# Onboarding Diagnostic Baseline - FRONTDESKRECEPT - **Grade:** RED - **Host:** FRONTDESKRECEPT - **Client:** Rednour Law Offices (`rednour`) - **Collected (UTC):** 2026-05-29T19:55:43Z - **Agent ID:** 04765560-3e8a-46e5-a507-c5f5f4ead6eb - **Command ID:** 94966f79-74ea-4b47-98c5-6e0f33f819fa - **Findings:** 3 critical / 4 warning / 12 info / 0 unknown - **OS:** Microsoft Windows 11 Pro (build 26200) --- ## CRITICAL (3) ### Foreign management/remote-access agent: ScreenConnect / ConnectWise Control - **Category:** security - **ID:** `sec.foreign_agents.screenconnect_connectwise_control` - A competitor RMM or unmanaged remote-access tool is present. At onboarding this is a security and control risk (a prior MSP or attacker may retain remote access). Verify it is authorized; if not, remove it. ``` program: ScreenConnect Client (1912bf3444b41a08) 26.1.24.9579 service: ScreenConnect Client (1912bf3444b41a08) (ScreenConnect Client (1912bf3444b41a08)) Running ``` ### Foreign management/remote-access agent: Splashtop (SOS/Streamer) - **Category:** security - **ID:** `sec.foreign_agents.splashtop_sos_streamer_` - A competitor RMM or unmanaged remote-access tool is present. At onboarding this is a security and control risk (a prior MSP or attacker may retain remote access). Verify it is authorized; if not, remove it. ``` program: Splashtop Streamer 3.8.2.0 service: SplashtopRemoteService (Splashtop? Remote Service) Running ``` ### Foreign management/remote-access agent: Syncro / Kabuto - **Category:** security - **ID:** `sec.foreign_agents.syncro_kabuto` - A competitor RMM or unmanaged remote-access tool is present. At onboarding this is a security and control risk (a prior MSP or attacker may retain remote access). Verify it is authorized; if not, remove it. ``` program: Syncro 1.0.201.18410 service: Syncro (Syncro) Running ``` ## WARNING (4) ### OS volume is NOT encrypted with BitLocker - **Category:** security - **ID:** `sec.bitlocker.unencrypted` - The operating system volume is unencrypted. Data is exposed if the disk is removed or the device is lost. Enable BitLocker and escrow the recovery key. ``` Volume=C:; ProtectionStatus=Off; EncryptionPercentage=0; KeyProtectors= ``` ### 2 pending Windows updates - **Category:** security - **ID:** `sec.patch.pending` - Windows Update reports pending (not installed, not hidden) updates. Some may be security updates. Approve/install on the next maintenance window. ``` Microsoft.Update.Session search IsInstalled=0 and IsHidden=0 -> 2 ``` ### Reboot pending - **Category:** health - **ID:** `health.reboot_uptime.pending` - A reboot is pending. Pending reboots can block patches and leave the system in a half-updated state. Schedule a restart. ``` PendingFileRenameOperations ``` ### 3 auto-start service(s) not running - **Category:** health - **ID:** `health.failed_services.stopped` - These services are set to start automatically but are not running. Some may be benign; review for security agents, backup agents, or AV that should be running. ``` GoogleUpdaterInternalService149.0.7814.0 (Google Updater Internal Service (GoogleUpdaterInternalService149.0.7814.0)) = Stopped GoogleUpdaterService149.0.7814.0 (Google Updater Service (GoogleUpdaterService149.0.7814.0)) = Stopped Intel(R) TPM Provisioning Service (Intel(R) TPM Provisioning Service) = Stopped ``` ## INFO (12) ### Defender active and current - **Category:** security - **ID:** `sec.defender.ok` - Real-time protection on, service running, signatures current. ``` RealTimeProtectionEnabled=True; AMServiceEnabled=True; AntispywareSignatureAge=0 days; IsTamperProtected=True ``` ### Defender