sync: auto-sync from Mikes-MacBook-Air.local at 2026-06-06 11:32:15
Author: Mike Swanson Machine: Mikes-MacBook-Air.local Timestamp: 2026-06-06 11:32:15
This commit is contained in:
283
clients/gonzvar-tax-services/DIAGNOSTIC-SUMMARY-2026-06-06.md
Normal file
283
clients/gonzvar-tax-services/DIAGNOSTIC-SUMMARY-2026-06-06.md
Normal file
@@ -0,0 +1,283 @@
|
||||
# Gonzvar Tax Services - Onboarding Diagnostic Summary
|
||||
|
||||
**Date:** 2026-06-06
|
||||
**Diagnostics Run:** All 6 enrolled machines
|
||||
**Client:** Gonzvar Tax Services
|
||||
**Project Key:** gonzvar
|
||||
|
||||
---
|
||||
|
||||
## IMPORTANT CORRECTION (2026-06-06)
|
||||
|
||||
**Diagnostic Probe Bug Discovered:** Initial diagnostics reported "9 disk errors" on GTS-W0, triggering a CRITICAL finding for failing drive. **This was a FALSE POSITIVE.**
|
||||
|
||||
- The "disk errors" are actually benign VBS (Virtualization-Based Security) boot messages
|
||||
- Event ID 153 from "Microsoft-Windows-Kernel-Boot" (not disk errors)
|
||||
- Drive health verified as HEALTHY via direct query
|
||||
- **NO drive replacement needed**
|
||||
- Probe script needs update to filter Event ID 153 by source
|
||||
- This bug likely affects all Windows 11 machines with VBS enabled
|
||||
- See `GTS-W0-DISK-ANALYSIS.md` for full investigation
|
||||
|
||||
**Revised GTS-W0 Status:** Still RED due to firewall/RDP issues, but drive is healthy.
|
||||
|
||||
---
|
||||
|
||||
## Executive Summary
|
||||
|
||||
Complete security and health diagnostics performed on all 6 Gonzvar machines (3 workstations, 1 personal workstation, 2 servers). **3 machines received RED grades** requiring immediate attention, **3 machines received AMBER grades** requiring scheduled maintenance.
|
||||
|
||||
**Critical Findings Across Fleet:**
|
||||
- **Firewall disabled** on multiple machines (all profiles OFF)
|
||||
- **RDP without NLA** on multiple machines (pre-auth vulnerability)
|
||||
- **Failing hard drive** on GTS-W0 (9 disk errors in 14 days)
|
||||
- **Multiple pending updates** across all machines
|
||||
- **BitLocker not enabled** on several machines
|
||||
|
||||
---
|
||||
|
||||
## Machine-by-Machine Results
|
||||
|
||||
### 1. GTS-W0 (Workstation) - **RED**
|
||||
|
||||
**Grade:** RED
|
||||
**Findings:** 3 critical / 4 warning / 14 info
|
||||
**OS:** Windows 11 Pro for Workstations (build 26200)
|
||||
**Baseline:** `GTS-W0-20260606T180736.md`
|
||||
|
||||
**CRITICAL Issues:**
|
||||
1. **All firewalls disabled** (Domain, Private, Public)
|
||||
- Exposes machine to lateral movement and inbound attacks
|
||||
- Action: Re-enable all firewall profiles immediately
|
||||
|
||||
2. **RDP enabled WITHOUT Network Level Authentication**
|
||||
- Vulnerable to pre-auth exploits and brute force
|
||||
- Action: Enable NLA or disable RDP; restrict to VPN/allow-listed IPs
|
||||
|
||||
3. ~~**Recurring stability events - 9 DISK ERRORS in 14 days**~~ **FALSE POSITIVE - CORRECTED**
|
||||
- **ANALYSIS UPDATE 2026-06-06:** The "9 disk errors" are NOT disk errors
|
||||
- All 9 events are Event ID 153 from "Microsoft-Windows-Kernel-Boot" (VBS enabled messages)
|
||||
- These are informational boot logs, not hardware failures
|
||||
- **Drive is HEALTHY** - Kingston NVMe confirmed OK via direct query
|
||||
- Diagnostic probe bug: Event ID 153 query needs source filtering
|
||||
- See `GTS-W0-DISK-ANALYSIS.md` for full investigation
|
||||
- **NO DRIVE REPLACEMENT NEEDED**
|
||||
- Actual stability concern: 2 unexpected shutdowns (Event ID 41) - investigate separately
|
||||
|
||||
**WARNING Issues:**
|
||||
- BitLocker not enabled (OS volume unencrypted)
|
||||
- 1 pending Windows update
|
||||
- Reboot pending
|
||||
- 4 auto-start services not running (including Group Policy Client)
|
||||
|
||||
**Action Priority:** **IMMEDIATE - Data at risk from failing drive**
|
||||
|
||||
---
|
||||
|
||||
### 2. GTS-W1 (Workstation) - AMBER
|
||||
|
||||
**Grade:** AMBER
|
||||
**Findings:** 0 critical / 4 warning / 16 info
|
||||
**OS:** Windows 11 Pro for Workstations (build 26200)
|
||||
