sync: auto-sync from Mikes-MacBook-Air.local at 2026-06-06 11:32:15

Author: Mike Swanson
Machine: Mikes-MacBook-Air.local
Timestamp: 2026-06-06 11:32:15
This commit is contained in:
2026-06-06 11:32:16 -07:00
parent 6df62036a5
commit 9027557071
16 changed files with 8008 additions and 0 deletions

View File

@@ -0,0 +1,873 @@
{
"host": "GTS-PEDRO-H",
"collected_at_utc": "2026-06-06T18:10:36Z",
"os": {
"caption": "Microsoft Windows 11 Home",
"version": "10.0.26200",
"build": "26200",
"install_date": "2025-02-15T22:25:45Z",
"last_boot_utc": "2026-05-24T01:34:12Z",
"architecture": "64-bit"
},
"facts": {
"builtin_admin_enabled": false,
"os_eol": {
"eol_date": "2027-10-12",
"release": "Win11 25H2"
},
"pending_updates": 2,
"pending_reboot": true,
"uptime_days": 13.7,
"acg_managed_tools": "ScreenConnect / ConnectWise Control",
"hardware": {
"model": "90SM006QUS",
"manufacturer": "LENOVO",
"bios_date": "2023-01-03",
"cpu_logical": 12,
"bios_version": "M49KT21A",
"cpu_cores": 6,
"ram_gb": 15.7,
"serial": "MJ0J9LD1",
"cpu": "12th Gen Intel(R) Core(TM) i5-12400"
},
"third_party_av_active": false,
"os_build": "26200",
"secure_boot": true,
"backup_agents": null,
"autoruns_run_keys": [
{
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
"name": "SecurityHealth",
"value": "C:\\WINDOWS\\system32\\SecurityHealthSystray.exe"
},
{
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
"name": "RtkAudUService",
"value": "\"C:\\WINDOWS\\System32\\DriverStore\\FileRepository\\realtekservice.inf_amd64_23392958033090bf\\RtkAudUService64.exe\" -background"
},
{
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
"name": "msedge_cleanup_{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}",
"value": "\"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\149.0.4022.52\\Installer\\setup.exe\" --msedge --channel=stable --delete-old-versions --system-level --verbose-logging --on-logon"
}
],
"physical_disks": [
{
"health": "Healthy",
"model": "WDC PC SN540 SDDPNPF-1T00-1032",
"media_type": "SSD"
}
],
"local_users": [
{
"last_logon": "2022-08-26",
"name": "Administrator",
"password_never_expires": false,
"enabled": false
},
{
"last_logon": "",
"name": "DefaultAccount",
"password_never_expires": false,
"enabled": false
},
{
"last_logon": "",
"name": "Guest",
"password_never_expires": false,
"enabled": false
},
{
"last_logon": "",
"name": "pgonz",
"password_never_expires": false,
"enabled": true
},
{
"last_logon": "2026-05-23",
"name": "QBDataServiceUser33",
"password_never_expires": false,
"enabled": true
},
{
"last_logon": "",
"name": "WDAGUtilityAccount",
"password_never_expires": false,
"enabled": false
}
],
"scheduled_tasks_count": 35,
"volumes": [
{
"drive": "[SYSTEM]",
"size_gb": 0.2,
"free_pct": 76.9,
"free_gb": 0.2
},
{
"drive": "C:",
"size_gb": 951.6,
"free_pct": 76.1,
"free_gb": 723.7
},
{
"drive": "[WinRE_DRV]",
"size_gb": 2,
"free_pct": 64.3,
"free_gb": 1.3
}
],
"network_adapters": [
{
"dhcp": false,
"description": "ZeroTier Virtual Port",
"gateway": [
"25.255.255.254"
],
"mac": "7A:B3:7D:18:B8:91",
"ip": [
"10.244.10.231",
"fe80::2bae:96e1:f136:d2d9",
"fc2a:89c2:7b0d:1a52:bbed::1"
],
"dns": [
"10.244.163.165"
]
},
{
"dhcp": true,
"description": "Realtek RTL8852AE WiFi 6 802.11ax PCIe Adapter",
"gateway": [
"192.168.0.1",
"fe80::b293:5bff:feb7:1fe4"
],
"mac": "E0:0A:F6:A5:E8:4F",
"ip": [
"192.168.0.146",
"fe80::5f87:acec:b8fd:313f",
"2600:8800:782c:5c00:ecc4:b8ee:f191:f8e9",
"2600:8800:782c:5c00:94a1:fdd7:a658:a330",
"2600:8800:782c:5c00:2abd:1cc9:5150:9bc7",
"2600:8800:782c:5c00::bc77"
],
"dns": [
"68.105.28.11",
"68.105.29.11",
"68.105.28.12"
]
}
],
"failed_autostart_services": [
{
"name": "gpsvc",
"display": "Group Policy Client",
"state": "Stopped"
},
{
"name": "Intel(R) Platform License Manager Service",
"display": "Intel(R) Platform License Manager Service",
"state": "Stopped"
},
{
"name": "QBVSS",
"display": "QBIDPService",
"state": "Stopped"
},
{
"name": "GoogleUpdaterInternalService150.0.7863.0",
"display": "Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)",
"state": "Stopped"
},
{
"name": "GoogleUpdaterService150.0.7863.0",
"display": "Google Updater Service (GoogleUpdaterService150.0.7863.0)",
"state": "Stopped"
}
],
"stability_14d": {
"unexpected_shutdowns": 0,
"disk_errors": 1,
"bugchecks": 0
},
"exposure": {
"smb1_enabled": false,
"laps_present": true,
"rdp_enabled": false,
"uac_enabled": true,
"rdp_nla": true
},
"accounts_password_never_expires": [],
"installed_software": [
{
"publisher": "Atlas Business Solutions, Inc.",
"name": "ABS PDF Install",
"version": "4.6.0"
},
{
"publisher": "Lenovo",
"name": "Calliope_Keyboard",
"version": "1.00.08"
},
{
"publisher": "Microsoft Corporation",
"name": "Copilot",
"version": "148.0.3967.96"
},
{
"publisher": "Drake Software",
"name": "Drake Accounting 2025",
"version": "25.0.18"
},
{
"publisher": "Intel Corporation",
"name": "Dynamic Application Loader Host Interface Service",
"version": "1.0.0.0"
},
{
"publisher": "Google LLC",
"name": "Google Chrome",
"version": "148.0.7778.217"
},
{
"publisher": "Intel Corporation",
"name": "Intel(R) Chipset Device Software",
"version": "10.1.18836.8283"
},
{
"publisher": "Intel Corporation",
"name": "Intel(R) Icls",
"version": "1.0.0.0"
},
{
"publisher": "Intel Corporation",
"name": "Intel(R) Management Engine Components",
"version": "1.0.0.0"
},
{
"publisher": "Intel Corporation",
"name": "Intel(R) Management Engine Components",
"version": "2307.4.12.0"
},
{
"publisher": "Intel Corporation",
"name": "Intel(R) Management Engine Driver",
"version": "1.0.0.0"
},
{
"publisher": "Intel Corporation",
"name": "Intel(R) ME WMI Provider",
"version": "1.0.0.0"
},
{
"publisher": "Lenovo Group Ltd.",
"name": "Lenovo Vantage Service",
"version": "4.1.22.0"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Host - 6.0.36 (x86)",
"version": "48.144.23141"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Host - 8.0.27 (x86)",
"version": "64.108.52182"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Host FX Resolver - 6.0.36 (x86)",
"version": "48.144.23141"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Host FX Resolver - 8.0.27 (x86)",
"version": "64.108.52182"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Runtime - 6.0.36 (x86)",
"version": "48.144.23141"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Runtime - 8.0.27 (x86)",
"version": "64.108.52182"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft 365 - en-us",
"version": "16.0.20026.20112"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft ASP.NET Core 8.0.27 - Shared Framework (x86)",
"version": "8.0.27.26230"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft ASP.NET Core 8.0.27 Shared Framework (x86)",
"version": "8.0.27.26230"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Edge",
"version": "149.0.4022.52"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Edge WebView2 Runtime",
"version": "148.0.3967.96"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft OneNote - en-us",
"version": "16.0.20026.20112"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft SQL Server Compact 4.0 SP1 x64 ENU",
"version": "4.0.8876.1"
},
{
"publisher": "Microsoft",
"name": "Microsoft Teams Meeting Add-in for Microsoft Office",
"version": "1.25.28902"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Update Health Tools",
"version": "5.72.0.0"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17",
"version": "9.0.30729"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161",
"version": "9.0.30729.6161"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501",
"version": "12.0.30501.0"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501",
"version": "12.0.30501.0"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005",
"version": "12.0.21005"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005",
"version": "12.0.21005"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005",
"version": "12.0.21005"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005",
"version": "12.0.21005"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.44.35211",
"version": "14.44.35211.0"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.44.35211",
"version": "14.44.35211.0"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2022 X64 Additional Runtime - 14.44.35211",
"version": "14.44.35211"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.44.35211",
"version": "14.44.35211"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2022 X86 Additional Runtime - 14.44.35211",
"version": "14.44.35211"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.44.35211",
"version": "14.44.35211"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Windows Desktop Runtime - 6.0.36 (x86)",
"version": "48.144.23186"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Windows Desktop Runtime - 6.0.36 (x86)",
"version": "6.0.36.34217"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Windows Desktop Runtime - 8.0.27 (x86)",
"version": "64.108.52193"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Windows Desktop Runtime - 8.0.27 (x86)",
"version": "8.0.27.36030"
},
{
"publisher": "Microsoft Corporation",
"name": "Office 16 Click-to-Run Extensibility Component",
"version": "16.0.20026.20076"
},
{
"publisher": "Intuit Inc.",
"name": "QuickBooks",
"version": "33.0.4003.3302"
},
{
"publisher": "Intuit Inc.",
"name": "QuickBooks Enterprise Solutions 23.0",
"version": "33.0.4003.3302"
},
{
"publisher": "Intuit Inc.",
"name": "QuickBooks Runtime Redistributable",
"version": "1.00.0000"
},
{
"publisher": "Realtek Semiconductor Corp.",
"name": "Realtek Audio Driver",
"version": "6.0.9225.1"
},
{
"publisher": "Realtek Semiconductor Corp.",
"name": "Realtek Card Reader",
"version": "10.0.22000.31269"
},
{
"publisher": "ScreenConnect Software",
"name": "ScreenConnect Client (1912bf3444b41a08)",
"version": "26.1.24.9579"
},
{
"publisher": "win.rar GmbH",
"name": "WinRAR 7.00 beta 4 (64-bit)",
"version": "7.00.4"
},
{
"publisher": "ZeroTier, Inc.",
"name": "ZeroTier One",
"version": "1.12.2"
}
],
"tpm": {
"enabled": true,
"ready": true,
"present": true
},
"local_groups": [
"Administrators",
"Device Owners",
"Distributed COM Users",
"Event Log Readers",
"Guests",
"Hyper-V Administrators",
"IIS_IUSRS",
"OpenSSH Users",
"Performance Log Users",
"Performance Monitor Users",
"Remote Management Users",
"System Managed Accounts Group",
"User Mode Hardware Operators",
"Users"
],
"battery": {
"present": false
},
"activation": {
"edition": "Microsoft Windows 11 Home",
"description": "Windows(R) Operating System, OEM_DM channel",
"licensed": true,
"license_status_code": 1
},
"time_source": "time.windows.com,0x9",
"chassis_types": [
3
],
"last_hotfix": {
"hotfix_id": "KB5089549",
"installed_on": "2026-05-21T07:00:00Z"
},
"scheduled_tasks": [
{
"path": "\\",
"name": "Calliope_Keyboard",
"state": "Running"
},
{
"path": "\\",
"name": "MicrosoftEdgeUpdateTaskMachineCore",
"state": "Ready"
},
{
"path": "\\",
"name": "MicrosoftEdgeUpdateTaskMachineUA",
"state": "Ready"
},
{
"path": "\\",
"name": "OneDrive Reporting Task-S-1-5-21-3052971633-1913791397-467572743-1001",
"state": "Ready"
},
{
"path": "\\",
"name": "OneDrive Standalone Update Task-S-1-5-21-3052971633-1913791397-467572743-1001",
"state": "Ready"
},
{
"path": "\\",
"name": "OneDrive Startup Task-S-1-5-21-3052971633-1913791397-467572743-1001",
"state": "Ready"
},
{
"path": "\\GoogleSystem\\GoogleUpdater\\",
"name": "GoogleUpdaterTaskSystem150.0.7863.0{33CFAE4D-D353-44AD-948F-7D72E567628E}",
"state": "Ready"
},
{
"path": "\\GoogleUserPEH\\",
"name": "RunPlatformExperienceHelperOnUnlock",
"state": "Ready"
},
{
"path": "\\GoogleUserPEH\\",
"name": "RunPlatformExperienceHelper_Daily",
"state": "Ready"
},
{
"path": "\\GoogleUserPEH\\",
"name": "RunPlatformExperienceHelper_Metrics",
"state": "Ready"
},
{
"path": "\\Lenovo\\ImController\\",
"name": "Lenovo iM Controller Monitor",
"state": "Ready"
},
{
"path": "\\Lenovo\\ImController\\",
"name": "Lenovo iM Controller Scheduled Maintenance",
"state": "Ready"
},
{
"path": "\\Lenovo\\ImController\\Plugins\\",
"name": "LenovoSystemUpdatePlugin_WeeklyTask",
"state": "Ready"
},
{
"path": "\\Lenovo\\ImController\\TimeBasedEvents\\",
"name": "48df2383-15fe-49ab-8f16-d4274103ead0",
"state": "Ready"
},
{
"path": "\\Lenovo\\ImController\\TimeBasedEvents\\",
"name": "66724497-f49c-4fc3-aa8a-4d373ddeea45",
"state": "Ready"
},
{
"path": "\\Lenovo\\ImController\\TimeBasedEvents\\",
"name": "aadd3f56-8002-4b8c-aec2-d0ff202832d3",
"state": "Ready"
},
{
"path": "\\Lenovo\\UDC\\",
"name": "Lenovo UDC Idle Monitor",
"state": "Ready"
},
{
"path": "\\Lenovo\\UDC\\",
"name": "Lenovo UDC Lazy Deployment",
"state": "Ready"
},
{
"path": "\\Lenovo\\UDC\\",
"name": "Lenovo UDC Maintainance Task",
"state": "Ready"
},
{
"path": "\\Lenovo\\UDC\\",
"name": "Lenovo UDC Monitor",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\",
"name": "Lenovo.Vantage.ServiceMaintainance",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\",
"name": "StartupFixPlan",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "BatteryGaugeAddinDailyScheduleTask",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "DailyTelemetryTransmission",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "GenericMessagingAddin",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "HeartbeatAddinDailyScheduleTask",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "Lenovo.Vantage.SmartPerformance.MonthlyReport",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "Lenovo.Vantage.SmartPerformance.SScan",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "LenovoBoostAddin.Prompt",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "LenovoCompanionAppAddinDailyScheduleTask",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "LenovoSystemUpdateAddin_WeeklyTask",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "SmartPerformance.ExpireReminder",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "VantageCoreAddinWeekScheduleTask",
"state": "Ready"
},
{
"path": "\\SoftLanding\\S-1-5-21-3052971633-1913791397-467572743-1001\\",
"name": "SoftLandingCreativeManagementTask",
"state": "Ready"
},
{
"path": "\\SoftLanding\\S-1-5-21-3052971633-1913791397-467572743-1001\\",
"name": "SoftLandingDeferralTask-{327badb4-08f8-4096-87f5-ffbafcb0a5d8}",
"state": "Ready"
}
],
"antivirus_products": [
"Windows Defender"
],
"domain_joined": false,
"defender": {
"antispyware_signature_age": 0,
"tamper_protected": true,
"real_time_protection": true,
"nis_enabled": true,
"available": true,
"antivirus_enabled": true,
"am_service_enabled": true
},
"bitlocker": {
"os_volume": "C:",
"key_protectors": [],
"recovery_key_present": false,
"available": true,
"encryption_percent": 0,
"protection_status": "Off"
},
"is_laptop": false,
"installed_software_count": 55,
"local_administrators": [
"GTS-PEDRO-H\\Administrator",
"GTS-PEDRO-H\\pgonz"
],
"firewall_profiles": {
"Private": true,
"Domain": true,
"Public": true
},
"domain": "WORKGROUP",
"foreign_agents": null
},
"findings": [
{
"id": "sec.defender.ok",
"category": "security",
"severity": "info",
"title": "Defender active and current",
"detail": "Real-time protection on, service running, signatures current.",
"evidence": "RealTimeProtectionEnabled=True; AMServiceEnabled=True; AntispywareSignatureAge=0 days; IsTamperProtected=True"
},
{
"id": "sec.av_products.defender_only",
"category": "security",
"severity": "info",
"title": "Defender is the only registered AV",
"detail": "Only Microsoft/Windows Defender is registered in Security Center.",
"evidence": "Windows Defender"
},
{
"id": "sec.foreign_agents.none",
"category": "security",
"severity": "info",
"title": "No competitor/leftover management agents detected",
"detail": "No known competitor RMM or unmanaged remote-access agents found in installed programs or services.",
"evidence": "Scanned uninstall hives (HKLM + WOW6432Node) and Win32_Service"
},
{
"id": "sec.foreign_agents.acg.screenconnect_connectwise_control",
"category": "security",
"severity": "info",
"title": "Expected ACG management tooling present: ScreenConnect / ConnectWise Control",
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
"evidence": "program: ScreenConnect Client (1912bf3444b41a08) 26.1.24.9579\nservice: ScreenConnect Client (1912bf3444b41a08) (ScreenConnect Client (1912bf3444b41a08)) Running"
},
{
"id": "sec.firewall.ok",
"category": "security",
"severity": "info",
"title": "All firewall profiles enabled",
"detail": "Domain, Private, and Public firewall profiles are all enabled.",
"evidence": "Private=True; Domain=True; Public=True"
},
{
"id": "sec.bitlocker.unencrypted",
"category": "security",
"severity": "warning",
"title": "OS volume is NOT encrypted with BitLocker",
"detail": "The operating system volume is unencrypted. Data is exposed if the disk is removed or the device is lost. Enable BitLocker and escrow the recovery key.",
"evidence": "Volume=C:; ProtectionStatus=Off; EncryptionPercentage=0; KeyProtectors="
},
{
"id": "sec.local_admins.list",
"category": "security",
"severity": "info",
"title": "Local administrators (2)",
"detail": "Members of the local Administrators group. Review for unexpected or unknown accounts (especially leftover MSP/vendor accounts from a prior provider).",
"evidence": "GTS-PEDRO-H\\Administrator\nGTS-PEDRO-H\\pgonz"
},
{
"id": "sec.patch.os_supported",
"category": "security",
"severity": "info",
"title": "OS build supported: Win11 25H2",
"detail": "Build 26200 (Win11 25H2) is in support until 2027-10-12.",
"evidence": "Microsoft Windows 11 Home build 26200"
},
{
"id": "sec.patch.pending",
"category": "security",
"severity": "warning",
"title": "2 pending Windows updates",
"detail": "Windows Update reports pending (not installed, not hidden) updates. Some may be security updates. Approve/install on the next maintenance window.",
"evidence": "Microsoft.Update.Session search IsInstalled=0 and IsHidden=0 -> 2"
},
{
"id": "sec.patch.last_hotfix",
"category": "security",
"severity": "info",
"title": "Last hotfix: KB5089549",
"detail": "Most recently installed update (from Get-HotFix; reflects CBS/MSU packages, not all cumulative metadata).",
"evidence": "KB5089549 installed 2026-05-21T07:00:00Z"
},
{
"id": "sec.exposure.smb1_off",
"category": "security",
"severity": "info",
"title": "SMBv1 disabled",
"detail": "SMBv1 server protocol is disabled.",
"evidence": "EnableSMB1Protocol=False"
},
{
"id": "sec.exposure.laps_present",
"category": "security",
"severity": "info",
"title": "LAPS detected",
"detail": "A LAPS mechanism is present.",
"evidence": "Windows LAPS reg key"
},
{
"id": "health.stability.some",
"category": "health",
"severity": "warning",
"title": "Stability events present in the last 14 days",
"detail": "One or more unexpected shutdowns, BSODs, or disk errors occurred recently. Monitor and correlate with user reports.",
"evidence": "Unexpected shutdowns (id 41)=0; Bugchecks/BSOD (id 1001)=0; Disk errors (id 7/51/153)=1"
},
{
"id": "health.reboot_uptime.pending",
"category": "health",
"severity": "warning",
"title": "Reboot pending",
"detail": "A reboot is pending. Pending reboots can block patches and leave the system in a half-updated state. Schedule a restart.",
"evidence": "PendingFileRenameOperations"
},
{
"id": "health.failed_services.stopped",
"category": "health",
"severity": "warning",
"title": "5 auto-start service(s) not running",
"detail": "These services are set to start automatically but are not running. Some may be benign; review for security agents, backup agents, or AV that should be running.",
"evidence": "gpsvc (Group Policy Client) = Stopped\nIntel(R) Platform License Manager Service (Intel(R) Platform License Manager Service) = Stopped\nQBVSS (QBIDPService) = Stopped\nGoogleUpdaterInternalService150.0.7863.0 (Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)) = Stopped\nGoogleUpdaterService150.0.7863.0 (Google Updater Service (GoogleUpdaterService150.0.7863.0)) = Stopped"
},
{
"id": "health.domain.workgroup",
"category": "health",
"severity": "info",
"title": "Not domain-joined (workgroup)",
"detail": "This machine is in workgroup/Azure AD only mode (Domain=WORKGROUP). No on-prem AD secure channel applies.",
"evidence": "PartOfDomain=False; Domain=WORKGROUP"
},
{
"id": "health.time.source",
"category": "health",
"severity": "info",
"title": "Time service source",
"detail": "Current Windows Time service source.",
"evidence": "Source=time.windows.com,0x9"
},
{
"id": "health.backup.none",
"category": "health",
"severity": "info",
"title": "No backup agent detected",
"detail": "No known backup agent service found. Backup expectation varies by endpoint; confirm whether this machine is supposed to have local/cloud backup and whether server-side or M365 backup covers it.",
"evidence": "No matching backup service in Win32_Service"
}
]
}

