Summary
- Total Checks: 167
- Positive Checks: 26
- Penalties: 140
- Maximum Possible Points: 100
Forensics Questions
Question 1
File Path: C:\Users\benjamin\Desktop\Forensics Question 1.txt
Content:
A user reported a file will be accessable via the authorized SMB share that
may leak credentials. Management has asked you to find and remove this file
before creating the authorized SMB share.
What is the leaked password of the user "mross" according to this file?
( EXAMPLE: Password123! )
ANSWER: <Type Answer Here>
Question 2
File Path: C:\Users\benjamin\Desktop\Forensics Question 2.txt
Content:
During a recent audit, it was discovered that there is an open SMB share on
this machine. However, none should have been created just yet.
What user is responsible for creating the unauthorized SMB share?
( EXAMPLE: Guest )
ANSWER: <Type Answer Here>
Question 3
File Path: C:\Users\benjamin\Desktop\Forensics Question 3.txt
Content:
Management captured wireshark traffic of an attempted FTP brute force attack.
The pcap file is located on your desktop.
What is the username and password of the user that successfully logged in
during the attack?
( EXAMPLE: anonymous )
( EXAMPLE: Password123! )
ANSWER: <Type Answer Here>
ANSWER: <Type Answer Here>
Category: Account policy (F) (ACT)
✅ A secure minimum password length is required +2
Specific Conditions:
- Password Policy has Exists equal to
true - Password Policy has MinPasswordLen greater than
9
ID: MINL
✅ A secure lockout threshold exists +2
Specific Conditions:
- Account Lockout Policy has Exists equal to
true - Account Lockout Policy has LockoutThreshold greater than
4 - Account Lockout Policy has LockoutThreshold less than
51
ID: THR
Category: Application security (F) (APP)
✅ Exec SMB share permissions have been correctly configured +5
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Shares\Security\EXEChas Exists equal totrueHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Shares\Security\EXECmatches patternFF011F0001050000000000051500000073A8A7EE22E82BB11DC0FF17HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Shares\Security\EXECmatches patternFF011F0001020000000000052000000020020000HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Shares\Security\EXECdoes not match patternFF011F00010100000000000100000000HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Shares\Security\EXECdoes not match patternA9001200010100000000000100000000HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Shares\Security\EXECdoes not match patternBF011300010100000000000100000000
ID: SMB_EXEC_PERM
✅ SMB 1.x removed or disabled +5
Specific Conditions:
- Service
mrxsmb10has Exists equal tofalse -
OR
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mrxsmb10\Starthas Exists equal tofalse-
OR
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\SMB1has Exists equal totrueHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\SMB1has Value equal to0-
OR
-
OR
-
OR
-
OR
C:\Windows\Sysnative\Drivers\mrxsmb10.syshas Exists equal tofalse
ID: SMB_NOV1
Category: Application update (F) (AUP)
✅ Notepad++ has been updated +3
Specific Conditions:
C:\Program Files\Notepad++\notepad++.exehas Exists equal totrueC:\Program Files\Notepad++\notepad++.exehas FileVersionMajor greater than8-
OR
C:\Program Files\Notepad++\notepad++.exehas Exists equal totrueC:\Program Files\Notepad++\notepad++.exehas FileVersionMajor equal to8C:\Program Files\Notepad++\notepad++.exehas FileVersionMinor greater than5-
OR
C:\Program Files (x86)\Notepad++\notepad++.exehas Exists equal totrueC:\Program Files (x86)\Notepad++\notepad++.exehas FileVersionMajor greater than8-
OR
C:\Program Files (x86)\Notepad++\notepad++.exehas Exists equal totrueC:\Program Files (x86)\Notepad++\notepad++.exehas FileVersionMajor equal to8C:\Program Files (x86)\Notepad++\notepad++.exehas FileVersionMinor greater than5
ID: NTPP
✅ Wireshark has been updated +3
Specific Conditions:
C:\Program Files\Wireshark\Wireshark.exehas Exists equal totrueC:\Program Files\Wireshark\Wireshark.exehas FileVersionMajor greater than4-
OR
C:\Program Files\Wireshark\Wireshark.exehas Exists equal totrueC:\Program Files\Wireshark\Wireshark.exehas FileVersionMajor equal to4C:\Program Files\Wireshark\Wireshark.exehas FileVersionMinor greater than5-
OR
C:\Program Files (x86)\Wireshark\Wireshark.exehas Exists equal totrueC:\Program Files (x86)\Wireshark\Wireshark.exehas FileVersionMajor greater than4-
OR
C:\Program Files (x86)\Wireshark\Wireshark.exehas Exists equal totrueC:\Program Files (x86)\Wireshark\Wireshark.exehas FileVersionMajor equal to4C:\Program Files (x86)\Wireshark\Wireshark.exehas FileVersionMinor greater than5
ID: WRSHRK
Category: Prohibited file (F) (FIL)
✅ Removed plain text file with passwords in it +4
Specific Conditions:
C:\Exec\staff.csvhas Exists equal tofalse-
OR
C:\Exec\staff.csvhas Exists equal totrue- Data of
C:\Exec\staff.csvdoes not match patternT00GooD4Harvard! - Data of
C:\Exec\staff.csvdoes not match patternugotlittup - Data of
C:\Exec\staff.csvdoes not match patternHGrD48hwZ6 - Data of
C:\Exec\staff.csvdoes not match patternLZNg3yfiHU -
OR
C:\Exec\Merger Press Release.pdfhas Exists equal totrue-
OR
C:\Exec\Merger Press Release.pdfhas Exists equal totrue
ID: PWRD
Category: Forensic Question (F) (FOR)
✅ Forensics Question 1 correct +7
Specific Conditions:
C:\Users\benjamin\Desktop\Forensics Question 1.txthas Exists equal totrue- Data of
C:\Users\benjamin\Desktop\Forensics Question 1.txtmatches patternANSWER: T00GooD4Harvard!
