Files
claudetools/clients/ucryo/onboarding-baselines/KIRBY-20260603T003656.json
Mike Swanson 0413df8459 sync: auto-sync from GURU-5070 at 2026-06-02 18:44:13
Author: Mike Swanson
Machine: GURU-5070
Timestamp: 2026-06-02 18:44:13
2026-06-02 18:44:21 -07:00

961 lines
32 KiB
JSON

{
"host": "KIRBY",
"collected_at_utc": "2026-06-03T00:35:40Z",
"os": {
"caption": "Microsoft Windows 10 Pro",
"version": "10.0.19045",
"build": "19045",
"install_date": "2022-07-23T08:06:56Z",
"last_boot_utc": "2026-04-28T17:03:48Z",
"architecture": "64-bit"
},
"facts": {
"builtin_admin_enabled": false,
"os_eol": {
"eol_date": "2025-10-14",
"release": "Win10 22H2"
},
"pending_updates": 4,
"pending_reboot": true,
"uptime_days": 35.3,
"acg_managed_tools": [
"ScreenConnect / ConnectWise Control",
"Splashtop (SOS/Streamer)",
"Syncro / Kabuto"
],
"hardware": {
"model": "82K8",
"manufacturer": "LENOVO",
"bios_date": "2023-11-17",
"cpu_logical": 16,
"bios_version": "HACN42WW",
"cpu_cores": 8,
"ram_gb": 31.4,
"serial": "PF40739R",
"cpu": "AMD Ryzen 7 5800H with Radeon Graphics "
},
"local_administrators": [
"KIRBY\\Administrator",
"KIRBY\\localadmin",
"KIRBY\\paul",
"UCRYO\\Domain Admins"
],
"os_build": "19045",
"secure_boot": true,
"backup_agents": null,
"autoruns_run_keys": [
{
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
"name": "SecurityHealth",
"value": "C:\\Windows\\system32\\SecurityHealthSystray.exe"
},
{
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
"name": "RtkAudUService",
"value": "\"C:\\Windows\\System32\\DriverStore\\FileRepository\\realtekservice.inf_amd64_0a6e841b98282717\\RtkAudUService64.exe\" -background"
},
{
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
"name": "AdobeAAMUpdater-1.0",
"value": "\"C:\\Program Files (x86)\\Common Files\\Adobe\\OOBE\\PDApp\\UWA\\UpdaterStartupUtility.exe\""
},
{
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
"name": "Logitech Download Assistant",
"value": "C:\\Windows\\system32\\rundll32.exe C:\\Windows\\System32\\LogiLDA.dll,LogiFetch"
},
{
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run",
"name": "LogiOptions",
"value": "C:\\Program Files\\Logitech\\LogiOptions\\LogiOptions.exe /noui"
},
{
"key": "HKLM:\\Software\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\Run",
"name": "Acrobat Assistant 8.0",
"value": "\"C:\\Program Files (x86)\\Adobe\\Acrobat DC\\Acrobat\\Acrotray.exe\""
},
{
"key": "HKLM:\\Software\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\Run",
"name": "(default)",
"value": ""
},
{
"key": "HKLM:\\Software\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\Run",
"name": "ControlCenter4",
"value": "C:\\Program Files (x86)\\ControlCenter4\\BrCcBoot.exe /autorun"
},
{
"key": "HKLM:\\Software\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\Run",
"name": "BrStsMon00",
"value": "C:\\Program Files (x86)\\Browny02\\Brother\\BrStMonW.exe /AUTORUN"
},
{
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
"name": "Delete Cached Update Binary",
"value": "C:\\Windows\\system32\\cmd.exe /q /c del /q \"C:\\Program Files\\Microsoft OneDrive\\Update\\OneDriveSetup.exe\""
},
{
"key": "HKLM:\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
"name": "Delete Cached Standalone Update Binary",
"value": "C:\\Windows\\system32\\cmd.exe /q /c del /q \"C:\\Program Files\\Microsoft OneDrive\\StandaloneUpdater\\OneDriveSetup.exe\""
}
],
"physical_disks": [
{
"health": "Healthy",
"model": "SKHynix_HFS512GDE9X084N",
"media_type": "SSD"
}
],
"local_users": [
{
"last_logon": "",
"name": "Administrator",
"password_never_expires": false,
"enabled": false
},
{
"last_logon": "",
"name": "DefaultAccount",
"password_never_expires": false,
"enabled": false
},
{
"last_logon": "",
"name": "Guest",
"password_never_expires": false,
"enabled": false
},
{
"last_logon": "",
"name": "localadmin",
"password_never_expires": false,
"enabled": true
},
{
"last_logon": "2022-07-22",
"name": "paul",
"password_never_expires": false,
"enabled": true
},
{