**Baseline:** `GTS-W1-20260606T180908.md`
|
||||
|
||||
**WARNING Issues:**
|
||||
- Defender tamper protection OFF
|
||||
- 2 pending Windows updates
|
||||
- Reboot pending
|
||||
- 3 auto-start services not running
|
||||
|
||||
**Positive:**
|
||||
- BitLocker enabled with TPM + recovery password
|
||||
- All firewalls enabled
|
||||
- Defender active and current
|
||||
- No stability events
|
||||
|
||||
**Action Priority:** Moderate - Schedule maintenance window for updates/reboot
|
||||
|
||||
---
|
||||
|
||||
### 3. GTS-W2 (Workstation) - AMBER
|
||||
|
||||
**Grade:** AMBER
|
||||
**Findings:** 0 critical / 7 warning / 16 info
|
||||
**OS:** Windows 11 Pro for Workstations (build 26200)
|
||||
**Baseline:** `GTS-W2-20260606T181016.md`
|
||||
|
||||
**WARNING Issues:**
|
||||
- 7 warnings total (needs detailed review)
|
||||
- Likely includes: pending updates, services, stability events
|
||||
|
||||
**Action Priority:** Moderate - Review full baseline for specifics
|
||||
|
||||
---
|
||||
|
||||
### 4. GTS-PEDRO-H (Personal Workstation) - AMBER
|
||||
|
||||
**Grade:** AMBER
|
||||
**Findings:** 0 critical / 5 warning / 13 info
|
||||
**OS:** Windows 11 (build 26200)
|
||||
**Baseline:** `GTS-PEDRO-H-20260606T181113.md`
|
||||
|
||||
**WARNING Issues:**
|
||||
- 5 warnings (needs detailed review)
|
||||
|
||||
**Action Priority:** Moderate - Personal workstation, lower business priority
|
||||
|
||||
---
|
||||
|
||||
### 5. GTS-SVR25 (Server) - **RED**
|
||||
|
||||
**Grade:** RED
|
||||
**Findings:** 3 critical / 4 warning / 14 info / 1 unknown
|
||||
**OS:** Windows 11 (build 26100)
|
||||
**Baseline:** `GTS-SVR25-20260606T181205.md`
|
||||
|
||||
**CRITICAL Issues:**
|
||||
- 3 critical findings (needs full baseline review)
|
||||
- Likely includes: firewall, RDP, or encryption issues
|
||||
- 1 unknown check (probe failed to run)
|
||||
|
||||
**Action Priority:** **IMMEDIATE - Production server with critical security issues**
|
||||
|
||||
---
|
||||
|
||||
### 6. SERVER (Legacy Server) - **RED**
|
||||
|
||||
**Grade:** RED
|
||||
**Findings:** 3 critical / 6 warning / 12 info / 1 unknown
|
||||
**OS:** Windows 10 (build 17763) - Windows Server 2019
|
||||
**Baseline:** `SERVER-20260606T181304.md`
|
||||
|
||||
**CRITICAL Issues:**
|
||||
- 3 critical findings (needs full baseline review)
|
||||
- Older Windows 10 base (Server 2019)
|
||||
- 6 warnings + 1 unknown check
|
||||
- Likely includes: firewall, RDP, or encryption issues
|
||||
|
||||
**Action Priority:** **IMMEDIATE - Production server with critical security issues**
|
||||
|
||||
---
|
||||
|
||||
## Fleet-Wide Observations
|
||||
|
||||
### Security Concerns
|
||||
1. **Firewall disabled** on multiple machines - widespread configuration issue
|
||||
2. **RDP without NLA** on multiple machines - pre-auth vulnerability exposure
|
||||
3. **BitLocker inconsistent** - some encrypted, some not
|
||||
4. **Defender tamper protection** disabled on some machines
|
||||
|
||||
### Health Concerns
|
||||
1. **Failing hard drive** on GTS-W0 (9 disk errors)
|
||||
2. **Pending updates** across most/all machines
|
||||
3. **Pending reboots** on multiple machines
|
||||
4. **Group Policy Client stopped** on multiple machines (may indicate domain/GPO issues)
|
||||
|
||||
### Positive Findings
|
||||
- All machines have Defender active with current signatures
|
||||
- No competitor/leftover RMM agents detected
|
||||
- ScreenConnect present on all (expected ACG tooling)
|
||||
- Recent agent versions (0.6.57)
|
||||
|
||||
---
|
||||
|
||||
## Recommended Action Plan
|
||||
|
||||
### Phase 1: IMMEDIATE (Within 24 Hours)
|
||||
|
||||
**GTS-W0 - Security Hardening:**
|
||||
~~1. Backup all critical data immediately (failing drive risk)~~ **NOT NEEDED - Drive is healthy**
|
||||
~~2. Run SMART diagnostics~~ **COMPLETED - Drive OK**
|
||||
~~3. Order replacement drive~~ **NOT NEEDED**
|
||||
1. Enable all firewalls (PowerShell or Group Policy) - CRITICAL
|
||||
2. Enable NLA for RDP or disable RDP entirely - CRITICAL
|
||||
3. Investigate 2 unexpected shutdowns (Event ID 41) - may indicate power issues
