```
|
||||
|
||||
### Last hotfix: KB5089549
|
||||
- **Category:** security
|
||||
- **ID:** `sec.patch.last_hotfix`
|
||||
- Most recently installed update (from Get-HotFix; reflects CBS/MSU packages, not all cumulative metadata).
|
||||
|
||||
```
|
||||
KB5089549 installed 2026-05-21T07:00:00Z
|
||||
```
|
||||
|
||||
### SMBv1 disabled
|
||||
- **Category:** security
|
||||
- **ID:** `sec.exposure.smb1_off`
|
||||
- SMBv1 server protocol is disabled.
|
||||
|
||||
```
|
||||
EnableSMB1Protocol=False
|
||||
```
|
||||
|
||||
### LAPS detected
|
||||
- **Category:** security
|
||||
- **ID:** `sec.exposure.laps_present`
|
||||
- A LAPS mechanism is present.
|
||||
|
||||
```
|
||||
Windows LAPS reg key
|
||||
```
|
||||
|
||||
### Not domain-joined (workgroup)
|
||||
- **Category:** health
|
||||
- **ID:** `health.domain.workgroup`
|
||||
- This machine is in workgroup/Azure AD only mode (Domain=WORKGROUP). No on-prem AD secure channel applies.
|
||||
|
||||
```
|
||||
PartOfDomain=False; Domain=WORKGROUP
|
||||
```
|
||||
|
||||
### Time service source
|
||||
- **Category:** health
|
||||
- **ID:** `health.time.source`
|
||||
- Current Windows Time service source.
|
||||
|
||||
```
|
||||
Source=time.windows.com,0x9
|
||||
```
|
||||
|
||||
### No backup agent detected
|
||||
- **Category:** health
|
||||
- **ID:** `health.backup.none`
|
||||
- No known backup agent service found. Backup expectation varies by endpoint; confirm whether this machine is supposed to have local/cloud backup and whether server-side or M365 backup covers it.
|
||||
|
||||
```
|
||||
No matching backup service in Win32_Service
|
||||
```
|
||||
|
||||
|
||||
---
|
||||
|
||||
## Inventory Baseline Summary
|
||||
|
||||
- **Manufacturer / Model:** LENOVO / 90SM006QUS
|
||||
- **Serial:** MJ0J9LD1
|
||||
- **CPU:** 12th Gen Intel(R) Core(TM) i5-12400 (6 cores / 12 logical)
|
||||
- **RAM (GB):** 15.7
|
||||
- **BIOS:** M49KT21A (2023-01-03)
|
||||
- **Chassis is laptop:** false
|
||||
- **TPM present / Secure Boot:** true / true
|
||||
- **Domain joined:** false (WORKGROUP)
|
||||
- **OS activation licensed:** true
|
||||
- **Uptime (days):** 13.7
|
||||
- **Pending reboot:** true
|
||||
- **Installed software count:** 55
|
||||
- **Scheduled tasks (non-MS, enabled):** 35
|
||||
- **Local administrators:** GTS-PEDRO-H\Administrator, GTS-PEDRO-H\pgonz
|
||||
|
||||
### Fixed volumes
|
||||
|
||||
- [SYSTEM] - 0.2 GB free of 0.2 GB (76.9%)
|
||||
- C: - 723.7 GB free of 951.6 GB (76.1%)
|
||||
- [WinRE_DRV] - 1.3 GB free of 2 GB (64.3%)
|
||||
|
||||
### Network adapters
|
||||
|
||||
- ZeroTier Virtual Port - IP: 10.244.10.231, fe80::2bae:96e1:f136:d2d9, fc2a:89c2:7b0d:1a52:bbed::1 - DNS: 10.244.163.165 - DHCP: false
|
||||
- Realtek RTL8852AE WiFi 6 802.11ax PCIe Adapter - IP: 192.168.0.146, fe80::5f87:acec:b8fd:313f, 2600:8800:782c:5c00:ecc4:b8ee:f191:f8e9, 2600:8800:782c:5c00:94a1:fdd7:a658:a330, 2600:8800:782c:5c00:2abd:1cc9:5150:9bc7, 2600:8800:782c:5c00::bc77 - DNS: 68.105.28.11, 68.105.29.11, 68.105.28.12 - DHCP: true
|
||||
|
||||
---
|
||||
|
||||
## Diff vs Prior Baseline
|
||||
|
||||
- No prior baseline found for this host. This is the first baseline.
|
||||
|
||||
---
|
||||
|
||||
_Generated by run-onboarding-diagnostic.sh (GuruRMM onboarding diagnostic, Phase 1). Raw snapshot: `GTS-PEDRO-H-20260606T181113.json` (immutable)._
|
||||
@@ -0,0 +1,544 @@
|
||||
{
|
||||
"host": "GTS-SVR25",
|
||||
"collected_at_utc": "2026-06-06T18:13:24Z",
|
||||
"os": {
|
||||
"caption": "Microsoft Windows Server 2025 Standard",
|
||||
"version": "10.0.26100",
|
||||
"build": "26100",
|
||||
"install_date": "2025-10-18T18:21:32Z",
|
||||
"last_boot_utc": "2026-05-17T04:50:38Z",
|
||||
"architecture": "64-bit"
|
||||
},
|
||||
"facts": {
|
||||
"builtin_admin_enabled": false,
|
||||
"os_eol": {
|
||||
"eol_date": "2026-10-13",
|
||||
"release": "Win11 24H2"
|
||||
},
|
||||
"pending_updates": 0,
|
||||
"pending_reboot": true,
|
||||
"uptime_days": 20.6,
|
||||
"acg_managed_tools": [
|
||||
"ScreenConnect / ConnectWise Control",
|
||||
"Datto RMM",
|
||||
"Splashtop (SOS/Streamer)",
|
||||
"Syncro / Kabuto"
|
||||
],
|
||||
"hardware": {
|
||||
"model": "System Product Name",
|
||||
"manufacturer": "ASUS",
|
||||
"bios_date": "2022-08-12",
|
||||
"cpu_logical": 20,
|
||||
"bios_version": "1620",
|
||||
"cpu_cores": 12,
|
||||
"ram_gb": 31.7,
|
||||
"serial": "System Serial Number",
|
||||
"cpu": "12th Gen Intel(R) Core(TM) i7-12700"
|
||||
},
|
||||
"local_administrators": [
|
||||
"Administrator",
|
||||
"Domain Admins",
|
||||
"Enterprise Admins",
|
||||
"localadmin",
|
||||
"MediaAdmin$",
|
||||
"sysadmin"
|
||||
],
|
||||
"os_build": "26100",
|
||||
"secure_boot": false,
|
||||
"backup_agents": null,
|
||||
"autoruns_run_keys": [
|
||||
{
|
||||
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
|
||||
"name": "AzureArcSetup",
|
||||
"value": "C:\\WINDOWS\\AzureArcSetup\\Systray\\AzureArcSysTray.exe"
|
||||
},
|
||||
{
|
||||
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
|
||||
"name": "SecurityHealth",
|
||||
"value": "C:\\WINDOWS\\system32\\SecurityHealthSystray.exe"
|
||||
},
|
||||
{
|
||||
"key": "HKLM:\\Software\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\Run",
|
||||
"name": "CentraStage",
|
||||
"value": "C:\\Program Files (x86)\\CentraStage\\Gui.exe"
|
||||
},
|
||||
{
|
||||
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
|
||||
"name": "msedge_cleanup_{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}",
|
||||
"value": "\"C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\148.0.3967.96\\Installer\\setup.exe\" --msedgewebview --delete-old-versions --system-level --verbose-logging --on-logon"
|
||||
}
|
||||
],
|
||||
"physical_disks": [
|
||||
{
|
||||
"health": "Healthy",
|
||||
"model": "NVMe KINGSTON SNV3S2000G",
|
||||
"media_type": "SSD"
|
||||
}
|
||||
],
|
||||
"local_users": [
|
||||
{
|
||||
"last_logon": "",
|
||||
"name": "Administrator",
|
||||
"password_never_expires": false,
|
||||
"enabled": false
|
||||
},
|
||||
{
|
||||
"last_logon": "",
|
||||
"name": "Guest",
|
||||
"password_never_expires": false,
|
||||
"enabled": false
|
||||
},
|
||||
{
|
||||
"last_logon": "",
|
||||
"name": "krbtgt",
|
||||
"password_never_expires": false,
|
||||
"enabled": false
|
||||
},
|
||||
{
|
||||
"last_logon": "",
|
||||
"name": "DefaultAccount",
|
||||
"password_never_expires": false,
|
||||
"enabled": false
|
||||
},
|
||||
{
|
||||
"last_logon": "",
|
||||
"name": "localadmin",
|
||||
"password_never_expires": false,
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"last_logon": "2026-03-24",
|
||||
"name": "sysadmin",
|
||||
"password_never_expires": false,
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"last_logon": "2026-06-04",
|
||||
"name": "pedro",
|
||||
"password_never_expires": false,
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"last_logon": "2026-06-05",
|
||||
"name": "gonzvar",
|
||||
"password_never_expires": false,
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"last_logon": "2026-06-06",
|
||||
"name": "SERVER$",
|
||||
"password_never_expires": false,
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"last_logon": "",
|
||||
"name": "MediaAdmin$",
|
||||
"password_never_expires": false,
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"last_logon": "2026-06-06",
|
||||
"name": "GTS-W1$",
|
||||
"password_never_expires": false,
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"last_logon": "2026-06-06",
|
||||
"name": "GTS-W2$",
|
||||
"password_never_expires": false,
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"last_logon": "2026-06-06",
|
||||
"name": "GTS-W0$",
|
||||
"password_never_expires": false,
|
||||
"enabled": true
|
||||
}
|
||||
],
|
||||
"scheduled_tasks_count": 2,
|
||||
"volumes": [
|
||||
{
|
||||
"drive": "[unlabeled]",
|
||||
"size_gb": 0.8,
|
||||
"free_pct": 11.8,
|
||||
"free_gb": 0.1
|
||||
},
|
||||
{
|
||||
"drive": "C:",
|
||||
"size_gb": 1862.2,
|
||||
"free_pct": 90.5,
|
||||
"free_gb": 1684.5
|
||||
},
|
||||
{
|
||||
"drive": "[unlabeled]",
|
||||
"size_gb": 0.1,
|
||||
"free_pct": 64.4,
|
||||
"free_gb": 0.1
|
||||
}
|
||||
],
|
||||
"network_adapters": [
|
||||
{
|
||||
"dhcp": false,
|
||||
"description": "Realtek PCIe 2.5GbE Family Controller",
|
||||
"gateway": [
|
||||
"192.168.0.1"
|
||||
],
|
||||
"mac": "50:EB:F6:CF:69:80",
|
||||
"ip": [
|
||||
"192.168.0.2",
|
||||
"fe80::9386:5e2c:c38a:61b1"
|
||||
],
|
||||
"dns": [
|
||||
"192.168.0.2",
|
||||
"192.168.0.5"
|
||||
]
|
||||
}
|
||||
],
|
||||
"failed_autostart_services": [
|
||||
{
|
||||
"name": "AsusUpdateCheck",
|
||||
"display": "AsusUpdateCheck",
|
||||
"state": "Stopped"
|
||||
},
|
||||
{
|
||||
"name": "InventorySvc",
|
||||
"display": "Inventory and Compatibility Appraisal service",
|
||||
"state": "Stopped"
|
||||
}
|
||||
],
|
||||
"stability_14d": {
|
||||
"unexpected_shutdowns": 0,
|
||||
"disk_errors": 83,
|
||||
"bugchecks": 0
|
||||
},
|
||||
"exposure": {
|
||||
"smb1_enabled": false,
|
||||
"laps_present": true,
|
||||
"rdp_enabled": true,
|
||||
"uac_enabled": true,
|
||||
"rdp_nla": true
|
||||
},
|
||||
"accounts_password_never_expires": [],
|
||||
"installed_software": [
|
||||
{
|
||||
"publisher": "Webprofusion Pty Ltd",
|
||||
"name": "Certify Certificate Manager version 6.1.11",
|
||||
"version": "6.1.11"
|
||||
},
|
||||
{
|
||||
"publisher": "Datto Inc.",
|
||||
"name": "Datto RMM",
|
||||
"version": "4.4.11616.11616"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Host - 8.0.21 (x86)",
|
||||
"version": "64.84.40925"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Host FX Resolver - 8.0.21 (x86)",
|
||||
"version": "64.84.40925"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Runtime - 8.0.21 (x86)",
|
||||
"version": "64.84.40925"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft ASP.NET Core 8.0.21 - Shared Framework (x86)",
|
||||
"version": "8.0.21.25475"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft ASP.NET Core 8.0.21 Shared Framework (x86)",
|
||||
"version": "8.0.21.25475"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Edge",
|
||||
"version": "149.0.4022.52"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Edge WebView2 Runtime",
|
||||
"version": "148.0.3967.96"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Windows Desktop Runtime - 8.0.21 (x86)",
|
||||
"version": "64.84.40919"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Windows Desktop Runtime - 8.0.21 (x86)",
|
||||
"version": "8.0.21.35325"
|
||||
},
|
||||
{
|
||||
"publisher": "ScreenConnect Software",
|
||||
"name": "ScreenConnect Client (1912bf3444b41a08)",
|
||||
"version": "26.1.24.9579"
|
||||
},
|
||||
{
|
||||
"publisher": "Splashtop Inc.",
|
||||
"name": "Splashtop Software Updater",
|
||||
"version": "1.5.6.23"
|
||||
},
|
||||
{
|
||||
"publisher": "Splashtop Inc.",
|
||||
"name": "Splashtop Streamer",
|
||||
"version": "3.8.2.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Servably, Inc.",
|
||||
"name": "Syncro",
|
||||
"version": "1.0.201.18410"
|
||||
}
|
||||
],
|
||||
"tpm": {
|
||||
"enabled": true,
|
||||
"ready": true,
|
||||
"present": true
|
||||
},
|
||||
"local_groups": [
|
||||
"Cert Publishers",
|
||||
"RAS and IAS Servers",
|
||||
"Allowed RODC Password Replication Group",
|
||||
"Denied RODC Password Replication Group"
|
||||
],
|
||||
"battery": {
|
||||
"present": false
|
||||
},
|
||||
"third_party_av_active": false,
|
||||
"activation": {
|
||||
"edition": "Microsoft Windows Server 2025 Standard",
|
||||
"description": "Windows(R) Operating System, VOLUME_KMSCLIENT channel",
|
||||
"licensed": true,
|
||||
"license_status_code": 1
|
||||
},
|
||||
"time_source": "Free-running System Clock",
|
||||
"chassis_types": [
|
||||
3
|
||||
],
|
||||
"last_hotfix": {
|
||||
"hotfix_id": "KB5089717",
|
||||
"installed_on": "2026-05-17T07:00:00Z"
|
||||
},
|
||||
"scheduled_tasks": [
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "MicrosoftEdgeUpdateTaskMachineCore{3F3B8390-0879-4598-A0FB-FCCC9A4FBAA9}",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "MicrosoftEdgeUpdateTaskMachineUA{F6534644-528C-456C-ABC0-2A47E8920650}",
|
||||
"state": "Ready"
|
||||
}
|
||||
],
|
||||
"antivirus_products": [],
|
||||
"domain_joined": true,
|
||||
"defender": {
|
||||
"antispyware_signature_age": 0,
|
||||
"tamper_protected": false,
|
||||
"real_time_protection": false,
|
||||
"nis_enabled": false,
|
||||
"available": true,
|
||||
"antivirus_enabled": false,
|
||||
"am_service_enabled": false
|
||||
},
|
||||
"bitlocker": {
|
||||
"available": false,
|
||||
"os_volume": "C:"
|
||||
},
|
||||
"is_laptop": false,
|
||||
"installed_software_count": 15,
|
||||
"secure_channel_ok": null,
|
||||
"firewall_profiles": {
|
||||
"Private": true,
|
||||
"Domain": true,
|
||||
"Public": true
|
||||
},
|
||||
"domain": "GTS.local",
|
||||
"foreign_agents": null
|
||||
},
|
||||
"findings": [
|
||||
{
|
||||
"id": "sec.defender.rtp_off",
|
||||
"category": "security",
|
||||
"severity": "critical",
|
||||
"title": "Defender real-time protection is OFF",
|
||||
"detail": "Real-time protection is disabled. The endpoint is unprotected against active threats. Re-enable immediately or confirm a managed 3rd-party AV is providing real-time protection.",
|
||||
"evidence": "RealTimeProtectionEnabled=False; AMServiceEnabled=False; AntispywareSignatureAge=0 days; IsTamperProtected=False"
|
||||
},
|
||||
{
|
||||
"id": "sec.defender.amservice_off",
|
||||
"category": "security",
|
||||
"severity": "critical",
|
||||
"title": "Defender antimalware service is not running",
|
||||
"detail": "The Defender antimalware service is not active. If no 3rd-party AV is present, this endpoint has no antivirus protection.",
|
||||
"evidence": "RealTimeProtectionEnabled=False; AMServiceEnabled=False; AntispywareSignatureAge=0 days; IsTamperProtected=False"
|
||||
},
|
||||
{
|
||||
"id": "sec.defender.tamper_off",
|
||||
"category": "security",
|
||||
"severity": "warning",
|
||||
"title": "Defender tamper protection is OFF",
|
||||
"detail": "Tamper protection is disabled, so malware or a local admin can silently disable Defender. Enable tamper protection (typically via Intune / Security Center).",
|
||||
"evidence": "RealTimeProtectionEnabled=False; AMServiceEnabled=False; AntispywareSignatureAge=0 days; IsTamperProtected=False"
|
||||
},
|
||||
{
|
||||
"id": "sec.av_products.none_registered",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "No AV products registered in Security Center",
|
||||
"detail": "SecurityCenter2 returned no AntiVirusProduct entries. This is normal on Windows Server SKUs (Security Center is a client feature). On a workstation, confirm Defender or a managed AV is active.",
|
||||
"evidence": "root\\SecurityCenter2 AntiVirusProduct: none"
|
||||
},
|
||||
{
|
||||
"id": "sec.foreign_agents.none",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "No competitor/leftover management agents detected",
|
||||
"detail": "No known competitor RMM or unmanaged remote-access agents found in installed programs or services.",
|
||||
"evidence": "Scanned uninstall hives (HKLM + WOW6432Node) and Win32_Service"
|
||||
},
|
||||
{
|
||||
"id": "sec.foreign_agents.acg.screenconnect_connectwise_control",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Expected ACG management tooling present: ScreenConnect / ConnectWise Control",
|
||||
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
|
||||
"evidence": "program: ScreenConnect Client (1912bf3444b41a08) 26.1.24.9579\nservice: ScreenConnect Client (1912bf3444b41a08) (ScreenConnect Client (1912bf3444b41a08)) Running"
|
||||
},
|
||||
{
|
||||
"id": "sec.foreign_agents.acg.datto_rmm",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Expected ACG management tooling present: Datto RMM",
|
||||
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
|
||||
"evidence": "program: Datto RMM 4.4.11616.11616\nservice: CagService (Datto RMM) Running"
|
||||
},
|
||||
{
|
||||
"id": "sec.foreign_agents.acg.splashtop_sos_streamer_",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Expected ACG management tooling present: Splashtop (SOS/Streamer)",
|
||||
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
|
||||
"evidence": "program: Splashtop Software Updater 1.5.6.23\nprogram: Splashtop Streamer 3.8.2.0\nservice: SplashtopRemoteService (Splashtop? Remote Service) Running\nservice: SSUService (Splashtop Software Updater Service) Running"
|
||||
},
|
||||
{
|
||||
"id": "sec.foreign_agents.acg.syncro_kabuto",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Expected ACG management tooling present: Syncro / Kabuto",
|
||||
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
|
||||
"evidence": "program: Syncro 1.0.201.18410\nservice: Syncro (Syncro) Running"
|
||||
},
|
||||
{
|
||||
"id": "sec.firewall.ok",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "All firewall profiles enabled",
|
||||
"detail": "Domain, Private, and Public firewall profiles are all enabled.",
|
||||
"evidence": "Private=True; Domain=True; Public=True"
|
||||
},
|
||||
{
|
||||
"id": "sec.bitlocker.unavailable",
|
||||
"category": "security",
|
||||
"severity": "unknown",
|
||||
"title": "BitLocker status unavailable",
|
||||
"detail": "Get-BitLockerVolume failed for the OS volume. BitLocker may not be installed (Home edition) or the cmdlet is unavailable. Verify encryption manually (manage-bde -status).",
|
||||
"evidence": "MountPoint=C:, Get-BitLockerVolume returned null"
|
||||
},
|
||||
{
|
||||
"id": "sec.local_admins.list",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Local administrators (6)",
|
||||
"detail": "Members of the local Administrators group. Review for unexpected or unknown accounts (especially leftover MSP/vendor accounts from a prior provider).",
|
||||
"evidence": "Administrator\nDomain Admins\nEnterprise Admins\nlocaladmin\nMediaAdmin$\nsysadmin"
|
||||
},
|
||||
{
|
||||
"id": "sec.patch.os_supported",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "OS build supported: Win11 24H2",
|
||||
"detail": "Build 26100 (Win11 24H2) is in support until 2026-10-13.",
|
||||
"evidence": "Microsoft Windows Server 2025 Standard build 26100"
|
||||
},
|
||||
{
|
||||
"id": "sec.patch.last_hotfix",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Last hotfix: KB5089717",
|
||||
"detail": "Most recently installed update (from Get-HotFix; reflects CBS/MSU packages, not all cumulative metadata).",
|
||||
"evidence": "KB5089717 installed 2026-05-17T07:00:00Z"
|
||||
},
|
||||
{
|
||||
"id": "sec.exposure.rdp_on",
|
||||
"category": "security",
|
||||
"severity": "warning",
|
||||
"title": "RDP is enabled",
|
||||
"detail": "Remote Desktop is enabled (NLA required). Confirm it is restricted to VPN or specific source IPs and not exposed to the internet.",
|
||||
"evidence": "fDenyTSConnections=0; UserAuthentication=1"
|
||||
},
|
||||
{
|
||||
"id": "sec.exposure.smb1_off",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "SMBv1 disabled",
|
||||
"detail": "SMBv1 server protocol is disabled.",
|
||||
"evidence": "EnableSMB1Protocol=False"
|
||||
},
|
||||
{
|
||||
"id": "sec.exposure.laps_present",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "LAPS detected",
|
||||
"detail": "A LAPS mechanism is present.",
|
||||
"evidence": "Windows LAPS reg key"
|
||||
},
|
||||
{
|
||||
"id": "health.stability.recurring",
|
||||
"category": "health",
|
||||
"severity": "critical",
|
||||
"title": "Recurring stability events in the last 14 days",
|
||||
"detail": "Three or more of one event class (unexpected shutdown, BSOD, or disk error) in 14 days indicates a hardware or driver problem. Investigate memory, disk, PSU, and drivers.",
|
||||
"evidence": "Unexpected shutdowns (id 41)=0; Bugchecks/BSOD (id 1001)=0; Disk errors (id 7/51/153)=83"
|
||||
},
|
||||
{
|
||||
"id": "health.reboot_uptime.pending",
|
||||
"category": "health",
|
||||
"severity": "warning",
|
||||
"title": "Reboot pending",
|
||||
"detail": "A reboot is pending. Pending reboots can block patches and leave the system in a half-updated state. Schedule a restart.",
|
||||
"evidence": "PendingFileRenameOperations"
|
||||
},
|
||||
{
|
||||
"id": "health.failed_services.stopped",
|
||||
"category": "health",
|
||||
"severity": "warning",
|
||||
"title": "2 auto-start service(s) not running",
|
||||
"detail": "These services are set to start automatically but are not running. Some may be benign; review for security agents, backup agents, or AV that should be running.",
|
||||
"evidence": "AsusUpdateCheck (AsusUpdateCheck) = Stopped\nInventorySvc (Inventory and Compatibility Appraisal service) = Stopped"
|
||||
},
|
||||
{
|
||||
"id": "health.time.source",
|
||||
"category": "health",
|
||||
"severity": "info",
|
||||
"title": "Time service source",
|
||||
"detail": "Current Windows Time service source.",
|
||||
"evidence": "Source=Free-running System Clock"
|
||||
},
|
||||
{
|
||||
"id": "health.backup.none",
|
||||
"category": "health",
|
||||
"severity": "info",
|
||||
"title": "No backup agent detected",
|
||||
"detail": "No known backup agent service found. Backup expectation varies by endpoint; confirm whether this machine is supposed to have local/cloud backup and whether server-side or M365 backup covers it.",
|
||||
"evidence": "No matching backup service in Win32_Service"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,274 @@
|
||||
# Onboarding Diagnostic Baseline - GTS-SVR25
|
||||
|
||||
- **Grade:** RED
|
||||
- **Host:** GTS-SVR25
|
||||
- **Client:** Gonzvar Tax Services (`gonzvar-tax-services`)
|
||||
- **Collected (UTC):** 2026-06-06T18:13:24Z
|
||||
- **Agent ID:** 3f202b0e-5f48-4f76-833c-d7d1bd00ed58
|
||||
- **Command ID:** 144165ca-d232-4a3d-b904-cb622b431fd9
|
||||
- **Findings:** 3 critical / 4 warning / 14 info / 1 unknown
|
||||
|
||||
- **OS:** Microsoft Windows Server 2025 Standard (build 26100)
|
||||
|
||||
---
|
||||
|
||||
## CRITICAL (3)
|
||||
|
||||
### Defender real-time protection is OFF
|
||||
- **Category:** security
|
||||
- **ID:** `sec.defender.rtp_off`
|
||||
- Real-time protection is disabled. The endpoint is unprotected against active threats. Re-enable immediately or confirm a managed 3rd-party AV is providing real-time protection.