ID: Q1
✅ Forensics Question 2 correct +7
Specific Conditions:
C:\Users\benjamin\Desktop\Forensics Question 2.txthas Exists equal totrue- Data of
C:\Users\benjamin\Desktop\Forensics Question 2.txtmatches patternANSWER: jpearson
ID: Q2
✅ Forensics Question 3 correct +7
Specific Conditions:
C:\Users\benjamin\Desktop\Forensics Question 3.txthas Exists equal totrue- Data of
C:\Users\benjamin\Desktop\Forensics Question 3.txtmatches patternANSWER: dscott - Data of
C:\Users\benjamin\Desktop\Forensics Question 3.txtmatches patternANSWER: harvey123
ID: Q3
Category: Malware (F) (MAL)
✅ Removed netcat backdoor +5
Specific Conditions:
C:\Windows\Sysnative\exportfile.exehas Exists equal tofalse-
OR
C:\Windows\has Exists equal totrue-
OR
- Process
\Windows\System32\exportfile.exedoes not exists
ID: NCAT
Category: Operating system update (F) (OUP)
✅ Windows automatically checks for updates +3
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\NoAutoUpdatehas Exists equal tofalse-
OR
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\NoAutoUpdatehas Exists equal totrueHKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\NoAutoUpdatehas Value not equal to1
ID: AUTO_10
Category: Penalty (F) (PEN)
➖ WARNING: VirtualBox is unsupported 0
Specific Conditions:
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\VideoBiosVersionhas Exists equal totrueHKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\VideoBiosVersionmatches patternVirtualBox-
OR
HKEY_LOCAL_MACHINE\HARDWARE\ACPI\RSDT\VBOX__\Nonehas Exists equal totrue
ID: VBX
❌ Account lockout threshold less than 5 is deprecated -3
Specific Conditions:
- Account Lockout Policy has Exists equal to
true - Account Lockout Policy has LockoutThreshold greater than
0 - Account Lockout Policy has LockoutThreshold less than
5
ID: LOCK
❌ Remote Desktop is disabled -5
Specific Conditions:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Terminal Server\fDenyTSConnectionshas Exists equal tofalse-
OR
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Terminal Server\fDenyTSConnectionshas Exists equal totrueHKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Terminal Server\fDenyTSConnectionshas Value not equal to0
ID: RDSK
❌ SMB client service (v2/v3) disabled -5
Specific Conditions:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mrxsmb20\Starthas Exists equal totrueHKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mrxsmb20\Starthas Value equal to4-
OR
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mrxsmb20\Starthas Exists equal tofalse
ID: SRV_SMBC
❌ Google Chrome is not installed at the default location -5
Specific Conditions:
C:\Program Files\Google\Chrome\Application\chrome.exehas Exists not equal totrue-
OR
C:\Program Files (x86)\Google\Chrome\Application\chrome.exehas Exists not equal totrue
ID: SFT_GCHR
❌ Notepad++ is not installed at the default location -5
Specific Conditions:
C:\Program Files\Notepad++\notepad++.exehas Exists not equal totrue-
OR
C:\Program Files (X86)\Notepad++\notepad++.exehas Exists not equal totrue
ID: SFT_NPP
❌ 7-Zip is not installed at the default location -5
Specific Conditions:
C:\Program Files\7-Zip\7z.exehas Exists not equal totrue-
OR
C:\Program Files (x86)\7-Zip\7z.exehas Exists not equal totrue
ID: SFT_7ZIP
❌ Wireshark is not installed at the default location -5
Specific Conditions:
C:\Program Files\Wireshark\Wireshark.exehas Exists not equal totrue-
OR
C:\Program Files (x86)\Wireshark\Wireshark.exehas Exists not equal totrue
ID: SFT_WRSH
❌ Critical business file(s) deleted from SMB share -5
Specific Conditions:
C:\Exec\Merger press release.pdfhas Exists equal tofalse
ID: FIL_SMB
❌ Removed one or more authorized administrators -5
Specific Conditions:
benjaminhas Admin equal tofalse-
OR
benjaminhas Exists equal tofalse-
OR
edarbyhas Admin equal tofalse-
OR
edarbyhas Exists equal tofalse-
OR
jpearsonhas Admin equal tofalse-
OR
jpearsonhas Exists equal tofalse-
OR
hspecterhas Admin equal tofalse-
OR
hspecterhas Exists equal tofalse-
OR
llitthas Admin equal tofalse-
OR
llitthas Exists equal tofalse
ID: USRA
❌ Removed one or more authorized users -5
Specific Conditions:
dscotthas Exists equal tofalse-
OR
nnesbitthas Exists equal tofalse-
OR
pporterhas Exists equal tofalse-
OR
kbennetthas Exists equal tofalse-
OR
mrosshas Exists equal tofalse-
OR
rzanehas Exists equal tofalse-
OR
dpaulsenhas Exists equal tofalse-
OR
shuntleyhas Exists equal tofalse-
OR
jpomavillehas Exists equal tofalse-
OR
sbandaruhas Exists equal tofalse-
OR
sthomashas Exists equal tofalse
ID: USRS
❌ Removed one or more authorized user directories -5