View File

@@ -0,0 +1,227 @@
# Onboarding Diagnostic Baseline - GTS-PEDRO-H
- **Grade:** AMBER
- **Host:** GTS-PEDRO-H
- **Client:** Gonzvar Tax Services (`gonzvar-tax-services`)
- **Collected (UTC):** 2026-06-06T18:10:36Z
- **Agent ID:** 2f1499f8-2e04-44fa-89a8-ad93736e9787
- **Command ID:** d7e48e75-c5ba-44df-85e5-63c463916854
- **Findings:** 0 critical / 5 warning / 13 info / 0 unknown
- **OS:** Microsoft Windows 11 Home (build 26200)
---
## WARNING (5)
### OS volume is NOT encrypted with BitLocker
- **Category:** security
- **ID:** `sec.bitlocker.unencrypted`
- The operating system volume is unencrypted. Data is exposed if the disk is removed or the device is lost. Enable BitLocker and escrow the recovery key.
```
Volume=C:; ProtectionStatus=Off; EncryptionPercentage=0; KeyProtectors=
```
### 2 pending Windows updates
- **Category:** security
- **ID:** `sec.patch.pending`
- Windows Update reports pending (not installed, not hidden) updates. Some may be security updates. Approve/install on the next maintenance window.
```
Microsoft.Update.Session search IsInstalled=0 and IsHidden=0 -> 2
```
### Stability events present in the last 14 days
- **Category:** health
- **ID:** `health.stability.some`
- One or more unexpected shutdowns, BSODs, or disk errors occurred recently. Monitor and correlate with user reports.
```
Unexpected shutdowns (id 41)=0; Bugchecks/BSOD (id 1001)=0; Disk errors (id 7/51/153)=1
```
### Reboot pending
- **Category:** health
- **ID:** `health.reboot_uptime.pending`
- A reboot is pending. Pending reboots can block patches and leave the system in a half-updated state. Schedule a restart.
```
PendingFileRenameOperations
```
### 5 auto-start service(s) not running
- **Category:** health
- **ID:** `health.failed_services.stopped`
- These services are set to start automatically but are not running. Some may be benign; review for security agents, backup agents, or AV that should be running.
```
gpsvc (Group Policy Client) = Stopped
Intel(R) Platform License Manager Service (Intel(R) Platform License Manager Service) = Stopped
QBVSS (QBIDPService) = Stopped
GoogleUpdaterInternalService150.0.7863.0 (Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)) = Stopped
GoogleUpdaterService150.0.7863.0 (Google Updater Service (GoogleUpdaterService150.0.7863.0)) = Stopped
```
## INFO (13)
### Defender active and current
- **Category:** security
- **ID:** `sec.defender.ok`
- Real-time protection on, service running, signatures current.
```
RealTimeProtectionEnabled=True; AMServiceEnabled=True; AntispywareSignatureAge=0 days; IsTamperProtected=True
```
### Defender is the only registered AV
- **Category:** security
- **ID:** `sec.av_products.defender_only`
- Only Microsoft/Windows Defender is registered in Security Center.
```
Windows Defender
```
### No competitor/leftover management agents detected
- **Category:** security
- **ID:** `sec.foreign_agents.none`
- No known competitor RMM or unmanaged remote-access agents found in installed programs or services.
```
Scanned uninstall hives (HKLM + WOW6432Node) and Win32_Service
```
### Expected ACG management tooling present: ScreenConnect / ConnectWise Control
- **Category:** security
- **ID:** `sec.foreign_agents.acg.screenconnect_connectwise_control`
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
```
program: ScreenConnect Client (1912bf3444b41a08) 26.1.24.9579
service: ScreenConnect Client (1912bf3444b41a08) (ScreenConnect Client (1912bf3444b41a08)) Running
```
### All firewall profiles enabled
- **Category:** security
- **ID:** `sec.firewall.ok`
- Domain, Private, and Public firewall profiles are all enabled.
```
Private=True; Domain=True; Public=True
```
### Local administrators (2)
- **Category:** security
- **ID:** `sec.local_admins.list`
- Members of the local Administrators group. Review for unexpected or unknown accounts (especially leftover MSP/vendor accounts from a prior provider).
```
GTS-PEDRO-H\Administrator
GTS-PEDRO-H\pgonz
```
### OS build supported: Win11 25H2
- **Category:** security
- **ID:** `sec.patch.os_supported`
- Build 26200 (Win11 25H2) is in support until 2027-10-12.
```
Microsoft Windows 11 Home build 26200
```
### Last hotfix: KB5089549
- **Category:** security
- **ID:** `sec.patch.last_hotfix`
- Most recently installed update (from Get-HotFix; reflects CBS/MSU packages, not all cumulative metadata).
```
KB5089549 installed 2026-05-21T07:00:00Z
```
### SMBv1 disabled
- **Category:** security
- **ID:** `sec.exposure.smb1_off`
- SMBv1 server protocol is disabled.
```
EnableSMB1Protocol=False
```
### LAPS detected
- **Category:** security
- **ID:** `sec.exposure.laps_present`
- A LAPS mechanism is present.
```
Windows LAPS reg key
```
### Not domain-joined (workgroup)
- **Category:** health
- **ID:** `health.domain.workgroup`
- This machine is in workgroup/Azure AD only mode (Domain=WORKGROUP). No on-prem AD secure channel applies.
```
PartOfDomain=False; Domain=WORKGROUP
```
### Time service source
- **Category:** health
- **ID:** `health.time.source`
- Current Windows Time service source.
```
Source=time.windows.com,0x9
```
### No backup agent detected
- **Category:** health
- **ID:** `health.backup.none`
- No known backup agent service found. Backup expectation varies by endpoint; confirm whether this machine is supposed to have local/cloud backup and whether server-side or M365 backup covers it.
```
No matching backup service in Win32_Service
```
---
## Inventory Baseline Summary
- **Manufacturer / Model:** LENOVO / 90SM006QUS
- **Serial:** MJ0J9LD1
- **CPU:** 12th Gen Intel(R) Core(TM) i5-12400 (6 cores / 12 logical)
- **RAM (GB):** 15.7
- **BIOS:** M49KT21A (2023-01-03)
- **Chassis is laptop:** false
- **TPM present / Secure Boot:** true / true
- **Domain joined:** false (WORKGROUP)
- **OS activation licensed:** true
- **Uptime (days):** 13.7
- **Pending reboot:** true
- **Installed software count:** 55
- **Scheduled tasks (non-MS, enabled):** 35
- **Local administrators:** GTS-PEDRO-H\Administrator, GTS-PEDRO-H\pgonz
### Fixed volumes
- [SYSTEM] - 0.2 GB free of 0.2 GB (76.9%)
- C: - 723.7 GB free of 951.6 GB (76.1%)
- [WinRE_DRV] - 1.3 GB free of 2 GB (64.3%)
### Network adapters
- ZeroTier Virtual Port - IP: 10.244.10.231, fe80::2bae:96e1:f136:d2d9, fc2a:89c2:7b0d:1a52:bbed::1 - DNS: 10.244.163.165 - DHCP: false
- Realtek RTL8852AE WiFi 6 802.11ax PCIe Adapter - IP: 192.168.0.146, fe80::5f87:acec:b8fd:313f, 2600:8800:782c:5c00:ecc4:b8ee:f191:f8e9, 2600:8800:782c:5c00:94a1:fdd7:a658:a330, 2600:8800:782c:5c00:2abd:1cc9:5150:9bc7, 2600:8800:782c:5c00::bc77 - DNS: 68.105.28.11, 68.105.29.11, 68.105.28.12 - DHCP: true
---
## Diff vs Prior Baseline
- No prior baseline found for this host. This is the first baseline.
---
_Generated by run-onboarding-diagnostic.sh (GuruRMM onboarding diagnostic, Phase 1). Raw snapshot: `GTS-PEDRO-H-20260606T181113.json` (immutable)._

View File

@@ -0,0 +1,544 @@
{
"host": "GTS-SVR25",
"collected_at_utc": "2026-06-06T18:13:24Z",
"os": {
"caption": "Microsoft Windows Server 2025 Standard",
"version": "10.0.26100",
"build": "26100",
"install_date": "2025-10-18T18:21:32Z",
"last_boot_utc": "2026-05-17T04:50:38Z",
"architecture": "64-bit"
},
"facts": {
"builtin_admin_enabled": false,
"os_eol": {
"eol_date": "2026-10-13",
"release": "Win11 24H2"
},
"pending_updates": 0,
"pending_reboot": true,
"uptime_days": 20.6,
"acg_managed_tools": [
"ScreenConnect / ConnectWise Control",
"Datto RMM",
"Splashtop (SOS/Streamer)",
"Syncro / Kabuto"
],
"hardware": {
"model": "System Product Name",
"manufacturer": "ASUS",
"bios_date": "2022-08-12",
"cpu_logical": 20,
"bios_version": "1620",
"cpu_cores": 12,
"ram_gb": 31.7,
"serial": "System Serial Number",
"cpu": "12th Gen Intel(R) Core(TM) i7-12700"
},
"local_administrators": [
"Administrator",
"Domain Admins",
"Enterprise Admins",
"localadmin",
"MediaAdmin$",
"sysadmin"
],
"os_build": "26100",
"secure_boot": false,
"backup_agents": null,
"autoruns_run_keys": [
{
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
"name": "AzureArcSetup",
"value": "C:\\WINDOWS\\AzureArcSetup\\Systray\\AzureArcSysTray.exe"
},
{
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
"name": "SecurityHealth",
"value": "C:\\WINDOWS\\system32\\SecurityHealthSystray.exe"
},
{
"key": "HKLM:\\Software\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\Run",
"name": "CentraStage",
"value": "C:\\Program Files (x86)\\CentraStage\\Gui.exe"
},
{
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
"name": "msedge_cleanup_{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}",
"value": "\"C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\148.0.3967.96\\Installer\\setup.exe\" --msedgewebview --delete-old-versions --system-level --verbose-logging --on-logon"
}
],
"physical_disks": [
{
"health": "Healthy",
"model": "NVMe KINGSTON SNV3S2000G",
"media_type": "SSD"
}
],
"local_users": [
{
"last_logon": "",
"name": "Administrator",
"password_never_expires": false,
"enabled": false
},
{
"last_logon": "",
"name": "Guest",
"password_never_expires": false,
"enabled": false
},
{
"last_logon": "",
"name": "krbtgt",
"password_never_expires": false,
"enabled": false
},
{
"last_logon": "",
"name": "DefaultAccount",
"password_never_expires": false,
"enabled": false
},
{
"last_logon": "",
"name": "localadmin",
"password_never_expires": false,
"enabled": true
},
{
"last_logon": "2026-03-24",
"name": "sysadmin",
"password_never_expires": false,
"enabled": true
},
{
"last_logon": "2026-06-04",
"name": "pedro",
"password_never_expires": false,
"enabled": true
},
{
"last_logon": "2026-06-05",
"name": "gonzvar",
"password_never_expires": false,
"enabled": true
},
{
"last_logon": "2026-06-06",
"name": "SERVER$",
"password_never_expires": false,
"enabled": true
},
{
"last_logon": "",
"name": "MediaAdmin$",
"password_never_expires": false,
"enabled": true
},
{
"last_logon": "2026-06-06",
"name": "GTS-W1$",
"password_never_expires": false,
"enabled": true
},
{
"last_logon": "2026-06-06",
"name": "GTS-W2$",
"password_never_expires": false,
"enabled": true
},
{
"last_logon": "2026-06-06",
"name": "GTS-W0$",
"password_never_expires": false,
"enabled": true
}
],
"scheduled_tasks_count": 2,
"volumes": [
{
"drive": "[unlabeled]",
"size_gb": 0.8,
"free_pct": 11.8,
"free_gb": 0.1
},
{
"drive": "C:",
"size_gb": 1862.2,
"free_pct": 90.5,
"free_gb": 1684.5
},
{
"drive": "[unlabeled]",
"size_gb": 0.1,
"free_pct": 64.4,
"free_gb": 0.1
}
],
"network_adapters": [
{
"dhcp": false,
"description": "Realtek PCIe 2.5GbE Family Controller",
"gateway": [
"192.168.0.1"
],
"mac": "50:EB:F6:CF:69:80",
"ip": [
"192.168.0.2",
"fe80::9386:5e2c:c38a:61b1"
],
"dns": [
"192.168.0.2",
"192.168.0.5"
]
}
],
"failed_autostart_services": [
{
"name": "AsusUpdateCheck",
"display": "AsusUpdateCheck",
"state": "Stopped"
},
{
"name": "InventorySvc",
"display": "Inventory and Compatibility Appraisal service",
"state": "Stopped"
}
],
"stability_14d": {
"unexpected_shutdowns": 0,
"disk_errors": 83,
"bugchecks": 0
},
"exposure": {
"smb1_enabled": false,
"laps_present": true,
"rdp_enabled": true,
"uac_enabled": true,
"rdp_nla": true
},
"accounts_password_never_expires": [],
"installed_software": [
{
"publisher": "Webprofusion Pty Ltd",
"name": "Certify Certificate Manager version 6.1.11",
"version": "6.1.11"
},
{
"publisher": "Datto Inc.",
"name": "Datto RMM",
"version": "4.4.11616.11616"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Host - 8.0.21 (x86)",
"version": "64.84.40925"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Host FX Resolver - 8.0.21 (x86)",
"version": "64.84.40925"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Runtime - 8.0.21 (x86)",
"version": "64.84.40925"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft ASP.NET Core 8.0.21 - Shared Framework (x86)",
"version": "8.0.21.25475"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft ASP.NET Core 8.0.21 Shared Framework (x86)",
"version": "8.0.21.25475"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Edge",
"version": "149.0.4022.52"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Edge WebView2 Runtime",
"version": "148.0.3967.96"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Windows Desktop Runtime - 8.0.21 (x86)",
"version": "64.84.40919"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Windows Desktop Runtime - 8.0.21 (x86)",
"version": "8.0.21.35325"
},
{
"publisher": "ScreenConnect Software",
"name": "ScreenConnect Client (1912bf3444b41a08)",
"version": "26.1.24.9579"
},
{
"publisher": "Splashtop Inc.",
"name": "Splashtop Software Updater",
"version": "1.5.6.23"
},
{
"publisher": "Splashtop Inc.",
"name": "Splashtop Streamer",
"version": "3.8.2.0"
},
{
"publisher": "Servably, Inc.",
"name": "Syncro",
"version": "1.0.201.18410"
}
],
"tpm": {
"enabled": true,
"ready": true,
"present": true
},
"local_groups": [
"Cert Publishers",
"RAS and IAS Servers",
"Allowed RODC Password Replication Group",
"Denied RODC Password Replication Group"
],
"battery": {
"present": false
},
"third_party_av_active": false,
"activation": {
"edition": "Microsoft Windows Server 2025 Standard",
"description": "Windows(R) Operating System, VOLUME_KMSCLIENT channel",
"licensed": true,
"license_status_code": 1
},
"time_source": "Free-running System Clock",
"chassis_types": [
3
],
"last_hotfix": {
"hotfix_id": "KB5089717",
"installed_on": "2026-05-17T07:00:00Z"
},
"scheduled_tasks": [
{
"path": "\\",
"name": "MicrosoftEdgeUpdateTaskMachineCore{3F3B8390-0879-4598-A0FB-FCCC9A4FBAA9}",
"state": "Ready"
},
{
"path": "\\",
"name": "MicrosoftEdgeUpdateTaskMachineUA{F6534644-528C-456C-ABC0-2A47E8920650}",
"state": "Ready"
}
],
"antivirus_products": [],
"domain_joined": true,
"defender": {
"antispyware_signature_age": 0,
"tamper_protected": false,
"real_time_protection": false,
"nis_enabled": false,
"available": true,
"antivirus_enabled": false,
"am_service_enabled": false
},
"bitlocker": {
"available": false,
"os_volume": "C:"
},
"is_laptop": false,
"installed_software_count": 15,
"secure_channel_ok": null,
"firewall_profiles": {
"Private": true,
"Domain": true,
"Public": true
},
"domain": "GTS.local",
"foreign_agents": null
},
"findings": [
{
"id": "sec.defender.rtp_off",
"category": "security",
"severity": "critical",
"title": "Defender real-time protection is OFF",
"detail": "Real-time protection is disabled. The endpoint is unprotected against active threats. Re-enable immediately or confirm a managed 3rd-party AV is providing real-time protection.",
"evidence": "RealTimeProtectionEnabled=False; AMServiceEnabled=False; AntispywareSignatureAge=0 days; IsTamperProtected=False"
},
{
"id": "sec.defender.amservice_off",
"category": "security",
"severity": "critical",
"title": "Defender antimalware service is not running",
"detail": "The Defender antimalware service is not active. If no 3rd-party AV is present, this endpoint has no antivirus protection.",
"evidence": "RealTimeProtectionEnabled=False; AMServiceEnabled=False; AntispywareSignatureAge=0 days; IsTamperProtected=False"
},
{
"id": "sec.defender.tamper_off",
"category": "security",
"severity": "warning",
"title": "Defender tamper protection is OFF",
"detail": "Tamper protection is disabled, so malware or a local admin can silently disable Defender. Enable tamper protection (typically via Intune / Security Center).",
"evidence": "RealTimeProtectionEnabled=False; AMServiceEnabled=False; AntispywareSignatureAge=0 days; IsTamperProtected=False"
},
{
"id": "sec.av_products.none_registered",
"category": "security",
"severity": "info",
"title": "No AV products registered in Security Center",
"detail": "SecurityCenter2 returned no AntiVirusProduct entries. This is normal on Windows Server SKUs (Security Center is a client feature). On a workstation, confirm Defender or a managed AV is active.",
"evidence": "root\\SecurityCenter2 AntiVirusProduct: none"
},
{
"id": "sec.foreign_agents.none",
"category": "security",
"severity": "info",
"title": "No competitor/leftover management agents detected",
"detail": "No known competitor RMM or unmanaged remote-access agents found in installed programs or services.",
"evidence": "Scanned uninstall hives (HKLM + WOW6432Node) and Win32_Service"
},
{
"id": "sec.foreign_agents.acg.screenconnect_connectwise_control",
"category": "security",
"severity": "info",
"title": "Expected ACG management tooling present: ScreenConnect / ConnectWise Control",
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
"evidence": "program: ScreenConnect Client (1912bf3444b41a08) 26.1.24.9579\nservice: ScreenConnect Client (1912bf3444b41a08) (ScreenConnect Client (1912bf3444b41a08)) Running"
},
{
"id": "sec.foreign_agents.acg.datto_rmm",
"category": "security",
"severity": "info",
"title": "Expected ACG management tooling present: Datto RMM",
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
"evidence": "program: Datto RMM 4.4.11616.11616\nservice: CagService (Datto RMM) Running"
},
{
"id": "sec.foreign_agents.acg.splashtop_sos_streamer_",
"category": "security",
"severity": "info",
"title": "Expected ACG management tooling present: Splashtop (SOS/Streamer)",
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
"evidence": "program: Splashtop Software Updater 1.5.6.23\nprogram: Splashtop Streamer 3.8.2.0\nservice: SplashtopRemoteService (Splashtop? Remote Service) Running\nservice: SSUService (Splashtop Software Updater Service) Running"
},
{
"id": "sec.foreign_agents.acg.syncro_kabuto",
"category": "security",
"severity": "info",
"title": "Expected ACG management tooling present: Syncro / Kabuto",
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
"evidence": "program: Syncro 1.0.201.18410\nservice: Syncro (Syncro) Running"
},
{
"id": "sec.firewall.ok",
"category": "security",
"severity": "info",
"title": "All firewall profiles enabled",
"detail": "Domain, Private, and Public firewall profiles are all enabled.",
"evidence": "Private=True; Domain=True; Public=True"
},
{
"id": "sec.bitlocker.unavailable",
"category": "security",
"severity": "unknown",
"title": "BitLocker status unavailable",
"detail": "Get-BitLockerVolume failed for the OS volume. BitLocker may not be installed (Home edition) or the cmdlet is unavailable. Verify encryption manually (manage-bde -status).",
"evidence": "MountPoint=C:, Get-BitLockerVolume returned null"
},
{
"id": "sec.local_admins.list",
"category": "security",
"severity": "info",
"title": "Local administrators (6)",
"detail": "Members of the local Administrators group. Review for unexpected or unknown accounts (especially leftover MSP/vendor accounts from a prior provider).",
"evidence": "Administrator\nDomain Admins\nEnterprise Admins\nlocaladmin\nMediaAdmin$\nsysadmin"
},
{
"id": "sec.patch.os_supported",
"category": "security",
"severity": "info",
"title": "OS build supported: Win11 24H2",
"detail": "Build 26100 (Win11 24H2) is in support until 2026-10-13.",
"evidence": "Microsoft Windows Server 2025 Standard build 26100"
},
{
"id": "sec.patch.last_hotfix",
"category": "security",
"severity": "info",
"title": "Last hotfix: KB5089717",
"detail": "Most recently installed update (from Get-HotFix; reflects CBS/MSU packages, not all cumulative metadata).",
"evidence": "KB5089717 installed 2026-05-17T07:00:00Z"
},
{
"id": "sec.exposure.rdp_on",
"category": "security",
"severity": "warning",
"title": "RDP is enabled",
"detail": "Remote Desktop is enabled (NLA required). Confirm it is restricted to VPN or specific source IPs and not exposed to the internet.",
"evidence": "fDenyTSConnections=0; UserAuthentication=1"
},
{
"id": "sec.exposure.smb1_off",
"category": "security",
"severity": "info",
"title": "SMBv1 disabled",
"detail": "SMBv1 server protocol is disabled.",
"evidence": "EnableSMB1Protocol=False"
},
{
"id": "sec.exposure.laps_present",
"category": "security",
"severity": "info",
"title": "LAPS detected",
"detail": "A LAPS mechanism is present.",
"evidence": "Windows LAPS reg key"
},
{
"id": "health.stability.recurring",
"category": "health",
"severity": "critical",
"title": "Recurring stability events in the last 14 days",
"detail": "Three or more of one event class (unexpected shutdown, BSOD, or disk error) in 14 days indicates a hardware or driver problem. Investigate memory, disk, PSU, and drivers.",
"evidence": "Unexpected shutdowns (id 41)=0; Bugchecks/BSOD (id 1001)=0; Disk errors (id 7/51/153)=83"
},
{
"id": "health.reboot_uptime.pending",
"category": "health",
"severity": "warning",
"title": "Reboot pending",
"detail": "A reboot is pending. Pending reboots can block patches and leave the system in a half-updated state. Schedule a restart.",
"evidence": "PendingFileRenameOperations"
},
{
"id": "health.failed_services.stopped",
"category": "health",
"severity": "warning",
"title": "2 auto-start service(s) not running",
"detail": "These services are set to start automatically but are not running. Some may be benign; review for security agents, backup agents, or AV that should be running.",
"evidence": "AsusUpdateCheck (AsusUpdateCheck) = Stopped\nInventorySvc (Inventory and Compatibility Appraisal service) = Stopped"
},
{
"id": "health.time.source",
"category": "health",
"severity": "info",
"title": "Time service source",
"detail": "Current Windows Time service source.",
"evidence": "Source=Free-running System Clock"
},
{
"id": "health.backup.none",
"category": "health",
"severity": "info",
"title": "No backup agent detected",
"detail": "No known backup agent service found. Backup expectation varies by endpoint; confirm whether this machine is supposed to have local/cloud backup and whether server-side or M365 backup covers it.",
"evidence": "No matching backup service in Win32_Service"
}
]
}