|
||||
|
||||
```
|
||||
RealTimeProtectionEnabled=False; AMServiceEnabled=False; AntispywareSignatureAge=0 days; IsTamperProtected=False
|
||||
```
|
||||
|
||||
### Defender antimalware service is not running
|
||||
- **Category:** security
|
||||
- **ID:** `sec.defender.amservice_off`
|
||||
- The Defender antimalware service is not active. If no 3rd-party AV is present, this endpoint has no antivirus protection.
|
||||
|
||||
```
|
||||
RealTimeProtectionEnabled=False; AMServiceEnabled=False; AntispywareSignatureAge=0 days; IsTamperProtected=False
|
||||
```
|
||||
|
||||
### Recurring stability events in the last 14 days
|
||||
- **Category:** health
|
||||
- **ID:** `health.stability.recurring`
|
||||
- Three or more of one event class (unexpected shutdown, BSOD, or disk error) in 14 days indicates a hardware or driver problem. Investigate memory, disk, PSU, and drivers.
|
||||
|
||||
```
|
||||
Unexpected shutdowns (id 41)=0; Bugchecks/BSOD (id 1001)=0; Disk errors (id 7/51/153)=83
|
||||
```
|
||||
|
||||
|
||||
## WARNING (4)
|
||||
|
||||
### Defender tamper protection is OFF
|
||||
- **Category:** security
|
||||
- **ID:** `sec.defender.tamper_off`
|
||||
- Tamper protection is disabled, so malware or a local admin can silently disable Defender. Enable tamper protection (typically via Intune / Security Center).
|
||||
|
||||
```
|
||||
RealTimeProtectionEnabled=False; AMServiceEnabled=False; AntispywareSignatureAge=0 days; IsTamperProtected=False
|
||||
```
|
||||
|
||||
### RDP is enabled
|
||||
- **Category:** security
|
||||
- **ID:** `sec.exposure.rdp_on`
|
||||
- Remote Desktop is enabled (NLA required). Confirm it is restricted to VPN or specific source IPs and not exposed to the internet.
|
||||
|
||||
```
|
||||
fDenyTSConnections=0; UserAuthentication=1
|
||||
```
|
||||
|
||||
### Reboot pending
|
||||
- **Category:** health
|
||||
- **ID:** `health.reboot_uptime.pending`
|
||||
- A reboot is pending. Pending reboots can block patches and leave the system in a half-updated state. Schedule a restart.
|
||||
|
||||
```
|
||||
PendingFileRenameOperations
|
||||
```
|
||||
|
||||
### 2 auto-start service(s) not running
|
||||
- **Category:** health
|
||||
- **ID:** `health.failed_services.stopped`
|
||||
- These services are set to start automatically but are not running. Some may be benign; review for security agents, backup agents, or AV that should be running.
|
||||
|
||||
```
|
||||
AsusUpdateCheck (AsusUpdateCheck) = Stopped
|
||||
InventorySvc (Inventory and Compatibility Appraisal service) = Stopped
|
||||
```
|
||||
|
||||
|
||||
## INFO (14)
|
||||
|
||||
### No AV products registered in Security Center
|
||||
- **Category:** security
|
||||
- **ID:** `sec.av_products.none_registered`
|
||||
- SecurityCenter2 returned no AntiVirusProduct entries. This is normal on Windows Server SKUs (Security Center is a client feature). On a workstation, confirm Defender or a managed AV is active.
|
||||
|
||||
```
|
||||
root\SecurityCenter2 AntiVirusProduct: none
|
||||
```
|
||||
|
||||
### No competitor/leftover management agents detected
|
||||
- **Category:** security
|
||||
- **ID:** `sec.foreign_agents.none`
|
||||
- No known competitor RMM or unmanaged remote-access agents found in installed programs or services.
|
||||
|
||||
```
|
||||
Scanned uninstall hives (HKLM + WOW6432Node) and Win32_Service
|
||||
```
|
||||
|
||||
### Expected ACG management tooling present: ScreenConnect / ConnectWise Control
|
||||
- **Category:** security
|
||||
- **ID:** `sec.foreign_agents.acg.screenconnect_connectwise_control`
|
||||
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
|
||||
|
||||
```
|
||||
program: ScreenConnect Client (1912bf3444b41a08) 26.1.24.9579
|
||||
service: ScreenConnect Client (1912bf3444b41a08) (ScreenConnect Client (1912bf3444b41a08)) Running
|
||||
```
|
||||
|
||||
### Expected ACG management tooling present: Datto RMM
|
||||
- **Category:** security
|
||||
- **ID:** `sec.foreign_agents.acg.datto_rmm`
|
||||
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
|
||||
|
||||
```
|
||||
program: Datto RMM 4.4.11616.11616
|
||||
service: CagService (Datto RMM) Running
|
||||
```
|
||||
|
||||
### Expected ACG management tooling present: Splashtop (SOS/Streamer)
|
||||
- **Category:** security
|
||||
- **ID:** `sec.foreign_agents.acg.splashtop_sos_streamer_`
|
||||
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
|
||||
|
||||
```
|
||||
program: Splashtop Software Updater 1.5.6.23
|
||||
program: Splashtop Streamer 3.8.2.0
|
||||
service: SplashtopRemoteService (Splashtop? Remote Service) Running
|
||||
service: SSUService (Splashtop Software Updater Service) Running
|
||||
```
|
||||
|
||||
### Expected ACG management tooling present: Syncro / Kabuto
|
||||
- **Category:** security
|
||||
- **ID:** `sec.foreign_agents.acg.syncro_kabuto`
|
||||
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
|
||||
|
||||
```
|
||||
program: Syncro 1.0.201.18410
|
||||
service: Syncro (Syncro) Running
|
||||
```
|
||||
|
||||
### All firewall profiles enabled
|
||||
- **Category:** security
|
||||
- **ID:** `sec.firewall.ok`
|
||||
- Domain, Private, and Public firewall profiles are all enabled.
|
||||
|
||||
```
|
||||
Private=True; Domain=True; Public=True
|
||||
```
|
||||
|
||||
### Local administrators (6)
|
||||
- **Category:** security
|
||||
- **ID:** `sec.local_admins.list`
|
||||
- Members of the local Administrators group. Review for unexpected or unknown accounts (especially leftover MSP/vendor accounts from a prior provider).
|
||||
|
||||
```
|
||||
Administrator
|
||||
Domain Admins
|
||||
Enterprise Admins
|
||||
localadmin
|
||||
MediaAdmin$
|
||||
sysadmin
|
||||
```
|
||||
|
||||
### OS build supported: Win11 24H2
|
||||
- **Category:** security
|
||||
- **ID:** `sec.patch.os_supported`
|
||||
- Build 26100 (Win11 24H2) is in support until 2026-10-13.
|
||||
|
||||
```
|
||||
Microsoft Windows Server 2025 Standard build 26100
|
||||
```
|
||||
|
||||
### Last hotfix: KB5089717
|
||||
- **Category:** security
|
||||
- **ID:** `sec.patch.last_hotfix`
|
||||
- Most recently installed update (from Get-HotFix; reflects CBS/MSU packages, not all cumulative metadata).
|
||||
|
||||
```
|
||||
KB5089717 installed 2026-05-17T07:00:00Z
|
||||
```
|
||||
|
||||
### SMBv1 disabled
|
||||
- **Category:** security
|
||||
- **ID:** `sec.exposure.smb1_off`
|
||||
- SMBv1 server protocol is disabled.
|
||||
|
||||
```
|
||||
EnableSMB1Protocol=False
|
||||
```
|
||||
|
||||
### LAPS detected
|
||||
- **Category:** security
|
||||
- **ID:** `sec.exposure.laps_present`
|
||||
- A LAPS mechanism is present.
|
||||
|
||||
```
|
||||
Windows LAPS reg key
|
||||
```
|
||||
|
||||
### Time service source
|
||||
- **Category:** health
|
||||
- **ID:** `health.time.source`
|
||||
- Current Windows Time service source.
|
||||
|
||||
```
|
||||
Source=Free-running System Clock
|
||||
```
|
||||
|
||||
### No backup agent detected
|
||||
- **Category:** health
|
||||
- **ID:** `health.backup.none`
|
||||
- No known backup agent service found. Backup expectation varies by endpoint; confirm whether this machine is supposed to have local/cloud backup and whether server-side or M365 backup covers it.
|
||||
|
||||
```
|
||||
No matching backup service in Win32_Service
|
||||
```
|
||||
|
||||
|
||||
## UNKNOWN (1)
|
||||
|
||||
### BitLocker status unavailable
|
||||
- **Category:** security
|
||||
- **ID:** `sec.bitlocker.unavailable`
|
||||
- Get-BitLockerVolume failed for the OS volume. BitLocker may not be installed (Home edition) or the cmdlet is unavailable. Verify encryption manually (manage-bde -status).
|
||||
|
||||
```
|
||||
MountPoint=C:, Get-BitLockerVolume returned null
|
||||
```
|
||||
|
||||
|
||||
---
|
||||
|
||||
## Inventory Baseline Summary
|
||||
|
||||
- **Manufacturer / Model:** ASUS / System Product Name
|
||||
- **Serial:** System Serial Number
|
||||
- **CPU:** 12th Gen Intel(R) Core(TM) i7-12700 (12 cores / 20 logical)
|
||||
- **RAM (GB):** 31.7
|
||||
- **BIOS:** 1620 (2022-08-12)
|
||||
- **Chassis is laptop:** false
|
||||
- **TPM present / Secure Boot:** true / ?
|
||||
- **Domain joined:** true (GTS.local)
|
||||
- **OS activation licensed:** true
|
||||
- **Uptime (days):** 20.6
|
||||
- **Pending reboot:** true
|
||||
- **Installed software count:** 15
|
||||
- **Scheduled tasks (non-MS, enabled):** 2
|
||||
- **Local administrators:** Administrator, Domain Admins, Enterprise Admins, localadmin, MediaAdmin$, sysadmin
|
||||
|
||||
### Fixed volumes
|
||||
|
||||
- [unlabeled] - 0.1 GB free of 0.8 GB (11.8%)
|
||||
- C: - 1684.5 GB free of 1862.2 GB (90.5%)
|
||||
- [unlabeled] - 0.1 GB free of 0.1 GB (64.4%)
|
||||
|
||||
### Network adapters
|
||||
|
||||
- Realtek PCIe 2.5GbE Family Controller - IP: 192.168.0.2, fe80::9386:5e2c:c38a:61b1 - DNS: 192.168.0.2, 192.168.0.5 - DHCP: false
|
||||
|
||||
---
|
||||
|
||||
## Diff vs Prior Baseline
|
||||
|
||||
- No prior baseline found for this host. This is the first baseline.
|
||||
|
||||
---
|
||||
|
||||
_Generated by run-onboarding-diagnostic.sh (GuruRMM onboarding diagnostic, Phase 1). Raw snapshot: `GTS-SVR25-20260606T181205.json` (immutable)._
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,261 @@
|
||||
# Onboarding Diagnostic Baseline - GTS-W0
|
||||
|
||||
- **Grade:** RED
|
||||
- **Host:** GTS-W0
|
||||
- **Client:** Gonzvar Tax Services (`gonzvar-tax-services`)
|
||||
- **Collected (UTC):** 2026-06-06T18:08:45Z
|
||||
- **Agent ID:** 14751270-35fd-4b89-a083-a014a725e356
|
||||
- **Command ID:** c6247347-570f-45f8-9357-92208252029b
|
||||
- **Findings:** 3 critical / 4 warning / 14 info / 0 unknown
|
||||
|
||||
- **OS:** Microsoft Windows 11 Pro for Workstations (build 26200)
|
||||
|
||||
---
|
||||
|
||||
## CRITICAL (3)
|
||||
|
||||
### Firewall disabled on profile(s): Domain, Private, Public
|
||||
- **Category:** security
|
||||
- **ID:** `sec.firewall.disabled`
|
||||
- One or more firewall profiles are OFF. The endpoint is exposed to lateral movement and inbound attacks on those networks. Re-enable all profiles.
|
||||
|
||||
```
|
||||
Profile states: Private=False; Domain=False; Public=False
|
||||
```
|
||||
|
||||
### RDP enabled WITHOUT Network Level Authentication
|
||||
- **Category:** security
|
||||
- **ID:** `sec.exposure.rdp_no_nla`
|
||||
- RDP is on and NLA is not required. This exposes the logon screen pre-auth and is vulnerable to pre-auth exploits and brute force. Require NLA, restrict RDP to VPN/allow-listed IPs, or disable RDP.
|
||||
|
||||
```
|
||||
fDenyTSConnections=0; UserAuthentication=0
|
||||
```
|
||||
|
||||
### Recurring stability events in the last 14 days
|
||||
- **Category:** health
|
||||
- **ID:** `health.stability.recurring`
|
||||
- Three or more of one event class (unexpected shutdown, BSOD, or disk error) in 14 days indicates a hardware or driver problem. Investigate memory, disk, PSU, and drivers.
|
||||
|
||||
```
|
||||
Unexpected shutdowns (id 41)=2; Bugchecks/BSOD (id 1001)=0; Disk errors (id 7/51/153)=9
|
||||
```
|
||||
|
||||
|
||||
## WARNING (4)
|
||||
|
||||
### OS volume is NOT encrypted with BitLocker
|
||||
- **Category:** security
|
||||
- **ID:** `sec.bitlocker.unencrypted`
|
||||
- The operating system volume is unencrypted. Data is exposed if the disk is removed or the device is lost. Enable BitLocker and escrow the recovery key.
|
||||
|
||||
```
|
||||
Volume=C:; ProtectionStatus=Off; EncryptionPercentage=0; KeyProtectors=
|
||||
```
|
||||
|
||||
### 1 pending Windows updates
|
||||
- **Category:** security
|
||||
- **ID:** `sec.patch.pending`
|
||||
- Windows Update reports pending (not installed, not hidden) updates. Some may be security updates. Approve/install on the next maintenance window.
|
||||
|
||||
```
|
||||
Microsoft.Update.Session search IsInstalled=0 and IsHidden=0 -> 1
|
||||
```
|
||||
|
||||
### Reboot pending
|
||||
- **Category:** health
|
||||
- **ID:** `health.reboot_uptime.pending`
|
||||
- A reboot is pending. Pending reboots can block patches and leave the system in a half-updated state. Schedule a restart.