Specific Conditions:
C:\Users\benjaminhas Exists equal tofalse-
OR
C:\Users\edarbyhas Exists equal tofalse-
OR
C:\Users\jpearsonhas Exists equal tofalse-
OR
C:\Users\hspecterhas Exists equal tofalse-
OR
C:\Users\llitthas Exists equal tofalse-
OR
C:\Users\dscotthas Exists equal tofalse-
OR
C:\Users\nnesbitthas Exists equal tofalse-
OR
C:\Users\pporterhas Exists equal tofalse-
OR
C:\Users\kbennetthas Exists equal tofalse-
OR
C:\Users\mrosshas Exists equal tofalse-
OR
C:\Users\rzanehas Exists equal tofalse-
OR
C:\Users\dpaulsenhas Exists equal tofalse-
OR
C:\Users\shuntleyhas Exists equal tofalse-
OR
C:\Users\jpomavillehas Exists equal tofalse-
OR
C:\Users\sbandaruhas Exists equal tofalse-
OR
C:\Users\sthomashas Exists equal tofalse
ID: USRD
Category: Local policy (F) (POL)
✅ Everyone may not access this computer from the network +3
Specific Conditions:
- User Rights object
Everyonehas Exists equal totrue - User Rights object
Everyonehas SeNetworkLogonRight not equal totrue
ID: SE_NLR
✅ Limit local use of blank passwords to console only [enabled] +3
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\LimitBlankPasswordUsehas Exists equal totrueHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\LimitBlankPasswordUsehas Value equal to1
ID: AC_LBPU
✅ Microsoft network server: Digitally sign communications (always) [enabled] +3
Specific Conditions:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\RequireSecuritySignaturehas Value equal to1
ID: MNS_RSIG
✅ Audit File Share [Success] +2
Specific Conditions:
- Audit Policy has Exists equal to
true - Audit Policy has ObjectAccess.FileShare equal to
Success
ID: AU_FSS
❌ Performed an unspecified action on the registry -2
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}\Namehas Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}\Namehas Value equal to1
ID: CXCCF
❌ Performed an unspecified action on the registry -2
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\e73a048d-bf27-4f12-9731-8b2076e8891f\637ea02f-bbcb-4015-8e2c-a1c7b9c0b546\DefaultPowerSchemeValues\381b4222-f694-41f0-9685-ff5bb260df2e\ACSettingIndexhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\e73a048d-bf27-4f12-9731-8b2076e8891f\637ea02f-bbcb-4015-8e2c-a1c7b9c0b546\DefaultPowerSchemeValues\381b4222-f694-41f0-9685-ff5bb260df2e\ACSettingIndexhas Value equal to1
ID: JQKYF
❌ Performed an unspecified action on the registry -2
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\CaretTracking\{DE66E1FD-06EE-4677-813A-D791EE9DBB06}\12.0.0.0\paneClassDC\UsePreXPCaretTranslationhas Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\CaretTracking\{DE66E1FD-06EE-4677-813A-D791EE9DBB06}\12.0.0.0\paneClassDC\UsePreXPCaretTranslationhas Value equal to1
ID: FZKAL
❌ Performed an unspecified action on the registry -2
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedInterfaces\IfIso\FirewallRules\Microsoft.Windows.NarratorQuickStart_8wekyb3d8bbwe_S-1-5-21-4003965043-2972444706-402636829-1000_In_emptyRemoteName_Allhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedInterfaces\IfIso\FirewallRules\Microsoft.Windows.NarratorQuickStart_8wekyb3d8bbwe_S-1-5-21-4003965043-2972444706-402636829-1000_In_emptyRemoteName_Allhas Value equal to1
ID: LVPVB
❌ Performed an unspecified action on the registry -2
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\New Zealand Standard Time\Dynamic DST\LastEntryhas Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\New Zealand Standard Time\Dynamic DST\LastEntryhas Value equal to1
ID: QERBA
❌ Performed an unspecified action on the registry -2
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e96a-e325-11ce-bfc1-08002be10318}\Configuration\Variables\UseBusDeviceDesc\KeyRoothas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e96a-e325-11ce-bfc1-08002be10318}\Configuration\Variables\UseBusDeviceDesc\KeyRoothas Value equal to1
ID: UICDG
❌ Performed an unspecified action on the registry -2
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\EventLog-System\{aa3aa23b-bb6d-425a-b58c-1d7e37f5d02a}\MatchAllKeywordhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\EventLog-System\{aa3aa23b-bb6d-425a-b58c-1d7e37f5d02a}\MatchAllKeywordhas Value equal to1
ID: FHYKR
❌ Performed an unspecified action on the registry -2
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceClasses\{86841137-ed8e-4d97-9975-f2ed56b4430e}\##?#HDAUDIO#FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001#5&217be3d6&0&0001#{86841137-ed8e-4d97-9975-f2ed56b4430e}\DeviceInstancehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceClasses\{86841137-ed8e-4d97-9975-f2ed56b4430e}\##?#HDAUDIO#FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001#5&217be3d6&0&0001#{86841137-ed8e-4d97-9975-f2ed56b4430e}\DeviceInstancehas Value equal to1