View File

@@ -0,0 +1,274 @@
# Onboarding Diagnostic Baseline - GTS-SVR25
- **Grade:** RED
- **Host:** GTS-SVR25
- **Client:** Gonzvar Tax Services (`gonzvar-tax-services`)
- **Collected (UTC):** 2026-06-06T18:13:24Z
- **Agent ID:** 3f202b0e-5f48-4f76-833c-d7d1bd00ed58
- **Command ID:** 144165ca-d232-4a3d-b904-cb622b431fd9
- **Findings:** 3 critical / 4 warning / 14 info / 1 unknown
- **OS:** Microsoft Windows Server 2025 Standard (build 26100)
---
## CRITICAL (3)
### Defender real-time protection is OFF
- **Category:** security
- **ID:** `sec.defender.rtp_off`
- Real-time protection is disabled. The endpoint is unprotected against active threats. Re-enable immediately or confirm a managed 3rd-party AV is providing real-time protection.
```
RealTimeProtectionEnabled=False; AMServiceEnabled=False; AntispywareSignatureAge=0 days; IsTamperProtected=False
```
### Defender antimalware service is not running
- **Category:** security
- **ID:** `sec.defender.amservice_off`
- The Defender antimalware service is not active. If no 3rd-party AV is present, this endpoint has no antivirus protection.
```
RealTimeProtectionEnabled=False; AMServiceEnabled=False; AntispywareSignatureAge=0 days; IsTamperProtected=False
```
### Recurring stability events in the last 14 days
- **Category:** health
- **ID:** `health.stability.recurring`
- Three or more of one event class (unexpected shutdown, BSOD, or disk error) in 14 days indicates a hardware or driver problem. Investigate memory, disk, PSU, and drivers.
```
Unexpected shutdowns (id 41)=0; Bugchecks/BSOD (id 1001)=0; Disk errors (id 7/51/153)=83
```
## WARNING (4)
### Defender tamper protection is OFF
- **Category:** security
- **ID:** `sec.defender.tamper_off`
- Tamper protection is disabled, so malware or a local admin can silently disable Defender. Enable tamper protection (typically via Intune / Security Center).
```
RealTimeProtectionEnabled=False; AMServiceEnabled=False; AntispywareSignatureAge=0 days; IsTamperProtected=False
```
### RDP is enabled
- **Category:** security
- **ID:** `sec.exposure.rdp_on`
- Remote Desktop is enabled (NLA required). Confirm it is restricted to VPN or specific source IPs and not exposed to the internet.
```
fDenyTSConnections=0; UserAuthentication=1
```
### Reboot pending
- **Category:** health
- **ID:** `health.reboot_uptime.pending`
- A reboot is pending. Pending reboots can block patches and leave the system in a half-updated state. Schedule a restart.
```
PendingFileRenameOperations
```
### 2 auto-start service(s) not running
- **Category:** health
- **ID:** `health.failed_services.stopped`
- These services are set to start automatically but are not running. Some may be benign; review for security agents, backup agents, or AV that should be running.
```
AsusUpdateCheck (AsusUpdateCheck) = Stopped
InventorySvc (Inventory and Compatibility Appraisal service) = Stopped
```
## INFO (14)
### No AV products registered in Security Center
- **Category:** security
- **ID:** `sec.av_products.none_registered`
- SecurityCenter2 returned no AntiVirusProduct entries. This is normal on Windows Server SKUs (Security Center is a client feature). On a workstation, confirm Defender or a managed AV is active.
```
root\SecurityCenter2 AntiVirusProduct: none
```
### No competitor/leftover management agents detected
- **Category:** security
- **ID:** `sec.foreign_agents.none`
- No known competitor RMM or unmanaged remote-access agents found in installed programs or services.
```
Scanned uninstall hives (HKLM + WOW6432Node) and Win32_Service
```
### Expected ACG management tooling present: ScreenConnect / ConnectWise Control
- **Category:** security
- **ID:** `sec.foreign_agents.acg.screenconnect_connectwise_control`
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
```
program: ScreenConnect Client (1912bf3444b41a08) 26.1.24.9579
service: ScreenConnect Client (1912bf3444b41a08) (ScreenConnect Client (1912bf3444b41a08)) Running
```
### Expected ACG management tooling present: Datto RMM
- **Category:** security
- **ID:** `sec.foreign_agents.acg.datto_rmm`
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
```
program: Datto RMM 4.4.11616.11616
service: CagService (Datto RMM) Running
```
### Expected ACG management tooling present: Splashtop (SOS/Streamer)
- **Category:** security
- **ID:** `sec.foreign_agents.acg.splashtop_sos_streamer_`
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
```
program: Splashtop Software Updater 1.5.6.23
program: Splashtop Streamer 3.8.2.0
service: SplashtopRemoteService (Splashtop? Remote Service) Running
service: SSUService (Splashtop Software Updater Service) Running
```
### Expected ACG management tooling present: Syncro / Kabuto
- **Category:** security
- **ID:** `sec.foreign_agents.acg.syncro_kabuto`
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
```
program: Syncro 1.0.201.18410
service: Syncro (Syncro) Running
```
### All firewall profiles enabled
- **Category:** security
- **ID:** `sec.firewall.ok`
- Domain, Private, and Public firewall profiles are all enabled.
```
Private=True; Domain=True; Public=True
```
### Local administrators (6)
- **Category:** security
- **ID:** `sec.local_admins.list`
- Members of the local Administrators group. Review for unexpected or unknown accounts (especially leftover MSP/vendor accounts from a prior provider).
```
Administrator
Domain Admins
Enterprise Admins
localadmin
MediaAdmin$
sysadmin
```
### OS build supported: Win11 24H2
- **Category:** security
- **ID:** `sec.patch.os_supported`
- Build 26100 (Win11 24H2) is in support until 2026-10-13.
```
Microsoft Windows Server 2025 Standard build 26100
```
### Last hotfix: KB5089717
- **Category:** security
- **ID:** `sec.patch.last_hotfix`
- Most recently installed update (from Get-HotFix; reflects CBS/MSU packages, not all cumulative metadata).
```
KB5089717 installed 2026-05-17T07:00:00Z
```
### SMBv1 disabled
- **Category:** security
- **ID:** `sec.exposure.smb1_off`
- SMBv1 server protocol is disabled.
```
EnableSMB1Protocol=False
```
### LAPS detected
- **Category:** security
- **ID:** `sec.exposure.laps_present`
- A LAPS mechanism is present.
```
Windows LAPS reg key
```
### Time service source
- **Category:** health
- **ID:** `health.time.source`
- Current Windows Time service source.
```
Source=Free-running System Clock
```
### No backup agent detected
- **Category:** health
- **ID:** `health.backup.none`
- No known backup agent service found. Backup expectation varies by endpoint; confirm whether this machine is supposed to have local/cloud backup and whether server-side or M365 backup covers it.
```
No matching backup service in Win32_Service
```
## UNKNOWN (1)
### BitLocker status unavailable
- **Category:** security
- **ID:** `sec.bitlocker.unavailable`
- Get-BitLockerVolume failed for the OS volume. BitLocker may not be installed (Home edition) or the cmdlet is unavailable. Verify encryption manually (manage-bde -status).
```
MountPoint=C:, Get-BitLockerVolume returned null
```
---
## Inventory Baseline Summary
- **Manufacturer / Model:** ASUS / System Product Name
- **Serial:** System Serial Number
- **CPU:** 12th Gen Intel(R) Core(TM) i7-12700 (12 cores / 20 logical)
- **RAM (GB):** 31.7
- **BIOS:** 1620 (2022-08-12)
- **Chassis is laptop:** false
- **TPM present / Secure Boot:** true / ?
- **Domain joined:** true (GTS.local)
- **OS activation licensed:** true
- **Uptime (days):** 20.6
- **Pending reboot:** true
- **Installed software count:** 15
- **Scheduled tasks (non-MS, enabled):** 2
- **Local administrators:** Administrator, Domain Admins, Enterprise Admins, localadmin, MediaAdmin$, sysadmin
### Fixed volumes
- [unlabeled] - 0.1 GB free of 0.8 GB (11.8%)
- C: - 1684.5 GB free of 1862.2 GB (90.5%)
- [unlabeled] - 0.1 GB free of 0.1 GB (64.4%)
### Network adapters
- Realtek PCIe 2.5GbE Family Controller - IP: 192.168.0.2, fe80::9386:5e2c:c38a:61b1 - DNS: 192.168.0.2, 192.168.0.5 - DHCP: false
---
## Diff vs Prior Baseline
- No prior baseline found for this host. This is the first baseline.
---
_Generated by run-onboarding-diagnostic.sh (GuruRMM onboarding diagnostic, Phase 1). Raw snapshot: `GTS-SVR25-20260606T181205.json` (immutable)._

