255 lines
7.6 KiB
Markdown
255 lines
7.6 KiB
Markdown
# Onboarding Diagnostic Baseline - MJ-PARALEGAL
|
|
|
|
- **Grade:** RED
|
|
- **Host:** MJ-PARALEGAL
|
|
- **Client:** Michael Johnson (`michaeljohnson`)
|
|
- **Collected (UTC):** 2026-06-29T21:17:55Z
|
|
- **Agent ID:** 4537ac34-e548-484c-b4e9-fd91e7f97a23
|
|
- **Command ID:** a3095ece-7fd3-4751-acc6-867a1b41507b
|
|
- **Findings:** 2 critical / 4 warning / 14 info / 0 unknown
|
|
|
|
- **OS:** Microsoft Windows 11 Pro (build 26200)
|
|
|
|
---
|
|
|
|
## CRITICAL (2)
|
|
|
|
### Firewall disabled on profile(s): Private, Public
|
|
- **Category:** security
|
|
- **ID:** `sec.firewall.disabled`
|
|
- One or more firewall profiles are OFF. The endpoint is exposed to lateral movement and inbound attacks on those networks. Re-enable all profiles.
|
|
|
|
```
|
|
Profile states: Private=False; Domain=True; Public=False
|
|
```
|
|
|
|
### Disk critically low: E: at 0% free
|
|
- **Category:** health
|
|
- **ID:** `health.disk_space.E`
|
|
- Less than 8 percent free. Risk of failed updates, crashes, and corruption. Free space or expand the volume urgently.
|
|
|
|
```
|
|
E: free 0 GB of 255.6 GB (0%)
|
|
```
|
|
|
|
|
|
## WARNING (4)
|
|
|
|
### OS volume is NOT encrypted with BitLocker
|
|
- **Category:** security
|
|
- **ID:** `sec.bitlocker.unencrypted`
|
|
- The operating system volume is unencrypted. Data is exposed if the disk is removed or the device is lost. Enable BitLocker and escrow the recovery key.
|
|
|
|
```
|
|
Volume=C:; ProtectionStatus=Off; EncryptionPercentage=0; KeyProtectors=
|
|
```
|
|
|
|
### 2 pending Windows updates
|
|
- **Category:** security
|
|
- **ID:** `sec.patch.pending`
|
|
- Windows Update reports pending (not installed, not hidden) updates. Some may be security updates. Approve/install on the next maintenance window.
|
|
|
|
```
|
|
Microsoft.Update.Session search IsInstalled=0 and IsHidden=0 -> 2
|
|
```
|
|
|
|
### Stability events present in the last 14 days
|
|
- **Category:** health
|
|
- **ID:** `health.stability.some`
|
|
- One or more unexpected shutdowns, BSODs, or disk errors occurred recently. Monitor and correlate with user reports.
|
|
|
|
```
|
|
Unexpected shutdowns (id 41)=1; Bugchecks/BSOD (id 1001)=0; Disk errors (id 7/51/153)=0
|
|
```
|
|
|
|
### 6 auto-start service(s) not running
|
|
- **Category:** health
|
|
- **ID:** `health.failed_services.stopped`
|
|
- These services are set to start automatically but are not running. Some may be benign; review for security agents, backup agents, or AV that should be running.
|
|
|
|
```
|
|
AsusUpdateCheck (AsusUpdateCheck) = Stopped
|
|
GoogleUpdaterInternalService150.0.7863.0 (Google Updater Internal Service (GoogleUpdaterInternalService150.0.7863.0)) = Stopped
|
|
GoogleUpdaterService150.0.7863.0 (Google Updater Service (GoogleUpdaterService150.0.7863.0)) = Stopped
|
|
IBMPMSVC (Lenovo PM Service) = Stopped
|
|
Intel(R) TPM Provisioning Service (Intel(R) TPM Provisioning Service) = Stopped
|
|
LPlatSvc (Lenovo Platform Service) = Stopped
|
|
```
|
|
|
|
|
|
## INFO (14)
|
|
|
|
### Defender active and current
|
|
- **Category:** security
|
|
- **ID:** `sec.defender.ok`
|
|
- Real-time protection on, service running, signatures current.
|
|
|
|
```
|
|
RealTimeProtectionEnabled=True; AMServiceEnabled=True; AntispywareSignatureAge=1 days; IsTamperProtected=True
|
|
```
|
|
|
|
### Defender is the only registered AV
|
|
- **Category:** security
|
|
- **ID:** `sec.av_products.defender_only`
|
|
- Only Microsoft/Windows Defender is registered in Security Center.
|
|
|
|
```
|
|
Windows Defender
|
|
```
|
|
|
|
### No competitor/leftover management agents detected
|
|
- **Category:** security
|
|
- **ID:** `sec.foreign_agents.none`
|
|
- No known competitor RMM or unmanaged remote-access agents found in installed programs or services.
|
|
|
|
```
|
|
Scanned uninstall hives (HKLM + WOW6432Node) and Win32_Service
|
|
```
|
|
|
|
### Expected ACG management tooling present: ScreenConnect / ConnectWise Control
|
|
- **Category:** security
|
|
- **ID:** `sec.foreign_agents.acg.screenconnect_connectwise_control`
|
|
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
|
|
|
|
```
|
|
program: ScreenConnect Client (1912bf3444b41a08) 26.3.11.9650
|
|
service: ScreenConnect Client (1912bf3444b41a08) (ScreenConnect Client (1912bf3444b41a08)) Running
|
|
```
|
|
|
|
### Expected ACG management tooling present: Splashtop (SOS/Streamer)
|
|
- **Category:** security
|
|
- **ID:** `sec.foreign_agents.acg.splashtop_sos_streamer_`
|
|
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
|
|
|
|
```
|
|
program: Splashtop Streamer 3.8.4.0
|
|
service: SplashtopRemoteService (Splashtop? Remote Service) Running
|
|
```
|
|
|
|
### Expected ACG management tooling present: Syncro / Kabuto
|
|
- **Category:** security
|
|
- **ID:** `sec.foreign_agents.acg.syncro_kabuto`
|
|
- This is Arizona Computer Guru managed/remote-access tooling that we deploy. Its presence is expected and not a foreign-agent risk.