ID: DSWPX
❌ Performed an unspecified action on the registry -2
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBIOS\Grouphas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBIOS\Grouphas Value equal to1
ID: RZTRS
❌ Performed an unspecified action on the registry -2
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTPROMPT\ALLOW\HKeyRoothas Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTPROMPT\ALLOW\HKeyRoothas Value equal to1
ID: CJXUI
❌ Performed an unspecified action on the registry -2
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e97d-e325-11ce-bfc1-08002be10318}\0123\InfPathhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e97d-e325-11ce-bfc1-08002be10318}\0123\InfPathhas Value equal to1
ID: FOVCE
❌ Performed an unspecified action on the registry -2
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DoSvc\TriggerInfo\0\DataType0has Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DoSvc\TriggerInfo\0\DataType0has Value equal to1
ID: OTZQI
❌ Performed an unspecified action on the registry -2
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderTypes\{631958a6-ad0f-4035-a745-28ac066dc6ed}\TopViews\{2c0bc161-7181-49ba-8337-10584d53d8d0}\PrimaryPropertyhas Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderTypes\{631958a6-ad0f-4035-a745-28ac066dc6ed}\TopViews\{2c0bc161-7181-49ba-8337-10584d53d8d0}\PrimaryPropertyhas Value equal to1
ID: JLKLV
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\StillImage\Events\EmailImage\GUIDhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\StillImage\Events\EmailImage\GUIDhas Value equal to1
ID: TFULU
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT\HelpPane.exehas Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT\HelpPane.exehas Value equal to1
ID: RHSQU
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Diagtrack-Listener\{207CF9D5-B3E5-5F45-9A58-C1308F9ABDDA}\MatchAnyKeywordhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Diagtrack-Listener\{207CF9D5-B3E5-5F45-9A58-C1308F9ABDDA}\MatchAnyKeywordhas Value equal to1
ID: EBNWL
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceContainers\{00000000-0000-0000-FFFF-FFFFFFFFFFFF}\BaseContainers\{00000000-0000-0000-FFFF-FFFFFFFFFFFF}\ACPI\PNP0A05\39has Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceContainers\{00000000-0000-0000-FFFF-FFFFFFFFFFFF}\BaseContainers\{00000000-0000-0000-FFFF-FFFFFFFFFFFF}\ACPI\PNP0A05\39has Value equal to1
ID: ZVRDD
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Turks And Caicos Standard Time\MUI_Stdhas Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Turks And Caicos Standard Time\MUI_Stdhas Value equal to1
ID: EVYGZ
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\QWAVEdrv\Security\Securityhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\QWAVEdrv\Security\Securityhas Value equal to1
ID: FOFDN
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\ACCESSIBILITY\CARETBROWSING\CheckedValuehas Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\ACCESSIBILITY\CARETBROWSING\CheckedValuehas Value equal to1
ID: EBEHA
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UALSVC\ObjectNamehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UALSVC\ObjectNamehas Value equal to1
ID: QHQSQ
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\smphost\DependOnServicehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\smphost\DependOnServicehas Value equal to1
ID: NJBXY
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\AnimateMinMax\Nonehas Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\AnimateMinMax\Nonehas Value equal to1
ID: OIWMI
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bindflt\Parameters\WppRecorder_TraceGuidhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bindflt\Parameters\WppRecorder_TraceGuidhas Value equal to1
ID: XNZOA
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\54533251-82be-4824-96c1-47b60b740d00\4bdaf4e9-d103-46d7-a5f0-6280121616ef\DefaultPowerSchemeValues\Nonehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\54533251-82be-4824-96c1-47b60b740d00\4bdaf4e9-d103-46d7-a5f0-6280121616ef\DefaultPowerSchemeValues\Nonehas Value equal to1
ID: NSRPX