File diff suppressed because it is too large Load Diff

View File

@@ -0,0 +1,261 @@
# Onboarding Diagnostic Baseline - GTS-W0
- **Grade:** RED
- **Host:** GTS-W0
- **Client:** Gonzvar Tax Services (`gonzvar-tax-services`)
- **Collected (UTC):** 2026-06-06T18:08:45Z
- **Agent ID:** 14751270-35fd-4b89-a083-a014a725e356
- **Command ID:** c6247347-570f-45f8-9357-92208252029b
- **Findings:** 3 critical / 4 warning / 14 info / 0 unknown
- **OS:** Microsoft Windows 11 Pro for Workstations (build 26200)
---
## CRITICAL (3)
### Firewall disabled on profile(s): Domain, Private, Public
- **Category:** security
- **ID:** `sec.firewall.disabled`
- One or more firewall profiles are OFF. The endpoint is exposed to lateral movement and inbound attacks on those networks. Re-enable all profiles.
```
Profile states: Private=False; Domain=False; Public=False
```
### RDP enabled WITHOUT Network Level Authentication
- **Category:** security
- **ID:** `sec.exposure.rdp_no_nla`
- RDP is on and NLA is not required. This exposes the logon screen pre-auth and is vulnerable to pre-auth exploits and brute force. Require NLA, restrict RDP to VPN/allow-listed IPs, or disable RDP.
```
fDenyTSConnections=0; UserAuthentication=0
```
### Recurring stability events in the last 14 days
- **Category:** health
- **ID:** `health.stability.recurring`
- Three or more of one event class (unexpected shutdown, BSOD, or disk error) in 14 days indicates a hardware or driver problem. Investigate memory, disk, PSU, and drivers.
```
Unexpected shutdowns (id 41)=2; Bugchecks/BSOD (id 1001)=0; Disk errors (id 7/51/153)=9
```
## WARNING (4)
### OS volume is NOT encrypted with BitLocker
- **Category:** security
- **ID:** `sec.bitlocker.unencrypted`
- The operating system volume is unencrypted. Data is exposed if the disk is removed or the device is lost. Enable BitLocker and escrow the recovery key.
```
Volume=C:; ProtectionStatus=Off; EncryptionPercentage=0; KeyProtectors=
```
### 1 pending Windows updates
- **Category:** security
- **ID:** `sec.patch.pending`
- Windows Update reports pending (not installed, not hidden) updates. Some may be security updates. Approve/install on the next maintenance window.
```
Microsoft.Update.Session search IsInstalled=0 and IsHidden=0 -> 1
```
### Reboot pending
- **Category:** health
- **ID:** `health.reboot_uptime.pending`
- A reboot is pending. Pending reboots can block patches and leave the system in a half-updated state. Schedule a restart.
```
PendingFileRenameOperations
```
### 4 auto-start service(s) not running
- **Category:** health
- **ID:** `health.failed_services.stopped`
- These services are set to start automatically but are not running. Some may be benign; review for security agents, backup agents, or AV that should be running.
```
GoogleUpdaterInternalService150.0.7863.0 (Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)) = Stopped
GoogleUpdaterService150.0.7863.0 (Google Updater Service (GoogleUpdaterService150.0.7863.0)) = Stopped
gpsvc (Group Policy Client) = Stopped
Intel(R) Platform License Manager Service (Intel(R) Platform License Manager Service) = Stopped
```
## INFO (14)
### Defender active and current
- **Category:** security
- **ID:** `sec.defender.ok`
- Real-time protection on, service running, signatures current.
```
RealTimeProtectionEnabled=True; AMServiceEnabled=True; AntispywareSignatureAge=0 days; IsTamperProtected=True
```
### Defender is the only registered AV
- **Category:** security
- **ID:** `sec.av_products.defender_only`
- Only Microsoft/Windows Defender is registered in Security Center.
```
Windows Defender
```
### No competitor/leftover management agents detected
- **Category:** security
- **ID:** `sec.foreign_agents.none`
- No known competitor RMM or unmanaged remote-access agents found in installed programs or services.
```
Scanned uninstall hives (HKLM + WOW6432Node) and Win32_Service
```
### Expected ACG management tooling present: ScreenConnect / ConnectWise Control
- **Category:** security
- **ID:** `sec.foreign_agents.acg.screenconnect_connectwise_control`
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
```
program: ScreenConnect Client (1912bf3444b41a08) 26.1.24.9579
service: ScreenConnect Client (1912bf3444b41a08) (ScreenConnect Client (1912bf3444b41a08)) Running
```
### Expected ACG management tooling present: Splashtop (SOS/Streamer)
- **Category:** security
- **ID:** `sec.foreign_agents.acg.splashtop_sos_streamer_`
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
```
program: Splashtop Streamer 3.8.4.0
service: SplashtopRemoteService (Splashtop? Remote Service) Running
```
### Expected ACG management tooling present: Syncro / Kabuto
- **Category:** security
- **ID:** `sec.foreign_agents.acg.syncro_kabuto`
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
```
program: Syncro 1.0.201.18410
service: Syncro (Syncro) Running
```
### Local administrators (5)
- **Category:** security
- **ID:** `sec.local_admins.list`
- Members of the local Administrators group. Review for unexpected or unknown accounts (especially leftover MSP/vendor accounts from a prior provider).
```
GTS\Domain Admins
GTS\pedro
GTS-W0\Administrator
GTS-W0\localadmin
GTS-W0\pgonz
```
### OS build supported: Win11 25H2
- **Category:** security
- **ID:** `sec.patch.os_supported`
- Build 26200 (Win11 25H2) is in support until 2027-10-12.
```
Microsoft Windows 11 Pro for Workstations build 26200
```
### Last hotfix: KB5089549
- **Category:** security
- **ID:** `sec.patch.last_hotfix`
- Most recently installed update (from Get-HotFix; reflects CBS/MSU packages, not all cumulative metadata).
```
KB5089549 installed 2026-05-13T07:00:00Z
```
### SMBv1 disabled
- **Category:** security
- **ID:** `sec.exposure.smb1_off`
- SMBv1 server protocol is disabled.
```
EnableSMB1Protocol=False
```
### LAPS detected
- **Category:** security
- **ID:** `sec.exposure.laps_present`
- A LAPS mechanism is present.
```
Windows LAPS reg key
```
### Domain secure channel healthy
- **Category:** health
- **ID:** `health.domain.secure_channel_ok`
- Machine trust relationship with the domain is intact.
```
Domain=GTS.local
```
### Time service source
- **Category:** health
- **ID:** `health.time.source`
- Current Windows Time service source.
```
Source=GTS-SVR25.GTS.local
```
### No backup agent detected
- **Category:** health
- **ID:** `health.backup.none`
- No known backup agent service found. Backup expectation varies by endpoint; confirm whether this machine is supposed to have local/cloud backup and whether server-side or M365 backup covers it.
```
No matching backup service in Win32_Service
```
---
## Inventory Baseline Summary
- **Manufacturer / Model:** LENOVO / 90SM006QUS
- **Serial:** MJ0JAX1V
- **CPU:** 12th Gen Intel(R) Core(TM) i5-12400 (6 cores / 12 logical)
- **RAM (GB):** 15.7
- **BIOS:** M49KT29A (2024-01-04)
- **Chassis is laptop:** false
- **TPM present / Secure Boot:** true / true
- **Domain joined:** true (GTS.local)
- **OS activation licensed:** true
- **Uptime (days):** 1
- **Pending reboot:** true
- **Installed software count:** 98
- **Scheduled tasks (non-MS, enabled):** 50
- **Local administrators:** GTS\Domain Admins, GTS\pedro, GTS-W0\Administrator, GTS-W0\localadmin, GTS-W0\pgonz
### Fixed volumes
- [SYSTEM] - 0.2 GB free of 0.2 GB (76.9%)
- C: - 759.6 GB free of 929.3 GB (81.7%)
- [WinRE_DRV] - 1.1 GB free of 2 GB (58.4%)
### Network adapters
- ZeroTier Virtual Port - IP: 10.244.136.41, fe80::3d86:b469:1b75:a41a, fc2a:89c2:7ba6:1abe:37ee::1 - DNS: - DHCP: false
- Realtek PCIe GbE Family Controller - IP: 192.168.0.145, fe80::1da6:3314:1e3b:8ade - DNS: 192.168.0.2, 192.168.0.5 - DHCP: true
---
## Diff vs Prior Baseline
- No prior baseline found for this host. This is the first baseline.
---
_Generated by run-onboarding-diagnostic.sh (GuruRMM onboarding diagnostic, Phase 1). Raw snapshot: `GTS-W0-20260606T180736.json` (immutable)._

View File

@@ -0,0 +1,897 @@
{
"host": "GTS-W1",
"collected_at_utc": "2026-06-06T18:09:51Z",
"os": {
"caption": "Microsoft Windows 11 Pro for Workstations",
"version": "10.0.26200",
"build": "26200",
"install_date": "2025-03-05T16:34:47Z",
"last_boot_utc": "2026-05-13T05:55:08Z",
"architecture": "64-bit"
},
"facts": {
"builtin_admin_enabled": false,
"os_eol": {
"eol_date": "2027-10-12",
"release": "Win11 25H2"
},
"pending_updates": 3,
"pending_reboot": true,
"uptime_days": 24.5,
"acg_managed_tools": [
"ScreenConnect / ConnectWise Control",
"Splashtop (SOS/Streamer)",
"Syncro / Kabuto"
],
"hardware": {
"model": "90SM006QUS",
"manufacturer": "LENOVO",
"bios_date": "2024-01-04",
"cpu_logical": 12,
"bios_version": "M49KT29A",
"cpu_cores": 6,
"ram_gb": 15.7,
"serial": "MJ0J9LD0",
"cpu": "12th Gen Intel(R) Core(TM) i5-12400"
},
"local_administrators": [
"GTS\\Domain Admins",
"GTS\\gonzvar",
"GTS-W1\\Administrator",
"GTS-W1\\localadmin",
"GTS-W1\\pgonz"
],
"os_build": "26200",
"secure_boot": true,
"backup_agents": null,
"autoruns_run_keys": [
{
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
"name": "SecurityHealth",
"value": "C:\\WINDOWS\\system32\\SecurityHealthSystray.exe"
},
{
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
"name": "RtkAudUService",
"value": "\"C:\\WINDOWS\\System32\\DriverStore\\FileRepository\\realtekservice.inf_amd64_23392958033090bf\\RtkAudUService64.exe\" -background"
},
{
"key": "HKCU:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
"name": "GoogleDriveFS",
"value": "\"C:\\Program Files\\Google\\Drive File Stream\\126.0.5.0\\GoogleDriveFS.exe\" --startup_mode"
},
{
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
"name": "msedge_cleanup_{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}",
"value": "\"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\149.0.4022.52\\Installer\\setup.exe\" --msedge --channel=stable --delete-old-versions --system-level --verbose-logging --on-logon"
},
{
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
"name": "Delete Cached Update Binary",
"value": "C:\\WINDOWS\\system32\\cmd.exe /q /c del /q \"C:\\Program Files\\Microsoft OneDrive\\Update\\OneDriveSetup.exe\""
},
{
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
"name": "Delete Cached Standalone Update Binary",
"value": "C:\\WINDOWS\\system32\\cmd.exe /q /c del /q \"C:\\Program Files\\Microsoft OneDrive\\StandaloneUpdater\\OneDriveSetup.exe\""
}
],
"physical_disks": [
{
"health": "Healthy",
"model": "KBG40ZNV1T02 KIOXIA",
"media_type": "SSD"
}
],
"local_users": [
{
"last_logon": "2022-08-26",
"name": "Administrator",
"password_never_expires": false,
"enabled": false
},
{
"last_logon": "",
"name": "DefaultAccount",
"password_never_expires": false,
"enabled": false
},
{
"last_logon": "",
"name": "Guest",
"password_never_expires": false,
"enabled": false
},
{
"last_logon": "",
"name": "localadmin",
"password_never_expires": false,
"enabled": true
},
{
"last_logon": "",
"name": "pgonz",
"password_never_expires": false,
"enabled": true
},
{
"last_logon": "",
"name": "WDAGUtilityAccount",
"password_never_expires": false,
"enabled": false
}
],
"scheduled_tasks_count": 45,
"volumes": [
{
"drive": "[SYSTEM]",
"size_gb": 0.2,
"free_pct": 76.9,
"free_gb": 0.2
},
{
"drive": "C:",
"size_gb": 951.6,
"free_pct": 84.5,
"free_gb": 803.9
},
{
"drive": "[WinRE_DRV]",
"size_gb": 2,
"free_pct": 65,
"free_gb": 1.3
}
],
"network_adapters": [
{
"dhcp": true,
"description": "Realtek PCIe GbE Family Controller",
"gateway": [
"192.168.0.1"
],
"mac": "F4:6B:8C:C7:83:A9",
"ip": [
"192.168.0.143",
"fe80::1651:1e3f:81d6:335b"
],
"dns": [
"192.168.0.2",
"192.168.0.5"
]
}
],
"failed_autostart_services": [
{
"name": "gpsvc",
"display": "Group Policy Client",
"state": "Stopped"
},
{
"name": "Intel(R) Platform License Manager Service",
"display": "Intel(R) Platform License Manager Service",
"state": "Stopped"
},
{
"name": "SysMain",
"display": "SysMain",
"state": "Stopped"
},
{
"name": "GoogleUpdaterInternalService150.0.7863.0",
"display": "Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)",
"state": "Stopped"
},
{
"name": "GoogleUpdaterService150.0.7863.0",
"display": "Google Updater Service (GoogleUpdaterService150.0.7863.0)",
"state": "Stopped"
}
],
"stability_14d": {
"unexpected_shutdowns": 0,
"disk_errors": 0,
"bugchecks": 0
},
"exposure": {
"smb1_enabled": false,
"laps_present": true,
"rdp_enabled": false,
"uac_enabled": true,
"rdp_nla": true
},
"accounts_password_never_expires": [],
"installed_software": [
{
"publisher": "Lenovo",
"name": "Calliope_Keyboard",
"version": "1.00.08"
},
{
"publisher": "Microsoft Corporation",
"name": "Copilot",
"version": "148.0.3967.96"
},
{
"publisher": "Drake Software",
"name": "Drake Accounting 2025",
"version": "25.0.19"
},
{
"publisher": "Intel Corporation",
"name": "Dynamic Application Loader Host Interface Service",
"version": "1.0.0.0"
},
{
"publisher": "Google LLC",
"name": "Google Chrome",
"version": "148.0.7778.218"
},
{
"publisher": "Google LLC",
"name": "Google Drive",
"version": "126.0.5.0"
},
{
"publisher": "Intel(R) Corporation",
"name": "Intel(R) Chipset Device Software",
"version": "10.1.18836.8283"
},
{
"publisher": "Intel Corporation",
"name": "Intel(R) LMS",
"version": "1.0.0.0"
},
{
"publisher": "Intel Corporation",
"name": "Intel(R) Management Engine Components",
"version": "1.0.0.0"
},
{
"publisher": "Intel Corporation",
"name": "Intel(R) Management Engine Components",
"version": "2130.16.0.2387"
},
{
"publisher": "Intel Corporation",
"name": "Intel(R) Management Engine Driver",
"version": "1.0.0.0"
},
{
"publisher": "Lenovo",
"name": "Lenovo Now",
"version": "4.6.0.44"
},
{
"publisher": "Lenovo Group Ltd.",
"name": "Lenovo Vantage Service",
"version": "4.2601.31.0"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Host - 6.0.13 (x86)",
"version": "48.55.52137"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Host - 8.0.0 (x86)",
"version": "64.0.4211"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Host FX Resolver - 6.0.13 (x86)",
"version": "48.55.52137"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Host FX Resolver - 8.0.0 (x86)",
"version": "64.0.4211"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Runtime - 6.0.13 (x86)",
"version": "48.55.52137"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Runtime - 8.0.0 (x86)",
"version": "64.0.4211"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft 365 - en-us",
"version": "16.0.20026.20112"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft ASP.NET Core 8.0.0 - Shared Framework (x86)",
"version": "8.0.0.23531"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft ASP.NET Core 8.0.0 Shared Framework (x86)",
"version": "8.0.0.23531"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Edge",
"version": "149.0.4022.52"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Edge WebView2 Runtime",
"version": "148.0.3967.96"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft OneDrive",
"version": "26.088.0510.0004"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft OneNote - en-us",
"version": "16.0.20026.20112"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft SQL Server Compact 4.0 SP1 x64 ENU",
"version": "4.0.8876.1"
},
{
"publisher": "Microsoft",
"name": "Microsoft Teams Meeting Add-in for Microsoft Office",
"version": "1.25.24601"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Update Health Tools",
"version": "5.72.0.0"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.44.35211",
"version": "14.44.35211.0"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.44.35211",
"version": "14.44.35211.0"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2022 X64 Additional Runtime - 14.44.35211",
"version": "14.44.35211"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.44.35211",
"version": "14.44.35211"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2022 X86 Additional Runtime - 14.44.35211",
"version": "14.44.35211"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.44.35211",
"version": "14.44.35211"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Windows Desktop Runtime - 6.0.13 (x86)",
"version": "48.55.53270"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Windows Desktop Runtime - 6.0.13 (x86)",
"version": "6.0.13.32001"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Windows Desktop Runtime - 8.0.0 (x86)",
"version": "64.0.5329"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Windows Desktop Runtime - 8.0.0 (x86)",
"version": "8.0.0.33101"
},
{
"publisher": "Microsoft Corporation",
"name": "Office 16 Click-to-Run Extensibility Component",
"version": "16.0.20026.20076"
},
{
"publisher": "Realtek Semiconductor Corp.",
"name": "Realtek Audio Driver",
"version": "6.0.9225.1"
},
{
"publisher": "Realtek Semiconductor Corp.",
"name": "Realtek Card Reader",
"version": "10.0.26100.31287"
},
{
"publisher": "ScreenConnect Software",
"name": "ScreenConnect Client (1912bf3444b41a08)",
"version": "26.1.24.9579"
},
{
"publisher": "Splashtop Inc.",
"name": "Splashtop Streamer",
"version": "3.8.2.0"
},
{
"publisher": "Servably, Inc.",
"name": "Syncro",
"version": "1.0.201.18410"
}
],
"tpm": {
"enabled": true,
"ready": true,
"present": true
},
"local_groups": [
"Access Control Assistance Operators",
"Administrators",
"Backup Operators",
"Cryptographic Operators",
"Device Owners",
"Distributed COM Users",
"Event Log Readers",
"Guests",
"Hyper-V Administrators",
"IIS_IUSRS",
"Network Configuration Operators",
"OpenSSH Users",
"Performance Log Users",
"Performance Monitor Users",
"Power Users",
"Remote Desktop Users",
"Remote Management Users",
"Replicator",
"System Managed Accounts Group",
"User Mode Hardware Operators",
"Users"
],
"battery": {
"present": false
},
"third_party_av_active": false,
"activation": {
"edition": "Microsoft Windows 11 Pro for Workstations",
"description": "Windows(R) Operating System, VOLUME_MAK channel",
"licensed": true,
"license_status_code": 1
},
"time_source": "GTS-SVR25.GTS.local",
"chassis_types": [
3
],
"last_hotfix": {
"hotfix_id": "KB5089549",
"installed_on": "2026-05-13T07:00:00Z"
},
"scheduled_tasks": [
{
"path": "\\",
"name": "Calliope_Keyboard",
"state": "Ready"
},
{
"path": "\\",
"name": "MicrosoftEdgeUpdateTaskMachineCore",
"state": "Ready"
},
{
"path": "\\",
"name": "MicrosoftEdgeUpdateTaskMachineUA",
"state": "Ready"
},
{
"path": "\\",
"name": "OneDrive Per-Machine Standalone Update Task",
"state": "Ready"
},
{
"path": "\\",
"name": "OneDrive Reporting Task-S-1-5-21-1734567741-2755581958-76075995-1121",
"state": "Ready"
},
{
"path": "\\",
"name": "OneDrive Reporting Task-S-1-5-21-3052971633-1913791397-467572743-1001",
"state": "Ready"
},
{
"path": "\\",
"name": "OneDrive Startup Task-S-1-5-21-1734567741-2755581958-76075995-1121",
"state": "Ready"
},
{
"path": "\\",
"name": "OneDrive Startup Task-S-1-5-21-3052971633-1913791397-467572743-1001",
"state": "Ready"
},
{
"path": "\\",
"name": "OneLaunchUpdateTask",
"state": "Ready"
},
{
"path": "\\GoogleSystem\\GoogleUpdater\\",
"name": "GoogleUpdaterTaskSystem150.0.7863.0{09941C4E-E337-463E-BE02-F432DB9AD38E}",
"state": "Ready"
},
{
"path": "\\GoogleUserPEH\\",
"name": "RunPlatformExperienceHelper_Daily",
"state": "Ready"
},
{
"path": "\\GoogleUserPEH\\",
"name": "RunPlatformExperienceHelper_Metrics",
"state": "Ready"
},
{
"path": "\\Lenovo\\",
"name": "LenovoNowQuarterlyLaunch",
"state": "Ready"
},
{
"path": "\\Lenovo\\",
"name": "LenovoWelcomeLauncher",
"state": "Ready"
},
{
"path": "\\Lenovo\\",
"name": "LenovoWelcomeQuarterlyLaunch",
"state": "Ready"
},
{
"path": "\\Lenovo\\",
"name": "LenovoWelcomeTask",
"state": "Ready"
},
{
"path": "\\Lenovo\\ImController\\",
"name": "Lenovo iM Controller Monitor",
"state": "Ready"
},
{
"path": "\\Lenovo\\ImController\\",
"name": "Lenovo iM Controller Scheduled Maintenance",
"state": "Ready"
},
{
"path": "\\Lenovo\\ImController\\Plugins\\",
"name": "LenovoSystemUpdatePlugin_WeeklyTask",
"state": "Ready"
},
{
"path": "\\Lenovo\\ImController\\TimeBasedEvents\\",
"name": "44cd4312-be7a-427e-a5d6-50d4648309e5",
"state": "Ready"
},
{
"path": "\\Lenovo\\ImController\\TimeBasedEvents\\",
"name": "e3e75683-06a2-428f-8ece-9845b32c6bbe",
"state": "Ready"
},
{
"path": "\\Lenovo\\ImController\\TimeBasedEvents\\",
"name": "e8e5f7dd-7e58-4558-ac68-a494321cff6c",
"state": "Ready"
},
{
"path": "\\Lenovo\\UDC\\",
"name": "Lenovo UDC Idle Monitor",
"state": "Ready"
},
{
"path": "\\Lenovo\\UDC\\",
"name": "Lenovo UDC Lazy Deployment",
"state": "Ready"
},
{
"path": "\\Lenovo\\UDC\\",
"name": "Lenovo UDC Maintainance Task",
"state": "Ready"
},
{
"path": "\\Lenovo\\UDC\\",
"name": "Lenovo UDC Monitor",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\",
"name": "Lenovo.Vantage.ServiceMaintainance",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\",
"name": "StartupFixPlan",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "BatteryGaugeAddinDailyScheduleTask",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "ConsumerAddinDailyScheduleTask",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "DailyTelemetryTransmission",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "GenericMessagingAddin",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "GenericMessagingAddin_Pulsation",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "HeartbeatAddinDailyScheduleTask",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "Lenovo.Vantage.SmartPerformance.MonthlyReport",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "LenovoBoostAddin.Prompt",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "LenovoCompanionAppAddinDailyScheduleTask",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "LenovoSystemUpdateAddin_WeeklyTask",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "NotificationCenter",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "SmartPerformance.ExpireReminder",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "VantageCoreAddinDailyScheduleTask",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "VantageCoreAddinIdleScheduleTask",
"state": "Running"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "VantageCoreAddinWeekScheduleTask",
"state": "Ready"
},
{
"path": "\\SoftLanding\\S-1-5-21-1734567741-2755581958-76075995-1121\\",
"name": "SoftLandingCreativeManagementTask",
"state": "Ready"
},
{
"path": "\\SoftLanding\\S-1-5-21-1734567741-2755581958-76075995-1121\\",
"name": "SoftLandingDeferralTask-{06948242-2a07-4683-a193-612c85a68ebf}",
"state": "Ready"
}
],
"antivirus_products": [
"Windows Defender"
],
"domain_joined": true,
"defender": {
"antispyware_signature_age": 0,
"tamper_protected": true,
"real_time_protection": true,
"nis_enabled": true,
"available": true,
"antivirus_enabled": true,
"am_service_enabled": true
},
"bitlocker": {
"os_volume": "C:",
"key_protectors": [],
"recovery_key_present": false,
"available": true,
"encryption_percent": 0,
"protection_status": "Off"
},
"is_laptop": false,
"installed_software_count": 45,
"secure_channel_ok": true,
"firewall_profiles": {
"Private": true,
"Domain": true,
"Public": true
},
"domain": "GTS.local",
"foreign_agents": null
},
"findings": [
{
"id": "sec.defender.ok",
"category": "security",
"severity": "info",
"title": "Defender active and current",
"detail": "Real-time protection on, service running, signatures current.",
"evidence": "RealTimeProtectionEnabled=True; AMServiceEnabled=True; AntispywareSignatureAge=0 days; IsTamperProtected=True"
},
{
"id": "sec.av_products.defender_only",
"category": "security",
"severity": "info",
"title": "Defender is the only registered AV",
"detail": "Only Microsoft/Windows Defender is registered in Security Center.",
"evidence": "Windows Defender"
},
{
"id": "sec.foreign_agents.none",
"category": "security",
"severity": "info",
"title": "No competitor/leftover management agents detected",
"detail": "No known competitor RMM or unmanaged remote-access agents found in installed programs or services.",
"evidence": "Scanned uninstall hives (HKLM + WOW6432Node) and Win32_Service"
},
{
"id": "sec.foreign_agents.acg.screenconnect_connectwise_control",
"category": "security",
"severity": "info",
"title": "Expected ACG management tooling present: ScreenConnect / ConnectWise Control",
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
"evidence": "program: ScreenConnect Client (1912bf3444b41a08) 26.1.24.9579\nservice: ScreenConnect Client (1912bf3444b41a08) (ScreenConnect Client (1912bf3444b41a08)) Running"
},
{
"id": "sec.foreign_agents.acg.splashtop_sos_streamer_",
"category": "security",
"severity": "info",
"title": "Expected ACG management tooling present: Splashtop (SOS/Streamer)",
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
"evidence": "program: Splashtop Streamer 3.8.2.0\nservice: SplashtopRemoteService (Splashtop? Remote Service) Running"
},
{
"id": "sec.foreign_agents.acg.syncro_kabuto",
"category": "security",
"severity": "info",
"title": "Expected ACG management tooling present: Syncro / Kabuto",
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
"evidence": "program: Syncro 1.0.201.18410\nservice: Syncro (Syncro) Running"
},
{
"id": "sec.firewall.ok",
"category": "security",
"severity": "info",
"title": "All firewall profiles enabled",
"detail": "Domain, Private, and Public firewall profiles are all enabled.",
"evidence": "Private=True; Domain=True; Public=True"
},
{
"id": "sec.bitlocker.unencrypted",
"category": "security",
"severity": "warning",
"title": "OS volume is NOT encrypted with BitLocker",
"detail": "The operating system volume is unencrypted. Data is exposed if the disk is removed or the device is lost. Enable BitLocker and escrow the recovery key.",
"evidence": "Volume=C:; ProtectionStatus=Off; EncryptionPercentage=0; KeyProtectors="
},
{
"id": "sec.local_admins.list",
"category": "security",
"severity": "info",
"title": "Local administrators (5)",
"detail": "Members of the local Administrators group. Review for unexpected or unknown accounts (especially leftover MSP/vendor accounts from a prior provider).",
"evidence": "GTS\\Domain Admins\nGTS\\gonzvar\nGTS-W1\\Administrator\nGTS-W1\\localadmin\nGTS-W1\\pgonz"
},
{
"id": "sec.patch.os_supported",
"category": "security",
"severity": "info",
"title": "OS build supported: Win11 25H2",
"detail": "Build 26200 (Win11 25H2) is in support until 2027-10-12.",
"evidence": "Microsoft Windows 11 Pro for Workstations build 26200"
},
{
"id": "sec.patch.pending",
"category": "security",
"severity": "warning",
"title": "3 pending Windows updates",
"detail": "Windows Update reports pending (not installed, not hidden) updates. Some may be security updates. Approve/install on the next maintenance window.",
"evidence": "Microsoft.Update.Session search IsInstalled=0 and IsHidden=0 -> 3"
},
{
"id": "sec.patch.last_hotfix",
"category": "security",
"severity": "info",
"title": "Last hotfix: KB5089549",
"detail": "Most recently installed update (from Get-HotFix; reflects CBS/MSU packages, not all cumulative metadata).",
"evidence": "KB5089549 installed 2026-05-13T07:00:00Z"
},
{
"id": "sec.exposure.smb1_off",
"category": "security",
"severity": "info",
"title": "SMBv1 disabled",
"detail": "SMBv1 server protocol is disabled.",
"evidence": "EnableSMB1Protocol=False"
},
{
"id": "sec.exposure.laps_present",
"category": "security",
"severity": "info",
"title": "LAPS detected",
"detail": "A LAPS mechanism is present.",
"evidence": "Windows LAPS reg key"
},
{
"id": "health.stability.clean",
"category": "health",
"severity": "info",
"title": "No stability events in the last 14 days",
"detail": "No unexpected shutdowns, BSODs, or disk errors logged.",
"evidence": "Unexpected shutdowns (id 41)=0; Bugchecks/BSOD (id 1001)=0; Disk errors (id 7/51/153)=0"
},
{
"id": "health.reboot_uptime.pending",
"category": "health",
"severity": "warning",
"title": "Reboot pending",
"detail": "A reboot is pending. Pending reboots can block patches and leave the system in a half-updated state. Schedule a restart.",
"evidence": "PendingFileRenameOperations"
},
{
"id": "health.failed_services.stopped",
"category": "health",
"severity": "warning",
"title": "5 auto-start service(s) not running",
"detail": "These services are set to start automatically but are not running. Some may be benign; review for security agents, backup agents, or AV that should be running.",
"evidence": "gpsvc (Group Policy Client) = Stopped\nIntel(R) Platform License Manager Service (Intel(R) Platform License Manager Service) = Stopped\nSysMain (SysMain) = Stopped\nGoogleUpdaterInternalService150.0.7863.0 (Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)) = Stopped\nGoogleUpdaterService150.0.7863.0 (Google Updater Service (GoogleUpdaterService150.0.7863.0)) = Stopped"
},
{
"id": "health.domain.secure_channel_ok",
"category": "health",
"severity": "info",
"title": "Domain secure channel healthy",
"detail": "Machine trust relationship with the domain is intact.",
"evidence": "Domain=GTS.local"
},
{
"id": "health.time.source",
"category": "health",
"severity": "info",
"title": "Time service source",
"detail": "Current Windows Time service source.",
"evidence": "Source=GTS-SVR25.GTS.local"
},
{
"id": "health.backup.none",
"category": "health",
"severity": "info",
"title": "No backup agent detected",
"detail": "No known backup agent service found. Backup expectation varies by endpoint; confirm whether this machine is supposed to have local/cloud backup and whether server-side or M365 backup covers it.",
"evidence": "No matching backup service in Win32_Service"
}
]
}