|
||||
|
||||
```
|
||||
PendingFileRenameOperations
|
||||
```
|
||||
|
||||
### 4 auto-start service(s) not running
|
||||
- **Category:** health
|
||||
- **ID:** `health.failed_services.stopped`
|
||||
- These services are set to start automatically but are not running. Some may be benign; review for security agents, backup agents, or AV that should be running.
|
||||
|
||||
```
|
||||
GoogleUpdaterInternalService150.0.7863.0 (Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)) = Stopped
|
||||
GoogleUpdaterService150.0.7863.0 (Google Updater Service (GoogleUpdaterService150.0.7863.0)) = Stopped
|
||||
gpsvc (Group Policy Client) = Stopped
|
||||
Intel(R) Platform License Manager Service (Intel(R) Platform License Manager Service) = Stopped
|
||||
```
|
||||
|
||||
|
||||
## INFO (14)
|
||||
|
||||
### Defender active and current
|
||||
- **Category:** security
|
||||
- **ID:** `sec.defender.ok`
|
||||
- Real-time protection on, service running, signatures current.
|
||||
|
||||
```
|
||||
RealTimeProtectionEnabled=True; AMServiceEnabled=True; AntispywareSignatureAge=0 days; IsTamperProtected=True
|
||||
```
|
||||
|
||||
### Defender is the only registered AV
|
||||
- **Category:** security
|
||||
- **ID:** `sec.av_products.defender_only`
|
||||
- Only Microsoft/Windows Defender is registered in Security Center.
|
||||
|
||||
```
|
||||
Windows Defender
|
||||
```
|
||||
|
||||
### No competitor/leftover management agents detected
|
||||
- **Category:** security
|
||||
- **ID:** `sec.foreign_agents.none`
|
||||
- No known competitor RMM or unmanaged remote-access agents found in installed programs or services.
|
||||
|
||||
```
|
||||
Scanned uninstall hives (HKLM + WOW6432Node) and Win32_Service
|
||||
```
|
||||
|
||||
### Expected ACG management tooling present: ScreenConnect / ConnectWise Control
|
||||
- **Category:** security
|
||||
- **ID:** `sec.foreign_agents.acg.screenconnect_connectwise_control`
|
||||
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
|
||||
|
||||
```
|
||||
program: ScreenConnect Client (1912bf3444b41a08) 26.1.24.9579
|
||||
service: ScreenConnect Client (1912bf3444b41a08) (ScreenConnect Client (1912bf3444b41a08)) Running
|
||||
```
|
||||
|
||||
### Expected ACG management tooling present: Splashtop (SOS/Streamer)
|
||||
- **Category:** security
|
||||
- **ID:** `sec.foreign_agents.acg.splashtop_sos_streamer_`
|
||||
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
|
||||
|
||||
```
|
||||
program: Splashtop Streamer 3.8.4.0
|
||||
service: SplashtopRemoteService (Splashtop? Remote Service) Running
|
||||
```
|
||||
|
||||
### Expected ACG management tooling present: Syncro / Kabuto
|
||||
- **Category:** security
|
||||
- **ID:** `sec.foreign_agents.acg.syncro_kabuto`
|
||||
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
|
||||
|
||||
```
|
||||
program: Syncro 1.0.201.18410
|
||||
service: Syncro (Syncro) Running
|
||||
```
|
||||
|
||||
### Local administrators (5)
|
||||
- **Category:** security
|
||||
- **ID:** `sec.local_admins.list`
|
||||
- Members of the local Administrators group. Review for unexpected or unknown accounts (especially leftover MSP/vendor accounts from a prior provider).
|
||||
|
||||
```
|
||||
GTS\Domain Admins
|
||||
GTS\pedro
|
||||
GTS-W0\Administrator
|
||||
GTS-W0\localadmin
|
||||
GTS-W0\pgonz
|
||||
```
|
||||
|
||||
### OS build supported: Win11 25H2
|
||||
- **Category:** security
|
||||
- **ID:** `sec.patch.os_supported`
|
||||
- Build 26200 (Win11 25H2) is in support until 2027-10-12.
|
||||
|
||||
```
|
||||
Microsoft Windows 11 Pro for Workstations build 26200
|
||||
```
|
||||
|
||||
### Last hotfix: KB5089549
|
||||
- **Category:** security
|
||||
- **ID:** `sec.patch.last_hotfix`
|
||||
- Most recently installed update (from Get-HotFix; reflects CBS/MSU packages, not all cumulative metadata).
|
||||
|
||||
```
|
||||
KB5089549 installed 2026-05-13T07:00:00Z
|
||||
```
|
||||
|
||||
### SMBv1 disabled
|
||||
- **Category:** security
|
||||
- **ID:** `sec.exposure.smb1_off`
|
||||
- SMBv1 server protocol is disabled.
|
||||
|
||||
```
|
||||
EnableSMB1Protocol=False
|
||||
```
|
||||
|
||||
### LAPS detected
|
||||
- **Category:** security
|
||||
- **ID:** `sec.exposure.laps_present`
|
||||
- A LAPS mechanism is present.
|
||||
|
||||
```
|
||||
Windows LAPS reg key
|
||||
```
|
||||
|
||||
### Domain secure channel healthy
|
||||
- **Category:** health
|
||||
- **ID:** `health.domain.secure_channel_ok`
|
||||
- Machine trust relationship with the domain is intact.
|
||||
|
||||
```
|
||||
Domain=GTS.local
|
||||
```
|
||||
|
||||
### Time service source
|
||||
- **Category:** health
|
||||
- **ID:** `health.time.source`
|
||||
- Current Windows Time service source.
|
||||
|
||||
```
|
||||
Source=GTS-SVR25.GTS.local
|
||||
```
|
||||
|
||||
### No backup agent detected
|
||||
- **Category:** health
|
||||
- **ID:** `health.backup.none`
|
||||
- No known backup agent service found. Backup expectation varies by endpoint; confirm whether this machine is supposed to have local/cloud backup and whether server-side or M365 backup covers it.
|
||||
|
||||
```
|
||||
No matching backup service in Win32_Service
|
||||
```
|
||||
|
||||
|
||||
---
|
||||
|
||||
## Inventory Baseline Summary
|
||||
|
||||
- **Manufacturer / Model:** LENOVO / 90SM006QUS
|
||||
- **Serial:** MJ0JAX1V
|
||||
- **CPU:** 12th Gen Intel(R) Core(TM) i5-12400 (6 cores / 12 logical)
|
||||
- **RAM (GB):** 15.7
|
||||
- **BIOS:** M49KT29A (2024-01-04)
|
||||
- **Chassis is laptop:** false
|
||||
- **TPM present / Secure Boot:** true / true
|
||||
- **Domain joined:** true (GTS.local)
|
||||
- **OS activation licensed:** true
|
||||
- **Uptime (days):** 1
|
||||
- **Pending reboot:** true
|
||||
- **Installed software count:** 98
|
||||
- **Scheduled tasks (non-MS, enabled):** 50
|
||||
- **Local administrators:** GTS\Domain Admins, GTS\pedro, GTS-W0\Administrator, GTS-W0\localadmin, GTS-W0\pgonz
|
||||
|
||||
### Fixed volumes
|
||||
|
||||
- [SYSTEM] - 0.2 GB free of 0.2 GB (76.9%)
|
||||
- C: - 759.6 GB free of 929.3 GB (81.7%)
|
||||
- [WinRE_DRV] - 1.1 GB free of 2 GB (58.4%)
|
||||
|
||||
### Network adapters
|
||||
|
||||
- ZeroTier Virtual Port - IP: 10.244.136.41, fe80::3d86:b469:1b75:a41a, fc2a:89c2:7ba6:1abe:37ee::1 - DNS: - DHCP: false
|
||||
- Realtek PCIe GbE Family Controller - IP: 192.168.0.145, fe80::1da6:3314:1e3b:8ade - DNS: 192.168.0.2, 192.168.0.5 - DHCP: true
|
||||
|
||||
---
|
||||
|
||||
## Diff vs Prior Baseline
|
||||
|
||||
- No prior baseline found for this host. This is the first baseline.
|
||||
|
||||
---
|
||||
|
||||
_Generated by run-onboarding-diagnostic.sh (GuruRMM onboarding diagnostic, Phase 1). Raw snapshot: `GTS-W0-20260606T180736.json` (immutable)._
|
||||
@@ -0,0 +1,897 @@
|
||||
{
|
||||
"host": "GTS-W1",
|
||||
"collected_at_utc": "2026-06-06T18:09:51Z",
|
||||
"os": {
|
||||
"caption": "Microsoft Windows 11 Pro for Workstations",
|
||||
"version": "10.0.26200",
|
||||
"build": "26200",
|
||||
"install_date": "2025-03-05T16:34:47Z",
|
||||
"last_boot_utc": "2026-05-13T05:55:08Z",
|
||||
"architecture": "64-bit"
|
||||
},
|
||||
"facts": {
|
||||
"builtin_admin_enabled": false,
|
||||
"os_eol": {
|
||||
"eol_date": "2027-10-12",
|
||||
"release": "Win11 25H2"
|
||||
},
|
||||
"pending_updates": 3,
|
||||
"pending_reboot": true,
|
||||
"uptime_days": 24.5,
|
||||
"acg_managed_tools": [
|
||||
"ScreenConnect / ConnectWise Control",
|
||||
"Splashtop (SOS/Streamer)",
|
||||
"Syncro / Kabuto"
|
||||
],
|
||||
"hardware": {
|
||||
"model": "90SM006QUS",
|
||||
"manufacturer": "LENOVO",
|
||||
"bios_date": "2024-01-04",
|
||||
"cpu_logical": 12,
|
||||
"bios_version": "M49KT29A",
|
||||
"cpu_cores": 6,
|
||||
"ram_gb": 15.7,
|
||||
"serial": "MJ0J9LD0",
|
||||
"cpu": "12th Gen Intel(R) Core(TM) i5-12400"
|
||||
},
|
||||
"local_administrators": [
|
||||
"GTS\\Domain Admins",
|
||||
"GTS\\gonzvar",
|
||||
"GTS-W1\\Administrator",
|
||||
"GTS-W1\\localadmin",
|
||||
"GTS-W1\\pgonz"
|
||||
],
|
||||
"os_build": "26200",
|
||||
"secure_boot": true,
|
||||
"backup_agents": null,
|
||||
"autoruns_run_keys": [
|
||||
{
|
||||
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
|
||||
"name": "SecurityHealth",
|
||||
"value": "C:\\WINDOWS\\system32\\SecurityHealthSystray.exe"
|
||||
},
|
||||
{
|
||||
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
|
||||
"name": "RtkAudUService",
|
||||
"value": "\"C:\\WINDOWS\\System32\\DriverStore\\FileRepository\\realtekservice.inf_amd64_23392958033090bf\\RtkAudUService64.exe\" -background"
|
||||
},
|
||||
{
|
||||
"key": "HKCU:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
|
||||
"name": "GoogleDriveFS",
|
||||
"value": "\"C:\\Program Files\\Google\\Drive File Stream\\126.0.5.0\\GoogleDriveFS.exe\" --startup_mode"
|
||||
},
|
||||
{
|
||||
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
|
||||
"name": "msedge_cleanup_{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}",
|
||||
"value": "\"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\149.0.4022.52\\Installer\\setup.exe\" --msedge --channel=stable --delete-old-versions --system-level --verbose-logging --on-logon"
|
||||
},
|
||||
{
|
||||
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
|
||||
"name": "Delete Cached Update Binary",
|
||||
"value": "C:\\WINDOWS\\system32\\cmd.exe /q /c del /q \"C:\\Program Files\\Microsoft OneDrive\\Update\\OneDriveSetup.exe\""
|
||||
},
|
||||
{
|
||||
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
|
||||
"name": "Delete Cached Standalone Update Binary",
|
||||
"value": "C:\\WINDOWS\\system32\\cmd.exe /q /c del /q \"C:\\Program Files\\Microsoft OneDrive\\StandaloneUpdater\\OneDriveSetup.exe\""
|
||||
}
|
||||
],
|
||||
"physical_disks": [
|
||||
{
|
||||
"health": "Healthy",
|
||||
"model": "KBG40ZNV1T02 KIOXIA",
|
||||
"media_type": "SSD"
|
||||
}
|
||||
],
|
||||
"local_users": [
|
||||
{
|
||||
"last_logon": "2022-08-26",
|
||||
"name": "Administrator",
|
||||
"password_never_expires": false,
|
||||
"enabled": false
|
||||
},
|
||||
{
|
||||
"last_logon": "",
|
||||
"name": "DefaultAccount",
|
||||
"password_never_expires": false,
|
||||
"enabled": false
|
||||
},
|
||||
{
|
||||
"last_logon": "",
|
||||
"name": "Guest",
|
||||
"password_never_expires": false,
|
||||
"enabled": false
|
||||
},
|
||||
{
|
||||
"last_logon": "",
|
||||
"name": "localadmin",
|
||||
"password_never_expires": false,
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"last_logon": "",
|
||||
"name": "pgonz",
|
||||
"password_never_expires": false,
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"last_logon": "",
|
||||
"name": "WDAGUtilityAccount",
|
||||
"password_never_expires": false,
|
||||
"enabled": false
|
||||
}
|
||||
],
|
||||
"scheduled_tasks_count": 45,
|
||||
"volumes": [
|
||||
{
|
||||
"drive": "[SYSTEM]",
|
||||
"size_gb": 0.2,
|
||||
"free_pct": 76.9,
|
||||
"free_gb": 0.2
|
||||
},
|
||||
{
|
||||
"drive": "C:",
|
||||
"size_gb": 951.6,
|
||||
"free_pct": 84.5,
|
||||
"free_gb": 803.9
|
||||
},
|
||||
{
|
||||
"drive": "[WinRE_DRV]",
|
||||
"size_gb": 2,
|
||||
"free_pct": 65,
|
||||
"free_gb": 1.3
|
||||
}
|
||||
],
|
||||
"network_adapters": [
|
||||
{
|
||||
"dhcp": true,
|
||||
"description": "Realtek PCIe GbE Family Controller",
|
||||
"gateway": [
|
||||
"192.168.0.1"
|
||||
],
|
||||
"mac": "F4:6B:8C:C7:83:A9",
|
||||
"ip": [
|
||||
"192.168.0.143",
|
||||
"fe80::1651:1e3f:81d6:335b"
|
||||
],
|
||||
"dns": [
|
||||
"192.168.0.2",
|
||||
"192.168.0.5"
|
||||
]
|
||||
}
|
||||
],
|
||||
"failed_autostart_services": [
|
||||
{
|
||||
"name": "gpsvc",
|
||||
"display": "Group Policy Client",
|
||||
"state": "Stopped"
|
||||
},
|
||||
{
|
||||
"name": "Intel(R) Platform License Manager Service",
|
||||
"display": "Intel(R) Platform License Manager Service",
|
||||
"state": "Stopped"
|
||||
},
|
||||
{
|
||||
"name": "SysMain",
|
||||
"display": "SysMain",
|
||||
"state": "Stopped"
|
||||
},
|
||||
{
|
||||
"name": "GoogleUpdaterInternalService150.0.7863.0",
|
||||
"display": "Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)",
|
||||
"state": "Stopped"
|
||||
},
|
||||
{
|
||||
"name": "GoogleUpdaterService150.0.7863.0",
|
||||
"display": "Google Updater Service (GoogleUpdaterService150.0.7863.0)",
|
||||
"state": "Stopped"
|
||||
}
|
||||
],
|
||||
"stability_14d": {
|
||||
"unexpected_shutdowns": 0,
|
||||
"disk_errors": 0,
|
||||
"bugchecks": 0
|
||||
},
|
||||
"exposure": {
|
||||
"smb1_enabled": false,
|
||||
"laps_present": true,
|
||||
"rdp_enabled": false,
|
||||
"uac_enabled": true,
|
||||
"rdp_nla": true
|
||||
},
|
||||
"accounts_password_never_expires": [],
|
||||
"installed_software": [
|
||||
{
|
||||
"publisher": "Lenovo",
|
||||
"name": "Calliope_Keyboard",
|
||||
"version": "1.00.08"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Copilot",
|
||||
"version": "148.0.3967.96"
|
||||
},
|
||||
{
|
||||
"publisher": "Drake Software",
|
||||
"name": "Drake Accounting 2025",
|
||||
"version": "25.0.19"
|
||||
},
|
||||
{
|
||||
"publisher": "Intel Corporation",
|
||||
"name": "Dynamic Application Loader Host Interface Service",
|
||||
"version": "1.0.0.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Google LLC",
|
||||
"name": "Google Chrome",
|
||||
"version": "148.0.7778.218"
|
||||
},
|
||||
{
|
||||
"publisher": "Google LLC",
|
||||
"name": "Google Drive",
|
||||
"version": "126.0.5.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Intel(R) Corporation",
|
||||
"name": "Intel(R) Chipset Device Software",
|
||||
"version": "10.1.18836.8283"
|
||||
},
|
||||
{
|
||||
"publisher": "Intel Corporation",
|
||||
"name": "Intel(R) LMS",
|
||||
"version": "1.0.0.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Intel Corporation",
|
||||
"name": "Intel(R) Management Engine Components",
|
||||
"version": "1.0.0.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Intel Corporation",
|
||||
"name": "Intel(R) Management Engine Components",
|
||||
"version": "2130.16.0.2387"
|
||||
},
|
||||
{
|
||||
"publisher": "Intel Corporation",
|
||||
"name": "Intel(R) Management Engine Driver",
|
||||
"version": "1.0.0.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Lenovo",
|
||||
"name": "Lenovo Now",
|
||||
"version": "4.6.0.44"
|
||||
},
|
||||
{
|
||||
"publisher": "Lenovo Group Ltd.",
|
||||
"name": "Lenovo Vantage Service",
|
||||
"version": "4.2601.31.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Host - 6.0.13 (x86)",
|
||||
"version": "48.55.52137"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Host - 8.0.0 (x86)",
|
||||
"version": "64.0.4211"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Host FX Resolver - 6.0.13 (x86)",
|
||||
"version": "48.55.52137"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Host FX Resolver - 8.0.0 (x86)",
|
||||
"version": "64.0.4211"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Runtime - 6.0.13 (x86)",
|
||||
"version": "48.55.52137"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Runtime - 8.0.0 (x86)",
|
||||
"version": "64.0.4211"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft 365 - en-us",
|
||||
"version": "16.0.20026.20112"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft ASP.NET Core 8.0.0 - Shared Framework (x86)",
|
||||
"version": "8.0.0.23531"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft ASP.NET Core 8.0.0 Shared Framework (x86)",
|
||||
"version": "8.0.0.23531"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Edge",
|
||||
"version": "149.0.4022.52"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Edge WebView2 Runtime",
|
||||
"version": "148.0.3967.96"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft OneDrive",
|
||||
"version": "26.088.0510.0004"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft OneNote - en-us",
|
||||
"version": "16.0.20026.20112"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft SQL Server Compact 4.0 SP1 x64 ENU",
|
||||
"version": "4.0.8876.1"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft",
|
||||
"name": "Microsoft Teams Meeting Add-in for Microsoft Office",
|
||||
"version": "1.25.24601"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Update Health Tools",
|
||||
"version": "5.72.0.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.44.35211",
|
||||
"version": "14.44.35211.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.44.35211",
|
||||
"version": "14.44.35211.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2022 X64 Additional Runtime - 14.44.35211",
|
||||
"version": "14.44.35211"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.44.35211",
|
||||
"version": "14.44.35211"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2022 X86 Additional Runtime - 14.44.35211",
|
||||
"version": "14.44.35211"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.44.35211",
|
||||
"version": "14.44.35211"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Windows Desktop Runtime - 6.0.13 (x86)",
|
||||
"version": "48.55.53270"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Windows Desktop Runtime - 6.0.13 (x86)",
|
||||
"version": "6.0.13.32001"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Windows Desktop Runtime - 8.0.0 (x86)",
|
||||
"version": "64.0.5329"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Windows Desktop Runtime - 8.0.0 (x86)",
|
||||
"version": "8.0.0.33101"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Office 16 Click-to-Run Extensibility Component",
|
||||
"version": "16.0.20026.20076"
|
||||
},
|
||||
{
|
||||
"publisher": "Realtek Semiconductor Corp.",
|
||||
"name": "Realtek Audio Driver",
|
||||
"version": "6.0.9225.1"
|
||||
},
|
||||
{
|
||||
"publisher": "Realtek Semiconductor Corp.",
|
||||
"name": "Realtek Card Reader",
|
||||
"version": "10.0.26100.31287"
|
||||
},
|
||||
{
|
||||
"publisher": "ScreenConnect Software",
|
||||
"name": "ScreenConnect Client (1912bf3444b41a08)",
|
||||
"version": "26.1.24.9579"
|
||||
},
|
||||
{
|
||||
"publisher": "Splashtop Inc.",
|
||||
"name": "Splashtop Streamer",
|
||||
"version": "3.8.2.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Servably, Inc.",
|
||||
"name": "Syncro",
|
||||
"version": "1.0.201.18410"
|
||||
}
|
||||
],
|
||||
"tpm": {
|
||||
"enabled": true,
|
||||
"ready": true,
|
||||
"present": true
|
||||
},
|
||||
"local_groups": [
|
||||
"Access Control Assistance Operators",
|
||||
"Administrators",
|
||||
"Backup Operators",
|
||||
"Cryptographic Operators",
|
||||
"Device Owners",
|
||||
"Distributed COM Users",
|
||||
"Event Log Readers",
|
||||
"Guests",
|
||||
"Hyper-V Administrators",
|
||||
