Files
claudetools/clients/gonzvar-tax-services/DIAGNOSTIC-SUMMARY-2026-06-06.md
Mike Swanson 9027557071 sync: auto-sync from Mikes-MacBook-Air.local at 2026-06-06 11:32:15
Author: Mike Swanson
Machine: Mikes-MacBook-Air.local
Timestamp: 2026-06-06 11:32:15
2026-06-06 11:32:16 -07:00

9.8 KiB

Gonzvar Tax Services - Onboarding Diagnostic Summary

Date: 2026-06-06 Diagnostics Run: All 6 enrolled machines Client: Gonzvar Tax Services Project Key: gonzvar


IMPORTANT CORRECTION (2026-06-06)

Diagnostic Probe Bug Discovered: Initial diagnostics reported "9 disk errors" on GTS-W0, triggering a CRITICAL finding for failing drive. This was a FALSE POSITIVE.

  • The "disk errors" are actually benign VBS (Virtualization-Based Security) boot messages
  • Event ID 153 from "Microsoft-Windows-Kernel-Boot" (not disk errors)
  • Drive health verified as HEALTHY via direct query
  • NO drive replacement needed
  • Probe script needs update to filter Event ID 153 by source
  • This bug likely affects all Windows 11 machines with VBS enabled
  • See GTS-W0-DISK-ANALYSIS.md for full investigation

Revised GTS-W0 Status: Still RED due to firewall/RDP issues, but drive is healthy.


Executive Summary

Complete security and health diagnostics performed on all 6 Gonzvar machines (3 workstations, 1 personal workstation, 2 servers). 3 machines received RED grades requiring immediate attention, 3 machines received AMBER grades requiring scheduled maintenance.

Critical Findings Across Fleet:

  • Firewall disabled on multiple machines (all profiles OFF)
  • RDP without NLA on multiple machines (pre-auth vulnerability)
  • Failing hard drive on GTS-W0 (9 disk errors in 14 days)
  • Multiple pending updates across all machines
  • BitLocker not enabled on several machines

Machine-by-Machine Results

1. GTS-W0 (Workstation) - RED

Grade: RED Findings: 3 critical / 4 warning / 14 info OS: Windows 11 Pro for Workstations (build 26200) Baseline: GTS-W0-20260606T180736.md

CRITICAL Issues:

  1. All firewalls disabled (Domain, Private, Public)

    • Exposes machine to lateral movement and inbound attacks
    • Action: Re-enable all firewall profiles immediately
  2. RDP enabled WITHOUT Network Level Authentication

    • Vulnerable to pre-auth exploits and brute force
    • Action: Enable NLA or disable RDP; restrict to VPN/allow-listed IPs
  3. Recurring stability events - 9 DISK ERRORS in 14 days FALSE POSITIVE - CORRECTED

    • ANALYSIS UPDATE 2026-06-06: The "9 disk errors" are NOT disk errors
    • All 9 events are Event ID 153 from "Microsoft-Windows-Kernel-Boot" (VBS enabled messages)
    • These are informational boot logs, not hardware failures
    • Drive is HEALTHY - Kingston NVMe confirmed OK via direct query
    • Diagnostic probe bug: Event ID 153 query needs source filtering
    • See GTS-W0-DISK-ANALYSIS.md for full investigation
    • NO DRIVE REPLACEMENT NEEDED
    • Actual stability concern: 2 unexpected shutdowns (Event ID 41) - investigate separately

WARNING Issues:

  • BitLocker not enabled (OS volume unencrypted)
  • 1 pending Windows update
  • Reboot pending
  • 4 auto-start services not running (including Group Policy Client)

Action Priority: IMMEDIATE - Data at risk from failing drive


2. GTS-W1 (Workstation) - AMBER

Grade: AMBER Findings: 0 critical / 4 warning / 16 info OS: Windows 11 Pro for Workstations (build 26200) Baseline: GTS-W1-20260606T180908.md

WARNING Issues:

  • Defender tamper protection OFF
  • 2 pending Windows updates
  • Reboot pending
  • 3 auto-start services not running

Positive:

  • BitLocker enabled with TPM + recovery password
  • All firewalls enabled
  • Defender active and current
  • No stability events

Action Priority: Moderate - Schedule maintenance window for updates/reboot


3. GTS-W2 (Workstation) - AMBER

Grade: AMBER Findings: 0 critical / 7 warning / 16 info OS: Windows 11 Pro for Workstations (build 26200) Baseline: GTS-W2-20260606T181016.md

WARNING Issues:

  • 7 warnings total (needs detailed review)
  • Likely includes: pending updates, services, stability events

Action Priority: Moderate - Review full baseline for specifics


4. GTS-PEDRO-H (Personal Workstation) - AMBER

Grade: AMBER Findings: 0 critical / 5 warning / 13 info OS: Windows 11 (build 26200) Baseline: GTS-PEDRO-H-20260606T181113.md

WARNING Issues:

  • 5 warnings (needs detailed review)

Action Priority: Moderate - Personal workstation, lower business priority


5. GTS-SVR25 (Server) - RED

Grade: RED Findings: 3 critical / 4 warning / 14 info / 1 unknown OS: Windows 11 (build 26100) Baseline: GTS-SVR25-20260606T181205.md

CRITICAL Issues:

  • 3 critical findings (needs full baseline review)
  • Likely includes: firewall, RDP, or encryption issues
  • 1 unknown check (probe failed to run)