View File

@@ -0,0 +1,249 @@
# Onboarding Diagnostic Baseline - GTS-W1
- **Grade:** AMBER
- **Host:** GTS-W1
- **Client:** Gonzvar Tax Services (`gonzvar-tax-services`)
- **Collected (UTC):** 2026-06-06T18:09:51Z
- **Agent ID:** 151c0c38-eb28-48c7-87d8-51ef8d81cc75
- **Command ID:** 748d8235-1d1f-4015-a74e-f03c4aade06b
- **Findings:** 0 critical / 4 warning / 16 info / 0 unknown
- **OS:** Microsoft Windows 11 Pro for Workstations (build 26200)
---
## WARNING (4)
### OS volume is NOT encrypted with BitLocker
- **Category:** security
- **ID:** `sec.bitlocker.unencrypted`
- The operating system volume is unencrypted. Data is exposed if the disk is removed or the device is lost. Enable BitLocker and escrow the recovery key.
```
Volume=C:; ProtectionStatus=Off; EncryptionPercentage=0; KeyProtectors=
```
### 3 pending Windows updates
- **Category:** security
- **ID:** `sec.patch.pending`
- Windows Update reports pending (not installed, not hidden) updates. Some may be security updates. Approve/install on the next maintenance window.
```
Microsoft.Update.Session search IsInstalled=0 and IsHidden=0 -> 3
```
### Reboot pending
- **Category:** health
- **ID:** `health.reboot_uptime.pending`
- A reboot is pending. Pending reboots can block patches and leave the system in a half-updated state. Schedule a restart.
```
PendingFileRenameOperations
```
### 5 auto-start service(s) not running
- **Category:** health
- **ID:** `health.failed_services.stopped`
- These services are set to start automatically but are not running. Some may be benign; review for security agents, backup agents, or AV that should be running.
```
gpsvc (Group Policy Client) = Stopped
Intel(R) Platform License Manager Service (Intel(R) Platform License Manager Service) = Stopped
SysMain (SysMain) = Stopped
GoogleUpdaterInternalService150.0.7863.0 (Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)) = Stopped
GoogleUpdaterService150.0.7863.0 (Google Updater Service (GoogleUpdaterService150.0.7863.0)) = Stopped
```
## INFO (16)
### Defender active and current
- **Category:** security
- **ID:** `sec.defender.ok`
- Real-time protection on, service running, signatures current.
```
RealTimeProtectionEnabled=True; AMServiceEnabled=True; AntispywareSignatureAge=0 days; IsTamperProtected=True
```
### Defender is the only registered AV
- **Category:** security
- **ID:** `sec.av_products.defender_only`
- Only Microsoft/Windows Defender is registered in Security Center.
```
Windows Defender
```
### No competitor/leftover management agents detected
- **Category:** security
- **ID:** `sec.foreign_agents.none`
- No known competitor RMM or unmanaged remote-access agents found in installed programs or services.
```
Scanned uninstall hives (HKLM + WOW6432Node) and Win32_Service
```
### Expected ACG management tooling present: ScreenConnect / ConnectWise Control
- **Category:** security
- **ID:** `sec.foreign_agents.acg.screenconnect_connectwise_control`
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
```
program: ScreenConnect Client (1912bf3444b41a08) 26.1.24.9579
service: ScreenConnect Client (1912bf3444b41a08) (ScreenConnect Client (1912bf3444b41a08)) Running
```
### Expected ACG management tooling present: Splashtop (SOS/Streamer)
- **Category:** security
- **ID:** `sec.foreign_agents.acg.splashtop_sos_streamer_`
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
```
program: Splashtop Streamer 3.8.2.0
service: SplashtopRemoteService (Splashtop? Remote Service) Running
```
### Expected ACG management tooling present: Syncro / Kabuto
- **Category:** security
- **ID:** `sec.foreign_agents.acg.syncro_kabuto`
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
```
program: Syncro 1.0.201.18410
service: Syncro (Syncro) Running
```
### All firewall profiles enabled
- **Category:** security
- **ID:** `sec.firewall.ok`
- Domain, Private, and Public firewall profiles are all enabled.
```
Private=True; Domain=True; Public=True
```
### Local administrators (5)
- **Category:** security
- **ID:** `sec.local_admins.list`
- Members of the local Administrators group. Review for unexpected or unknown accounts (especially leftover MSP/vendor accounts from a prior provider).
```
GTS\Domain Admins
GTS\gonzvar
GTS-W1\Administrator
GTS-W1\localadmin
GTS-W1\pgonz
```
### OS build supported: Win11 25H2
- **Category:** security
- **ID:** `sec.patch.os_supported`
- Build 26200 (Win11 25H2) is in support until 2027-10-12.
```
Microsoft Windows 11 Pro for Workstations build 26200
```
### Last hotfix: KB5089549
- **Category:** security
- **ID:** `sec.patch.last_hotfix`
- Most recently installed update (from Get-HotFix; reflects CBS/MSU packages, not all cumulative metadata).
```
KB5089549 installed 2026-05-13T07:00:00Z
```
### SMBv1 disabled
- **Category:** security
- **ID:** `sec.exposure.smb1_off`
- SMBv1 server protocol is disabled.
```
EnableSMB1Protocol=False
```
### LAPS detected
- **Category:** security
- **ID:** `sec.exposure.laps_present`
- A LAPS mechanism is present.
```
Windows LAPS reg key
```
### No stability events in the last 14 days
- **Category:** health
- **ID:** `health.stability.clean`
- No unexpected shutdowns, BSODs, or disk errors logged.
```
Unexpected shutdowns (id 41)=0; Bugchecks/BSOD (id 1001)=0; Disk errors (id 7/51/153)=0
```
### Domain secure channel healthy
- **Category:** health
- **ID:** `health.domain.secure_channel_ok`
- Machine trust relationship with the domain is intact.
```
Domain=GTS.local
```
### Time service source
- **Category:** health
- **ID:** `health.time.source`
- Current Windows Time service source.
```
Source=GTS-SVR25.GTS.local
```
### No backup agent detected
- **Category:** health
- **ID:** `health.backup.none`
- No known backup agent service found. Backup expectation varies by endpoint; confirm whether this machine is supposed to have local/cloud backup and whether server-side or M365 backup covers it.
```
No matching backup service in Win32_Service
```
---
## Inventory Baseline Summary
- **Manufacturer / Model:** LENOVO / 90SM006QUS
- **Serial:** MJ0J9LD0
- **CPU:** 12th Gen Intel(R) Core(TM) i5-12400 (6 cores / 12 logical)
- **RAM (GB):** 15.7
- **BIOS:** M49KT29A (2024-01-04)
- **Chassis is laptop:** false
- **TPM present / Secure Boot:** true / true
- **Domain joined:** true (GTS.local)
- **OS activation licensed:** true
- **Uptime (days):** 24.5
- **Pending reboot:** true
- **Installed software count:** 45
- **Scheduled tasks (non-MS, enabled):** 45
- **Local administrators:** GTS\Domain Admins, GTS\gonzvar, GTS-W1\Administrator, GTS-W1\localadmin, GTS-W1\pgonz
### Fixed volumes
- [SYSTEM] - 0.2 GB free of 0.2 GB (76.9%)
- C: - 803.9 GB free of 951.6 GB (84.5%)
- [WinRE_DRV] - 1.3 GB free of 2 GB (65%)
### Network adapters
- Realtek PCIe GbE Family Controller - IP: 192.168.0.143, fe80::1651:1e3f:81d6:335b - DNS: 192.168.0.2, 192.168.0.5 - DHCP: true
---
## Diff vs Prior Baseline
- No prior baseline found for this host. This is the first baseline.
---
_Generated by run-onboarding-diagnostic.sh (GuruRMM onboarding diagnostic, Phase 1). Raw snapshot: `GTS-W1-20260606T180908.json` (immutable)._