"IIS_IUSRS",
|
||||
"Network Configuration Operators",
|
||||
"OpenSSH Users",
|
||||
"Performance Log Users",
|
||||
"Performance Monitor Users",
|
||||
"Power Users",
|
||||
"Remote Desktop Users",
|
||||
"Remote Management Users",
|
||||
"Replicator",
|
||||
"System Managed Accounts Group",
|
||||
"User Mode Hardware Operators",
|
||||
"Users"
|
||||
],
|
||||
"battery": {
|
||||
"present": false
|
||||
},
|
||||
"third_party_av_active": false,
|
||||
"activation": {
|
||||
"edition": "Microsoft Windows 11 Pro for Workstations",
|
||||
"description": "Windows(R) Operating System, VOLUME_MAK channel",
|
||||
"licensed": true,
|
||||
"license_status_code": 1
|
||||
},
|
||||
"time_source": "GTS-SVR25.GTS.local",
|
||||
"chassis_types": [
|
||||
3
|
||||
],
|
||||
"last_hotfix": {
|
||||
"hotfix_id": "KB5089549",
|
||||
"installed_on": "2026-05-13T07:00:00Z"
|
||||
},
|
||||
"scheduled_tasks": [
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "Calliope_Keyboard",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "MicrosoftEdgeUpdateTaskMachineCore",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "MicrosoftEdgeUpdateTaskMachineUA",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "OneDrive Per-Machine Standalone Update Task",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "OneDrive Reporting Task-S-1-5-21-1734567741-2755581958-76075995-1121",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "OneDrive Reporting Task-S-1-5-21-3052971633-1913791397-467572743-1001",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "OneDrive Startup Task-S-1-5-21-1734567741-2755581958-76075995-1121",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "OneDrive Startup Task-S-1-5-21-3052971633-1913791397-467572743-1001",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "OneLaunchUpdateTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\GoogleSystem\\GoogleUpdater\\",
|
||||
"name": "GoogleUpdaterTaskSystem150.0.7863.0{09941C4E-E337-463E-BE02-F432DB9AD38E}",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\GoogleUserPEH\\",
|
||||
"name": "RunPlatformExperienceHelper_Daily",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\GoogleUserPEH\\",
|
||||
"name": "RunPlatformExperienceHelper_Metrics",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\",
|
||||
"name": "LenovoNowQuarterlyLaunch",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\",
|
||||
"name": "LenovoWelcomeLauncher",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\",
|
||||
"name": "LenovoWelcomeQuarterlyLaunch",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\",
|
||||
"name": "LenovoWelcomeTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\ImController\\",
|
||||
"name": "Lenovo iM Controller Monitor",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\ImController\\",
|
||||
"name": "Lenovo iM Controller Scheduled Maintenance",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\ImController\\Plugins\\",
|
||||
"name": "LenovoSystemUpdatePlugin_WeeklyTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\ImController\\TimeBasedEvents\\",
|
||||
"name": "44cd4312-be7a-427e-a5d6-50d4648309e5",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\ImController\\TimeBasedEvents\\",
|
||||
"name": "e3e75683-06a2-428f-8ece-9845b32c6bbe",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\ImController\\TimeBasedEvents\\",
|
||||
"name": "e8e5f7dd-7e58-4558-ac68-a494321cff6c",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\UDC\\",
|
||||
"name": "Lenovo UDC Idle Monitor",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\UDC\\",
|
||||
"name": "Lenovo UDC Lazy Deployment",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\UDC\\",
|
||||
"name": "Lenovo UDC Maintainance Task",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\UDC\\",
|
||||
"name": "Lenovo UDC Monitor",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\",
|
||||
"name": "Lenovo.Vantage.ServiceMaintainance",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\",
|
||||
"name": "StartupFixPlan",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "BatteryGaugeAddinDailyScheduleTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "ConsumerAddinDailyScheduleTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "DailyTelemetryTransmission",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "GenericMessagingAddin",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "GenericMessagingAddin_Pulsation",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "HeartbeatAddinDailyScheduleTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "Lenovo.Vantage.SmartPerformance.MonthlyReport",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "LenovoBoostAddin.Prompt",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "LenovoCompanionAppAddinDailyScheduleTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "LenovoSystemUpdateAddin_WeeklyTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "NotificationCenter",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "SmartPerformance.ExpireReminder",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "VantageCoreAddinDailyScheduleTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "VantageCoreAddinIdleScheduleTask",
|
||||
"state": "Running"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "VantageCoreAddinWeekScheduleTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\SoftLanding\\S-1-5-21-1734567741-2755581958-76075995-1121\\",
|
||||
"name": "SoftLandingCreativeManagementTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\SoftLanding\\S-1-5-21-1734567741-2755581958-76075995-1121\\",
|
||||
"name": "SoftLandingDeferralTask-{06948242-2a07-4683-a193-612c85a68ebf}",
|
||||
"state": "Ready"
|
||||
}
|
||||
],
|
||||
"antivirus_products": [
|
||||
"Windows Defender"
|
||||
],
|
||||
"domain_joined": true,
|
||||
"defender": {
|
||||
"antispyware_signature_age": 0,
|
||||
"tamper_protected": true,
|
||||
"real_time_protection": true,
|
||||
"nis_enabled": true,
|
||||
"available": true,
|
||||
"antivirus_enabled": true,
|
||||
"am_service_enabled": true
|
||||
},
|
||||
"bitlocker": {
|
||||
"os_volume": "C:",
|
||||
"key_protectors": [],
|
||||
"recovery_key_present": false,
|
||||
"available": true,
|
||||
"encryption_percent": 0,
|
||||
"protection_status": "Off"
|
||||
},
|
||||
"is_laptop": false,
|
||||
"installed_software_count": 45,
|
||||
"secure_channel_ok": true,
|
||||
"firewall_profiles": {
|
||||
"Private": true,
|
||||
"Domain": true,
|
||||
"Public": true
|
||||
},
|
||||
"domain": "GTS.local",
|
||||
"foreign_agents": null
|
||||
},
|
||||
"findings": [
|
||||
{
|
||||
"id": "sec.defender.ok",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Defender active and current",
|
||||
"detail": "Real-time protection on, service running, signatures current.",
|
||||
"evidence": "RealTimeProtectionEnabled=True; AMServiceEnabled=True; AntispywareSignatureAge=0 days; IsTamperProtected=True"
|
||||
},
|
||||
{
|
||||
"id": "sec.av_products.defender_only",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Defender is the only registered AV",
|
||||
"detail": "Only Microsoft/Windows Defender is registered in Security Center.",
|
||||
"evidence": "Windows Defender"
|
||||
},
|
||||
{
|
||||
"id": "sec.foreign_agents.none",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "No competitor/leftover management agents detected",
|
||||
"detail": "No known competitor RMM or unmanaged remote-access agents found in installed programs or services.",
|
||||
"evidence": "Scanned uninstall hives (HKLM + WOW6432Node) and Win32_Service"
|
||||
},
|
||||
{
|
||||
"id": "sec.foreign_agents.acg.screenconnect_connectwise_control",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Expected ACG management tooling present: ScreenConnect / ConnectWise Control",
|
||||
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
|
||||
"evidence": "program: ScreenConnect Client (1912bf3444b41a08) 26.1.24.9579\nservice: ScreenConnect Client (1912bf3444b41a08) (ScreenConnect Client (1912bf3444b41a08)) Running"
|
||||
},
|
||||
{
|
||||
"id": "sec.foreign_agents.acg.splashtop_sos_streamer_",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Expected ACG management tooling present: Splashtop (SOS/Streamer)",
|
||||
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
|
||||
"evidence": "program: Splashtop Streamer 3.8.2.0\nservice: SplashtopRemoteService (Splashtop? Remote Service) Running"
|
||||
},
|
||||
{
|
||||
"id": "sec.foreign_agents.acg.syncro_kabuto",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Expected ACG management tooling present: Syncro / Kabuto",
|
||||
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
|
||||
"evidence": "program: Syncro 1.0.201.18410\nservice: Syncro (Syncro) Running"
|
||||
},
|
||||
{
|
||||
"id": "sec.firewall.ok",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "All firewall profiles enabled",
|
||||
"detail": "Domain, Private, and Public firewall profiles are all enabled.",
|
||||
"evidence": "Private=True; Domain=True; Public=True"
|
||||
},
|
||||
{
|
||||
"id": "sec.bitlocker.unencrypted",
|
||||
"category": "security",
|
||||
"severity": "warning",
|
||||
"title": "OS volume is NOT encrypted with BitLocker",
|
||||
"detail": "The operating system volume is unencrypted. Data is exposed if the disk is removed or the device is lost. Enable BitLocker and escrow the recovery key.",
|
||||
"evidence": "Volume=C:; ProtectionStatus=Off; EncryptionPercentage=0; KeyProtectors="
|
||||
},
|
||||
{
|
||||
"id": "sec.local_admins.list",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Local administrators (5)",
|
||||
"detail": "Members of the local Administrators group. Review for unexpected or unknown accounts (especially leftover MSP/vendor accounts from a prior provider).",
|
||||
"evidence": "GTS\\Domain Admins\nGTS\\gonzvar\nGTS-W1\\Administrator\nGTS-W1\\localadmin\nGTS-W1\\pgonz"
|
||||
},
|
||||
{
|
||||
"id": "sec.patch.os_supported",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "OS build supported: Win11 25H2",
|
||||
"detail": "Build 26200 (Win11 25H2) is in support until 2027-10-12.",
|
||||
"evidence": "Microsoft Windows 11 Pro for Workstations build 26200"
|
||||
},
|
||||
{
|
||||
"id": "sec.patch.pending",
|
||||
"category": "security",
|
||||
"severity": "warning",
|
||||
"title": "3 pending Windows updates",
|
||||
"detail": "Windows Update reports pending (not installed, not hidden) updates. Some may be security updates. Approve/install on the next maintenance window.",
|
||||
"evidence": "Microsoft.Update.Session search IsInstalled=0 and IsHidden=0 -> 3"
|
||||
},
|
||||
{
|
||||
"id": "sec.patch.last_hotfix",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Last hotfix: KB5089549",
|
||||
"detail": "Most recently installed update (from Get-HotFix; reflects CBS/MSU packages, not all cumulative metadata).",
|
||||
"evidence": "KB5089549 installed 2026-05-13T07:00:00Z"
|
||||
},
|
||||
{
|
||||
"id": "sec.exposure.smb1_off",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "SMBv1 disabled",
|
||||
"detail": "SMBv1 server protocol is disabled.",
|
||||
"evidence": "EnableSMB1Protocol=False"
|
||||
},
|
||||
{
|
||||
"id": "sec.exposure.laps_present",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "LAPS detected",
|
||||
"detail": "A LAPS mechanism is present.",
|
||||
"evidence": "Windows LAPS reg key"
|
||||
},
|
||||
{
|
||||
"id": "health.stability.clean",
|
||||
"category": "health",
|
||||
"severity": "info",
|
||||
"title": "No stability events in the last 14 days",
|
||||
"detail": "No unexpected shutdowns, BSODs, or disk errors logged.",
|
||||
"evidence": "Unexpected shutdowns (id 41)=0; Bugchecks/BSOD (id 1001)=0; Disk errors (id 7/51/153)=0"
|
||||
},
|
||||
{
|
||||
"id": "health.reboot_uptime.pending",
|
||||
"category": "health",
|
||||
"severity": "warning",
|
||||
"title": "Reboot pending",
|
||||
"detail": "A reboot is pending. Pending reboots can block patches and leave the system in a half-updated state. Schedule a restart.",
|
||||
"evidence": "PendingFileRenameOperations"
|
||||
},
|
||||
{
|
||||
"id": "health.failed_services.stopped",
|
||||
"category": "health",
|
||||
"severity": "warning",
|
||||
"title": "5 auto-start service(s) not running",
|
||||
"detail": "These services are set to start automatically but are not running. Some may be benign; review for security agents, backup agents, or AV that should be running.",
|
||||
"evidence": "gpsvc (Group Policy Client) = Stopped\nIntel(R) Platform License Manager Service (Intel(R) Platform License Manager Service) = Stopped\nSysMain (SysMain) = Stopped\nGoogleUpdaterInternalService150.0.7863.0 (Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)) = Stopped\nGoogleUpdaterService150.0.7863.0 (Google Updater Service (GoogleUpdaterService150.0.7863.0)) = Stopped"
|
||||
},
|
||||
{
|
||||
"id": "health.domain.secure_channel_ok",
|
||||
"category": "health",
|
||||
"severity": "info",
|
||||
"title": "Domain secure channel healthy",
|
||||
"detail": "Machine trust relationship with the domain is intact.",
|
||||
"evidence": "Domain=GTS.local"
|
||||
},
|
||||
{
|
||||
"id": "health.time.source",
|
||||
"category": "health",
|
||||
"severity": "info",
|
||||
"title": "Time service source",
|
||||
"detail": "Current Windows Time service source.",
|
||||
"evidence": "Source=GTS-SVR25.GTS.local"
|
||||
},
|
||||
{
|
||||
"id": "health.backup.none",
|
||||
"category": "health",
|
||||
"severity": "info",
|
||||
"title": "No backup agent detected",
|
||||
"detail": "No known backup agent service found. Backup expectation varies by endpoint; confirm whether this machine is supposed to have local/cloud backup and whether server-side or M365 backup covers it.",
|
||||
"evidence": "No matching backup service in Win32_Service"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,249 @@
|
||||
# Onboarding Diagnostic Baseline - GTS-W1
|
||||
|
||||
- **Grade:** AMBER
|
||||
- **Host:** GTS-W1
|
||||
- **Client:** Gonzvar Tax Services (`gonzvar-tax-services`)
|
||||
- **Collected (UTC):** 2026-06-06T18:09:51Z
|
||||
- **Agent ID:** 151c0c38-eb28-48c7-87d8-51ef8d81cc75
|
||||
- **Command ID:** 748d8235-1d1f-4015-a74e-f03c4aade06b
|
||||
- **Findings:** 0 critical / 4 warning / 16 info / 0 unknown
|
||||
|
||||
- **OS:** Microsoft Windows 11 Pro for Workstations (build 26200)
|
||||
|
||||
---
|
||||
|
||||
## WARNING (4)
|
||||
|
||||
### OS volume is NOT encrypted with BitLocker
|
||||
- **Category:** security
|
||||
- **ID:** `sec.bitlocker.unencrypted`
|
||||
- The operating system volume is unencrypted. Data is exposed if the disk is removed or the device is lost. Enable BitLocker and escrow the recovery key.
|
||||
|
||||
```
|
||||
Volume=C:; ProtectionStatus=Off; EncryptionPercentage=0; KeyProtectors=
|
||||
```
|
||||
|
||||
### 3 pending Windows updates
|
||||
- **Category:** security
|
||||
- **ID:** `sec.patch.pending`
|
||||
- Windows Update reports pending (not installed, not hidden) updates. Some may be security updates. Approve/install on the next maintenance window.
|
||||
|
||||
```
|
||||
Microsoft.Update.Session search IsInstalled=0 and IsHidden=0 -> 3
|
||||
```
|
||||
|
||||
### Reboot pending
|
||||
- **Category:** health
|
||||
- **ID:** `health.reboot_uptime.pending`
|
||||
- A reboot is pending. Pending reboots can block patches and leave the system in a half-updated state. Schedule a restart.
|
||||
|
||||
```
|
||||
PendingFileRenameOperations
|
||||
```
|
||||
|
||||
### 5 auto-start service(s) not running
|
||||
- **Category:** health
|
||||
- **ID:** `health.failed_services.stopped`
|
||||
- These services are set to start automatically but are not running. Some may be benign; review for security agents, backup agents, or AV that should be running.
|
||||
|
||||
```
|
||||
gpsvc (Group Policy Client) = Stopped
|
||||
Intel(R) Platform License Manager Service (Intel(R) Platform License Manager Service) = Stopped
|
||||
SysMain (SysMain) = Stopped
|
||||
GoogleUpdaterInternalService150.0.7863.0 (Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)) = Stopped
|
||||
GoogleUpdaterService150.0.7863.0 (Google Updater Service (GoogleUpdaterService150.0.7863.0)) = Stopped
|
||||
```
|
||||
|
||||
|
||||
## INFO (16)
|
||||
|
||||
### Defender active and current
|
||||
- **Category:** security
|
||||
- **ID:** `sec.defender.ok`
|
||||
- Real-time protection on, service running, signatures current.
|
||||
|
||||
```
|
||||
RealTimeProtectionEnabled=True; AMServiceEnabled=True; AntispywareSignatureAge=0 days; IsTamperProtected=True
|
||||
```
|
||||
|
||||
### Defender is the only registered AV
|
||||
- **Category:** security
|
||||
- **ID:** `sec.av_products.defender_only`
|
||||
- Only Microsoft/Windows Defender is registered in Security Center.
|
||||
|
||||
```
|
||||
Windows Defender
|
||||
```
|
||||
|
||||
### No competitor/leftover management agents detected
|
||||
- **Category:** security
|
||||
- **ID:** `sec.foreign_agents.none`
|
||||
- No known competitor RMM or unmanaged remote-access agents found in installed programs or services.
|
||||
|
||||
```
|
||||
Scanned uninstall hives (HKLM + WOW6432Node) and Win32_Service
|
||||
```
|
||||
|
||||
### Expected ACG management tooling present: ScreenConnect / ConnectWise Control
|
||||
- **Category:** security
|
||||
- **ID:** `sec.foreign_agents.acg.screenconnect_connectwise_control`
|
||||
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
|
||||
|
||||
```
|
||||
program: ScreenConnect Client (1912bf3444b41a08) 26.1.24.9579
|
||||
service: ScreenConnect Client (1912bf3444b41a08) (ScreenConnect Client (1912bf3444b41a08)) Running
|
||||
```
|
||||
|
||||
### Expected ACG management tooling present: Splashtop (SOS/Streamer)
|
||||
- **Category:** security
|
||||
- **ID:** `sec.foreign_agents.acg.splashtop_sos_streamer_`
|
||||
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
|
||||
|
||||
```
|
||||
program: Splashtop Streamer 3.8.2.0
|
||||
service: SplashtopRemoteService (Splashtop? Remote Service) Running
|
||||
```
|
||||
|
||||
### Expected ACG management tooling present: Syncro / Kabuto
|
||||
- **Category:** security
|
||||
- **ID:** `sec.foreign_agents.acg.syncro_kabuto`
|
||||
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
|
||||
|
||||
```
|
||||
program: Syncro 1.0.201.18410
|
||||
service: Syncro (Syncro) Running
|
||||
```
|
||||
|
||||
### All firewall profiles enabled
|
||||
- **Category:** security
|
||||
- **ID:** `sec.firewall.ok`
|
||||
- Domain, Private, and Public firewall profiles are all enabled.