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\238c9fa8-0aad-41ed-83f4-97be242c8f20\25dfa149-5dd1-4736-b5ab-e8a37b5b8187\DefaultPowerSchemeValues\a1841308-3541-4fab-bc81-f71556f20b4a\ACSettingIndexhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\238c9fa8-0aad-41ed-83f4-97be242c8f20\25dfa149-5dd1-4736-b5ab-e8a37b5b8187\DefaultPowerSchemeValues\a1841308-3541-4fab-bc81-f71556f20b4a\ACSettingIndexhas Value equal to1
ID: JHRGB
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\Content Indexer Cleaner\Nonehas Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\Content Indexer Cleaner\Nonehas Value equal to1
ID: GRGGH
❌ Performed an unspecified action on the registry -4
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CoreUI\Navigation\Timeouts\BeginHidehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CoreUI\Navigation\Timeouts\BeginHidehas Value equal to1
ID: SQXML
❌ Performed an unspecified action on the registry -4
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CompositeBus\Starthas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CompositeBus\Starthas Value equal to1
ID: OFDLN
❌ Performed an unspecified action on the registry -4
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0010\Ndi\Nonehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0010\Ndi\Nonehas Value equal to1
ID: MCZDD
❌ Performed an unspecified action on the registry -4
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\54533251-82be-4824-96c1-47b60b740d00\1facfc65-a930-4bc5-9f38-504ec097bbc0\DefaultPowerSchemeValues\381b4222-f694-41f0-9685-ff5bb260df2e\DCSettingIndexhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\54533251-82be-4824-96c1-47b60b740d00\1facfc65-a930-4bc5-9f38-504ec097bbc0\DefaultPowerSchemeValues\381b4222-f694-41f0-9685-ff5bb260df2e\DCSettingIndexhas Value equal to1
ID: SOIOO
❌ Performed an unspecified action on the registry -4
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System\Microsoft-Windows-WMPNSS-Service\ProviderGuidhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System\Microsoft-Windows-WMPNSS-Service\ProviderGuidhas Value equal to1
ID: MMMGP
❌ Performed an unspecified action on the registry -4
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SecurityHealthService\Security\Nonehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SecurityHealthService\Security\Nonehas Value equal to1
ID: TMGHZ
❌ Performed an unspecified action on the registry -4
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetDiagFx\Microsoft\HostDLLs\WPPTrace\HelperClasses\dhcp_wpp\Providers\{CC3DF8E3-4111-48D0-9B21-7631021F7CA6}\Levelhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetDiagFx\Microsoft\HostDLLs\WPPTrace\HelperClasses\dhcp_wpp\Providers\{CC3DF8E3-4111-48D0-9B21-7631021F7CA6}\Levelhas Value equal to1
ID: HNXKB
❌ Performed an unspecified action on the registry -4
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Wdf\Schema\UmdfImpersonationLevel\Map\Delegationhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Wdf\Schema\UmdfImpersonationLevel\Map\Delegationhas Value equal to1
ID: QCEIY
❌ Performed an unspecified action on the registry -4
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\_V2Providers\{f3991d9d-fc17-4f37-b12f-8984a43e1aeb}\{c0c9c676-ac38-40d4-a23c-69f05d12a306}\Last Counterhas Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\_V2Providers\{f3991d9d-fc17-4f37-b12f-8984a43e1aeb}\{c0c9c676-ac38-40d4-a23c-69f05d12a306}\Last Counterhas Value equal to1
ID: HOEKV
❌ Performed an unspecified action on the registry -5
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SystemEventsBroker\Parameters\EventPolicyTable\SebSmartCardFieldEntryNotification\Nonehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SystemEventsBroker\Parameters\EventPolicyTable\SebSmartCardFieldEntryNotification\Nonehas Value equal to1
ID: KDJJA
❌ Performed an unspecified action on the registry -5
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e97d-e325-11ce-bfc1-08002be10318}\0124\ResourcePickerExceptionshas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e97d-e325-11ce-bfc1-08002be10318}\0124\ResourcePickerExceptionshas Value equal to1
ID: BMPTF
❌ Performed an unspecified action on the registry -5
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Keyboard Layouts\00030437\Nonehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Keyboard Layouts\00030437\Nonehas Value equal to1
ID: QBMUY
❌ Performed an unspecified action on the registry -5
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DcomLaunch\FailureActionshas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DcomLaunch\FailureActionshas Value equal to1
ID: GSMRN
❌ Performed an unspecified action on the registry -5