View File

@@ -0,0 +1,912 @@
{
"host": "GTS-W2",
"collected_at_utc": "2026-06-06T18:11:25Z",
"os": {
"caption": "Microsoft Windows 11 Pro for Workstations",
"version": "10.0.26200",
"build": "26200",
"install_date": "2025-02-21T09:16:13Z",
"last_boot_utc": "2026-04-17T22:07:40Z",
"architecture": "64-bit"
},
"facts": {
"builtin_admin_enabled": false,
"os_eol": {
"eol_date": "2027-10-12",
"release": "Win11 25H2"
},
"pending_updates": 6,
"pending_reboot": true,
"uptime_days": 49.8,
"acg_managed_tools": [
"ScreenConnect / ConnectWise Control",
"Splashtop (SOS/Streamer)",
"Syncro / Kabuto"
],
"hardware": {
"model": "90SM006QUS",
"manufacturer": "LENOVO",
"bios_date": "2024-01-04",
"cpu_logical": 12,
"bios_version": "M49KT29A",
"cpu_cores": 6,
"ram_gb": 15.7,
"serial": "MJ0JAWPT",
"cpu": "12th Gen Intel(R) Core(TM) i5-12400"
},
"local_administrators": [
"GTS\\Domain Admins",
"GTS\\gonzvar",
"GTS-W2\\Administrator",
"GTS-W2\\localadmin",
"GTS-W2\\pgonz"
],
"os_build": "26200",
"secure_boot": true,
"backup_agents": null,
"autoruns_run_keys": [
{
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
"name": "SecurityHealth",
"value": "C:\\WINDOWS\\system32\\SecurityHealthSystray.exe"
},
{
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
"name": "RtkAudUService",
"value": "\"C:\\WINDOWS\\System32\\DriverStore\\FileRepository\\realtekservice.inf_amd64_23392958033090bf\\RtkAudUService64.exe\" -background"
}
],
"physical_disks": [
{
"health": "Healthy",
"model": "KINGSTON SNV2S1000G",
"media_type": "SSD"
}
],
"local_users": [
{
"last_logon": "2022-08-26",
"name": "Administrator",
"password_never_expires": false,
"enabled": false
},
{
"last_logon": "",
"name": "DefaultAccount",
"password_never_expires": false,
"enabled": false
},
{
"last_logon": "",
"name": "Guest",
"password_never_expires": false,
"enabled": false
},
{
"last_logon": "",
"name": "localadmin",
"password_never_expires": false,
"enabled": true
},
{
"last_logon": "",
"name": "pgonz",
"password_never_expires": false,
"enabled": true
},
{
"last_logon": "",
"name": "WDAGUtilityAccount",
"password_never_expires": false,
"enabled": false
}
],
"scheduled_tasks_count": 46,
"volumes": [
{
"drive": "[SYSTEM]",
"size_gb": 0.2,
"free_pct": 76.9,
"free_gb": 0.2
},
{
"drive": "C:",
"size_gb": 929.3,
"free_pct": 81.4,
"free_gb": 756.7
},
{
"drive": "[WinRE_DRV]",
"size_gb": 2,
"free_pct": 60.2,
"free_gb": 1.2
}
],
"network_adapters": [
{
"dhcp": true,
"description": "Realtek PCIe GbE Family Controller",
"gateway": [
"192.168.0.1"
],
"mac": "F4:6B:8C:C7:84:BC",
"ip": [
"192.168.0.146",
"fe80::826b:1844:b416:d971"
],
"dns": [
"192.168.0.2",
"192.168.0.5"
]
}
],
"failed_autostart_services": [
{
"name": "Intel(R) Platform License Manager Service",
"display": "Intel(R) Platform License Manager Service",
"state": "Stopped"
},
{
"name": "GoogleUpdaterInternalService150.0.7863.0",
"display": "Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)",
"state": "Stopped"
},
{
"name": "GoogleUpdaterService150.0.7863.0",
"display": "Google Updater Service (GoogleUpdaterService150.0.7863.0)",
"state": "Stopped"
}
],
"stability_14d": {
"unexpected_shutdowns": 0,
"disk_errors": 0,
"bugchecks": 0
},
"exposure": {
"smb1_enabled": false,
"laps_present": true,
"rdp_enabled": false,
"uac_enabled": true,
"rdp_nla": true
},
"accounts_password_never_expires": [],
"installed_software": [
{
"publisher": "Adobe",
"name": "Adobe Acrobat (64-bit)",
"version": "26.001.21563"
},
{
"publisher": "Adobe Systems Incorporated",
"name": "Adobe Refresh Manager",
"version": "1.8.0"
},
{
"publisher": "Bitdefender",
"name": "Bitdefender Endpoint Security Tools",
"version": "8.26.6.644"
},
{
"publisher": "Lenovo",
"name": "Calliope_Keyboard",
"version": "1.00.08"
},
{
"publisher": "Microsoft Corporation",
"name": "Copilot",
"version": "147.0.3912.60"
},
{
"publisher": "Drake Software",
"name": "Drake Accounting 2025",
"version": "25.0.18"
},
{
"publisher": "Intel Corporation",
"name": "Dynamic Application Loader Host Interface Service",
"version": "1.0.0.0"
},
{
"publisher": "Google LLC",
"name": "Google Chrome",
"version": "148.0.7778.217"
},
{
"publisher": "",
"name": "Ingenico USB Drivers 3.40 (remove only)",
"version": "3.40"
},
{
"publisher": "Intel Corporation",
"name": "Intel(R) Chipset Device Software",
"version": "10.1.18836.8283"
},
{
"publisher": "Intel Corporation",
"name": "Intel(R) LMS",
"version": "1.0.0.0"
},
{
"publisher": "Intel Corporation",
"name": "Intel(R) Management Engine Components",
"version": "1.0.0.0"
},
{
"publisher": "Intel Corporation",
"name": "Intel(R) Management Engine Components",
"version": "2130.16.0.2387"
},
{
"publisher": "Intel Corporation",
"name": "Intel(R) Management Engine Driver",
"version": "1.0.0.0"
},
{
"publisher": "Lenovo",
"name": "Lenovo Now",
"version": "4.4.0.61"
},
{
"publisher": "Lenovo Group Ltd.",
"name": "Lenovo Vantage Service",
"version": "4.2601.31.0"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Host - 6.0.13 (x86)",
"version": "48.55.52137"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Host - 8.0.0 (x86)",
"version": "64.0.4211"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Host FX Resolver - 6.0.13 (x86)",
"version": "48.55.52137"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Host FX Resolver - 8.0.0 (x86)",
"version": "64.0.4211"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Runtime - 6.0.13 (x86)",
"version": "48.55.52137"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Runtime - 8.0.0 (x86)",
"version": "64.0.4211"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft 365 - en-us",
"version": "16.0.19822.20168"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft ASP.NET Core 8.0.0 - Shared Framework (x86)",
"version": "8.0.0.23531"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft ASP.NET Core 8.0.0 Shared Framework (x86)",
"version": "8.0.0.23531"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Edge",
"version": "147.0.3912.60"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Edge WebView2 Runtime",
"version": "147.0.3912.60"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft OneNote - en-us",
"version": "16.0.19822.20168"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft SQL Server Compact 4.0 SP1 x64 ENU",
"version": "4.0.8876.1"
},
{
"publisher": "Microsoft",
"name": "Microsoft Teams Meeting Add-in for Microsoft Office",
"version": "1.24.25506"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Update Health Tools",
"version": "5.72.0.0"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.44.35211",
"version": "14.44.35211.0"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.44.35211",
"version": "14.44.35211.0"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2022 X64 Additional Runtime - 14.44.35211",
"version": "14.44.35211"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.44.35211",
"version": "14.44.35211"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2022 X86 Additional Runtime - 14.44.35211",
"version": "14.44.35211"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.44.35211",
"version": "14.44.35211"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Windows Desktop Runtime - 6.0.13 (x86)",
"version": "48.55.53270"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Windows Desktop Runtime - 6.0.13 (x86)",
"version": "6.0.13.32001"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Windows Desktop Runtime - 8.0.0 (x86)",
"version": "64.0.5329"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Windows Desktop Runtime - 8.0.0 (x86)",
"version": "8.0.0.33101"
},
{
"publisher": "Microsoft Corporation",
"name": "Office 16 Click-to-Run Extensibility Component",
"version": "16.0.19822.20104"
},
{
"publisher": "Sober Lemur S.r.l.",
"name": "PDFsam Visual",
"version": "4.3.0"
},
{
"publisher": "Realtek Semiconductor Corp.",
"name": "Realtek Audio Driver",
"version": "6.0.9225.1"
},
{
"publisher": "Realtek Semiconductor Corp.",
"name": "Realtek Card Reader",
"version": "10.0.26100.31287"
},
{
"publisher": "ScreenConnect Software",
"name": "ScreenConnect Client (1912bf3444b41a08)",
"version": "26.1.24.9579"
},
{
"publisher": "Splashtop Inc.",
"name": "Splashtop Streamer",
"version": "3.8.2.0"
},
{
"publisher": "Servably, Inc.",
"name": "Syncro",
"version": "1.0.201.18410"
}
],
"tpm": {
"enabled": true,
"ready": true,
"present": true
},
"local_groups": [
"Access Control Assistance Operators",
"Administrators",
"Backup Operators",
"Cryptographic Operators",
"Device Owners",
"Distributed COM Users",
"Event Log Readers",
"Guests",
"Hyper-V Administrators",
"IIS_IUSRS",
"Network Configuration Operators",
"OpenSSH Users",
"Performance Log Users",
"Performance Monitor Users",
"Power Users",
"Remote Desktop Users",
"Remote Management Users",
"Replicator",
"System Managed Accounts Group",
"User Mode Hardware Operators",
"Users"
],
"battery": {
"present": false
},
"third_party_av_active": true,
"activation": {
"edition": "Microsoft Windows 11 Pro for Workstations",
"description": "Windows(R) Operating System, VOLUME_MAK channel",
"licensed": true,
"license_status_code": 1
},
"time_source": "GTS-SVR25.GTS.local",
"chassis_types": [
3
],
"last_hotfix": {
"hotfix_id": "KB5083769",
"installed_on": "2026-04-15T07:00:00Z"
},
"scheduled_tasks": [
{
"path": "\\",
"name": "Adobe Acrobat Update Task",
"state": "Ready"
},
{
"path": "\\",
"name": "Calliope_Keyboard",
"state": "Ready"
},
{
"path": "\\",
"name": "MicrosoftEdgeUpdateTaskMachineCore",
"state": "Ready"
},
{
"path": "\\",
"name": "MicrosoftEdgeUpdateTaskMachineUA",
"state": "Ready"
},
{
"path": "\\",
"name": "OneDrive Reporting Task-S-1-5-21-1734567741-2755581958-76075995-1121",
"state": "Ready"
},
{
"path": "\\",
"name": "OneDrive Reporting Task-S-1-5-21-3052971633-1913791397-467572743-1001",
"state": "Ready"
},
{
"path": "\\",
"name": "OneDrive Standalone Update Task-S-1-5-21-1734567741-2755581958-76075995-1121",
"state": "Ready"
},
{
"path": "\\",
"name": "OneDrive Standalone Update Task-S-1-5-21-3052971633-1913791397-467572743-1001",
"state": "Ready"
},
{
"path": "\\",
"name": "OneDrive Startup Task-S-1-5-21-1734567741-2755581958-76075995-1121",
"state": "Ready"
},
{
"path": "\\GoogleSystem\\GoogleUpdater\\",
"name": "GoogleUpdaterTaskSystem150.0.7863.0{12AFA30B-C755-45D6-85CC-33CDD9BF2243}",
"state": "Ready"
},
{
"path": "\\GoogleUserPEH\\",
"name": "RunPlatformExperienceHelper_Daily",
"state": "Ready"
},
{
"path": "\\Lenovo\\",
"name": "LenovoNowQuarterlyLaunch",
"state": "Ready"
},
{
"path": "\\Lenovo\\",
"name": "LenovoWelcomeLauncher",
"state": "Ready"
},
{
"path": "\\Lenovo\\",
"name": "LenovoWelcomeQuarterlyLaunch",
"state": "Ready"
},
{
"path": "\\Lenovo\\",
"name": "LenovoWelcomeTask",
"state": "Ready"
},
{
"path": "\\Lenovo\\ImController\\",
"name": "Lenovo iM Controller Monitor",
"state": "Ready"
},
{
"path": "\\Lenovo\\ImController\\",
"name": "Lenovo iM Controller Scheduled Maintenance",
"state": "Ready"
},
{
"path": "\\Lenovo\\ImController\\Plugins\\",
"name": "LenovoSystemUpdatePlugin_WeeklyTask",
"state": "Ready"
},
{
"path": "\\Lenovo\\ImController\\TimeBasedEvents\\",
"name": "05655d16-248b-4767-838a-1fde57338d36",
"state": "Ready"
},
{
"path": "\\Lenovo\\ImController\\TimeBasedEvents\\",
"name": "ea1a50a7-715a-4c26-b922-ac42ec877042",
"state": "Ready"
},
{
"path": "\\Lenovo\\ImController\\TimeBasedEvents\\",
"name": "fea6f267-63b1-48d6-ac80-caab635a514f",
"state": "Ready"
},
{
"path": "\\Lenovo\\UDC\\",
"name": "Lenovo UDC Idle Monitor",
"state": "Ready"
},
{
"path": "\\Lenovo\\UDC\\",
"name": "Lenovo UDC Lazy Deployment",
"state": "Ready"
},
{
"path": "\\Lenovo\\UDC\\",
"name": "Lenovo UDC Maintainance Task",
"state": "Ready"
},
{
"path": "\\Lenovo\\UDC\\",
"name": "Lenovo UDC Monitor",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\",
"name": "Lenovo.Vantage.ServiceMaintainance",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\",
"name": "StartupFixPlan",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "BatteryGaugeAddinDailyScheduleTask",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "ConsumerAddinDailyScheduleTask",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "DailyTelemetryTransmission",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "GenericMessagingAddin",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "GenericMessagingAddin_Pulsation",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "HeartbeatAddinDailyScheduleTask",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "Lenovo.Vantage.SmartPerformance.MonthlyReport",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "LenovoBoostAddin.Prompt",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "LenovoCompanionAppAddinDailyScheduleTask",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "LenovoSystemUpdateAddin_WeeklyTask",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "NotificationCenter",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "SmartLock.ExpireReminder",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "SmartPerformance.ExpireReminder",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "VantageCoreAddinDailyScheduleTask",
"state": "Ready"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "VantageCoreAddinIdleScheduleTask",
"state": "Running"
},
{
"path": "\\Lenovo\\Vantage\\Schedule\\",
"name": "VantageCoreAddinWeekScheduleTask",
"state": "Ready"
},
{
"path": "\\McAfeeTsk\\",
"name": "OOBEUpgrader",
"state": "Ready"
},
{
"path": "\\SoftLanding\\S-1-5-21-1734567741-2755581958-76075995-1121\\",
"name": "SoftLandingCreativeManagementTask",
"state": "Ready"
},
{
"path": "\\SoftLanding\\S-1-5-21-1734567741-2755581958-76075995-1121\\",
"name": "SoftLandingDeferralTask-{94a334fe-d698-472a-a23e-c320fa58dbdd}",
"state": "Ready"
}
],
"antivirus_products": [
"Windows Defender",
"Bitdefender Endpoint Security Tools Antimalware"
],
"domain_joined": true,
"defender": {
"antispyware_signature_age": 0,
"tamper_protected": false,
"real_time_protection": false,
"nis_enabled": false,
"available": true,
"antivirus_enabled": false,
"am_service_enabled": false
},
"bitlocker": {
"os_volume": "C:",
"key_protectors": [],
"recovery_key_present": false,
"available": true,
"encryption_percent": 0,
"protection_status": "Off"
},
"is_laptop": false,
"installed_software_count": 48,
"secure_channel_ok": true,
"firewall_profiles": {
"Private": true,
"Domain": true,
"Public": true
},
"domain": "GTS.local",
"foreign_agents": null
},
"findings": [
{
"id": "sec.defender.rtp_off",
"category": "security",
"severity": "info",
"title": "Defender real-time protection is OFF (3rd-party AV active)",
"detail": "Defender real-time protection is off because a managed/known 3rd-party AV is active. Windows disables Defender real-time protection when another AV registers, so this is expected. Confirm the 3rd-party AV is providing real-time protection.",
"evidence": "RealTimeProtectionEnabled=False; AMServiceEnabled=False; AntispywareSignatureAge=0 days; IsTamperProtected=False; SecurityCenter2 AntiVirusProduct: Bitdefender Endpoint Security Tools Antimalware (productState=0x41000, RTP on)"
},
{
"id": "sec.defender.amservice_off",
"category": "security",
"severity": "info",
"title": "Defender antimalware service is not running (3rd-party AV active)",
"detail": "The Defender antimalware service is not active because a managed/known 3rd-party AV is registered. Windows stands Defender down when another AV provides protection, so this is expected. Confirm the 3rd-party AV is running.",
"evidence": "RealTimeProtectionEnabled=False; AMServiceEnabled=False; AntispywareSignatureAge=0 days; IsTamperProtected=False; SecurityCenter2 AntiVirusProduct: Bitdefender Endpoint Security Tools Antimalware (productState=0x41000, RTP on)"
},
{
"id": "sec.defender.tamper_off",
"category": "security",
"severity": "warning",
"title": "Defender tamper protection is OFF",
"detail": "Tamper protection is disabled, so malware or a local admin can silently disable Defender. Enable tamper protection (typically via Intune / Security Center).",
"evidence": "RealTimeProtectionEnabled=False; AMServiceEnabled=False; AntispywareSignatureAge=0 days; IsTamperProtected=False"
},
{
"id": "sec.av_products.third_party",
"category": "security",
"severity": "warning",
"title": "Third-party AV present: Bitdefender Endpoint Security Tools Antimalware",
"detail": "A non-Defender antivirus is registered. Running two real-time AV engines causes conflicts, performance loss, and detection gaps. Confirm the intended AV and ensure only one provides real-time protection.",
"evidence": "Registered AV: Windows Defender, Bitdefender Endpoint Security Tools Antimalware"
},
{
"id": "sec.foreign_agents.none",
"category": "security",
"severity": "info",
"title": "No competitor/leftover management agents detected",
"detail": "No known competitor RMM or unmanaged remote-access agents found in installed programs or services.",
"evidence": "Scanned uninstall hives (HKLM + WOW6432Node) and Win32_Service"
},
{
"id": "sec.foreign_agents.acg.screenconnect_connectwise_control",
"category": "security",
"severity": "info",
"title": "Expected ACG management tooling present: ScreenConnect / ConnectWise Control",
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
"evidence": "program: ScreenConnect Client (1912bf3444b41a08) 26.1.24.9579\nservice: ScreenConnect Client (1912bf3444b41a08) (ScreenConnect Client (1912bf3444b41a08)) Running"
},
{
"id": "sec.foreign_agents.acg.splashtop_sos_streamer_",
"category": "security",
"severity": "info",
"title": "Expected ACG management tooling present: Splashtop (SOS/Streamer)",
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
"evidence": "program: Splashtop Streamer 3.8.2.0\nservice: SplashtopRemoteService (Splashtop? Remote Service) Running"
},
{
"id": "sec.foreign_agents.acg.syncro_kabuto",
"category": "security",
"severity": "info",
"title": "Expected ACG management tooling present: Syncro / Kabuto",
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
"evidence": "program: Syncro 1.0.201.18410\nservice: Syncro (Syncro) Running"
},
{
"id": "sec.firewall.ok",
"category": "security",
"severity": "info",
"title": "All firewall profiles enabled",
"detail": "Domain, Private, and Public firewall profiles are all enabled.",
"evidence": "Private=True; Domain=True; Public=True"
},
{
"id": "sec.bitlocker.unencrypted",
"category": "security",
"severity": "warning",
"title": "OS volume is NOT encrypted with BitLocker",
"detail": "The operating system volume is unencrypted. Data is exposed if the disk is removed or the device is lost. Enable BitLocker and escrow the recovery key.",
"evidence": "Volume=C:; ProtectionStatus=Off; EncryptionPercentage=0; KeyProtectors="
},
{
"id": "sec.local_admins.list",
"category": "security",
"severity": "info",
"title": "Local administrators (5)",
"detail": "Members of the local Administrators group. Review for unexpected or unknown accounts (especially leftover MSP/vendor accounts from a prior provider).",
"evidence": "GTS\\Domain Admins\nGTS\\gonzvar\nGTS-W2\\Administrator\nGTS-W2\\localadmin\nGTS-W2\\pgonz"
},
{
"id": "sec.patch.os_supported",
"category": "security",
"severity": "info",
"title": "OS build supported: Win11 25H2",
"detail": "Build 26200 (Win11 25H2) is in support until 2027-10-12.",
"evidence": "Microsoft Windows 11 Pro for Workstations build 26200"
},
{
"id": "sec.patch.pending",
"category": "security",
"severity": "warning",
"title": "6 pending Windows updates",
"detail": "Windows Update reports pending (not installed, not hidden) updates. Some may be security updates. Approve/install on the next maintenance window.",
"evidence": "Microsoft.Update.Session search IsInstalled=0 and IsHidden=0 -> 6"
},
{
"id": "sec.patch.last_hotfix",
"category": "security",
"severity": "info",
"title": "Last hotfix: KB5083769",
"detail": "Most recently installed update (from Get-HotFix; reflects CBS/MSU packages, not all cumulative metadata).",
"evidence": "KB5083769 installed 2026-04-15T07:00:00Z"
},
{
"id": "sec.exposure.smb1_off",
"category": "security",
"severity": "info",
"title": "SMBv1 disabled",
"detail": "SMBv1 server protocol is disabled.",
"evidence": "EnableSMB1Protocol=False"
},
{
"id": "sec.exposure.laps_present",
"category": "security",
"severity": "info",
"title": "LAPS detected",
"detail": "A LAPS mechanism is present.",
"evidence": "Windows LAPS reg key"
},
{
"id": "health.stability.clean",
"category": "health",
"severity": "info",
"title": "No stability events in the last 14 days",
"detail": "No unexpected shutdowns, BSODs, or disk errors logged.",
"evidence": "Unexpected shutdowns (id 41)=0; Bugchecks/BSOD (id 1001)=0; Disk errors (id 7/51/153)=0"
},
{
"id": "health.reboot_uptime.pending",
"category": "health",
"severity": "warning",
"title": "Reboot pending",
"detail": "A reboot is pending. Pending reboots can block patches and leave the system in a half-updated state. Schedule a restart.",
"evidence": "PendingFileRenameOperations"
},
{
"id": "health.reboot_uptime.long_uptime",
"category": "health",
"severity": "warning",
"title": "Uptime is 49.8 days",
"detail": "Uptime exceeds 30 days. Long uptime usually means pending updates have not been applied (reboots deferred). Schedule maintenance.",
"evidence": "LastBootUpTime=2026-04-17 15:07:40Z"
},
{
"id": "health.failed_services.stopped",
"category": "health",
"severity": "warning",
"title": "3 auto-start service(s) not running",
"detail": "These services are set to start automatically but are not running. Some may be benign; review for security agents, backup agents, or AV that should be running.",
"evidence": "Intel(R) Platform License Manager Service (Intel(R) Platform License Manager Service) = Stopped\nGoogleUpdaterInternalService150.0.7863.0 (Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)) = Stopped\nGoogleUpdaterService150.0.7863.0 (Google Updater Service (GoogleUpdaterService150.0.7863.0)) = Stopped"
},
{
"id": "health.domain.secure_channel_ok",
"category": "health",
"severity": "info",
"title": "Domain secure channel healthy",
"detail": "Machine trust relationship with the domain is intact.",
"evidence": "Domain=GTS.local"
},
{
"id": "health.time.source",
"category": "health",
"severity": "info",
"title": "Time service source",
"detail": "Current Windows Time service source.",
"evidence": "Source=GTS-SVR25.GTS.local"
},
{
"id": "health.backup.none",
"category": "health",
"severity": "info",
"title": "No backup agent detected",
"detail": "No known backup agent service found. Backup expectation varies by endpoint; confirm whether this machine is supposed to have local/cloud backup and whether server-side or M365 backup covers it.",
"evidence": "No matching backup service in Win32_Service"
}
]
}