|
||||
|
||||
```
|
||||
Private=True; Domain=True; Public=True
|
||||
```
|
||||
|
||||
### Local administrators (5)
|
||||
- **Category:** security
|
||||
- **ID:** `sec.local_admins.list`
|
||||
- Members of the local Administrators group. Review for unexpected or unknown accounts (especially leftover MSP/vendor accounts from a prior provider).
|
||||
|
||||
```
|
||||
GTS\Domain Admins
|
||||
GTS\gonzvar
|
||||
GTS-W1\Administrator
|
||||
GTS-W1\localadmin
|
||||
GTS-W1\pgonz
|
||||
```
|
||||
|
||||
### OS build supported: Win11 25H2
|
||||
- **Category:** security
|
||||
- **ID:** `sec.patch.os_supported`
|
||||
- Build 26200 (Win11 25H2) is in support until 2027-10-12.
|
||||
|
||||
```
|
||||
Microsoft Windows 11 Pro for Workstations build 26200
|
||||
```
|
||||
|
||||
### Last hotfix: KB5089549
|
||||
- **Category:** security
|
||||
- **ID:** `sec.patch.last_hotfix`
|
||||
- Most recently installed update (from Get-HotFix; reflects CBS/MSU packages, not all cumulative metadata).
|
||||
|
||||
```
|
||||
KB5089549 installed 2026-05-13T07:00:00Z
|
||||
```
|
||||
|
||||
### SMBv1 disabled
|
||||
- **Category:** security
|
||||
- **ID:** `sec.exposure.smb1_off`
|
||||
- SMBv1 server protocol is disabled.
|
||||
|
||||
```
|
||||
EnableSMB1Protocol=False
|
||||
```
|
||||
|
||||
### LAPS detected
|
||||
- **Category:** security
|
||||
- **ID:** `sec.exposure.laps_present`
|
||||
- A LAPS mechanism is present.
|
||||
|
||||
```
|
||||
Windows LAPS reg key
|
||||
```
|
||||
|
||||
### No stability events in the last 14 days
|
||||
- **Category:** health
|
||||
- **ID:** `health.stability.clean`
|
||||
- No unexpected shutdowns, BSODs, or disk errors logged.
|
||||
|
||||
```
|
||||
Unexpected shutdowns (id 41)=0; Bugchecks/BSOD (id 1001)=0; Disk errors (id 7/51/153)=0
|
||||
```
|
||||
|
||||
### Domain secure channel healthy
|
||||
- **Category:** health
|
||||
- **ID:** `health.domain.secure_channel_ok`
|
||||
- Machine trust relationship with the domain is intact.
|
||||
|
||||
```
|
||||
Domain=GTS.local
|
||||
```
|
||||
|
||||
### Time service source
|
||||
- **Category:** health
|
||||
- **ID:** `health.time.source`
|
||||
- Current Windows Time service source.
|
||||
|
||||
```
|
||||
Source=GTS-SVR25.GTS.local
|
||||
```
|
||||
|
||||
### No backup agent detected
|
||||
- **Category:** health
|
||||
- **ID:** `health.backup.none`
|
||||
- No known backup agent service found. Backup expectation varies by endpoint; confirm whether this machine is supposed to have local/cloud backup and whether server-side or M365 backup covers it.
|
||||
|
||||
```
|
||||
No matching backup service in Win32_Service
|
||||
```
|
||||
|
||||
|
||||
---
|
||||
|
||||
## Inventory Baseline Summary
|
||||
|
||||
- **Manufacturer / Model:** LENOVO / 90SM006QUS
|
||||
- **Serial:** MJ0J9LD0
|
||||
- **CPU:** 12th Gen Intel(R) Core(TM) i5-12400 (6 cores / 12 logical)
|
||||
- **RAM (GB):** 15.7
|
||||
- **BIOS:** M49KT29A (2024-01-04)
|
||||
- **Chassis is laptop:** false
|
||||
- **TPM present / Secure Boot:** true / true
|
||||
- **Domain joined:** true (GTS.local)
|
||||
- **OS activation licensed:** true
|
||||
- **Uptime (days):** 24.5
|
||||
- **Pending reboot:** true
|
||||
- **Installed software count:** 45
|
||||
- **Scheduled tasks (non-MS, enabled):** 45
|
||||
- **Local administrators:** GTS\Domain Admins, GTS\gonzvar, GTS-W1\Administrator, GTS-W1\localadmin, GTS-W1\pgonz
|
||||
|
||||
### Fixed volumes
|
||||
|
||||
- [SYSTEM] - 0.2 GB free of 0.2 GB (76.9%)
|
||||
- C: - 803.9 GB free of 951.6 GB (84.5%)
|
||||
- [WinRE_DRV] - 1.3 GB free of 2 GB (65%)
|
||||
|
||||
### Network adapters
|
||||
|
||||
- Realtek PCIe GbE Family Controller - IP: 192.168.0.143, fe80::1651:1e3f:81d6:335b - DNS: 192.168.0.2, 192.168.0.5 - DHCP: true
|
||||
|
||||
---
|
||||
|
||||
## Diff vs Prior Baseline
|
||||
|
||||
- No prior baseline found for this host. This is the first baseline.
|
||||
|
||||
---
|
||||
|
||||
_Generated by run-onboarding-diagnostic.sh (GuruRMM onboarding diagnostic, Phase 1). Raw snapshot: `GTS-W1-20260606T180908.json` (immutable)._
|
||||
@@ -0,0 +1,912 @@
|
||||
{
|
||||
"host": "GTS-W2",
|
||||
"collected_at_utc": "2026-06-06T18:11:25Z",
|
||||
"os": {
|
||||
"caption": "Microsoft Windows 11 Pro for Workstations",
|
||||
"version": "10.0.26200",
|
||||
"build": "26200",
|
||||
"install_date": "2025-02-21T09:16:13Z",
|
||||
"last_boot_utc": "2026-04-17T22:07:40Z",
|
||||
"architecture": "64-bit"
|
||||
},
|
||||
"facts": {
|
||||
"builtin_admin_enabled": false,
|
||||
"os_eol": {
|
||||
"eol_date": "2027-10-12",
|
||||
"release": "Win11 25H2"
|
||||
},
|
||||
"pending_updates": 6,
|
||||
"pending_reboot": true,
|
||||
"uptime_days": 49.8,
|
||||
"acg_managed_tools": [
|
||||
"ScreenConnect / ConnectWise Control",
|
||||
"Splashtop (SOS/Streamer)",
|
||||
"Syncro / Kabuto"
|
||||
],
|
||||
"hardware": {
|
||||
"model": "90SM006QUS",
|
||||
"manufacturer": "LENOVO",
|
||||
"bios_date": "2024-01-04",
|
||||
"cpu_logical": 12,
|
||||
"bios_version": "M49KT29A",
|
||||
"cpu_cores": 6,
|
||||
"ram_gb": 15.7,
|
||||
"serial": "MJ0JAWPT",
|
||||
"cpu": "12th Gen Intel(R) Core(TM) i5-12400"
|
||||
},
|
||||
"local_administrators": [
|
||||
"GTS\\Domain Admins",
|
||||
"GTS\\gonzvar",
|
||||
"GTS-W2\\Administrator",
|
||||
"GTS-W2\\localadmin",
|
||||
"GTS-W2\\pgonz"
|
||||
],
|
||||
"os_build": "26200",
|
||||
"secure_boot": true,
|
||||
"backup_agents": null,
|
||||
"autoruns_run_keys": [
|
||||
{
|
||||
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
|
||||
"name": "SecurityHealth",
|
||||
"value": "C:\\WINDOWS\\system32\\SecurityHealthSystray.exe"
|
||||
},
|
||||
{
|
||||
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
|
||||
"name": "RtkAudUService",
|
||||
"value": "\"C:\\WINDOWS\\System32\\DriverStore\\FileRepository\\realtekservice.inf_amd64_23392958033090bf\\RtkAudUService64.exe\" -background"
|
||||
}
|
||||
],
|
||||
"physical_disks": [
|
||||
{
|
||||
"health": "Healthy",
|
||||
"model": "KINGSTON SNV2S1000G",
|
||||
"media_type": "SSD"
|
||||
}
|
||||
],
|
||||
"local_users": [
|
||||
{
|
||||
"last_logon": "2022-08-26",
|
||||
"name": "Administrator",
|
||||
"password_never_expires": false,
|
||||
"enabled": false
|
||||
},
|
||||
{
|
||||
"last_logon": "",
|
||||
"name": "DefaultAccount",
|
||||
"password_never_expires": false,
|
||||
"enabled": false
|
||||
},
|
||||
{
|
||||
"last_logon": "",
|
||||
"name": "Guest",
|
||||
"password_never_expires": false,
|
||||
"enabled": false
|
||||
},
|
||||
{
|
||||
"last_logon": "",
|
||||
"name": "localadmin",
|
||||
"password_never_expires": false,
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"last_logon": "",
|
||||
"name": "pgonz",
|
||||
"password_never_expires": false,
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"last_logon": "",
|
||||
"name": "WDAGUtilityAccount",
|
||||
"password_never_expires": false,
|
||||
"enabled": false
|
||||
}
|
||||
],
|
||||
"scheduled_tasks_count": 46,
|
||||
"volumes": [
|
||||
{
|
||||
"drive": "[SYSTEM]",
|
||||
"size_gb": 0.2,
|
||||
"free_pct": 76.9,
|
||||
"free_gb": 0.2
|
||||
},
|
||||
{
|
||||
"drive": "C:",
|
||||
"size_gb": 929.3,
|
||||
"free_pct": 81.4,
|
||||
"free_gb": 756.7
|
||||
},
|
||||
{
|
||||
"drive": "[WinRE_DRV]",
|
||||
"size_gb": 2,
|
||||
"free_pct": 60.2,
|
||||
"free_gb": 1.2
|
||||
}
|
||||
],
|
||||
"network_adapters": [
|
||||
{
|
||||
"dhcp": true,
|
||||
"description": "Realtek PCIe GbE Family Controller",
|
||||
"gateway": [
|
||||
"192.168.0.1"
|
||||
],
|
||||
"mac": "F4:6B:8C:C7:84:BC",
|
||||
"ip": [
|
||||
"192.168.0.146",
|
||||
"fe80::826b:1844:b416:d971"
|
||||
],
|
||||
"dns": [
|
||||
"192.168.0.2",
|
||||
"192.168.0.5"
|
||||
]
|
||||
}
|
||||
],
|
||||
"failed_autostart_services": [
|
||||
{
|
||||
"name": "Intel(R) Platform License Manager Service",
|
||||
"display": "Intel(R) Platform License Manager Service",
|
||||
"state": "Stopped"
|
||||
},
|
||||
{
|
||||
"name": "GoogleUpdaterInternalService150.0.7863.0",
|
||||
"display": "Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)",
|
||||
"state": "Stopped"
|
||||
},
|
||||
{
|
||||
"name": "GoogleUpdaterService150.0.7863.0",
|
||||
"display": "Google Updater Service (GoogleUpdaterService150.0.7863.0)",
|
||||
"state": "Stopped"
|
||||
}
|
||||
],
|
||||
"stability_14d": {
|
||||
"unexpected_shutdowns": 0,
|
||||
"disk_errors": 0,
|
||||
"bugchecks": 0
|
||||
},
|
||||
"exposure": {
|
||||
"smb1_enabled": false,
|
||||
"laps_present": true,
|
||||
"rdp_enabled": false,
|
||||
"uac_enabled": true,
|
||||
"rdp_nla": true
|
||||
},
|
||||
"accounts_password_never_expires": [],
|
||||
"installed_software": [
|
||||
{
|
||||
"publisher": "Adobe",
|
||||
"name": "Adobe Acrobat (64-bit)",
|
||||
"version": "26.001.21563"
|
||||
},
|
||||
{
|
||||
"publisher": "Adobe Systems Incorporated",
|
||||
"name": "Adobe Refresh Manager",
|
||||
"version": "1.8.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Bitdefender",
|
||||
"name": "Bitdefender Endpoint Security Tools",
|
||||
"version": "8.26.6.644"
|
||||
},
|
||||
{
|
||||
"publisher": "Lenovo",
|
||||
"name": "Calliope_Keyboard",
|
||||
"version": "1.00.08"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Copilot",
|
||||
"version": "147.0.3912.60"
|
||||
},
|
||||
{
|
||||
"publisher": "Drake Software",
|
||||
"name": "Drake Accounting 2025",
|
||||
"version": "25.0.18"
|
||||
},
|
||||
{
|
||||
"publisher": "Intel Corporation",
|
||||
"name": "Dynamic Application Loader Host Interface Service",
|
||||
"version": "1.0.0.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Google LLC",
|
||||
"name": "Google Chrome",
|
||||
"version": "148.0.7778.217"
|
||||
},
|
||||
{
|
||||
"publisher": "",
|
||||
"name": "Ingenico USB Drivers 3.40 (remove only)",
|
||||
"version": "3.40"
|
||||
},
|
||||
{
|
||||
"publisher": "Intel Corporation",
|
||||
"name": "Intel(R) Chipset Device Software",
|
||||
"version": "10.1.18836.8283"
|
||||
},
|
||||
{
|
||||
"publisher": "Intel Corporation",
|
||||
"name": "Intel(R) LMS",
|
||||
"version": "1.0.0.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Intel Corporation",
|
||||
"name": "Intel(R) Management Engine Components",
|
||||
"version": "1.0.0.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Intel Corporation",
|
||||
"name": "Intel(R) Management Engine Components",
|
||||
"version": "2130.16.0.2387"
|
||||
},
|
||||
{
|
||||
"publisher": "Intel Corporation",
|
||||
"name": "Intel(R) Management Engine Driver",
|
||||
"version": "1.0.0.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Lenovo",
|
||||
"name": "Lenovo Now",
|
||||
"version": "4.4.0.61"
|
||||
},
|
||||
{
|
||||
"publisher": "Lenovo Group Ltd.",
|
||||
"name": "Lenovo Vantage Service",
|
||||
"version": "4.2601.31.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Host - 6.0.13 (x86)",
|
||||
"version": "48.55.52137"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Host - 8.0.0 (x86)",
|
||||
"version": "64.0.4211"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Host FX Resolver - 6.0.13 (x86)",
|
||||
"version": "48.55.52137"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Host FX Resolver - 8.0.0 (x86)",
|
||||
"version": "64.0.4211"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Runtime - 6.0.13 (x86)",
|
||||
"version": "48.55.52137"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Runtime - 8.0.0 (x86)",
|
||||
"version": "64.0.4211"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft 365 - en-us",
|
||||
"version": "16.0.19822.20168"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft ASP.NET Core 8.0.0 - Shared Framework (x86)",
|
||||
"version": "8.0.0.23531"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft ASP.NET Core 8.0.0 Shared Framework (x86)",
|
||||
"version": "8.0.0.23531"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Edge",
|
||||
"version": "147.0.3912.60"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Edge WebView2 Runtime",
|
||||
"version": "147.0.3912.60"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft OneNote - en-us",
|
||||
"version": "16.0.19822.20168"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft SQL Server Compact 4.0 SP1 x64 ENU",
|
||||
"version": "4.0.8876.1"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft",
|
||||
"name": "Microsoft Teams Meeting Add-in for Microsoft Office",
|
||||
"version": "1.24.25506"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Update Health Tools",
|
||||
"version": "5.72.0.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.44.35211",
|
||||
"version": "14.44.35211.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.44.35211",
|
||||
"version": "14.44.35211.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2022 X64 Additional Runtime - 14.44.35211",
|
||||
"version": "14.44.35211"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.44.35211",
|
||||
"version": "14.44.35211"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2022 X86 Additional Runtime - 14.44.35211",
|
||||
"version": "14.44.35211"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.44.35211",
|
||||
"version": "14.44.35211"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Windows Desktop Runtime - 6.0.13 (x86)",
|
||||
"version": "48.55.53270"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Windows Desktop Runtime - 6.0.13 (x86)",
|
||||
"version": "6.0.13.32001"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Windows Desktop Runtime - 8.0.0 (x86)",
|
||||
"version": "64.0.5329"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Windows Desktop Runtime - 8.0.0 (x86)",
|
||||
"version": "8.0.0.33101"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Office 16 Click-to-Run Extensibility Component",
|
||||
"version": "16.0.19822.20104"
|
||||
},
|
||||
{
|
||||
"publisher": "Sober Lemur S.r.l.",
|
||||
"name": "PDFsam Visual",
|
||||
"version": "4.3.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Realtek Semiconductor Corp.",
|
||||
"name": "Realtek Audio Driver",
|
||||
"version": "6.0.9225.1"
|
||||
},
|
||||
{
|
||||
"publisher": "Realtek Semiconductor Corp.",
|
||||
"name": "Realtek Card Reader",
|
||||
"version": "10.0.26100.31287"
|
||||
},
|
||||
{
|
||||
"publisher": "ScreenConnect Software",
|
||||
"name": "ScreenConnect Client (1912bf3444b41a08)",
|
||||
"version": "26.1.24.9579"
|
||||
},
|
||||
{
|
||||
"publisher": "Splashtop Inc.",
|
||||
"name": "Splashtop Streamer",
|
||||
"version": "3.8.2.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Servably, Inc.",
|
||||
"name": "Syncro",
|
||||
"version": "1.0.201.18410"
|
||||
}
|
||||
],
|
||||
"tpm": {
|
||||
"enabled": true,
|
||||
"ready": true,
|
||||
"present": true
|
||||
},
|
||||
"local_groups": [
|
||||
"Access Control Assistance Operators",
|
||||
"Administrators",
|
||||
"Backup Operators",
|
||||
"Cryptographic Operators",
|
||||
"Device Owners",
|
||||
"Distributed COM Users",
|
||||
"Event Log Readers",
|
||||
"Guests",
|
||||
"Hyper-V Administrators",
|
||||
"IIS_IUSRS",
|
||||
"Network Configuration Operators",
|
||||
"OpenSSH Users",
|
||||
"Performance Log Users",
|
||||
"Performance Monitor Users",
|
||||
"Power Users",
|
||||
"Remote Desktop Users",
|
||||
"Remote Management Users",
|
||||
"Replicator",
|
||||
"System Managed Accounts Group",
|
||||
"User Mode Hardware Operators",
|
||||
"Users"
|
||||
],
|
||||
"battery": {
|
||||
"present": false
|
||||
},
|
||||
"third_party_av_active": true,
|
||||
"activation": {
|
||||
"edition": "Microsoft Windows 11 Pro for Workstations",
|
||||
"description": "Windows(R) Operating System, VOLUME_MAK channel",
|
||||
"licensed": true,
|
||||
"license_status_code": 1
|
||||
},
|
||||
"time_source": "GTS-SVR25.GTS.local",
|
||||
"chassis_types": [
|
||||
3
|
||||
],
|
||||
"last_hotfix": {
|
||||
"hotfix_id": "KB5083769",
|
||||
"installed_on": "2026-04-15T07:00:00Z"
|
||||
},
|
||||
"scheduled_tasks": [
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "Adobe Acrobat Update Task",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "Calliope_Keyboard",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "MicrosoftEdgeUpdateTaskMachineCore",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "MicrosoftEdgeUpdateTaskMachineUA",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "OneDrive Reporting Task-S-1-5-21-1734567741-2755581958-76075995-1121",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "OneDrive Reporting Task-S-1-5-21-3052971633-1913791397-467572743-1001",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "OneDrive Standalone Update Task-S-1-5-21-1734567741-2755581958-76075995-1121",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "OneDrive Standalone Update Task-S-1-5-21-3052971633-1913791397-467572743-1001",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "OneDrive Startup Task-S-1-5-21-1734567741-2755581958-76075995-1121",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\GoogleSystem\\GoogleUpdater\\",
|
||||
"name": "GoogleUpdaterTaskSystem150.0.7863.0{12AFA30B-C755-45D6-85CC-33CDD9BF2243}",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\GoogleUserPEH\\",
|
||||
"name": "RunPlatformExperienceHelper_Daily",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\",
|
||||
"name": "LenovoNowQuarterlyLaunch",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\",
|
||||
"name": "LenovoWelcomeLauncher",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\",
|
||||
"name": "LenovoWelcomeQuarterlyLaunch",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\",
|
||||
"name": "LenovoWelcomeTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\ImController\\",
|
||||
"name": "Lenovo iM Controller Monitor",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\ImController\\",
|
||||
"name": "Lenovo iM Controller Scheduled Maintenance",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\ImController\\Plugins\\",
|
||||
"name": "LenovoSystemUpdatePlugin_WeeklyTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\ImController\\TimeBasedEvents\\",
|
||||
"name": "05655d16-248b-4767-838a-1fde57338d36",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\ImController\\TimeBasedEvents\\",
|
||||
"name": "ea1a50a7-715a-4c26-b922-ac42ec877042",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\ImController\\TimeBasedEvents\\",
|
||||
"name": "fea6f267-63b1-48d6-ac80-caab635a514f",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\UDC\\",
|
||||
"name": "Lenovo UDC Idle Monitor",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\UDC\\",
|
||||
"name": "Lenovo UDC Lazy Deployment",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\UDC\\",
|
||||
"name": "Lenovo UDC Maintainance Task",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\UDC\\",
|
||||
"name": "Lenovo UDC Monitor",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\",
|
||||