"last_logon": "",
"name": "WDAGUtilityAccount",
"password_never_expires": false,
"enabled": false
}
],
"scheduled_tasks_count": 15,
"volumes": [
{
"drive": "C:",
"size_gb": 474.4,
"free_pct": 59.6,
"free_gb": 282.7
},
{
"drive": "[WINRE_DRV]",
"size_gb": 2,
"free_pct": 56.5,
"free_gb": 1.1
},
{
"drive": "[unlabeled]",
"size_gb": 0.1,
"free_pct": 72,
"free_gb": 0.1
},
{
"drive": "[unlabeled]",
"size_gb": 0.5,
"free_pct": 16.6,
"free_gb": 0.1
}
],
"network_adapters": [
{
"dhcp": true,
"description": "MediaTek Wi-Fi 6 MT7921 Wireless LAN Card",
"gateway": [
"172.29.0.1"
],
"mac": "88:94:EB:1B:F0:DD",
"ip": [
"172.29.0.148",
"fe80::d7aa:6bcd:882c:e640"
],
"dns": [
"172.29.0.5",
"8.8.8.8"
]
}
],
"failed_autostart_services": null,
"stability_14d": {
"unexpected_shutdowns": 0,
"disk_errors": 0,
"bugchecks": 0
},
"exposure": {
"smb1_enabled": false,
"laps_present": true,
"rdp_enabled": true,
"uac_enabled": true,
"rdp_nla": true
},
"accounts_password_never_expires": [],
"installed_software": [
{
"publisher": "Dassault Systemes SolidWorks Corp",
"name": "3DEXPERIENCE Exchange for SOLIDWORKS",
"version": "34.11.0011"
},
{
"publisher": "Dassault Systemes SolidWorks Corp",
"name": "3DEXPERIENCE Marketplace for SOLIDWORKS",
"version": "6.32.1051"
},
{
"publisher": "Atlas Business Solutions, Inc.",
"name": "ABS PDF Install",
"version": "4.2.2"
},
{
"publisher": "Adobe Systems Incorporated",
"name": "Adobe Acrobat DC",
"version": "15.009.20077"
},
{
"publisher": "Adobe Systems Incorporated",
"name": "Adobe Refresh Manager",
"version": "1.8.0"
},
{
"publisher": "Apple Inc.",
"name": "Bonjour",
"version": "3.0.0.10"
},
{
"publisher": "Brother Industries, Ltd.",
"name": "Brother MFL-Pro Suite MFC-9130CW",
"version": "1.0.1.0"
},
{
"publisher": "Dassault Systemes SolidWorks Corp",
"name": "CEF for SOLIDWORKS Applications",
"version": "142.0.34576.0"
},
{
"publisher": "Microsoft Corporation",
"name": "Copilot",
"version": "148.0.3967.70"
},
{
"publisher": "Logi",
"name": "Logi Bolt",
"version": "1.01.415.0"
},
{
"publisher": "Logitech",
"name": "Logitech Options",
"version": "9.40.86"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Edge",
"version": "148.0.3967.96"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Edge WebView2 Runtime",
"version": "148.0.3967.96"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Office Professional Plus 2019 - en-us",
"version": "16.0.19127.20302"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft OneDrive",
"version": "26.084.0504.0007"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Update Health Tools",
"version": "3.74.0.0"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual Basic for Applications 7.1 (x64)",
"version": "7.1.11.28"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual Basic for Applications 7.1 (x64) English",
"version": "7.1.11.28"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2005 Redistributable",
"version": "8.0.61001"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2005 Redistributable (x64)",
"version": "8.0.61000"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161",
"version": "9.0.30729.6161"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17",
"version": "9.0.30729"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161",
"version": "9.0.30729.6161"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219",
"version": "10.0.40219"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219",
"version": "10.0.40219"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030",
"version": "11.0.61030.0"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030",
"version": "11.0.61030.0"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030",
"version": "11.0.61030"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030",
"version": "11.0.61030"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030",
"version": "11.0.61030"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030",
"version": "11.0.61030"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501",