|
|
|
|
```
|
|
program: Syncro 1.0.201.18410
|
|
service: Syncro (Syncro) Running
|
|
```
|
|
|
|
### Local administrators (3)
|
|
- **Category:** security
|
|
- **ID:** `sec.local_admins.list`
|
|
- Members of the local Administrators group. Review for unexpected or unknown accounts (especially leftover MSP/vendor accounts from a prior provider).
|
|
|
|
```
|
|
MJ-PARALEGAL\Administrator
|
|
MJ-PARALEGAL\localadmin
|
|
MJ-PARALEGAL\Paralegal
|
|
```
|
|
|
|
### OS build supported: Win11 25H2
|
|
- **Category:** security
|
|
- **ID:** `sec.patch.os_supported`
|
|
- Build 26200 (Win11 25H2) is in support until 2027-10-12.
|
|
|
|
```
|
|
Microsoft Windows 11 Pro build 26200
|
|
```
|
|
|
|
### Last hotfix: KB5094126
|
|
- **Category:** security
|
|
- **ID:** `sec.patch.last_hotfix`
|
|
- Most recently installed update (from Get-HotFix; reflects CBS/MSU packages, not all cumulative metadata).
|
|
|
|
```
|
|
KB5094126 installed 2026-06-10T07:00:00Z
|
|
```
|
|
|
|
### SMBv1 disabled
|
|
- **Category:** security
|
|
- **ID:** `sec.exposure.smb1_off`
|
|
- SMBv1 server protocol is disabled.
|
|
|
|
```
|
|
EnableSMB1Protocol=False
|
|
```
|
|
|
|
### LAPS detected
|
|
- **Category:** security
|
|
- **ID:** `sec.exposure.laps_present`
|
|
- A LAPS mechanism is present.
|
|
|
|
```
|
|
Windows LAPS reg key
|
|
```
|
|
|
|
### Not domain-joined (workgroup)
|
|
- **Category:** health
|
|
- **ID:** `health.domain.workgroup`
|
|
- This machine is in workgroup/Azure AD only mode (Domain=WORKGROUP). No on-prem AD secure channel applies.
|
|
|
|
```
|
|
PartOfDomain=False; Domain=WORKGROUP
|
|
```
|
|
|
|
### Time service source
|
|
- **Category:** health
|
|
- **ID:** `health.time.source`
|
|
- Current Windows Time service source.
|
|
|
|
```
|
|
Source=time.windows.com,0x9
|
|
```
|
|
|
|
### No backup agent detected
|
|
- **Category:** health
|
|
- **ID:** `health.backup.none`
|
|
- No known backup agent service found. Backup expectation varies by endpoint; confirm whether this machine is supposed to have local/cloud backup and whether server-side or M365 backup covers it.
|
|
|
|
```
|
|
No matching backup service in Win32_Service
|
|
```
|
|
|
|
|
|
---
|
|
|
|
## Inventory Baseline Summary
|
|
|
|
- **Manufacturer / Model:** ASUS / System Product Name
|
|
- **Serial:** System Serial Number
|
|
- **CPU:** Intel(R) Core(TM) i5-10400 CPU @ 2.90GHz (6 cores / 12 logical)
|
|
- **RAM (GB):** 15.8
|
|
- **BIOS:** 1620 (2021-07-09)
|
|
- **Chassis is laptop:** false
|
|
- **TPM present / Secure Boot:** true / true
|
|
- **Domain joined:** false (WORKGROUP)
|
|
- **OS activation licensed:** true
|
|
- **Uptime (days):** 0.3
|
|
- **Pending reboot:** false
|
|
- **Installed software count:** 98
|
|
- **Scheduled tasks (non-MS, enabled):** 24
|
|
- **Local administrators:** MJ-PARALEGAL\Administrator, MJ-PARALEGAL\localadmin, MJ-PARALEGAL\Paralegal
|
|
|
|
### Fixed volumes
|
|
|
|
- E: - 0 GB free of 255.6 GB (0%)
|
|
- [unlabeled] - 0.2 GB free of 1 GB (18.7%)
|
|
- D: - 0 GB free of 0 GB (75.5%)
|
|
- C: - 70 GB free of 464.2 GB (15.1%)
|
|
- [unlabeled] - 0.1 GB free of 0.1 GB (64%)
|
|
- [unlabeled] - 0.1 GB free of 0.5 GB (16.6%)
|
|
|
|
### Network adapters
|
|
|
|
- Realtek PCIe GBE Family Controller - IP: 192.168.1.136, fe80::b20c:8d0b:48bf:1aea - DNS: 172.16.132.1 - DHCP: true
|
|
|
|
---
|
|
|
|
## Diff vs Prior Baseline
|
|
|
|
- No prior baseline found for this host. This is the first baseline.
|
|
|
|
---
|
|
|
|
_Generated by run-onboarding-diagnostic.sh (GuruRMM onboarding diagnostic, Phase 1). Raw snapshot: `MJ-PARALEGAL-20260629T211845.json` (immutable)._
|