"name": "Lenovo.Vantage.ServiceMaintainance",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\",
|
||||
"name": "StartupFixPlan",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "BatteryGaugeAddinDailyScheduleTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "ConsumerAddinDailyScheduleTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "DailyTelemetryTransmission",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "GenericMessagingAddin",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "GenericMessagingAddin_Pulsation",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "HeartbeatAddinDailyScheduleTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "Lenovo.Vantage.SmartPerformance.MonthlyReport",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "LenovoBoostAddin.Prompt",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "LenovoCompanionAppAddinDailyScheduleTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "LenovoSystemUpdateAddin_WeeklyTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "NotificationCenter",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "SmartLock.ExpireReminder",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "SmartPerformance.ExpireReminder",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "VantageCoreAddinDailyScheduleTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "VantageCoreAddinIdleScheduleTask",
|
||||
"state": "Running"
|
||||
},
|
||||
{
|
||||
"path": "\\Lenovo\\Vantage\\Schedule\\",
|
||||
"name": "VantageCoreAddinWeekScheduleTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\McAfeeTsk\\",
|
||||
"name": "OOBEUpgrader",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\SoftLanding\\S-1-5-21-1734567741-2755581958-76075995-1121\\",
|
||||
"name": "SoftLandingCreativeManagementTask",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\SoftLanding\\S-1-5-21-1734567741-2755581958-76075995-1121\\",
|
||||
"name": "SoftLandingDeferralTask-{94a334fe-d698-472a-a23e-c320fa58dbdd}",
|
||||
"state": "Ready"
|
||||
}
|
||||
],
|
||||
"antivirus_products": [
|
||||
"Windows Defender",
|
||||
"Bitdefender Endpoint Security Tools Antimalware"
|
||||
],
|
||||
"domain_joined": true,
|
||||
"defender": {
|
||||
"antispyware_signature_age": 0,
|
||||
"tamper_protected": false,
|
||||
"real_time_protection": false,
|
||||
"nis_enabled": false,
|
||||
"available": true,
|
||||
"antivirus_enabled": false,
|
||||
"am_service_enabled": false
|
||||
},
|
||||
"bitlocker": {
|
||||
"os_volume": "C:",
|
||||
"key_protectors": [],
|
||||
"recovery_key_present": false,
|
||||
"available": true,
|
||||
"encryption_percent": 0,
|
||||
"protection_status": "Off"
|
||||
},
|
||||
"is_laptop": false,
|
||||
"installed_software_count": 48,
|
||||
"secure_channel_ok": true,
|
||||
"firewall_profiles": {
|
||||
"Private": true,
|
||||
"Domain": true,
|
||||
"Public": true
|
||||
},
|
||||
"domain": "GTS.local",
|
||||
"foreign_agents": null
|
||||
},
|
||||
"findings": [
|
||||
{
|
||||
"id": "sec.defender.rtp_off",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Defender real-time protection is OFF (3rd-party AV active)",
|
||||
"detail": "Defender real-time protection is off because a managed/known 3rd-party AV is active. Windows disables Defender real-time protection when another AV registers, so this is expected. Confirm the 3rd-party AV is providing real-time protection.",
|
||||
"evidence": "RealTimeProtectionEnabled=False; AMServiceEnabled=False; AntispywareSignatureAge=0 days; IsTamperProtected=False; SecurityCenter2 AntiVirusProduct: Bitdefender Endpoint Security Tools Antimalware (productState=0x41000, RTP on)"
|
||||
},
|
||||
{
|
||||
"id": "sec.defender.amservice_off",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Defender antimalware service is not running (3rd-party AV active)",
|
||||
"detail": "The Defender antimalware service is not active because a managed/known 3rd-party AV is registered. Windows stands Defender down when another AV provides protection, so this is expected. Confirm the 3rd-party AV is running.",
|
||||
"evidence": "RealTimeProtectionEnabled=False; AMServiceEnabled=False; AntispywareSignatureAge=0 days; IsTamperProtected=False; SecurityCenter2 AntiVirusProduct: Bitdefender Endpoint Security Tools Antimalware (productState=0x41000, RTP on)"
|
||||
},
|
||||
{
|
||||
"id": "sec.defender.tamper_off",
|
||||
"category": "security",
|
||||
"severity": "warning",
|
||||
"title": "Defender tamper protection is OFF",
|
||||
"detail": "Tamper protection is disabled, so malware or a local admin can silently disable Defender. Enable tamper protection (typically via Intune / Security Center).",
|
||||
"evidence": "RealTimeProtectionEnabled=False; AMServiceEnabled=False; AntispywareSignatureAge=0 days; IsTamperProtected=False"
|
||||
},
|
||||
{
|
||||
"id": "sec.av_products.third_party",
|
||||
"category": "security",
|
||||
"severity": "warning",
|
||||
"title": "Third-party AV present: Bitdefender Endpoint Security Tools Antimalware",
|
||||
"detail": "A non-Defender antivirus is registered. Running two real-time AV engines causes conflicts, performance loss, and detection gaps. Confirm the intended AV and ensure only one provides real-time protection.",
|
||||
"evidence": "Registered AV: Windows Defender, Bitdefender Endpoint Security Tools Antimalware"
|
||||
},
|
||||
{
|
||||
"id": "sec.foreign_agents.none",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "No competitor/leftover management agents detected",
|
||||
"detail": "No known competitor RMM or unmanaged remote-access agents found in installed programs or services.",
|
||||
"evidence": "Scanned uninstall hives (HKLM + WOW6432Node) and Win32_Service"
|
||||
},
|
||||
{
|
||||
"id": "sec.foreign_agents.acg.screenconnect_connectwise_control",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Expected ACG management tooling present: ScreenConnect / ConnectWise Control",
|
||||
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
|
||||
"evidence": "program: ScreenConnect Client (1912bf3444b41a08) 26.1.24.9579\nservice: ScreenConnect Client (1912bf3444b41a08) (ScreenConnect Client (1912bf3444b41a08)) Running"
|
||||
},
|
||||
{
|
||||
"id": "sec.foreign_agents.acg.splashtop_sos_streamer_",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Expected ACG management tooling present: Splashtop (SOS/Streamer)",
|
||||
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
|
||||
"evidence": "program: Splashtop Streamer 3.8.2.0\nservice: SplashtopRemoteService (Splashtop? Remote Service) Running"
|
||||
},
|
||||
{
|
||||
"id": "sec.foreign_agents.acg.syncro_kabuto",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Expected ACG management tooling present: Syncro / Kabuto",
|
||||
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
|
||||
"evidence": "program: Syncro 1.0.201.18410\nservice: Syncro (Syncro) Running"
|
||||
},
|
||||
{
|
||||
"id": "sec.firewall.ok",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "All firewall profiles enabled",
|
||||
"detail": "Domain, Private, and Public firewall profiles are all enabled.",
|
||||
"evidence": "Private=True; Domain=True; Public=True"
|
||||
},
|
||||
{
|
||||
"id": "sec.bitlocker.unencrypted",
|
||||
"category": "security",
|
||||
"severity": "warning",
|
||||
"title": "OS volume is NOT encrypted with BitLocker",
|
||||
"detail": "The operating system volume is unencrypted. Data is exposed if the disk is removed or the device is lost. Enable BitLocker and escrow the recovery key.",
|
||||
"evidence": "Volume=C:; ProtectionStatus=Off; EncryptionPercentage=0; KeyProtectors="
|
||||
},
|
||||
{
|
||||
"id": "sec.local_admins.list",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Local administrators (5)",
|
||||
"detail": "Members of the local Administrators group. Review for unexpected or unknown accounts (especially leftover MSP/vendor accounts from a prior provider).",
|
||||
"evidence": "GTS\\Domain Admins\nGTS\\gonzvar\nGTS-W2\\Administrator\nGTS-W2\\localadmin\nGTS-W2\\pgonz"
|
||||
},
|
||||
{
|
||||
"id": "sec.patch.os_supported",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "OS build supported: Win11 25H2",
|
||||
"detail": "Build 26200 (Win11 25H2) is in support until 2027-10-12.",
|
||||
"evidence": "Microsoft Windows 11 Pro for Workstations build 26200"
|
||||
},
|
||||
{
|
||||
"id": "sec.patch.pending",
|
||||
"category": "security",
|
||||
"severity": "warning",
|
||||
"title": "6 pending Windows updates",
|
||||
"detail": "Windows Update reports pending (not installed, not hidden) updates. Some may be security updates. Approve/install on the next maintenance window.",
|
||||
"evidence": "Microsoft.Update.Session search IsInstalled=0 and IsHidden=0 -> 6"
|
||||
},
|
||||
{
|
||||
"id": "sec.patch.last_hotfix",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Last hotfix: KB5083769",
|
||||
"detail": "Most recently installed update (from Get-HotFix; reflects CBS/MSU packages, not all cumulative metadata).",
|
||||
"evidence": "KB5083769 installed 2026-04-15T07:00:00Z"
|
||||
},
|
||||
{
|
||||
"id": "sec.exposure.smb1_off",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "SMBv1 disabled",
|
||||
"detail": "SMBv1 server protocol is disabled.",
|
||||
"evidence": "EnableSMB1Protocol=False"
|
||||
},
|
||||
{
|
||||
"id": "sec.exposure.laps_present",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "LAPS detected",
|
||||
"detail": "A LAPS mechanism is present.",
|
||||
"evidence": "Windows LAPS reg key"
|
||||
},
|
||||
{
|
||||
"id": "health.stability.clean",
|
||||
"category": "health",
|
||||
"severity": "info",
|
||||
"title": "No stability events in the last 14 days",
|
||||
"detail": "No unexpected shutdowns, BSODs, or disk errors logged.",
|
||||
"evidence": "Unexpected shutdowns (id 41)=0; Bugchecks/BSOD (id 1001)=0; Disk errors (id 7/51/153)=0"
|
||||
},
|
||||
{
|
||||
"id": "health.reboot_uptime.pending",
|
||||
"category": "health",
|
||||
"severity": "warning",
|
||||
"title": "Reboot pending",
|
||||
"detail": "A reboot is pending. Pending reboots can block patches and leave the system in a half-updated state. Schedule a restart.",
|
||||
"evidence": "PendingFileRenameOperations"
|
||||
},
|
||||
{
|
||||
"id": "health.reboot_uptime.long_uptime",
|
||||
"category": "health",
|
||||
"severity": "warning",
|
||||
"title": "Uptime is 49.8 days",
|
||||
"detail": "Uptime exceeds 30 days. Long uptime usually means pending updates have not been applied (reboots deferred). Schedule maintenance.",
|
||||
"evidence": "LastBootUpTime=2026-04-17 15:07:40Z"
|
||||
},
|
||||
{
|
||||
"id": "health.failed_services.stopped",
|
||||
"category": "health",
|
||||
"severity": "warning",
|
||||
"title": "3 auto-start service(s) not running",
|
||||
"detail": "These services are set to start automatically but are not running. Some may be benign; review for security agents, backup agents, or AV that should be running.",
|
||||
"evidence": "Intel(R) Platform License Manager Service (Intel(R) Platform License Manager Service) = Stopped\nGoogleUpdaterInternalService150.0.7863.0 (Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)) = Stopped\nGoogleUpdaterService150.0.7863.0 (Google Updater Service (GoogleUpdaterService150.0.7863.0)) = Stopped"
|
||||
},
|
||||
{
|
||||
"id": "health.domain.secure_channel_ok",
|
||||
"category": "health",
|
||||
"severity": "info",
|
||||
"title": "Domain secure channel healthy",
|
||||
"detail": "Machine trust relationship with the domain is intact.",
|
||||
"evidence": "Domain=GTS.local"
|
||||
},
|
||||
{
|
||||
"id": "health.time.source",
|
||||
"category": "health",
|
||||
"severity": "info",
|
||||
"title": "Time service source",
|
||||
"detail": "Current Windows Time service source.",
|
||||
"evidence": "Source=GTS-SVR25.GTS.local"
|
||||
},
|
||||
{
|
||||
"id": "health.backup.none",
|
||||
"category": "health",
|
||||
"severity": "info",
|
||||
"title": "No backup agent detected",
|
||||
"detail": "No known backup agent service found. Backup expectation varies by endpoint; confirm whether this machine is supposed to have local/cloud backup and whether server-side or M365 backup covers it.",
|
||||
"evidence": "No matching backup service in Win32_Service"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,274 @@
|
||||
# Onboarding Diagnostic Baseline - GTS-W2
|
||||
|
||||
- **Grade:** AMBER
|
||||
- **Host:** GTS-W2
|
||||
- **Client:** Gonzvar Tax Services (`gonzvar-tax-services`)
|
||||
- **Collected (UTC):** 2026-06-06T18:11:25Z
|
||||
- **Agent ID:** d0c703c1-c9c9-4763-b219-d24442882fb6
|
||||
- **Command ID:** 447f17bd-9c1b-473a-9cd4-a45d90ced9cd
|
||||
- **Findings:** 0 critical / 7 warning / 16 info / 0 unknown
|
||||
|
||||
- **OS:** Microsoft Windows 11 Pro for Workstations (build 26200)
|
||||
|
||||
---
|
||||
|
||||
## WARNING (7)
|
||||
|
||||
### Defender tamper protection is OFF
|
||||
- **Category:** security
|
||||
- **ID:** `sec.defender.tamper_off`
|
||||
- Tamper protection is disabled, so malware or a local admin can silently disable Defender. Enable tamper protection (typically via Intune / Security Center).
|
||||
|
||||
```
|
||||
RealTimeProtectionEnabled=False; AMServiceEnabled=False; AntispywareSignatureAge=0 days; IsTamperProtected=False
|
||||
```
|
||||
|
||||
### Third-party AV present: Bitdefender Endpoint Security Tools Antimalware
|
||||
- **Category:** security
|
||||
- **ID:** `sec.av_products.third_party`
|
||||
- A non-Defender antivirus is registered. Running two real-time AV engines causes conflicts, performance loss, and detection gaps. Confirm the intended AV and ensure only one provides real-time protection.
|
||||
|
||||
```
|
||||
Registered AV: Windows Defender, Bitdefender Endpoint Security Tools Antimalware
|
||||
```
|
||||
|
||||
### OS volume is NOT encrypted with BitLocker
|
||||
- **Category:** security
|
||||
- **ID:** `sec.bitlocker.unencrypted`
|
||||
- The operating system volume is unencrypted. Data is exposed if the disk is removed or the device is lost. Enable BitLocker and escrow the recovery key.
|
||||
|
||||
```
|
||||
Volume=C:; ProtectionStatus=Off; EncryptionPercentage=0; KeyProtectors=
|
||||
```
|
||||
|
||||
### 6 pending Windows updates
|
||||
- **Category:** security
|
||||
- **ID:** `sec.patch.pending`
|
||||
- Windows Update reports pending (not installed, not hidden) updates. Some may be security updates. Approve/install on the next maintenance window.
|
||||
|
||||
```
|
||||
Microsoft.Update.Session search IsInstalled=0 and IsHidden=0 -> 6
|
||||
```
|
||||
|
||||
### Reboot pending
|
||||
- **Category:** health
|
||||
- **ID:** `health.reboot_uptime.pending`
|
||||
- A reboot is pending. Pending reboots can block patches and leave the system in a half-updated state. Schedule a restart.
|
||||
|
||||
```
|
||||
PendingFileRenameOperations
|
||||
```
|
||||
|
||||
### Uptime is 49.8 days
|
||||
- **Category:** health
|
||||
- **ID:** `health.reboot_uptime.long_uptime`
|
||||
- Uptime exceeds 30 days. Long uptime usually means pending updates have not been applied (reboots deferred). Schedule maintenance.
|
||||
|
||||
```
|
||||
LastBootUpTime=2026-04-17 15:07:40Z
|
||||
```
|
||||
|
||||
### 3 auto-start service(s) not running
|
||||
- **Category:** health
|
||||
- **ID:** `health.failed_services.stopped`
|
||||
- These services are set to start automatically but are not running. Some may be benign; review for security agents, backup agents, or AV that should be running.
|
||||
|
||||
```
|
||||
Intel(R) Platform License Manager Service (Intel(R) Platform License Manager Service) = Stopped
|
||||
GoogleUpdaterInternalService150.0.7863.0 (Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)) = Stopped
|
||||
GoogleUpdaterService150.0.7863.0 (Google Updater Service (GoogleUpdaterService150.0.7863.0)) = Stopped
|
||||
```
|
||||
|
||||
|
||||
## INFO (16)
|
||||
|
||||
### Defender real-time protection is OFF (3rd-party AV active)
|
||||
- **Category:** security
|
||||
- **ID:** `sec.defender.rtp_off`
|
||||
- Defender real-time protection is off because a managed/known 3rd-party AV is active. Windows disables Defender real-time protection when another AV registers, so this is expected. Confirm the 3rd-party AV is providing real-time protection.
|
||||
|
||||
```
|
||||
RealTimeProtectionEnabled=False; AMServiceEnabled=False; AntispywareSignatureAge=0 days; IsTamperProtected=False; SecurityCenter2 AntiVirusProduct: Bitdefender Endpoint Security Tools Antimalware (productState=0x41000, RTP on)
|
||||
```
|
||||
|
||||
### Defender antimalware service is not running (3rd-party AV active)
|
||||
- **Category:** security
|
||||
- **ID:** `sec.defender.amservice_off`
|
||||
- The Defender antimalware service is not active because a managed/known 3rd-party AV is registered. Windows stands Defender down when another AV provides protection, so this is expected. Confirm the 3rd-party AV is running.
|
||||
|
||||
```
|
||||
RealTimeProtectionEnabled=False; AMServiceEnabled=False; AntispywareSignatureAge=0 days; IsTamperProtected=False; SecurityCenter2 AntiVirusProduct: Bitdefender Endpoint Security Tools Antimalware (productState=0x41000, RTP on)
|
||||
```
|
||||
|
||||
### No competitor/leftover management agents detected
|
||||
- **Category:** security
|
||||
- **ID:** `sec.foreign_agents.none`
|
||||
- No known competitor RMM or unmanaged remote-access agents found in installed programs or services.
|
||||
|
||||
```
|
||||
Scanned uninstall hives (HKLM + WOW6432Node) and Win32_Service
|
||||
```
|
||||
|
||||
### Expected ACG management tooling present: ScreenConnect / ConnectWise Control
|
||||
- **Category:** security
|
||||
- **ID:** `sec.foreign_agents.acg.screenconnect_connectwise_control`
|
||||
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
|
||||
|
||||
```
|
||||
program: ScreenConnect Client (1912bf3444b41a08) 26.1.24.9579
|
||||
service: ScreenConnect Client (1912bf3444b41a08) (ScreenConnect Client (1912bf3444b41a08)) Running
|
||||
```
|
||||
|
||||
### Expected ACG management tooling present: Splashtop (SOS/Streamer)
|
||||
- **Category:** security
|
||||
- **ID:** `sec.foreign_agents.acg.splashtop_sos_streamer_`
|
||||
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
|
||||
|
||||
```
|
||||
program: Splashtop Streamer 3.8.2.0
|
||||
service: SplashtopRemoteService (Splashtop? Remote Service) Running
|
||||
```
|
||||
|
||||
### Expected ACG management tooling present: Syncro / Kabuto
|
||||
- **Category:** security
|
||||
- **ID:** `sec.foreign_agents.acg.syncro_kabuto`
|
||||
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
|
||||
|
||||
```
|
||||
program: Syncro 1.0.201.18410
|
||||
service: Syncro (Syncro) Running
|
||||
```
|
||||
|
||||
### All firewall profiles enabled
|
||||
- **Category:** security
|
||||
- **ID:** `sec.firewall.ok`
|
||||
- Domain, Private, and Public firewall profiles are all enabled.