View File

@@ -0,0 +1,274 @@
# Onboarding Diagnostic Baseline - GTS-W2
- **Grade:** AMBER
- **Host:** GTS-W2
- **Client:** Gonzvar Tax Services (`gonzvar-tax-services`)
- **Collected (UTC):** 2026-06-06T18:11:25Z
- **Agent ID:** d0c703c1-c9c9-4763-b219-d24442882fb6
- **Command ID:** 447f17bd-9c1b-473a-9cd4-a45d90ced9cd
- **Findings:** 0 critical / 7 warning / 16 info / 0 unknown
- **OS:** Microsoft Windows 11 Pro for Workstations (build 26200)
---
## WARNING (7)
### Defender tamper protection is OFF
- **Category:** security
- **ID:** `sec.defender.tamper_off`
- Tamper protection is disabled, so malware or a local admin can silently disable Defender. Enable tamper protection (typically via Intune / Security Center).
```
RealTimeProtectionEnabled=False; AMServiceEnabled=False; AntispywareSignatureAge=0 days; IsTamperProtected=False
```
### Third-party AV present: Bitdefender Endpoint Security Tools Antimalware
- **Category:** security
- **ID:** `sec.av_products.third_party`
- A non-Defender antivirus is registered. Running two real-time AV engines causes conflicts, performance loss, and detection gaps. Confirm the intended AV and ensure only one provides real-time protection.
```
Registered AV: Windows Defender, Bitdefender Endpoint Security Tools Antimalware
```
### OS volume is NOT encrypted with BitLocker
- **Category:** security
- **ID:** `sec.bitlocker.unencrypted`
- The operating system volume is unencrypted. Data is exposed if the disk is removed or the device is lost. Enable BitLocker and escrow the recovery key.
```
Volume=C:; ProtectionStatus=Off; EncryptionPercentage=0; KeyProtectors=
```
### 6 pending Windows updates
- **Category:** security
- **ID:** `sec.patch.pending`
- Windows Update reports pending (not installed, not hidden) updates. Some may be security updates. Approve/install on the next maintenance window.
```
Microsoft.Update.Session search IsInstalled=0 and IsHidden=0 -> 6
```
### Reboot pending
- **Category:** health
- **ID:** `health.reboot_uptime.pending`
- A reboot is pending. Pending reboots can block patches and leave the system in a half-updated state. Schedule a restart.
```
PendingFileRenameOperations
```
### Uptime is 49.8 days
- **Category:** health
- **ID:** `health.reboot_uptime.long_uptime`
- Uptime exceeds 30 days. Long uptime usually means pending updates have not been applied (reboots deferred). Schedule maintenance.
```
LastBootUpTime=2026-04-17 15:07:40Z
```
### 3 auto-start service(s) not running
- **Category:** health
- **ID:** `health.failed_services.stopped`
- These services are set to start automatically but are not running. Some may be benign; review for security agents, backup agents, or AV that should be running.
```
Intel(R) Platform License Manager Service (Intel(R) Platform License Manager Service) = Stopped
GoogleUpdaterInternalService150.0.7863.0 (Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)) = Stopped
GoogleUpdaterService150.0.7863.0 (Google Updater Service (GoogleUpdaterService150.0.7863.0)) = Stopped
```
## INFO (16)
### Defender real-time protection is OFF (3rd-party AV active)
- **Category:** security
- **ID:** `sec.defender.rtp_off`
- Defender real-time protection is off because a managed/known 3rd-party AV is active. Windows disables Defender real-time protection when another AV registers, so this is expected. Confirm the 3rd-party AV is providing real-time protection.
```
RealTimeProtectionEnabled=False; AMServiceEnabled=False; AntispywareSignatureAge=0 days; IsTamperProtected=False; SecurityCenter2 AntiVirusProduct: Bitdefender Endpoint Security Tools Antimalware (productState=0x41000, RTP on)
```
### Defender antimalware service is not running (3rd-party AV active)
- **Category:** security
- **ID:** `sec.defender.amservice_off`
- The Defender antimalware service is not active because a managed/known 3rd-party AV is registered. Windows stands Defender down when another AV provides protection, so this is expected. Confirm the 3rd-party AV is running.
```
RealTimeProtectionEnabled=False; AMServiceEnabled=False; AntispywareSignatureAge=0 days; IsTamperProtected=False; SecurityCenter2 AntiVirusProduct: Bitdefender Endpoint Security Tools Antimalware (productState=0x41000, RTP on)
```
### No competitor/leftover management agents detected
- **Category:** security
- **ID:** `sec.foreign_agents.none`
- No known competitor RMM or unmanaged remote-access agents found in installed programs or services.
```
Scanned uninstall hives (HKLM + WOW6432Node) and Win32_Service
```
### Expected ACG management tooling present: ScreenConnect / ConnectWise Control
- **Category:** security
- **ID:** `sec.foreign_agents.acg.screenconnect_connectwise_control`
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
```
program: ScreenConnect Client (1912bf3444b41a08) 26.1.24.9579
service: ScreenConnect Client (1912bf3444b41a08) (ScreenConnect Client (1912bf3444b41a08)) Running
```
### Expected ACG management tooling present: Splashtop (SOS/Streamer)
- **Category:** security
- **ID:** `sec.foreign_agents.acg.splashtop_sos_streamer_`
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
```
program: Splashtop Streamer 3.8.2.0
service: SplashtopRemoteService (Splashtop? Remote Service) Running
```
### Expected ACG management tooling present: Syncro / Kabuto
- **Category:** security
- **ID:** `sec.foreign_agents.acg.syncro_kabuto`
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
```
program: Syncro 1.0.201.18410
service: Syncro (Syncro) Running
```
### All firewall profiles enabled
- **Category:** security
- **ID:** `sec.firewall.ok`
- Domain, Private, and Public firewall profiles are all enabled.
```
Private=True; Domain=True; Public=True
```
### Local administrators (5)
- **Category:** security
- **ID:** `sec.local_admins.list`
- Members of the local Administrators group. Review for unexpected or unknown accounts (especially leftover MSP/vendor accounts from a prior provider).
```
GTS\Domain Admins
GTS\gonzvar
GTS-W2\Administrator
GTS-W2\localadmin
GTS-W2\pgonz
```
### OS build supported: Win11 25H2
- **Category:** security
- **ID:** `sec.patch.os_supported`
- Build 26200 (Win11 25H2) is in support until 2027-10-12.
```
Microsoft Windows 11 Pro for Workstations build 26200
```
### Last hotfix: KB5083769
- **Category:** security
- **ID:** `sec.patch.last_hotfix`
- Most recently installed update (from Get-HotFix; reflects CBS/MSU packages, not all cumulative metadata).
```
KB5083769 installed 2026-04-15T07:00:00Z
```
### SMBv1 disabled
- **Category:** security
- **ID:** `sec.exposure.smb1_off`
- SMBv1 server protocol is disabled.
```
EnableSMB1Protocol=False
```
### LAPS detected
- **Category:** security
- **ID:** `sec.exposure.laps_present`
- A LAPS mechanism is present.
```
Windows LAPS reg key
```
### No stability events in the last 14 days
- **Category:** health
- **ID:** `health.stability.clean`
- No unexpected shutdowns, BSODs, or disk errors logged.
```
Unexpected shutdowns (id 41)=0; Bugchecks/BSOD (id 1001)=0; Disk errors (id 7/51/153)=0
```
### Domain secure channel healthy
- **Category:** health
- **ID:** `health.domain.secure_channel_ok`
- Machine trust relationship with the domain is intact.
```
Domain=GTS.local
```
### Time service source
- **Category:** health
- **ID:** `health.time.source`
- Current Windows Time service source.
```
Source=GTS-SVR25.GTS.local
```
### No backup agent detected
- **Category:** health
- **ID:** `health.backup.none`
- No known backup agent service found. Backup expectation varies by endpoint; confirm whether this machine is supposed to have local/cloud backup and whether server-side or M365 backup covers it.
```
No matching backup service in Win32_Service
```
---
## Inventory Baseline Summary
- **Manufacturer / Model:** LENOVO / 90SM006QUS
- **Serial:** MJ0JAWPT
- **CPU:** 12th Gen Intel(R) Core(TM) i5-12400 (6 cores / 12 logical)
- **RAM (GB):** 15.7
- **BIOS:** M49KT29A (2024-01-04)
- **Chassis is laptop:** false
- **TPM present / Secure Boot:** true / true
- **Domain joined:** true (GTS.local)
- **OS activation licensed:** true
- **Uptime (days):** 49.8
- **Pending reboot:** true
- **Installed software count:** 48
- **Scheduled tasks (non-MS, enabled):** 46
- **Local administrators:** GTS\Domain Admins, GTS\gonzvar, GTS-W2\Administrator, GTS-W2\localadmin, GTS-W2\pgonz
### Fixed volumes
- [SYSTEM] - 0.2 GB free of 0.2 GB (76.9%)
- C: - 756.7 GB free of 929.3 GB (81.4%)
- [WinRE_DRV] - 1.2 GB free of 2 GB (60.2%)
### Network adapters
- Realtek PCIe GbE Family Controller - IP: 192.168.0.146, fe80::826b:1844:b416:d971 - DNS: 192.168.0.2, 192.168.0.5 - DHCP: true
---
## Diff vs Prior Baseline
- No prior baseline found for this host. This is the first baseline.
---
_Generated by run-onboarding-diagnostic.sh (GuruRMM onboarding diagnostic, Phase 1). Raw snapshot: `GTS-W2-20260606T181016.json` (immutable)._