"version": "12.0.30501.0"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501",
"version": "12.0.30501.0"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005",
"version": "12.0.21005"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005",
"version": "12.0.21005"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005",
"version": "12.0.21005"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005",
"version": "12.0.21005"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.42.34438",
"version": "14.42.34438.0"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.42.34438",
"version": "14.42.34438.0"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2022 X64 Additional Runtime - 14.42.34438",
"version": "14.42.34438"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.42.34438",
"version": "14.42.34438"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2022 X86 Additional Runtime - 14.42.34438",
"version": "14.42.34438"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.42.34438",
"version": "14.42.34438"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual Studio Tools for Applications 2015",
"version": "14.0.23829"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual Studio Tools for Applications 2015 Finalizer",
"version": "14.0.23829"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual Studio Tools for Applications 2015 x64 Hosting Support",
"version": "14.0.23829"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual Studio Tools for Applications 2015 x86 Hosting Support",
"version": "14.0.23829"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual Studio Tools for Applications 2019",
"version": "16.0.31110"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual Studio Tools for Applications 2019 x64 Hosting Support",
"version": "16.0.31110"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual Studio Tools for Applications 2019 x86 Hosting Support",
"version": "16.0.31110"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual Studio Tools for Applications 2022",
"version": "17.0.33529"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual Studio Tools for Applications 2022 x64 Hosting Support",
"version": "17.0.33529"
},
{
"publisher": "Microsoft Corporation",
"name": "Microsoft Visual Studio Tools for Applications 2022 x86 Hosting Support",
"version": "17.0.33529"
},
{
"publisher": "Mozilla",
"name": "Mozilla Firefox (x64 en-US)",
"version": "151.0.3"
},
{
"publisher": "Mozilla",
"name": "Mozilla Maintenance Service",
"version": "151.0.2"
},
{
"publisher": "NVIDIA Corporation",
"name": "NVIDIA Graphics Driver 527.99",
"version": "527.99"
},
{
"publisher": "NVIDIA Corporation",
"name": "NVIDIA Install Application",
"version": "2.1002.382.0"
},
{
"publisher": "Microsoft Corporation",
"name": "Office 16 Click-to-Run Extensibility Component",
"version": "16.0.19127.20154"
},
{
"publisher": "Microsoft Corporation",
"name": "Office 16 Click-to-Run Licensing Component",
"version": "16.0.19029.20184"
},
{
"publisher": "Intuit Inc.",
"name": "QuickBooks",
"version": "30.0.4017.3000"
},
{
"publisher": "Intuit Inc.",
"name": "QuickBooks Premier: Mfg and Whsle Edition 2020",
"version": "30.0.4006.3000"
},
{
"publisher": "Intuit Inc.",
"name": "QuickBooks Runtime Redistributable",
"version": "1.00.0000"
},
{
"publisher": "ScreenConnect Software",
"name": "ScreenConnect Client (1912bf3444b41a08)",
"version": "26.1.24.9579"
},
{
"publisher": "SolidWorks Corporation",
"name": "SOLIDWORKS 2024 SP01",
"version": "32.1.0.123"
},
{
"publisher": "Dassault Systemes SolidWorks Corp",
"name": "SOLIDWORKS 2024 SP01",
"version": "32.110.0123"
},
{
"publisher": "SolidWorks Corporation",
"name": "SOLIDWORKS 2026 SP01.1",
"version": "34.1.1.11"
},
{
"publisher": "Dassault Systemes SolidWorks Corp",
"name": "SOLIDWORKS 2026 SP01.1",
"version": "34.111.0011"
},
{
"publisher": "Dassault Systemes SolidWorks Corp",
"name": "SOLIDWORKS CAM 2024 SP01",