|
||||
|
||||
```
|
||||
Private=True; Domain=True; Public=True
|
||||
```
|
||||
|
||||
### Local administrators (5)
|
||||
- **Category:** security
|
||||
- **ID:** `sec.local_admins.list`
|
||||
- Members of the local Administrators group. Review for unexpected or unknown accounts (especially leftover MSP/vendor accounts from a prior provider).
|
||||
|
||||
```
|
||||
GTS\Domain Admins
|
||||
GTS\gonzvar
|
||||
GTS-W2\Administrator
|
||||
GTS-W2\localadmin
|
||||
GTS-W2\pgonz
|
||||
```
|
||||
|
||||
### OS build supported: Win11 25H2
|
||||
- **Category:** security
|
||||
- **ID:** `sec.patch.os_supported`
|
||||
- Build 26200 (Win11 25H2) is in support until 2027-10-12.
|
||||
|
||||
```
|
||||
Microsoft Windows 11 Pro for Workstations build 26200
|
||||
```
|
||||
|
||||
### Last hotfix: KB5083769
|
||||
- **Category:** security
|
||||
- **ID:** `sec.patch.last_hotfix`
|
||||
- Most recently installed update (from Get-HotFix; reflects CBS/MSU packages, not all cumulative metadata).
|
||||
|
||||
```
|
||||
KB5083769 installed 2026-04-15T07:00:00Z
|
||||
```
|
||||
|
||||
### SMBv1 disabled
|
||||
- **Category:** security
|
||||
- **ID:** `sec.exposure.smb1_off`
|
||||
- SMBv1 server protocol is disabled.
|
||||
|
||||
```
|
||||
EnableSMB1Protocol=False
|
||||
```
|
||||
|
||||
### LAPS detected
|
||||
- **Category:** security
|
||||
- **ID:** `sec.exposure.laps_present`
|
||||
- A LAPS mechanism is present.
|
||||
|
||||
```
|
||||
Windows LAPS reg key
|
||||
```
|
||||
|
||||
### No stability events in the last 14 days
|
||||
- **Category:** health
|
||||
- **ID:** `health.stability.clean`
|
||||
- No unexpected shutdowns, BSODs, or disk errors logged.
|
||||
|
||||
```
|
||||
Unexpected shutdowns (id 41)=0; Bugchecks/BSOD (id 1001)=0; Disk errors (id 7/51/153)=0
|
||||
```
|
||||
|
||||
### Domain secure channel healthy
|
||||
- **Category:** health
|
||||
- **ID:** `health.domain.secure_channel_ok`
|
||||
- Machine trust relationship with the domain is intact.
|
||||
|
||||
```
|
||||
Domain=GTS.local
|
||||
```
|
||||
|
||||
### Time service source
|
||||
- **Category:** health
|
||||
- **ID:** `health.time.source`
|
||||
- Current Windows Time service source.
|
||||
|
||||
```
|
||||
Source=GTS-SVR25.GTS.local
|
||||
```
|
||||
|
||||
### No backup agent detected
|
||||
- **Category:** health
|
||||
- **ID:** `health.backup.none`
|
||||
- No known backup agent service found. Backup expectation varies by endpoint; confirm whether this machine is supposed to have local/cloud backup and whether server-side or M365 backup covers it.
|
||||
|
||||
```
|
||||
No matching backup service in Win32_Service
|
||||
```
|
||||
|
||||
|
||||
---
|
||||
|
||||
## Inventory Baseline Summary
|
||||
|
||||
- **Manufacturer / Model:** LENOVO / 90SM006QUS
|
||||
- **Serial:** MJ0JAWPT
|
||||
- **CPU:** 12th Gen Intel(R) Core(TM) i5-12400 (6 cores / 12 logical)
|
||||
- **RAM (GB):** 15.7
|
||||
- **BIOS:** M49KT29A (2024-01-04)
|
||||
- **Chassis is laptop:** false
|
||||
- **TPM present / Secure Boot:** true / true
|
||||
- **Domain joined:** true (GTS.local)
|
||||
- **OS activation licensed:** true
|
||||
- **Uptime (days):** 49.8
|
||||
- **Pending reboot:** true
|
||||
- **Installed software count:** 48
|
||||
- **Scheduled tasks (non-MS, enabled):** 46
|
||||
- **Local administrators:** GTS\Domain Admins, GTS\gonzvar, GTS-W2\Administrator, GTS-W2\localadmin, GTS-W2\pgonz
|
||||
|
||||
### Fixed volumes
|
||||
|
||||
- [SYSTEM] - 0.2 GB free of 0.2 GB (76.9%)
|
||||
- C: - 756.7 GB free of 929.3 GB (81.4%)
|
||||
- [WinRE_DRV] - 1.2 GB free of 2 GB (60.2%)
|
||||
|
||||
### Network adapters
|
||||
|
||||
- Realtek PCIe GbE Family Controller - IP: 192.168.0.146, fe80::826b:1844:b416:d971 - DNS: 192.168.0.2, 192.168.0.5 - DHCP: true
|
||||
|
||||
---
|
||||
|
||||
## Diff vs Prior Baseline
|
||||
|
||||
- No prior baseline found for this host. This is the first baseline.
|
||||
|
||||
---
|
||||
|
||||
_Generated by run-onboarding-diagnostic.sh (GuruRMM onboarding diagnostic, Phase 1). Raw snapshot: `GTS-W2-20260606T181016.json` (immutable)._
|
||||
@@ -0,0 +1,601 @@
|
||||
{
|
||||
"host": "SERVER",
|
||||
"collected_at_utc": "2026-06-06T18:13:19Z",
|
||||
"os": {
|
||||
"caption": "Microsoft Windows Server 2019 Standard",
|
||||
"version": "10.0.17763",
|
||||
"build": "17763",
|
||||
"install_date": "2025-09-26T04:50:29Z",
|
||||
"last_boot_utc": "2026-02-22T00:37:40Z",
|
||||
"architecture": "64-bit"
|
||||
},
|
||||
"facts": {
|
||||
"builtin_admin_enabled": false,
|
||||
"os_eol": {
|
||||
"eol_date": "2020-11-10",
|
||||
"release": "Win10 1809"
|
||||
},
|
||||
"pending_updates": 5,
|
||||
"pending_reboot": true,
|
||||
"uptime_days": 104.8,
|
||||
"acg_managed_tools": [
|
||||
"ScreenConnect / ConnectWise Control",
|
||||
"Splashtop (SOS/Streamer)",
|
||||
"Syncro / Kabuto"
|
||||
],
|
||||
"hardware": {
|
||||
"model": "PowerEdge T440",
|
||||
"manufacturer": "Dell Inc.",
|
||||
"bios_date": "2020-08-31",
|
||||
"cpu_logical": 6,
|
||||
"bios_version": "2.8.2",
|
||||
"cpu_cores": 6,
|
||||
"ram_gb": 7.6,
|
||||
"serial": "5308R53",
|
||||
"cpu": "Intel(R) Xeon(R) Bronze 3204 CPU @ 1.90GHz"
|
||||
},
|
||||
"local_administrators": [
|
||||
"Administrator",
|
||||
"Domain Admins",
|
||||
"Enterprise Admins",
|
||||
"localadmin",
|
||||
"MediaAdmin$",
|
||||
"sysadmin"
|
||||
],
|
||||
"os_build": "17763",
|
||||
"secure_boot": null,
|
||||
"backup_agents": null,
|
||||
"autoruns_run_keys": [
|
||||
{
|
||||
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
|
||||
"name": "SecurityHealth",
|
||||
"value": "C:\\WINDOWS\\system32\\SecurityHealthSystray.exe"
|
||||
}
|
||||
],
|
||||
"physical_disks": [
|
||||
{
|
||||
"health": "Healthy",
|
||||
"model": "ST1000NM004A-2MN130",
|
||||
"media_type": "HDD"
|
||||
}
|
||||
],
|
||||
"local_users": [
|
||||
{
|
||||
"last_logon": "2020-10-25",
|
||||
"name": "Administrator",
|
||||
"password_never_expires": false,
|
||||
"enabled": false
|
||||
},
|
||||
{
|
||||
"last_logon": "",
|
||||
"name": "Guest",
|
||||
"password_never_expires": false,
|
||||
"enabled": false
|
||||
},
|
||||
{
|
||||
"last_logon": "",
|
||||
"name": "krbtgt",
|
||||
"password_never_expires": false,
|
||||
"enabled": false
|
||||
},
|
||||
{
|
||||
"last_logon": "",
|
||||
"name": "DefaultAccount",
|
||||
"password_never_expires": false,
|
||||
"enabled": false
|
||||
},
|
||||
{
|
||||
"last_logon": "2025-09-26",
|
||||
"name": "localadmin",
|
||||
"password_never_expires": false,
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"last_logon": "2026-01-07",
|
||||
"name": "sysadmin",
|
||||
"password_never_expires": false,
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"last_logon": "2026-06-06",
|
||||
"name": "pedro",
|
||||
"password_never_expires": false,
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"last_logon": "2026-06-05",
|
||||
"name": "gonzvar",
|
||||
"password_never_expires": false,
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"last_logon": "2026-06-06",
|
||||
"name": "SERVER$",
|
||||
"password_never_expires": false,
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"last_logon": "2025-09-24",
|
||||
"name": "MediaAdmin$",
|
||||
"password_never_expires": false,
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"last_logon": "2026-06-06",
|
||||
"name": "GTS-W1$",
|
||||
"password_never_expires": false,
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"last_logon": "2026-06-05",
|
||||
"name": "GTS-W2$",
|
||||
"password_never_expires": false,
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"last_logon": "2026-06-06",
|
||||
"name": "GTS-W0$",
|
||||
"password_never_expires": false,
|
||||
"enabled": true
|
||||
}
|
||||
],
|
||||
"scheduled_tasks_count": 3,
|
||||
"volumes": [
|
||||
{
|
||||
"drive": "[System Reserved]",
|
||||
"size_gb": 0.5,
|
||||
"free_pct": 93,
|
||||
"free_gb": 0.5
|
||||
},
|
||||
{
|
||||
"drive": "C:",
|
||||
"size_gb": 930.2,
|
||||
"free_pct": 80.7,
|
||||
"free_gb": 750.9
|
||||
},
|
||||
{
|
||||
"drive": "[unlabeled]",
|
||||
"size_gb": 0.8,
|
||||
"free_pct": 42.6,
|
||||
"free_gb": 0.3
|
||||
}
|
||||
],
|
||||
"network_adapters": [
|
||||
{
|
||||
"dhcp": false,
|
||||
"description": "Broadcom NetXtreme Gigabit Ethernet #2",
|
||||
"gateway": [
|
||||
"192.168.0.1"
|
||||
],
|
||||
"mac": "2C:EA:7F:57:98:E8",
|
||||
"ip": [
|
||||
"192.168.0.5",
|
||||
"fe80::bd6f:321c:c1d5:2f3c"
|
||||
],
|
||||
"dns": [
|
||||
"192.168.0.5",
|
||||
"192.168.0.2"
|
||||
]
|
||||
}
|
||||
],
|
||||
"failed_autostart_services": [
|
||||
{
|
||||
"name": "GoogleUpdaterInternalService150.0.7863.0",
|
||||
"display": "Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)",
|
||||
"state": "Stopped"
|
||||
},
|
||||
{
|
||||
"name": "GoogleUpdaterService150.0.7863.0",
|
||||
"display": "Google Updater Service (GoogleUpdaterService150.0.7863.0)",
|
||||
"state": "Stopped"
|
||||
}
|
||||
],
|
||||
"stability_14d": {
|
||||
"unexpected_shutdowns": 0,
|
||||
"disk_errors": 0,
|
||||
"bugchecks": 0
|
||||
},
|
||||
"exposure": {
|
||||
"smb1_enabled": true,
|
||||
"laps_present": false,
|
||||
"rdp_enabled": true,
|
||||
"uac_enabled": true,
|
||||
"rdp_nla": true
|
||||
},
|
||||
"accounts_password_never_expires": [],
|
||||
"installed_software": [
|
||||
{
|
||||
"publisher": "Webprofusion Pty Ltd",
|
||||
"name": "Certify Certificate Manager version 6.1.9",
|
||||
"version": "6.1.9"
|
||||
},
|
||||
{
|
||||
"publisher": "Dell Inc.",
|
||||
"name": "Dell EMC OpenManage Systems Management Software (64-Bit)",
|
||||
"version": "10.3.0.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Drake Software",
|
||||
"name": "Drake Accounting 2025",
|
||||
"version": "25.0.45"
|
||||
},
|
||||
{
|
||||
"publisher": "Google LLC",
|
||||
"name": "Google Chrome",
|
||||
"version": "148.0.7778.217"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Host - 6.0.7 (x86)",
|
||||
"version": "48.31.44002"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Host - 8.0.11 (x64)",
|
||||
"version": "64.44.23191"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Host - 8.0.20 (x86)",
|
||||
"version": "64.80.39230"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Host FX Resolver - 6.0.7 (x86)",
|
||||
"version": "48.31.44002"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Host FX Resolver - 8.0.11 (x64)",
|
||||
"version": "64.44.23191"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Host FX Resolver - 8.0.20 (x86)",
|
||||
"version": "64.80.39230"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Runtime - 6.0.7 (x86)",
|
||||
"version": "48.31.44002"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Runtime - 8.0.11 (x64)",
|
||||
"version": "64.44.23191"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft .NET Runtime - 8.0.20 (x86)",
|
||||
"version": "64.80.39230"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft ASP.NET Core 8.0.0 - Shared Framework (x86)",
|
||||
"version": "8.0.0.23531"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft ASP.NET Core 8.0.0 Shared Framework (x86)",
|
||||
"version": "8.0.0.23531"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft SQL Server Compact 4.0 SP1 x64 ENU",
|
||||
"version": "4.0.8876.1"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.28.29914",
|
||||
"version": "14.28.29914.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2019 X86 Additional Runtime - 14.28.29914",
|
||||
"version": "14.28.29914"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.28.29914",
|
||||
"version": "14.28.29914"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Windows Desktop Runtime - 6.0.7 (x86)",
|
||||
"version": "48.31.44003"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Windows Desktop Runtime - 6.0.7 (x86)",
|
||||
"version": "6.0.7.31422"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Windows Desktop Runtime - 8.0.11 (x64)",
|
||||
"version": "64.44.23253"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Windows Desktop Runtime - 8.0.11 (x64)",
|
||||
"version": "8.0.11.34221"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Windows Desktop Runtime - 8.0.20 (x86)",
|
||||
"version": "64.80.39251"
|
||||
},
|
||||
{
|
||||
"publisher": "Microsoft Corporation",
|
||||
"name": "Microsoft Windows Desktop Runtime - 8.0.20 (x86)",
|
||||
"version": "8.0.20.35221"
|
||||
},
|
||||
{
|
||||
"publisher": "ScreenConnect Software",
|
||||
"name": "ScreenConnect Client (1912bf3444b41a08)",
|
||||
"version": "26.1.24.9579"
|
||||
},
|
||||
{
|
||||
"publisher": "Splashtop Inc.",
|
||||
"name": "Splashtop Software Updater",
|
||||
"version": "1.5.6.23"
|
||||
},
|
||||
{
|
||||
"publisher": "Splashtop Inc.",
|
||||
"name": "Splashtop Streamer",
|
||||
"version": "3.8.2.0"
|
||||
},
|
||||
{
|
||||
"publisher": "Servably, Inc.",
|
||||
"name": "Syncro",
|
||||
"version": "1.0.201.18410"
|
||||
},
|
||||
{
|
||||
"publisher": "win.rar GmbH",
|
||||
"name": "WinRAR 7.13 (64-bit)",
|
||||
"version": "7.13.0"
|
||||
}
|
||||
],
|
||||
"tpm": {
|
||||
"enabled": false,
|
||||
"ready": false,
|
||||
"present": false
|
||||
},
|
||||
"local_groups": [
|
||||
"Cert Publishers",
|
||||
"RAS and IAS Servers",
|
||||
"Allowed RODC Password Replication Group",
|
||||
"Denied RODC Password Replication Group"
|
||||
],
|
||||
"battery": {
|
||||
"present": false
|
||||
},
|
||||
"activation": {
|
||||
"edition": "Microsoft Windows Server 2019 Standard",
|
||||
"description": "Windows(R) Operating System, VOLUME_KMSCLIENT channel",
|
||||
"licensed": false,
|
||||
"license_status_code": 5
|
||||
},
|
||||
"time_source": "Free-running System Clock",
|
||||
"chassis_types": [
|
||||
17
|
||||
],
|
||||
"last_hotfix": {
|
||||
"hotfix_id": "KB5070248",
|
||||
"installed_on": "2026-01-17T08:00:00Z"
|
||||
},
|
||||
"scheduled_tasks": [
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "Dell SupportAssistAgent AutoUpdate",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\",
|
||||
"name": "ShadowCopyVolume{5f67aa97-0000-0000-0000-501f00000000}",
|
||||
"state": "Ready"
|
||||
},
|
||||
{
|
||||
"path": "\\GoogleSystem\\GoogleUpdater\\",
|
||||
"name": "GoogleUpdaterTaskSystem150.0.7863.0{2E905B25-4378-464B-9268-EAB95C26A418}",
|
||||
"state": "Ready"
|
||||
}
|
||||
],
|
||||
"antivirus_products": [],
|
||||
"domain_joined": true,
|
||||
"defender": {
|
||||
"available": false
|
||||
},
|
||||
"bitlocker": {
|
||||
"available": false,
|
||||
"os_volume": "C:"
|
||||
},
|
||||
"is_laptop": false,
|
||||
"installed_software_count": 30,
|
||||
"secure_channel_ok": true,
|
||||
"firewall_profiles": {
|
||||
"Private": false,
|
||||
"Domain": false,
|
||||
"Public": false
|
||||
},
|
||||
"domain": "GTS.local",
|
||||
"foreign_agents": null
|
||||
},
|
||||
"findings": [
|
||||
{
|
||||
"id": "sec.defender.unavailable",
|
||||
"category": "security",
|
||||
"severity": "warning",
|
||||
"title": "Defender status unavailable",
|
||||
"detail": "Get-MpComputerStatus returned nothing. Defender may be disabled, replaced by a 3rd-party AV, or the cmdlet is unavailable. Confirm an active AV exists (see security-center check).",
|
||||
"evidence": "Get-MpComputerStatus returned null"
|
||||
},
|
||||
{
|
||||
"id": "sec.av_products.none_registered",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "No AV products registered in Security Center",
|
||||
"detail": "SecurityCenter2 returned no AntiVirusProduct entries. This is normal on Windows Server SKUs (Security Center is a client feature). On a workstation, confirm Defender or a managed AV is active.",
|
||||
"evidence": "root\\SecurityCenter2 AntiVirusProduct: none"
|
||||
},
|
||||
{
|
||||
"id": "sec.foreign_agents.none",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "No competitor/leftover management agents detected",
|
||||
"detail": "No known competitor RMM or unmanaged remote-access agents found in installed programs or services.",
|
||||
"evidence": "Scanned uninstall hives (HKLM + WOW6432Node) and Win32_Service"
|
||||
},
|
||||
{
|
||||
"id": "sec.foreign_agents.acg.screenconnect_connectwise_control",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Expected ACG management tooling present: ScreenConnect / ConnectWise Control",
|
||||
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
|
||||
"evidence": "program: ScreenConnect Client (1912bf3444b41a08) 26.1.24.9579\nservice: ScreenConnect Client (1912bf3444b41a08) (ScreenConnect Client (1912bf3444b41a08)) Running"
|
||||
},
|
||||
{
|
||||
"id": "sec.foreign_agents.acg.splashtop_sos_streamer_",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Expected ACG management tooling present: Splashtop (SOS/Streamer)",
|
||||
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
|
||||
"evidence": "program: Splashtop Software Updater 1.5.6.23\nprogram: Splashtop Streamer 3.8.2.0\nservice: SplashtopRemoteService (Splashtop? Remote Service) Running\nservice: SSUService (Splashtop Software Updater Service) Running"
|
||||
},
|
||||
{
|