is the only registered AV - **Category:** security - **ID:** `sec.av_products.defender_only` - Only Microsoft/Windows Defender is registered in Security Center. ``` Windows Defender ``` ### All firewall profiles enabled - **Category:** security - **ID:** `sec.firewall.ok` - Domain, Private, and Public firewall profiles are all enabled. ``` Private=True; Domain=True; Public=True ``` ### Local administrators (3) - **Category:** security - **ID:** `sec.local_admins.list` - Members of the local Administrators group. Review for unexpected or unknown accounts (especially leftover MSP/vendor accounts from a prior provider). ``` FRONTDESKRECEPT\Administrator FRONTDESKRECEPT\guru FRONTDESKRECEPT\localadmin ``` ### OS build supported: Win11 25H2 - **Category:** security - **ID:** `sec.patch.os_supported` - Build 26200 (Win11 25H2) is in support until 2027-10-12. ``` Microsoft Windows 11 Pro build 26200 ``` ### Last hotfix: KB5089549 - **Category:** security - **ID:** `sec.patch.last_hotfix` - Most recently installed update (from Get-HotFix; reflects CBS/MSU packages, not all cumulative metadata). ``` KB5089549 installed 2026-05-13T07:00:00Z ``` ### SMBv1 disabled - **Category:** security - **ID:** `sec.exposure.smb1_off` - SMBv1 server protocol is disabled. ``` EnableSMB1Protocol=False ``` ### LAPS detected - **Category:** security - **ID:** `sec.exposure.laps_present` - A LAPS mechanism is present. ``` Windows LAPS reg key ``` ### No stability events in the last 14 days - **Category:** health - **ID:** `health.stability.clean` - No unexpected shutdowns, BSODs, or disk errors logged. ``` Unexpected shutdowns (id 41)=0; Bugchecks/BSOD (id 1001)=0; Disk errors (id 7/51/153)=0 ``` ### Not domain-joined (workgroup) - **Category:** health - **ID:** `health.domain.workgroup` - This machine is in workgroup/Azure AD only mode (Domain=WORKGROUP). No on-prem AD secure channel applies. ``` PartOfDomain=False; Domain=WORKGROUP ``` ### Time service source - **Category:** health - **ID:** `health.time.source` - Current Windows Time service source. ``` Source=time.windows.com,0x9 ``` ### No backup agent detected - **Category:** health - **ID:** `health.backup.none` - No known backup agent service found. Backup expectation varies by endpoint; confirm whether this machine is supposed to have local/cloud backup and whether server-side or M365 backup covers it. ``` No matching backup service in Win32_Service ``` --- ## Inventory Baseline Summary - **Manufacturer / Model:** Dell Inc. / OptiPlex 3080 - **Serial:** DPZK1G3 - **CPU:** Intel(R) Core(TM) i5-10505 CPU @ 3.20GHz (6 cores / 12 logical) - **RAM (GB):** 15.8 - **BIOS:** 2.34.0 (2025-12-01) - **Chassis is laptop:** false - **TPM present / Secure Boot:** true / ? - **Domain joined:** false (WORKGROUP) - **OS activation licensed:** true - **Uptime (days):** 16.8 - **Pending reboot:** true - **Installed software count:** 58 - **Scheduled tasks (non-MS, enabled):** 10 - **Local administrators:** FRONTDESKRECEPT\Administrator, FRONTDESKRECEPT\guru, FRONTDESKRECEPT\localadmin ### Fixed volumes - [unlabeled] - 0 GB free of 0.1 GB (35.9%) - [unlabeled] - 0.1 GB free of 0.8 GB (14.4%) - [Recovery] - 0.5 GB free of 0.5 GB (97.4%) - C: - 394 GB free of 475.5 GB (82.8%) ### Network adapters - Realtek PCIe GbE Family Controller - IP: 192.168.10.115, fe80::b17c:c1aa:150b:e65b - DNS: 192.168.10.1 - DHCP: true --- ## Diff vs Prior Baseline - No prior baseline found for this host. This is the first baseline. --- _Generated by run-onboarding-diagnostic.sh (GuruRMM onboarding diagnostic, Phase 1). Raw snapshot: `FRONTDESKRECEPT-20260529T195614.json` (immutable)._