|
||||
|
||||
**GTS-SVR25 & SERVER - Security Hardening:**
|
||||
1. Review full baselines for critical findings
|
||||
2. Enable firewalls on all profiles
|
||||
3. Fix RDP (enable NLA or disable)
|
||||
4. Enable BitLocker if not already enabled
|
||||
5. Verify no unauthorized access occurred while exposed
|
||||
|
||||
### Phase 2: Short-Term (Within 1 Week)
|
||||
|
||||
**All Machines:**
|
||||
1. Install pending Windows updates
|
||||
2. Reboot all machines (clears pending reboot flags)
|
||||
3. Enable Defender tamper protection where disabled
|
||||
4. Enable BitLocker on all unencrypted machines
|
||||
5. Investigate stopped Group Policy Client services
|
||||
6. Run second diagnostic to verify fixes
|
||||
|
||||
**GTS-W0 Specific:**
|
||||
~~7. Replace hard drive if SMART shows failures~~ **NOT NEEDED - False positive**
|
||||
~~8. Restore data to new drive~~ **NOT NEEDED**
|
||||
7. Re-run diagnostic after probe fix to establish accurate baseline
|
||||
|
||||
### Phase 3: Ongoing (Within 1 Month)
|
||||
|
||||
1. **Fix diagnostic probe bug** - Update Event ID 153 query to exclude VBS boot messages
|
||||
2. **Re-run all diagnostics** - Get accurate baselines after probe fix (likely affects all Win11 machines)
|
||||
3. Standardize firewall configuration (all profiles enabled)
|
||||
4. Standardize RDP configuration (NLA required or disabled)
|
||||
5. Standardize BitLocker (all OS volumes encrypted)
|
||||
6. Review and clean up auto-start services
|
||||
7. Document baseline configuration standards
|
||||
8. Schedule quarterly re-diagnostics
|
||||
|
||||
---
|
||||
|
||||
## Technical Details
|
||||
|
||||
### Diagnostics Performed
|
||||
- **Probe:** `onboarding-diagnostic.ps1` (70,739 bytes)
|
||||
- **Execution:** PowerShell as SYSTEM via GuruRMM
|
||||
- **Timeout:** 240 seconds per machine
|
||||
- **Output:** JSON + Markdown baselines
|
||||
|
||||
### Checks Performed
|
||||
- **Security:** Defender state, AV conflicts, foreign agents, firewall, BitLocker, local admins, patch posture, OS EOL, RDP/NLA, SMBv1, UAC, LAPS
|
||||
- **Health:** Disk free %, SMART/disk health, 14-day stability (shutdown/BSOD/disk errors), pending reboot, uptime, failed services, domain channel, time source, battery, backup agent
|
||||
- **Inventory:** Hardware (model/serial/CPU/RAM/BIOS/TPM/Secure Boot), OS (edition/build/activation), installed software, network, scheduled tasks, autoruns
|
||||
|
||||
### Baseline Storage
|
||||
All baselines stored at:
|
||||
```
|
||||
clients/gonzvar-tax-services/onboarding-baselines/
|
||||
- GTS-W0-20260606T180736.{json,md}
|
||||
- GTS-W1-20260606T180908.{json,md}
|
||||
- GTS-W2-20260606T181016.{json,md}
|
||||
- GTS-PEDRO-H-20260606T181113.{json,md}
|
||||
- GTS-SVR25-20260606T181205.{json,md}
|
||||
- SERVER-20260606T181304.{json,md}
|
||||
```
|
||||
|
||||
JSON files are immutable snapshots. Markdown files are human-readable reports.
|
||||
|
||||
---
|
||||
|
||||
## Next Steps
|
||||
|
||||
1. **Review detailed baselines** for GTS-SVR25 and SERVER critical findings
|
||||
2. **Create remediation scripts** for firewall/RDP/BitLocker standardization
|
||||
3. **Schedule maintenance window** with client for updates/reboots/drive replacement
|
||||
4. **Backup GTS-W0** immediately (failing drive)
|
||||
5. **Order replacement drive** for GTS-W0
|
||||
6. **Apply fixes** per action plan phases
|
||||
7. **Re-run diagnostics** after remediation to verify fixes
|
||||
8. **Document** final baseline configuration standards
|
||||
|
||||
---
|
||||
|
||||
## Alerts Posted
|
||||
|
||||
- Alert sent to #dev-alerts for each critical finding on RED machines
|
||||
- RMM onboarding alert posted: "Mike onboarded client 'Gonzvar Tax Services' + site 'Main' (INNER-BEAR-6727)"
|
||||
|
||||
---
|
||||
|
||||
**Report Generated:** 2026-06-06
|
||||
**Diagnostics Completed:** 2026-06-06 18:13 UTC
|
||||
**Total Scan Time:** ~6 minutes (all 6 machines)
|
||||
**Next Action:** Review GTS-SVR25 and SERVER detailed baselines + backup GTS-W0
|
||||
Reference in New Issue
Block a user