Action Priority: IMMEDIATE - Production server with critical security issues


6. SERVER (Legacy Server) - RED

Grade: RED Findings: 3 critical / 6 warning / 12 info / 1 unknown OS: Windows 10 (build 17763) - Windows Server 2019 Baseline: SERVER-20260606T181304.md

CRITICAL Issues:

  • 3 critical findings (needs full baseline review)
  • Older Windows 10 base (Server 2019)
  • 6 warnings + 1 unknown check
  • Likely includes: firewall, RDP, or encryption issues

Action Priority: IMMEDIATE - Production server with critical security issues


Fleet-Wide Observations

Security Concerns

  1. Firewall disabled on multiple machines - widespread configuration issue
  2. RDP without NLA on multiple machines - pre-auth vulnerability exposure
  3. BitLocker inconsistent - some encrypted, some not
  4. Defender tamper protection disabled on some machines

Health Concerns

  1. Failing hard drive on GTS-W0 (9 disk errors)
  2. Pending updates across most/all machines
  3. Pending reboots on multiple machines
  4. Group Policy Client stopped on multiple machines (may indicate domain/GPO issues)

Positive Findings

  • All machines have Defender active with current signatures
  • No competitor/leftover RMM agents detected
  • ScreenConnect present on all (expected ACG tooling)
  • Recent agent versions (0.6.57)

Phase 1: IMMEDIATE (Within 24 Hours)

GTS-W0 - Security Hardening: 1. Backup all critical data immediately (failing drive risk) NOT NEEDED - Drive is healthy 2. Run SMART diagnostics COMPLETED - Drive OK 3. Order replacement drive NOT NEEDED

  1. Enable all firewalls (PowerShell or Group Policy) - CRITICAL
  2. Enable NLA for RDP or disable RDP entirely - CRITICAL
  3. Investigate 2 unexpected shutdowns (Event ID 41) - may indicate power issues

GTS-SVR25 & SERVER - Security Hardening:

  1. Review full baselines for critical findings
  2. Enable firewalls on all profiles
  3. Fix RDP (enable NLA or disable)
  4. Enable BitLocker if not already enabled
  5. Verify no unauthorized access occurred while exposed

Phase 2: Short-Term (Within 1 Week)

All Machines:

  1. Install pending Windows updates
  2. Reboot all machines (clears pending reboot flags)
  3. Enable Defender tamper protection where disabled
  4. Enable BitLocker on all unencrypted machines
  5. Investigate stopped Group Policy Client services
  6. Run second diagnostic to verify fixes

GTS-W0 Specific: 7. Replace hard drive if SMART shows failures NOT NEEDED - False positive 8. Restore data to new drive NOT NEEDED 7. Re-run diagnostic after probe fix to establish accurate baseline

Phase 3: Ongoing (Within 1 Month)

  1. Fix diagnostic probe bug - Update Event ID 153 query to exclude VBS boot messages
  2. Re-run all diagnostics - Get accurate baselines after probe fix (likely affects all Win11 machines)
  3. Standardize firewall configuration (all profiles enabled)
  4. Standardize RDP configuration (NLA required or disabled)
  5. Standardize BitLocker (all OS volumes encrypted)
  6. Review and clean up auto-start services
  7. Document baseline configuration standards
  8. Schedule quarterly re-diagnostics

Technical Details

Diagnostics Performed

  • Probe: onboarding-diagnostic.ps1 (70,739 bytes)
  • Execution: PowerShell as SYSTEM via GuruRMM
  • Timeout: 240 seconds per machine
  • Output: JSON + Markdown baselines

Checks Performed

  • Security: Defender state, AV conflicts, foreign agents, firewall, BitLocker, local admins, patch posture, OS EOL, RDP/NLA, SMBv1, UAC, LAPS
  • Health: Disk free %, SMART/disk health, 14-day stability (shutdown/BSOD/disk errors), pending reboot, uptime, failed services, domain channel, time source, battery, backup agent
  • Inventory: Hardware (model/serial/CPU/RAM/BIOS/TPM/Secure Boot), OS (edition/build/activation), installed software, network, scheduled tasks, autoruns

Baseline Storage

All baselines stored at:

clients/gonzvar-tax-services/onboarding-baselines/
  - GTS-W0-20260606T180736.{json,md}
  - GTS-W1-20260606T180908.{json,md}
  - GTS-W2-20260606T181016.{json,md}
  - GTS-PEDRO-H-20260606T181113.{json,md}
  - GTS-SVR25-20260606T181205.{json,md}
  - SERVER-20260606T181304.{json,md}

JSON files are immutable snapshots. Markdown files are human-readable reports.


Next Steps

  1. Review detailed baselines for GTS-SVR25 and SERVER critical findings
  2. Create remediation scripts for firewall/RDP/BitLocker standardization
  3. Schedule maintenance window with client for updates/reboots/drive replacement
  4. Backup GTS-W0 immediately (failing drive)
  5. Order replacement drive for GTS-W0
  6. Apply fixes per action plan phases
  7. Re-run diagnostics after remediation to verify fixes
  8. Document final baseline configuration standards

Alerts Posted

  • Alert sent to #dev-alerts for each critical finding on RED machines
  • RMM onboarding alert posted: "Mike onboarded client 'Gonzvar Tax Services' + site 'Main' (INNER-BEAR-6727)"

Report Generated: 2026-06-06 Diagnostics Completed: 2026-06-06 18:13 UTC Total Scan Time: ~6 minutes (all 6 machines) Next Action: Review GTS-SVR25 and SERVER detailed baselines + backup GTS-W0