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetDiagFx\Microsoft\HostDLLs\WPPTrace\HelperClasses\WirelessDisplay\Providers\{db6f6ddb-ac77-4e88-8253-819df9bbf140}\Namehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetDiagFx\Microsoft\HostDLLs\WPPTrace\HelperClasses\WirelessDisplay\Providers\{db6f6ddb-ac77-4e88-8253-819df9bbf140}\Namehas Value equal to1
ID: EYNYC
❌ Performed an unspecified action on the registry -5
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderTypes\{7d49d726-3c21-4f05-99aa-fdc2c9474656}\Modifiers\SearchResultshas Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderTypes\{7d49d726-3c21-4f05-99aa-fdc2c9474656}\Modifiers\SearchResultshas Value equal to1
ID: LUCER
❌ Performed an unspecified action on the registry -5
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetDiagFx\Microsoft\HostDLLs\Wireless LAN Helper Class\HelperClasses\AutoConfig Helper Class\RRMap\{ABCED36C-0543-4d71-B276-EA2DBA1AB9E1}\{69847C11-A993-41b7-AC2C-FB926C906339}has Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetDiagFx\Microsoft\HostDLLs\Wireless LAN Helper Class\HelperClasses\AutoConfig Helper Class\RRMap\{ABCED36C-0543-4d71-B276-EA2DBA1AB9E1}\{69847C11-A993-41b7-AC2C-FB926C906339}has Value equal to1
ID: HBTKK
❌ Performed an unspecified action on the registry -5
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderTypes\{24ccb8a6-c45a-477d-b940-3382b9225668}\CanonicalNamehas Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderTypes\{24ccb8a6-c45a-477d-b940-3382b9225668}\CanonicalNamehas Value equal to1
ID: PQWFA
❌ Performed an unspecified action on the registry -5
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\54533251-82be-4824-96c1-47b60b740d00\f565999f-3fb0-411a-a226-3f0198dec130\DefaultPowerSchemeValues\8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c\Nonehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\54533251-82be-4824-96c1-47b60b740d00\f565999f-3fb0-411a-a226-3f0198dec130\DefaultPowerSchemeValues\8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c\Nonehas Value equal to1
ID: QHYWI
❌ Performed an unspecified action on the registry -5
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Security\cb2ff72d-d4e4-585d-33f9-f3a395c40be7has Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Security\cb2ff72d-d4e4-585d-33f9-f3a395c40be7has Value equal to1
ID: MWGYI
❌ Performed an unspecified action on the registry -5
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.DisconnectNetworkDrive\command\DelegateExecutehas Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.DisconnectNetworkDrive\command\DelegateExecutehas Value equal to1
ID: GEVNA
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\EventLog-System\{66a5c15c-4f8e-4044-bf6e-71d896038977}\LoggerNamehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\EventLog-System\{66a5c15c-4f8e-4044-bf6e-71d896038977}\LoggerNamehas Value equal to1
ID: XTNRC
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\EventLog-Application\{db00dfb6-29f9-4a9c-9b3b-1f4f9e7d9770}\Enabledhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\EventLog-Application\{db00dfb6-29f9-4a9c-9b3b-1f4f9e7d9770}\Enabledhas Value equal to1
ID: SLRPW
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetDiagFx\Config\RC\{3564f41a-6610-4c46-8df2-9b490f2f4169}has Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetDiagFx\Config\RC\{3564f41a-6610-4c46-8df2-9b490f2f4169}has Value equal to1
ID: ZSGDC
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DeviceInstall\TriggerInfo\Nonehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DeviceInstall\TriggerInfo\Nonehas Value equal to1
ID: HHYLY
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Cryptography\Configuration\Local\Default\00010002\TLS_DHE_RSA_WITH_AES_128_GCM_SHA256\Flagshas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Cryptography\Configuration\Local\Default\00010002\TLS_DHE_RSA_WITH_AES_128_GCM_SHA256\Flagshas Value equal to1
ID: KUHVS
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CDPUserSvc_6a527\ImagePathhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CDPUserSvc_6a527\ImagePathhas Value equal to1
ID: LQECI
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaCategories\{65e8773e-8f56-11d0-a3b9-00a0c9223196}\Namehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaCategories\{65e8773e-8f56-11d0-a3b9-00a0c9223196}\Namehas Value equal to1
ID: NGXHU
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e97d-e325-11ce-bfc1-08002be10318}\0038\DriverDatehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e97d-e325-11ce-bfc1-08002be10318}\0038\DriverDatehas Value equal to1
ID: ZLCFN