"version": "32.10.0123"
},
{
"publisher": "Dassault Systemes SolidWorks Corp",
"name": "SOLIDWORKS Composer Player 2024 SP01",
"version": "32.10.0123"
},
{
"publisher": "Dassault Systemes SolidWorks Corp",
"name": "SOLIDWORKS Composer Player 2026 SP01.1",
"version": "34.11.0011"
},
{
"publisher": "Dassault Syst?mes SolidWorks Corp",
"name": "SOLIDWORKS eDrawings 2024 SP01",
"version": "32.10.0076"
},
{
"publisher": "Dassault Syst?mes SolidWorks Corp",
"name": "SOLIDWORKS eDrawings 2026 SP01.1",
"version": "34.11.0001"
},
{
"publisher": "Dassault Systemes SolidWorks Corp",
"name": "SOLIDWORKS File Utilities 2024 SP01",
"version": "32.10.0123"
},
{
"publisher": "Dassault Systemes SolidWorks Corp",
"name": "SOLIDWORKS File Utilities 2026 SP01.1",
"version": "34.11.0011"
},
{
"publisher": "Dassault Systemes SolidWorks Corp",
"name": "SOLIDWORKS Login Manager",
"version": "25.50.34500.0"
},
{
"publisher": "Dassault Systemes SolidWorks Corp",
"name": "SOLIDWORKS Visualize 2024 SP01",
"version": "32.10.0123"
},
{
"publisher": "Splashtop Inc.",
"name": "Splashtop Streamer",
"version": "3.8.2.0"
},
{
"publisher": "Servably, Inc.",
"name": "Syncro",
"version": "1.0.201.18410"
},
{
"publisher": "Microsoft Corporation",
"name": "Update for x64-based Windows Systems (KB5001716)",
"version": "8.94.0.0"
},
{
"publisher": "Microsoft Corporation",
"name": "Windows PC Health Check",
"version": "3.6.2204.08001"
},
{
"publisher": "Microsoft",
"name": "WPTx64",
"version": "8.100.26866"
},
{
"publisher": "Yubico AB",
"name": "Yubico Authenticator",
"version": "7.0.0"
}
],
"tpm": {
"enabled": true,
"ready": true,
"present": true
},
"local_groups": [
"Access Control Assistance Operators",
"Administrators",
"Backup Operators",
"Cryptographic Operators",
"Device Owners",
"Distributed COM Users",
"Event Log Readers",
"Guests",
"Hyper-V Administrators",
"IIS_IUSRS",
"Network Configuration Operators",
"Performance Log Users",
"Performance Monitor Users",
"Power Users",
"Remote Desktop Users",
"Remote Management Users",
"Replicator",
"System Managed Accounts Group",
"Users"
],
"battery": {
"estimated_charge_remaining": "94",
"status": "2",
"present": true
},
"third_party_av_active": false,
"activation": {
"edition": "Microsoft Windows 10 Pro",
"description": "Windows(R) Operating System, RETAIL channel",
"licensed": true,
"license_status_code": 1
},
"time_source": "UC2-SERVER.ucryo.local",
"chassis_types": [
10
],
"last_hotfix": {
"hotfix_id": "KB5072653",
"installed_on": "2025-11-20T07:00:00Z"
},
"scheduled_tasks": [
{
"path": "\\",
"name": "Adobe Acrobat Update Task",
"state": "Ready"
},
{
"path": "\\",
"name": "MicrosoftEdgeUpdateTaskMachineCore",
"state": "Ready"
},
{
"path": "\\",
"name": "MicrosoftEdgeUpdateTaskMachineUA",
"state": "Ready"
},
{
"path": "\\",
"name": "OneDrive Per-Machine Standalone Update Task",
"state": "Ready"
},
{
"path": "\\",
"name": "OneDrive Reporting Task-S-1-5-21-1051390473-2587535097-844096240-1115",
"state": "Ready"
},
{
"path": "\\",
"name": "OneDrive Reporting Task-S-1-5-21-1051390473-2587535097-844096240-1117",
"state": "Ready"
},
{
"path": "\\",
"name": "OneDrive Reporting Task-S-1-5-21-3167958784-13707620-2457732989-1001",
"state": "Ready"
},
{
"path": "\\",
"name": "OneDrive Startup Task-S-1-5-21-1051390473-2587535097-844096240-1115",
"state": "Ready"
},
{
"path": "\\",
"name": "OneDrive Startup Task-S-1-5-21-1051390473-2587535097-844096240-1117",
"state": "Ready"
},
{
"path": "\\",
"name": "OneDrive Startup Task-S-1-5-21-3167958784-13707620-2457732989-1001",
"state": "Ready"
},
{
"path": "\\",
"name": "ZoomUpdateTaskUser-S-1-5-21-1051390473-2587535097-844096240-1115",
"state": "Ready"
},
{
"path": "\\GoogleUser\\GoogleUpdater\\",
"name": "GoogleUpdaterTaskUser149.0.7814.0{E499484E-3F36-4644-8060-31171C0E93F1}",
"state": "Ready"
},
{
"path": "\\Mozilla\\",
"name": "Firefox Background Update 308046B0AF4A39CB",
"state": "Ready"
},
{
"path": "\\Mozilla\\",