||||
"id": "sec.foreign_agents.acg.syncro_kabuto",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Expected ACG management tooling present: Syncro / Kabuto",
|
||||
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
|
||||
"evidence": "program: Syncro 1.0.201.18410\nservice: Syncro (Syncro) Running"
|
||||
},
|
||||
{
|
||||
"id": "sec.firewall.disabled",
|
||||
"category": "security",
|
||||
"severity": "critical",
|
||||
"title": "Firewall disabled on profile(s): Domain, Private, Public",
|
||||
"detail": "One or more firewall profiles are OFF. The endpoint is exposed to lateral movement and inbound attacks on those networks. Re-enable all profiles.",
|
||||
"evidence": "Profile states: Private=False; Domain=False; Public=False"
|
||||
},
|
||||
{
|
||||
"id": "sec.bitlocker.unavailable",
|
||||
"category": "security",
|
||||
"severity": "unknown",
|
||||
"title": "BitLocker status unavailable",
|
||||
"detail": "Get-BitLockerVolume failed for the OS volume. BitLocker may not be installed (Home edition) or the cmdlet is unavailable. Verify encryption manually (manage-bde -status).",
|
||||
"evidence": "MountPoint=C:, Get-BitLockerVolume returned null"
|
||||
},
|
||||
{
|
||||
"id": "sec.local_admins.list",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Local administrators (6)",
|
||||
"detail": "Members of the local Administrators group. Review for unexpected or unknown accounts (especially leftover MSP/vendor accounts from a prior provider).",
|
||||
"evidence": "Administrator\nDomain Admins\nEnterprise Admins\nlocaladmin\nMediaAdmin$\nsysadmin"
|
||||
},
|
||||
{
|
||||
"id": "sec.patch.os_eol",
|
||||
"category": "security",
|
||||
"severity": "critical",
|
||||
"title": "OS build is end-of-life: Win10 1809",
|
||||
"detail": "This OS build (17763, Win10 1809) passed end-of-servicing on 2020-11-10. It no longer receives security updates. Plan a feature update or OS upgrade.",
|
||||
"evidence": "Microsoft Windows Server 2019 Standard build 17763; EOL 2020-11-10"
|
||||
},
|
||||
{
|
||||
"id": "sec.patch.pending",
|
||||
"category": "security",
|
||||
"severity": "warning",
|
||||
"title": "5 pending Windows updates",
|
||||
"detail": "Windows Update reports pending (not installed, not hidden) updates. Some may be security updates. Approve/install on the next maintenance window.",
|
||||
"evidence": "Microsoft.Update.Session search IsInstalled=0 and IsHidden=0 -> 5"
|
||||
},
|
||||
{
|
||||
"id": "sec.patch.last_hotfix",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "Last hotfix: KB5070248",
|
||||
"detail": "Most recently installed update (from Get-HotFix; reflects CBS/MSU packages, not all cumulative metadata).",
|
||||
"evidence": "KB5070248 installed 2026-01-17T08:00:00Z"
|
||||
},
|
||||
{
|
||||
"id": "sec.exposure.rdp_on",
|
||||
"category": "security",
|
||||
"severity": "warning",
|
||||
"title": "RDP is enabled",
|
||||
"detail": "Remote Desktop is enabled (NLA required). Confirm it is restricted to VPN or specific source IPs and not exposed to the internet.",
|
||||
"evidence": "fDenyTSConnections=0; UserAuthentication=1"
|
||||
},
|
||||
{
|
||||
"id": "sec.exposure.smb1",
|
||||
"category": "security",
|
||||
"severity": "critical",
|
||||
"title": "SMBv1 is ENABLED",
|
||||
"detail": "SMBv1 is an obsolete, insecure protocol (WannaCry/EternalBlue vector). Disable it: Set-SmbServerConfiguration -EnableSMB1Protocol $false and remove the SMB1 feature.",
|
||||
"evidence": "Get-SmbServerConfiguration EnableSMB1Protocol=True"
|
||||
},
|
||||
{
|
||||
"id": "sec.exposure.no_laps",
|
||||
"category": "security",
|
||||
"severity": "info",
|
||||
"title": "LAPS not detected",
|
||||
"detail": "No LAPS (Windows LAPS or legacy AdmPwd) detected. Without LAPS, the local admin password is likely static/shared across the fleet. Consider deploying LAPS to randomize and escrow local admin passwords.",
|
||||
"evidence": "No LAPS registry keys, CSE, or service found"
|
||||
},
|
||||
{
|
||||
"id": "health.stability.clean",
|
||||
"category": "health",
|
||||
"severity": "info",
|
||||
"title": "No stability events in the last 14 days",
|
||||
"detail": "No unexpected shutdowns, BSODs, or disk errors logged.",
|
||||
"evidence": "Unexpected shutdowns (id 41)=0; Bugchecks/BSOD (id 1001)=0; Disk errors (id 7/51/153)=0"
|
||||
},
|
||||
{
|
||||
"id": "health.reboot_uptime.pending",
|
||||
"category": "health",
|
||||
"severity": "warning",
|
||||
"title": "Reboot pending",
|
||||
"detail": "A reboot is pending. Pending reboots can block patches and leave the system in a half-updated state. Schedule a restart.",
|
||||
"evidence": "PendingFileRenameOperations"
|
||||
},
|
||||
{
|
||||
"id": "health.reboot_uptime.long_uptime",
|
||||
"category": "health",
|
||||
"severity": "warning",
|
||||
"title": "Uptime is 104.8 days",
|
||||
"detail": "Uptime exceeds 30 days. Long uptime usually means pending updates have not been applied (reboots deferred). Schedule maintenance.",
|
||||
"evidence": "LastBootUpTime=2026-02-21 16:37:40Z"
|
||||
},
|
||||
{
|
||||
"id": "health.failed_services.stopped",
|
||||
"category": "health",
|
||||
"severity": "warning",
|
||||
"title": "2 auto-start service(s) not running",
|
||||
"detail": "These services are set to start automatically but are not running. Some may be benign; review for security agents, backup agents, or AV that should be running.",
|
||||
"evidence": "GoogleUpdaterInternalService150.0.7863.0 (Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)) = Stopped\nGoogleUpdaterService150.0.7863.0 (Google Updater Service (GoogleUpdaterService150.0.7863.0)) = Stopped"
|
||||
},
|
||||
{
|
||||
"id": "health.domain.secure_channel_ok",
|
||||
"category": "health",
|
||||
"severity": "info",
|
||||
"title": "Domain secure channel healthy",
|
||||
"detail": "Machine trust relationship with the domain is intact.",
|
||||
"evidence": "Domain=GTS.local"
|
||||
},
|
||||
{
|
||||
"id": "health.time.source",
|
||||
"category": "health",
|
||||
"severity": "info",
|
||||
"title": "Time service source",
|
||||
"detail": "Current Windows Time service source.",
|
||||
"evidence": "Source=Free-running System Clock"
|
||||
},
|
||||
{
|
||||
"id": "health.backup.none",
|
||||
"category": "health",
|
||||
"severity": "info",
|
||||
"title": "No backup agent detected",
|
||||
"detail": "No known backup agent service found. Backup expectation varies by endpoint; confirm whether this machine is supposed to have local/cloud backup and whether server-side or M365 backup covers it.",
|
||||
"evidence": "No matching backup service in Win32_Service"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,273 @@
|
||||
# Onboarding Diagnostic Baseline - SERVER
|
||||
|
||||
- **Grade:** RED
|
||||
- **Host:** SERVER
|
||||
- **Client:** Gonzvar Tax Services (`gonzvar-tax-services`)
|
||||
- **Collected (UTC):** 2026-06-06T18:13:19Z
|
||||
- **Agent ID:** 9fe137ba-6164-4b7a-8a9d-4e8c4b9e40a5
|
||||
- **Command ID:** d91f435d-b67c-43e4-a872-adb82dd07157
|
||||
- **Findings:** 3 critical / 6 warning / 12 info / 1 unknown
|
||||
|
||||
- **OS:** Microsoft Windows Server 2019 Standard (build 17763)
|
||||
|
||||
---
|
||||
|
||||
## CRITICAL (3)
|
||||
|
||||
### Firewall disabled on profile(s): Domain, Private, Public
|
||||
- **Category:** security
|
||||
- **ID:** `sec.firewall.disabled`
|
||||
- One or more firewall profiles are OFF. The endpoint is exposed to lateral movement and inbound attacks on those networks. Re-enable all profiles.
|
||||
|
||||
```
|
||||
Profile states: Private=False; Domain=False; Public=False
|
||||
```
|
||||
|
||||
### OS build is end-of-life: Win10 1809
|
||||
- **Category:** security
|
||||
- **ID:** `sec.patch.os_eol`
|
||||
- This OS build (17763, Win10 1809) passed end-of-servicing on 2020-11-10. It no longer receives security updates. Plan a feature update or OS upgrade.
|
||||
|
||||
```
|
||||
Microsoft Windows Server 2019 Standard build 17763; EOL 2020-11-10
|
||||
```
|
||||
|
||||
### SMBv1 is ENABLED
|
||||
- **Category:** security
|
||||
- **ID:** `sec.exposure.smb1`
|
||||
- SMBv1 is an obsolete, insecure protocol (WannaCry/EternalBlue vector). Disable it: Set-SmbServerConfiguration -EnableSMB1Protocol $false and remove the SMB1 feature.
|
||||
|
||||
```
|
||||
Get-SmbServerConfiguration EnableSMB1Protocol=True
|
||||
```
|
||||
|
||||
|
||||
## WARNING (6)
|
||||
|
||||
### Defender status unavailable
|
||||
- **Category:** security
|
||||
- **ID:** `sec.defender.unavailable`
|
||||
- Get-MpComputerStatus returned nothing. Defender may be disabled, replaced by a 3rd-party AV, or the cmdlet is unavailable. Confirm an active AV exists (see security-center check).
|
||||
|
||||
```
|
||||
Get-MpComputerStatus returned null
|
||||
```
|
||||
|
||||
### 5 pending Windows updates
|
||||
- **Category:** security
|
||||
- **ID:** `sec.patch.pending`
|
||||
- Windows Update reports pending (not installed, not hidden) updates. Some may be security updates. Approve/install on the next maintenance window.
|
||||
|
||||
```
|
||||
Microsoft.Update.Session search IsInstalled=0 and IsHidden=0 -> 5
|
||||
```
|
||||
|
||||
### RDP is enabled
|
||||
- **Category:** security
|
||||
- **ID:** `sec.exposure.rdp_on`
|
||||
- Remote Desktop is enabled (NLA required). Confirm it is restricted to VPN or specific source IPs and not exposed to the internet.
|
||||
|
||||
```
|
||||
fDenyTSConnections=0; UserAuthentication=1
|
||||
```
|
||||
|
||||
### Reboot pending
|
||||
- **Category:** health
|
||||
- **ID:** `health.reboot_uptime.pending`
|
||||
- A reboot is pending. Pending reboots can block patches and leave the system in a half-updated state. Schedule a restart.
|
||||
|
||||
```
|
||||
PendingFileRenameOperations
|
||||
```
|
||||
|
||||
### Uptime is 104.8 days
|
||||
- **Category:** health
|
||||
- **ID:** `health.reboot_uptime.long_uptime`
|
||||
- Uptime exceeds 30 days. Long uptime usually means pending updates have not been applied (reboots deferred). Schedule maintenance.
|
||||
|
||||
```
|
||||
LastBootUpTime=2026-02-21 16:37:40Z
|
||||
```
|
||||
|
||||
### 2 auto-start service(s) not running
|
||||
- **Category:** health
|
||||
- **ID:** `health.failed_services.stopped`
|
||||
- These services are set to start automatically but are not running. Some may be benign; review for security agents, backup agents, or AV that should be running.
|
||||
|
||||
```
|
||||
GoogleUpdaterInternalService150.0.7863.0 (Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)) = Stopped
|
||||
GoogleUpdaterService150.0.7863.0 (Google Updater Service (GoogleUpdaterService150.0.7863.0)) = Stopped
|
||||
```
|
||||
|
||||
|
||||
## INFO (12)
|
||||
|
||||
### No AV products registered in Security Center
|
||||
- **Category:** security
|
||||
- **ID:** `sec.av_products.none_registered`
|
||||
- SecurityCenter2 returned no AntiVirusProduct entries. This is normal on Windows Server SKUs (Security Center is a client feature). On a workstation, confirm Defender or a managed AV is active.
|
||||
|
||||
```
|
||||
root\SecurityCenter2 AntiVirusProduct: none
|
||||
```
|
||||
|
||||
### No competitor/leftover management agents detected
|
||||
- **Category:** security
|
||||
- **ID:** `sec.foreign_agents.none`
|
||||
- No known competitor RMM or unmanaged remote-access agents found in installed programs or services.
|
||||
|
||||
```
|
||||
Scanned uninstall hives (HKLM + WOW6432Node) and Win32_Service
|
||||
```
|
||||
|
||||
### Expected ACG management tooling present: ScreenConnect / ConnectWise Control
|
||||
- **Category:** security
|
||||
- **ID:** `sec.foreign_agents.acg.screenconnect_connectwise_control`
|
||||
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
|
||||
|
||||
```
|
||||
program: ScreenConnect Client (1912bf3444b41a08) 26.1.24.9579
|
||||
service: ScreenConnect Client (1912bf3444b41a08) (ScreenConnect Client (1912bf3444b41a08)) Running
|
||||
```
|
||||
|
||||
### Expected ACG management tooling present: Splashtop (SOS/Streamer)
|
||||
- **Category:** security
|
||||
- **ID:** `sec.foreign_agents.acg.splashtop_sos_streamer_`
|
||||
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
|
||||
|
||||
```
|
||||
program: Splashtop Software Updater 1.5.6.23
|
||||
program: Splashtop Streamer 3.8.2.0
|
||||
service: SplashtopRemoteService (Splashtop? Remote Service) Running
|
||||
service: SSUService (Splashtop Software Updater Service) Running
|
||||
```
|
||||
|
||||
### Expected ACG management tooling present: Syncro / Kabuto
|
||||
- **Category:** security
|
||||
- **ID:** `sec.foreign_agents.acg.syncro_kabuto`
|
||||
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
|
||||
|
||||
```
|
||||
program: Syncro 1.0.201.18410
|
||||
service: Syncro (Syncro) Running
|
||||
```
|
||||
|
||||
### Local administrators (6)
|
||||
- **Category:** security
|
||||
- **ID:** `sec.local_admins.list`
|
||||
- Members of the local Administrators group. Review for unexpected or unknown accounts (especially leftover MSP/vendor accounts from a prior provider).
|
||||
|
||||
```
|
||||
Administrator
|
||||
Domain Admins
|
||||
Enterprise Admins
|
||||
localadmin
|
||||
MediaAdmin$
|
||||
sysadmin
|
||||
```
|
||||
|
||||
### Last hotfix: KB5070248
|
||||
- **Category:** security
|
||||
- **ID:** `sec.patch.last_hotfix`
|
||||
- Most recently installed update (from Get-HotFix; reflects CBS/MSU packages, not all cumulative metadata).
|
||||
|
||||
```
|
||||
KB5070248 installed 2026-01-17T08:00:00Z
|
||||
```
|
||||
|
||||
### LAPS not detected
|
||||
- **Category:** security
|
||||
- **ID:** `sec.exposure.no_laps`
|
||||
- No LAPS (Windows LAPS or legacy AdmPwd) detected. Without LAPS, the local admin password is likely static/shared across the fleet. Consider deploying LAPS to randomize and escrow local admin passwords.
|
||||
|
||||
```
|
||||
No LAPS registry keys, CSE, or service found
|
||||
```
|
||||
|
||||
### No stability events in the last 14 days
|
||||
- **Category:** health
|
||||
- **ID:** `health.stability.clean`
|
||||
- No unexpected shutdowns, BSODs, or disk errors logged.
|
||||
|
||||
```
|
||||
Unexpected shutdowns (id 41)=0; Bugchecks/BSOD (id 1001)=0; Disk errors (id 7/51/153)=0
|
||||
```
|
||||
|
||||
### Domain secure channel healthy
|
||||
- **Category:** health
|
||||
- **ID:** `health.domain.secure_channel_ok`
|
||||
- Machine trust relationship with the domain is intact.
|
||||
|
||||
```
|
||||
Domain=GTS.local
|
||||
```
|
||||
|
||||
### Time service source
|
||||
- **Category:** health
|
||||
- **ID:** `health.time.source`
|
||||
- Current Windows Time service source.
|
||||
|
||||
```
|
||||
Source=Free-running System Clock
|
||||
```
|
||||
|
||||
### No backup agent detected
|
||||
- **Category:** health
|
||||
- **ID:** `health.backup.none`
|
||||
- No known backup agent service found. Backup expectation varies by endpoint; confirm whether this machine is supposed to have local/cloud backup and whether server-side or M365 backup covers it.
|
||||
|
||||
```
|
||||
No matching backup service in Win32_Service
|
||||
```
|
||||
|
||||
|
||||
## UNKNOWN (1)
|
||||
|
||||
### BitLocker status unavailable
|
||||
- **Category:** security
|
||||
- **ID:** `sec.bitlocker.unavailable`
|
||||
- Get-BitLockerVolume failed for the OS volume. BitLocker may not be installed (Home edition) or the cmdlet is unavailable. Verify encryption manually (manage-bde -status).
|
||||
|
||||
```
|
||||
MountPoint=C:, Get-BitLockerVolume returned null
|
||||
```
|
||||
|
||||
|
||||
---
|
||||
|
||||
## Inventory Baseline Summary
|
||||
|
||||
- **Manufacturer / Model:** Dell Inc. / PowerEdge T440
|
||||
- **Serial:** 5308R53
|
||||
- **CPU:** Intel(R) Xeon(R) Bronze 3204 CPU @ 1.90GHz (6 cores / 6 logical)
|
||||
- **RAM (GB):** 7.6
|
||||
- **BIOS:** 2.8.2 (2020-08-31)
|
||||
- **Chassis is laptop:** false
|
||||
- **TPM present / Secure Boot:** ? / ?
|
||||
- **Domain joined:** true (GTS.local)
|
||||
- **OS activation licensed:** ?
|
||||
- **Uptime (days):** 104.8
|
||||
- **Pending reboot:** true
|
||||
- **Installed software count:** 30
|
||||
- **Scheduled tasks (non-MS, enabled):** 3
|
||||
- **Local administrators:** Administrator, Domain Admins, Enterprise Admins, localadmin, MediaAdmin$, sysadmin
|
||||
|
||||
### Fixed volumes
|
||||
|
||||
- [System Reserved] - 0.5 GB free of 0.5 GB (93%)
|
||||
- C: - 750.9 GB free of 930.2 GB (80.7%)
|
||||
- [unlabeled] - 0.3 GB free of 0.8 GB (42.6%)
|
||||
|
||||
### Network adapters
|
||||
|
||||
- Broadcom NetXtreme Gigabit Ethernet #2 - IP: 192.168.0.5, fe80::bd6f:321c:c1d5:2f3c - DNS: 192.168.0.5, 192.168.0.2 - DHCP: false
|
||||
|
||||
---
|
||||
|
||||
## Diff vs Prior Baseline
|
||||
|
||||
- No prior baseline found for this host. This is the first baseline.
|
||||
|
||||
---
|
||||
|
||||
_Generated by run-onboarding-diagnostic.sh (GuruRMM onboarding diagnostic, Phase 1). Raw snapshot: `SERVER-20260606T181304.json` (immutable)._
|
||||
Reference in New Issue
Block a user