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetDiagFx\Microsoft\HostDLLs\WPPTrace\HelperClasses\wireless_dbg\Dependencies\nid_wpphas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetDiagFx\Microsoft\HostDLLs\WPPTrace\HelperClasses\wireless_dbg\Dependencies\nid_wpphas Value equal to1
ID: DIDXS
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\EventLog-Application\{89300202-3cec-4981-9171-19f59559e0f2}\Statushas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\EventLog-Application\{89300202-3cec-4981-9171-19f59559e0f2}\Statushas Value equal to1
ID: TLPJQ
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\VAN\{1B02C1F5-555B-4802-96A7-ADDDCCBCA38A}\Nonehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\VAN\{1B02C1F5-555B-4802-96A7-ADDDCCBCA38A}\Nonehas Value equal to1
ID: MVQSG
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e97d-e325-11ce-bfc1-08002be10318}\0036\DriverDateDatahas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e97d-e325-11ce-bfc1-08002be10318}\0036\DriverDateDatahas Value equal to1
ID: OUOVI
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartMenu\StartPanel\PinnedItems\Devices\Typehas Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartMenu\StartPanel\PinnedItems\Devices\Typehas Value equal to1
ID: LMUMA
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\UnitedVideo\CONTROL\VIDEO\{9189F203-8AF5-11EC-942E-806E6F6E6963}\0000\DefaultSettings.Flagshas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\UnitedVideo\CONTROL\VIDEO\{9189F203-8AF5-11EC-942E-806E6F6E6963}\0000\DefaultSettings.Flagshas Value equal to1
ID: IQQZJ
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TrustedInstaller\Starthas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TrustedInstaller\Starthas Value equal to1
ID: ODPXZ
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceClasses\{0ecef634-6ef0-472a-8085-5ad023ecbccd}\##?#SWD#PRINTENUM#{CECFA109-1C57-4FA9-9356-AC955F6019F4}#{0ecef634-6ef0-472a-8085-5ad023ecbccd}\Nonehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceClasses\{0ecef634-6ef0-472a-8085-5ad023ecbccd}\##?#SWD#PRINTENUM#{CECFA109-1C57-4FA9-9356-AC955F6019F4}#{0ecef634-6ef0-472a-8085-5ad023ecbccd}\Nonehas Value equal to1
ID: PDEOH
Category: Penalty (F) (SCR)
❌ Removed multiple authorized user directories -2
Specific Conditions:
C:\Users\benjaminhas Exists equal tofalse-
OR
C:\Users\edarbyhas Exists equal tofalse-
OR
C:\Users\jpearsonhas Exists equal tofalse-
OR
C:\Users\hspecterhas Exists equal tofalse-
OR
C:\Users\llitthas Exists equal tofalse-
OR
C:\Users\dscotthas Exists equal tofalse-
OR
C:\Users\nnesbitthas Exists equal tofalse-
OR
C:\Users\pporterhas Exists equal tofalse-
OR
C:\Users\kbennetthas Exists equal tofalse-
OR
C:\Users\mrosshas Exists equal tofalse-
OR
C:\Users\rzanehas Exists equal tofalse-
OR
C:\Users\dpaulsenhas Exists equal tofalse-
OR
C:\Users\shuntleyhas Exists equal tofalse-
OR
C:\Users\jpomavillehas Exists equal tofalse-
OR
C:\Users\sbandaruhas Exists equal tofalse-
OR
C:\Users\sthomashas Exists equal tofalse
ID: SCRD
❌ Removed multiple authorized users -3
Specific Conditions:
dscotthas Exists equal tofalse-
OR
nnesbitthas Exists equal tofalse-
OR
pporterhas Exists equal tofalse-
OR
kbennetthas Exists equal tofalse-
OR
mrosshas Exists equal tofalse-
OR
rzanehas Exists equal tofalse-
OR
dpaulsenhas Exists equal tofalse-
OR
shuntleyhas Exists equal tofalse-
OR
jpomavillehas Exists equal tofalse-
OR
sbandaruhas Exists equal tofalse-
OR
sthomashas Exists equal tofalse-
OR
benjaminhas Exists equal tofalse-
OR
edarbyhas Exists equal tofalse-
OR
jpearsonhas Exists equal tofalse-
OR
hspecterhas Exists equal tofalse-
OR
llitthas Exists equal tofalse
ID: SCRU
Category: Unwanted software (F) (SFT)
✅ Removed TightVNC Server +5
Specific Conditions:
C:\Program Files\TightVNC\tvnserver.exehas Exists equal tofalse-
OR
C:\Program Files\has Exists equal totrue-
OR
- Process
\tvnserver.exedoes not exists
ID: TIVNC
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
C:\Windows\PolicyDefinitions\wlansvc.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: JLDW
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
C:\Windows\PolicyDefinitions\Winsrv.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: SSED
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
C:\Windows\PolicyDefinitions\StartMenu.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: DENF
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
C:\Windows\PolicyDefinitions\Radar.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: OKCO
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