"name": "Firefox Background Update S-1-5-21-1051390473-2587535097-844096240-1115 308046B0AF4A39CB",
"state": "Ready"
},
{
"path": "\\Mozilla\\",
"name": "Firefox Default Browser Agent 308046B0AF4A39CB",
"state": "Ready"
}
],
"antivirus_products": [
"Windows Defender"
],
"domain_joined": true,
"defender": {
"antispyware_signature_age": 0,
"tamper_protected": true,
"real_time_protection": true,
"nis_enabled": true,
"available": true,
"antivirus_enabled": true,
"am_service_enabled": true
},
"bitlocker": {
"os_volume": "C:",
"key_protectors": [],
"recovery_key_present": false,
"available": true,
"encryption_percent": 0,
"protection_status": "Off"
},
"is_laptop": true,
"installed_software_count": 82,
"secure_channel_ok": true,
"firewall_profiles": {
"Private": true,
"Domain": true,
"Public": true
},
"domain": "ucryo.local",
"foreign_agents": null
},
"findings": [
{
"id": "sec.defender.ok",
"category": "security",
"severity": "info",
"title": "Defender active and current",
"detail": "Real-time protection on, service running, signatures current.",
"evidence": "RealTimeProtectionEnabled=True; AMServiceEnabled=True; AntispywareSignatureAge=0 days; IsTamperProtected=True"
},
{
"id": "sec.av_products.defender_only",
"category": "security",
"severity": "info",
"title": "Defender is the only registered AV",
"detail": "Only Microsoft/Windows Defender is registered in Security Center.",
"evidence": "Windows Defender"
},
{
"id": "sec.foreign_agents.none",
"category": "security",
"severity": "info",
"title": "No competitor/leftover management agents detected",
"detail": "No known competitor RMM or unmanaged remote-access agents found in installed programs or services.",
"evidence": "Scanned uninstall hives (HKLM + WOW6432Node) and Win32_Service"
},
{
"id": "sec.foreign_agents.acg.screenconnect_connectwise_control",
"category": "security",
"severity": "info",
"title": "Expected ACG management tooling present: ScreenConnect / ConnectWise Control",
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
"evidence": "program: ScreenConnect Client (1912bf3444b41a08) 26.1.24.9579\nservice: ScreenConnect Client (1912bf3444b41a08) (ScreenConnect Client (1912bf3444b41a08)) Running"
},
{
"id": "sec.foreign_agents.acg.splashtop_sos_streamer_",
"category": "security",
"severity": "info",
"title": "Expected ACG management tooling present: Splashtop (SOS/Streamer)",
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
"evidence": "program: Splashtop Streamer 3.8.2.0\nservice: SplashtopRemoteService (Splashtop? Remote Service) Running"
},
{
"id": "sec.foreign_agents.acg.syncro_kabuto",
"category": "security",
"severity": "info",
"title": "Expected ACG management tooling present: Syncro / Kabuto",
"detail": "This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.",
"evidence": "program: Syncro 1.0.201.18410\nservice: Syncro (Syncro) Running"
},
{
"id": "sec.firewall.ok",
"category": "security",
"severity": "info",
"title": "All firewall profiles enabled",
"detail": "Domain, Private, and Public firewall profiles are all enabled.",
"evidence": "Private=True; Domain=True; Public=True"
},
{
"id": "sec.bitlocker.unencrypted",
"category": "security",
"severity": "critical",
"title": "OS volume is NOT encrypted with BitLocker",
"detail": "The operating system volume is unencrypted. Data is exposed if the disk is removed or the device is lost. This is a laptop (portable chassis), so the data-at-rest risk if lost or stolen is high. Enable BitLocker and escrow the recovery key.",
"evidence": "Volume=C:; ProtectionStatus=Off; EncryptionPercentage=0; KeyProtectors="
},
{
"id": "sec.local_admins.list",
"category": "security",
"severity": "info",
"title": "Local administrators (4)",
"detail": "Members of the local Administrators group. Review for unexpected or unknown accounts (especially leftover MSP/vendor accounts from a prior provider).",
"evidence": "KIRBY\\Administrator\nKIRBY\\localadmin\nKIRBY\\paul\nUCRYO\\Domain Admins"
},
{
"id": "sec.patch.os_eol",