View File

@@ -0,0 +1,601 @@
{
"host": "SERVER",
"collected_at_utc": "2026-06-06T18:13:19Z",
"os": {
"caption": "Microsoft Windows Server 2019 Standard",
"version": "10.0.17763",
"build": "17763",
"install_date": "2025-09-26T04:50:29Z",
"last_boot_utc": "2026-02-22T00:37:40Z",
"architecture": "64-bit"
},
"facts": {
"builtin_admin_enabled": false,
"os_eol": {
"eol_date": "2020-11-10",
"release": "Win10 1809"
},
"pending_updates": 5,
"pending_reboot": true,
"uptime_days": 104.8,
"acg_managed_tools": [
"ScreenConnect / ConnectWise Control",
"Splashtop (SOS/Streamer)",
"Syncro / Kabuto"
],
"hardware": {
"model": "PowerEdge T440",
"manufacturer": "Dell Inc.",
"bios_date": "2020-08-31",
"cpu_logical": 6,
"bios_version": "2.8.2",
"cpu_cores": 6,
"ram_gb": 7.6,
"serial": "5308R53",
"cpu": "Intel(R) Xeon(R) Bronze 3204 CPU @ 1.90GHz"
},
"local_administrators": [
"Administrator",
"Domain Admins",
"Enterprise Admins",
"localadmin",
"MediaAdmin$",
"sysadmin"
],
"os_build": "17763",
"secure_boot": null,
"backup_agents": null,
"autoruns_run_keys": [
{
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
"name": "SecurityHealth",
"value": "C:\\WINDOWS\\system32\\SecurityHealthSystray.exe"
}
],
"physical_disks": [
{
"health": "Healthy",
"model": "ST1000NM004A-2MN130",
"media_type": "HDD"
}
],
"local_users": [
{
"last_logon": "2020-10-25",
"name": "Administrator",
"password_never_expires": false,
"enabled": false
},
{
"last_logon": "",
"name": "Guest",
"password_never_expires": false,
"enabled": false
},
{
"last_logon": "",
"name": "krbtgt",
"password_never_expires": false,
"enabled": false
},
{
"last_logon": "",
"name": "DefaultAccount",
"password_never_expires": false,
"enabled": false
},
{
"last_logon": "2025-09-26",
"name": "localadmin",
"password_never_expires": false,
"enabled": true
},
{
"last_logon": "2026-01-07",
"name": "sysadmin",
"password_never_expires": false,
"enabled": true
},
{
"last_logon": "2026-06-06",
"name": "pedro",
"password_never_expires": false,
"enabled": true
},
{
"last_logon": "2026-06-05",
"name": "gonzvar",
"password_never_expires": false,
"enabled": true
},
{
"last_logon": "2026-06-06",
"name": "SERVER$",
"password_never_expires": false,
"enabled": true
},
{
"last_logon": "2025-09-24",
"name": "MediaAdmin$",
"password_never_expires": false,
"enabled": true
},
{
"last_logon": "2026-06-06",
"name": "GTS-W1$",
"password_never_expires": false,
"enabled": true
},
{
"last_logon": "2026-06-05",
"name": "GTS-W2$",
"password_never_expires": false,
"enabled": true
},
{
"last_logon": "2026-06-06",
"name": "GTS-W0$",
"password_never_expires": false,
"enabled": true
}
],
"scheduled_tasks_count": 3,
"volumes": [
{
"drive": "[System Reserved]",
"size_gb": 0.5,
"free_pct": 93,
"free_gb": 0.5
},
{
"drive": "C:",
"size_gb": 930.2,
"free_pct": 80.7,
"free_gb": 750.9
},
{
"drive": "[unlabeled]",
"size_gb": 0.8,
"free_pct": 42.6,
"free_gb": 0.3
}
],
"network_adapters": [
{
"dhcp": false,
"description": "Broadcom NetXtreme Gigabit Ethernet #2",
"gateway": [
"192.168.0.1"
],
"mac": "2C:EA:7F:57:98:E8",
"ip": [
"192.168.0.5",
"fe80::bd6f:321c:c1d5:2f3c"
],
"dns": [
"192.168.0.5",
"192.168.0.2"
]
}
],
"failed_autostart_services": [
{
"name": "GoogleUpdaterInternalService150.0.7863.0",
"display": "Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)",
"state": "Stopped"
},
{
"name": "GoogleUpdaterService150.0.7863.0",
"display": "Google Updater Service (GoogleUpdaterService150.0.7863.0)",
"state": "Stopped"
}
],
"stability_14d": {
"unexpected_shutdowns": 0,
"disk_errors": 0,
"bugchecks": 0
},
"exposure": {
"smb1_enabled": true,
"laps_present": false,
"rdp_enabled": true,
"uac_enabled": true,
"rdp_nla": true
},
"accounts_password_never_expires": [],
"installed_software": [
{
"publisher": "Webprofusion Pty Ltd",
"name": "Certify Certificate Manager version 6.1.9",
"version": "6.1.9"
},
{
"publisher": "Dell Inc.",
"name": "Dell EMC OpenManage Systems Management Software (64-Bit)",
"version": "10.3.0.0"
},
{
"publisher": "Drake Software",
"name": "Drake Accounting 2025",
"version": "25.0.45"
},
{
"publisher": "Google LLC",
"name": "Google Chrome",
"version": "148.0.7778.217"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Host - 6.0.7 (x86)",
"version": "48.31.44002"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Host - 8.0.11 (x64)",
"version": "64.44.23191"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Host - 8.0.20 (x86)",
"version": "64.80.39230"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Host FX Resolver - 6.0.7 (x86)",
"version": "48.31.44002"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Host FX Resolver - 8.0.11 (x64)",
"version": "64.44.23191"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Host FX Resolver - 8.0.20 (x86)",
"version": "64.80.39230"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Runtime - 6.0.7 (x86)",
"version": "48.31.44002"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Runtime - 8.0.11 (x64)",
"version": "64.44.23191"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft .NET Runtime - 8.0.20 (x86)",
"version": "64.80.39230"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft ASP.NET Core 8.0.0 - Shared Framework (x86)",
"version": "8.0.0.23531"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft ASP.NET Core 8.0.0 Shared Framework (x86)",
"version": "8.0.0.23531"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft SQL Server Compact 4.0 SP1 x64 ENU",
"version": "4.0.8876.1"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.28.29914",
"version": "14.28.29914.0"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2019 X86 Additional Runtime - 14.28.29914",
"version": "14.28.29914"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.28.29914",
"version": "14.28.29914"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Windows Desktop Runtime - 6.0.7 (x86)",
"version": "48.31.44003"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Windows Desktop Runtime - 6.0.7 (x86)",
"version": "6.0.7.31422"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Windows Desktop Runtime - 8.0.11 (x64)",
"version": "64.44.23253"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Windows Desktop Runtime - 8.0.11 (x64)",
"version": "8.0.11.34221"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Windows Desktop Runtime - 8.0.20 (x86)",
"version": "64.80.39251"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Windows Desktop Runtime - 8.0.20 (x86)",
"version": "8.0.20.35221"
},
{
"publisher": "ScreenConnect Software",
"name": "ScreenConnect Client (1912bf3444b41a08)",
"version": "26.1.24.9579"
},
{
"publisher": "Splashtop Inc.",
"name": "Splashtop Software Updater",
"version": "1.5.6.23"
},
{
"publisher": "Splashtop Inc.",
"name": "Splashtop Streamer",
"version": "3.8.2.0"
},
{
"publisher": "Servably, Inc.",
"name": "Syncro",
"version": "1.0.201.18410"
},
{
"publisher": "win.rar GmbH",
"name": "WinRAR 7.13 (64-bit)",
"version": "7.13.0"
}
],
"tpm": {
"enabled": false,
"ready": false,
"present": false
},
"local_groups": [
"Cert Publishers",
"RAS and IAS Servers",
"Allowed RODC Password Replication Group",
"Denied RODC Password Replication Group"
],
"battery": {
"present": false
},
"activation": {
"edition": "Microsoft Windows Server 2019 Standard",
"description": "Windows(R) Operating System, VOLUME_KMSCLIENT channel",
"licensed": false,
"license_status_code": 5
},
"time_source": "Free-running System Clock",
"chassis_types": [
17
],
"last_hotfix": {
"hotfix_id": "KB5070248",
"installed_on": "2026-01-17T08:00:00Z"
},
"scheduled_tasks": [
{
"path": "\\",
"name": "Dell SupportAssistAgent AutoUpdate",
"state": "Ready"
},
{
"path": "\\",
"name": "ShadowCopyVolume{5f67aa97-0000-0000-0000-501f00000000}",
"state": "Ready"
},
{
"path": "\\GoogleSystem\\GoogleUpdater\\",
"name": "GoogleUpdaterTaskSystem150.0.7863.0{2E905B25-4378-464B-9268-EAB95C26A418}",
"state": "Ready"
}
],
"antivirus_products": [],
"domain_joined": true,
"defender": {
"available": false
},
"bitlocker": {
"available": false,
"os_volume": "C:"
},
"is_laptop": false,
"installed_software_count": 30,
"secure_channel_ok": true,
"firewall_profiles": {
"Private": false,
"Domain": false,
"Public": false
},
"domain": "GTS.local",
"foreign_agents": null
},
"findings": [
{
"id": "sec.defender.unavailable",
"category": "security",
"severity": "warning",
"title": "Defender status unavailable",
"detail": "Get-MpComputerStatus returned nothing. Defender may be disabled, replaced by a 3rd-party AV, or the cmdlet is unavailable. Confirm an active AV exists (see security-center check).",
"evidence": "Get-MpComputerStatus returned null"
},
{
"id": "sec.av_products.none_registered",
"category": "security",
"severity": "info",
"title": "No AV products registered in Security Center",
"detail": "SecurityCenter2 returned no AntiVirusProduct entries. This is normal on Windows Server SKUs (Security Center is a client feature). On a workstation, confirm Defender or a managed AV is active.",
"evidence": "root\\SecurityCenter2 AntiVirusProduct: none"
},
{
"id": "sec.foreign_agents.none",
"category": "security",
"severity": "info",
"title": "No competitor/leftover management agents detected",
"detail": "No known competitor RMM or unmanaged remote-access agents found in installed programs or services.",
"evidence": "Scanned uninstall hives (HKLM + WOW6432Node) and Win32_Service"
},
{
"id": "sec.foreign_agents.acg.screenconnect_connectwise_control",
"category": "security",
"severity": "info",
"title": "Expected ACG management tooling present: ScreenConnect / ConnectWise Control",
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
"evidence": "program: ScreenConnect Client (1912bf3444b41a08) 26.1.24.9579\nservice: ScreenConnect Client (1912bf3444b41a08) (ScreenConnect Client (1912bf3444b41a08)) Running"
},
{
"id": "sec.foreign_agents.acg.splashtop_sos_streamer_",
"category": "security",
"severity": "info",
"title": "Expected ACG management tooling present: Splashtop (SOS/Streamer)",
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
"evidence": "program: Splashtop Software Updater 1.5.6.23\nprogram: Splashtop Streamer 3.8.2.0\nservice: SplashtopRemoteService (Splashtop? Remote Service) Running\nservice: SSUService (Splashtop Software Updater Service) Running"
},
{
"id": "sec.foreign_agents.acg.syncro_kabuto",
"category": "security",
"severity": "info",
"title": "Expected ACG management tooling present: Syncro / Kabuto",
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
"evidence": "program: Syncro 1.0.201.18410\nservice: Syncro (Syncro) Running"
},
{
"id": "sec.firewall.disabled",
"category": "security",
"severity": "critical",
"title": "Firewall disabled on profile(s): Domain, Private, Public",
"detail": "One or more firewall profiles are OFF. The endpoint is exposed to lateral movement and inbound attacks on those networks. Re-enable all profiles.",
"evidence": "Profile states: Private=False; Domain=False; Public=False"
},
{
"id": "sec.bitlocker.unavailable",
"category": "security",
"severity": "unknown",
"title": "BitLocker status unavailable",
"detail": "Get-BitLockerVolume failed for the OS volume. BitLocker may not be installed (Home edition) or the cmdlet is unavailable. Verify encryption manually (manage-bde -status).",
"evidence": "MountPoint=C:, Get-BitLockerVolume returned null"
},
{
"id": "sec.local_admins.list",
"category": "security",
"severity": "info",
"title": "Local administrators (6)",
"detail": "Members of the local Administrators group. Review for unexpected or unknown accounts (especially leftover MSP/vendor accounts from a prior provider).",
"evidence": "Administrator\nDomain Admins\nEnterprise Admins\nlocaladmin\nMediaAdmin$\nsysadmin"
},
{
"id": "sec.patch.os_eol",
"category": "security",
"severity": "critical",
"title": "OS build is end-of-life: Win10 1809",
"detail": "This OS build (17763, Win10 1809) passed end-of-servicing on 2020-11-10. It no longer receives security updates. Plan a feature update or OS upgrade.",
"evidence": "Microsoft Windows Server 2019 Standard build 17763; EOL 2020-11-10"
},
{
"id": "sec.patch.pending",
"category": "security",
"severity": "warning",
"title": "5 pending Windows updates",
"detail": "Windows Update reports pending (not installed, not hidden) updates. Some may be security updates. Approve/install on the next maintenance window.",
"evidence": "Microsoft.Update.Session search IsInstalled=0 and IsHidden=0 -> 5"
},
{
"id": "sec.patch.last_hotfix",
"category": "security",
"severity": "info",
"title": "Last hotfix: KB5070248",
"detail": "Most recently installed update (from Get-HotFix; reflects CBS/MSU packages, not all cumulative metadata).",
"evidence": "KB5070248 installed 2026-01-17T08:00:00Z"
},
{
"id": "sec.exposure.rdp_on",
"category": "security",
"severity": "warning",
"title": "RDP is enabled",
"detail": "Remote Desktop is enabled (NLA required). Confirm it is restricted to VPN or specific source IPs and not exposed to the internet.",
"evidence": "fDenyTSConnections=0; UserAuthentication=1"
},
{
"id": "sec.exposure.smb1",
"category": "security",
"severity": "critical",
"title": "SMBv1 is ENABLED",
"detail": "SMBv1 is an obsolete, insecure protocol (WannaCry/EternalBlue vector). Disable it: Set-SmbServerConfiguration -EnableSMB1Protocol $false and remove the SMB1 feature.",
"evidence": "Get-SmbServerConfiguration EnableSMB1Protocol=True"
},
{
"id": "sec.exposure.no_laps",
"category": "security",
"severity": "info",
"title": "LAPS not detected",
"detail": "No LAPS (Windows LAPS or legacy AdmPwd) detected. Without LAPS, the local admin password is likely static/shared across the fleet. Consider deploying LAPS to randomize and escrow local admin passwords.",
"evidence": "No LAPS registry keys, CSE, or service found"
},
{
"id": "health.stability.clean",
"category": "health",
"severity": "info",
"title": "No stability events in the last 14 days",
"detail": "No unexpected shutdowns, BSODs, or disk errors logged.",
"evidence": "Unexpected shutdowns (id 41)=0; Bugchecks/BSOD (id 1001)=0; Disk errors (id 7/51/153)=0"
},
{
"id": "health.reboot_uptime.pending",
"category": "health",
"severity": "warning",
"title": "Reboot pending",
"detail": "A reboot is pending. Pending reboots can block patches and leave the system in a half-updated state. Schedule a restart.",
"evidence": "PendingFileRenameOperations"
},
{
"id": "health.reboot_uptime.long_uptime",
"category": "health",
"severity": "warning",
"title": "Uptime is 104.8 days",
"detail": "Uptime exceeds 30 days. Long uptime usually means pending updates have not been applied (reboots deferred). Schedule maintenance.",
"evidence": "LastBootUpTime=2026-02-21 16:37:40Z"
},
{
"id": "health.failed_services.stopped",
"category": "health",
"severity": "warning",
"title": "2 auto-start service(s) not running",
"detail": "These services are set to start automatically but are not running. Some may be benign; review for security agents, backup agents, or AV that should be running.",
"evidence": "GoogleUpdaterInternalService150.0.7863.0 (Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)) = Stopped\nGoogleUpdaterService150.0.7863.0 (Google Updater Service (GoogleUpdaterService150.0.7863.0)) = Stopped"
},
{
"id": "health.domain.secure_channel_ok",
"category": "health",
"severity": "info",
"title": "Domain secure channel healthy",
"detail": "Machine trust relationship with the domain is intact.",
"evidence": "Domain=GTS.local"
},
{
"id": "health.time.source",
"category": "health",
"severity": "info",
"title": "Time service source",
"detail": "Current Windows Time service source.",
"evidence": "Source=Free-running System Clock"
},
{
"id": "health.backup.none",
"category": "health",
"severity": "info",
"title": "No backup agent detected",
"detail": "No known backup agent service found. Backup expectation varies by endpoint; confirm whether this machine is supposed to have local/cloud backup and whether server-side or M365 backup covers it.",
"evidence": "No matching backup service in Win32_Service"
}
]
}

View File

@@ -0,0 +1,273 @@
# Onboarding Diagnostic Baseline - SERVER
- **Grade:** RED
- **Host:** SERVER
- **Client:** Gonzvar Tax Services (`gonzvar-tax-services`)
- **Collected (UTC):** 2026-06-06T18:13:19Z
- **Agent ID:** 9fe137ba-6164-4b7a-8a9d-4e8c4b9e40a5
- **Command ID:** d91f435d-b67c-43e4-a872-adb82dd07157
- **Findings:** 3 critical / 6 warning / 12 info / 1 unknown
- **OS:** Microsoft Windows Server 2019 Standard (build 17763)
---
## CRITICAL (3)
### Firewall disabled on profile(s): Domain, Private, Public
- **Category:** security
- **ID:** `sec.firewall.disabled`
- One or more firewall profiles are OFF. The endpoint is exposed to lateral movement and inbound attacks on those networks. Re-enable all profiles.
```
Profile states: Private=False; Domain=False; Public=False
```
### OS build is end-of-life: Win10 1809
- **Category:** security
- **ID:** `sec.patch.os_eol`
- This OS build (17763, Win10 1809) passed end-of-servicing on 2020-11-10. It no longer receives security updates. Plan a feature update or OS upgrade.
```
Microsoft Windows Server 2019 Standard build 17763; EOL 2020-11-10
```
### SMBv1 is ENABLED
- **Category:** security
- **ID:** `sec.exposure.smb1`
- SMBv1 is an obsolete, insecure protocol (WannaCry/EternalBlue vector). Disable it: Set-SmbServerConfiguration -EnableSMB1Protocol $false and remove the SMB1 feature.
```
Get-SmbServerConfiguration EnableSMB1Protocol=True
```
## WARNING (6)
### Defender status unavailable
- **Category:** security
- **ID:** `sec.defender.unavailable`
- Get-MpComputerStatus returned nothing. Defender may be disabled, replaced by a 3rd-party AV, or the cmdlet is unavailable. Confirm an active AV exists (see security-center check).
```
Get-MpComputerStatus returned null
```
### 5 pending Windows updates
- **Category:** security
- **ID:** `sec.patch.pending`
- Windows Update reports pending (not installed, not hidden) updates. Some may be security updates. Approve/install on the next maintenance window.
```
Microsoft.Update.Session search IsInstalled=0 and IsHidden=0 -> 5
```
### RDP is enabled
- **Category:** security
- **ID:** `sec.exposure.rdp_on`
- Remote Desktop is enabled (NLA required). Confirm it is restricted to VPN or specific source IPs and not exposed to the internet.
```
fDenyTSConnections=0; UserAuthentication=1
```
### Reboot pending
- **Category:** health
- **ID:** `health.reboot_uptime.pending`
- A reboot is pending. Pending reboots can block patches and leave the system in a half-updated state. Schedule a restart.
```
PendingFileRenameOperations
```
### Uptime is 104.8 days
- **Category:** health
- **ID:** `health.reboot_uptime.long_uptime`
- Uptime exceeds 30 days. Long uptime usually means pending updates have not been applied (reboots deferred). Schedule maintenance.
```
LastBootUpTime=2026-02-21 16:37:40Z
```
### 2 auto-start service(s) not running
- **Category:** health
- **ID:** `health.failed_services.stopped`
- These services are set to start automatically but are not running. Some may be benign; review for security agents, backup agents, or AV that should be running.
```
GoogleUpdaterInternalService150.0.7863.0 (Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)) = Stopped
GoogleUpdaterService150.0.7863.0 (Google Updater Service (GoogleUpdaterService150.0.7863.0)) = Stopped
```
## INFO (12)
### No AV products registered in Security Center
- **Category:** security
- **ID:** `sec.av_products.none_registered`
- SecurityCenter2 returned no AntiVirusProduct entries. This is normal on Windows Server SKUs (Security Center is a client feature). On a workstation, confirm Defender or a managed AV is active.
```
root\SecurityCenter2 AntiVirusProduct: none
```
### No competitor/leftover management agents detected
- **Category:** security
- **ID:** `sec.foreign_agents.none`
- No known competitor RMM or unmanaged remote-access agents found in installed programs or services.
```
Scanned uninstall hives (HKLM + WOW6432Node) and Win32_Service
```
### Expected ACG management tooling present: ScreenConnect / ConnectWise Control
- **Category:** security
- **ID:** `sec.foreign_agents.acg.screenconnect_connectwise_control`
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
```
program: ScreenConnect Client (1912bf3444b41a08) 26.1.24.9579
service: ScreenConnect Client (1912bf3444b41a08) (ScreenConnect Client (1912bf3444b41a08)) Running
```
### Expected ACG management tooling present: Splashtop (SOS/Streamer)
- **Category:** security
- **ID:** `sec.foreign_agents.acg.splashtop_sos_streamer_`
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
```
program: Splashtop Software Updater 1.5.6.23
program: Splashtop Streamer 3.8.2.0
service: SplashtopRemoteService (Splashtop? Remote Service) Running
service: SSUService (Splashtop Software Updater Service) Running
```
### Expected ACG management tooling present: Syncro / Kabuto
- **Category:** security
- **ID:** `sec.foreign_agents.acg.syncro_kabuto`
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
```
program: Syncro 1.0.201.18410
service: Syncro (Syncro) Running
```
### Local administrators (6)
- **Category:** security
- **ID:** `sec.local_admins.list`
- Members of the local Administrators group. Review for unexpected or unknown accounts (especially leftover MSP/vendor accounts from a prior provider).
```
Administrator
Domain Admins
Enterprise Admins
localadmin
MediaAdmin$
sysadmin
```
### Last hotfix: KB5070248
- **Category:** security
- **ID:** `sec.patch.last_hotfix`
- Most recently installed update (from Get-HotFix; reflects CBS/MSU packages, not all cumulative metadata).
```
KB5070248 installed 2026-01-17T08:00:00Z
```
### LAPS not detected
- **Category:** security
- **ID:** `sec.exposure.no_laps`
- No LAPS (Windows LAPS or legacy AdmPwd) detected. Without LAPS, the local admin password is likely static/shared across the fleet. Consider deploying LAPS to randomize and escrow local admin passwords.
```
No LAPS registry keys, CSE, or service found
```
### No stability events in the last 14 days
- **Category:** health
- **ID:** `health.stability.clean`
- No unexpected shutdowns, BSODs, or disk errors logged.
```
Unexpected shutdowns (id 41)=0; Bugchecks/BSOD (id 1001)=0; Disk errors (id 7/51/153)=0
```
### Domain secure channel healthy
- **Category:** health
- **ID:** `health.domain.secure_channel_ok`
- Machine trust relationship with the domain is intact.
```
Domain=GTS.local
```
### Time service source
- **Category:** health
- **ID:** `health.time.source`
- Current Windows Time service source.
```
Source=Free-running System Clock
```
### No backup agent detected
- **Category:** health
- **ID:** `health.backup.none`
- No known backup agent service found. Backup expectation varies by endpoint; confirm whether this machine is supposed to have local/cloud backup and whether server-side or M365 backup covers it.
```
No matching backup service in Win32_Service
```
## UNKNOWN (1)
### BitLocker status unavailable
- **Category:** security
- **ID:** `sec.bitlocker.unavailable`
- Get-BitLockerVolume failed for the OS volume. BitLocker may not be installed (Home edition) or the cmdlet is unavailable. Verify encryption manually (manage-bde -status).
```
MountPoint=C:, Get-BitLockerVolume returned null
```
---
## Inventory Baseline Summary
- **Manufacturer / Model:** Dell Inc. / PowerEdge T440
- **Serial:** 5308R53
- **CPU:** Intel(R) Xeon(R) Bronze 3204 CPU @ 1.90GHz (6 cores / 6 logical)
- **RAM (GB):** 7.6
- **BIOS:** 2.8.2 (2020-08-31)
- **Chassis is laptop:** false
- **TPM present / Secure Boot:** ? / ?
- **Domain joined:** true (GTS.local)
- **OS activation licensed:** ?
- **Uptime (days):** 104.8
- **Pending reboot:** true
- **Installed software count:** 30
- **Scheduled tasks (non-MS, enabled):** 3
- **Local administrators:** Administrator, Domain Admins, Enterprise Admins, localadmin, MediaAdmin$, sysadmin
### Fixed volumes
- [System Reserved] - 0.5 GB free of 0.5 GB (93%)
- C: - 750.9 GB free of 930.2 GB (80.7%)
- [unlabeled] - 0.3 GB free of 0.8 GB (42.6%)
### Network adapters
- Broadcom NetXtreme Gigabit Ethernet #2 - IP: 192.168.0.5, fe80::bd6f:321c:c1d5:2f3c - DNS: 192.168.0.5, 192.168.0.2 - DHCP: false
---
## Diff vs Prior Baseline
- No prior baseline found for this host. This is the first baseline.
---
_Generated by run-onboarding-diagnostic.sh (GuruRMM onboarding diagnostic, Phase 1). Raw snapshot: `SERVER-20260606T181304.json` (immutable)._