"category": "security",
"severity": "critical",
"title": "OS build is end-of-life: Win10 22H2",
"detail": "This OS build (19045, Win10 22H2) passed end-of-servicing on 2025-10-14. It no longer receives security updates. Plan a feature update or OS upgrade.",
"evidence": "Microsoft Windows 10 Pro build 19045; EOL 2025-10-14"
},
{
"id": "sec.patch.pending",
"category": "security",
"severity": "warning",
"title": "4 pending Windows updates",
"detail": "Windows Update reports pending (not installed, not hidden) updates. Some may be security updates. Approve/install on the next maintenance window.",
"evidence": "Microsoft.Update.Session search IsInstalled=0 and IsHidden=0 -> 4"
},
{
"id": "sec.patch.last_hotfix",
"category": "security",
"severity": "info",
"title": "Last hotfix: KB5072653",
"detail": "Most recently installed update (from Get-HotFix; reflects CBS/MSU packages, not all cumulative metadata).",
"evidence": "KB5072653 installed 2025-11-20T07:00:00Z"
},
{
"id": "sec.exposure.rdp_on",
"category": "security",
"severity": "warning",
"title": "RDP is enabled",
"detail": "Remote Desktop is enabled (NLA required). Confirm it is restricted to VPN or specific source IPs and not exposed to the internet.",
"evidence": "fDenyTSConnections=0; UserAuthentication=1"
},
{
"id": "sec.exposure.smb1_off",
"category": "security",
"severity": "info",
"title": "SMBv1 disabled",
"detail": "SMBv1 server protocol is disabled.",
"evidence": "EnableSMB1Protocol=False"
},
{
"id": "sec.exposure.laps_present",
"category": "security",
"severity": "info",
"title": "LAPS detected",
"detail": "A LAPS mechanism is present.",
"evidence": "Windows LAPS reg key"
},
{
"id": "health.stability.clean",
"category": "health",
"severity": "info",
"title": "No stability events in the last 14 days",
"detail": "No unexpected shutdowns, BSODs, or disk errors logged.",
"evidence": "Unexpected shutdowns (id 41)=0; Bugchecks/BSOD (id 1001)=0; Disk errors (id 7/51/153)=0"
},
{
"id": "health.reboot_uptime.pending",
"category": "health",
"severity": "warning",
"title": "Reboot pending",
"detail": "A reboot is pending. Pending reboots can block patches and leave the system in a half-updated state. Schedule a restart.",
"evidence": "PendingFileRenameOperations"
},
{
"id": "health.reboot_uptime.long_uptime",
"category": "health",
"severity": "warning",
"title": "Uptime is 35.3 days",
"detail": "Uptime exceeds 30 days. Long uptime usually means pending updates have not been applied (reboots deferred). Schedule maintenance.",
"evidence": "LastBootUpTime=2026-04-28 10:03:48Z"
},
{
"id": "health.failed_services.ok",
"category": "health",
"severity": "info",
"title": "All auto-start services running",
"detail": "No automatic-start services found stopped (excluding known trigger-start/update services).",
"evidence": "Win32_Service StartMode=Auto State!=Running -> none significant"
},
{
"id": "health.domain.secure_channel_ok",
"category": "health",
"severity": "info",
"title": "Domain secure channel healthy",
"detail": "Machine trust relationship with the domain is intact.",
"evidence": "Domain=ucryo.local"
},
{
"id": "health.time.source",
"category": "health",
"severity": "info",
"title": "Time service source",
"detail": "Current Windows Time service source.",
"evidence": "Source=UC2-SERVER.ucryo.local"
},
{
"id": "health.battery.present",
"category": "health",
"severity": "info",
"title": "Battery present",
"detail": "Battery detected. (Wear-level / design-vs-full-capacity requires a powercfg battery report, not collected here.)",
"evidence": "EstimatedChargeRemaining=94%; BatteryStatus=2"
},
{
"id": "health.backup.none",
"category": "health",
"severity": "info",
"title": "No backup agent detected",
"detail": "No known backup agent service found. Backup expectation varies by endpoint; confirm whether this machine is supposed to have local/cloud backup and whether server-side or M365 backup covers it.",
"evidence": "No matching backup service in Win32_Service"
}
]
}