C:\Windows\PolicyDefinitions\Speech.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: MKWA
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
C:\Windows\PolicyDefinitions\DeviceGuard.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: QZUN
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
C:\Windows\Media\notify.wavhas Exists equal totrue-
OR
C:\Windows\Mediahas Exists equal tofalse
ID: BLQF
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
C:\Windows\PolicyDefinitions\Reliability.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: MPGI
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
C:\Windows\PolicyDefinitions\MMCSnapins.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: XEFN
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
C:\Windows\Media\Windows User Account Control.wavhas Exists equal totrue-
OR
C:\Windows\Mediahas Exists equal tofalse
ID: YVRS
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.inihas Exists equal totrue-
OR
C:\ProgramData\Microsoft\Windows\Start Menu\Programshas Exists equal tofalse
ID: SCEA
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
C:\Windows\Media\Ring01.wavhas Exists equal totrue-
OR
C:\Windows\Mediahas Exists equal tofalse
ID: OFXQ
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
C:\Windows\PolicyDefinitions\WindowsUpdate.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: TVFH
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
C:\Windows\PolicyDefinitions\CEIPEnable.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: QYDZ
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
C:\Windows\PolicyDefinitions\DeliveryOptimization.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: ZRKV
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
C:\Windows\Media\Windows Feed Discovered.wavhas Exists equal totrue-
OR
C:\Windows\Mediahas Exists equal tofalse
ID: DXRN
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
C:\Windows\PolicyDefinitions\RPC.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: RZSF
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
C:\Windows\PolicyDefinitions\fthsvc.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: JQVK
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
C:\Windows\Media\Alarm09.wavhas Exists equal totrue-
OR
C:\Windows\Mediahas Exists equal tofalse
ID: QZCO
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
C:\Windows\PolicyDefinitions\SoundRec.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: ZLMN
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
C:\Windows\PolicyDefinitions\NetworkConnections.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: KGBB
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
C:\Windows\PolicyDefinitions\MobilePCMobilityCenter.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: XZRW
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
C:\Windows\PolicyDefinitions\CredentialProviders.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: WYBG
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
C:\Windows\Media\Focus2_48000Hz.rawhas Exists equal totrue-
OR
C:\Windows\Mediahas Exists equal tofalse
ID: GKFH
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
C:\Windows\PolicyDefinitions\WindowsConnectNow.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: UJII
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
C:\Windows\Media\tada.wavhas Exists equal totrue-
OR
C:\Windows\Mediahas Exists equal tofalse
ID: NXWB
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
C:\Windows\PolicyDefinitions\EnhancedStorage.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: VFOK
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
C:\Windows\PolicyDefinitions\SharedFolders.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: JJWB
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
C:\Windows\PolicyDefinitions\DiskQuota.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: PYJH
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
C:\Windows\Media\Windows Balloon.wavhas Exists equal totrue-
OR
C:\Windows\Mediahas Exists equal tofalse
ID: EMWB
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
C:\Windows\Media\Windows Unlock.wavhas Exists equal totrue-
OR
C:\Windows\Mediahas Exists equal tofalse
ID: BLUA
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
C:\Windows\PolicyDefinitions\EncryptFilesonMove.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: IWAW
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
C:\Windows\Media\Windows Battery Critical.wavhas Exists equal totrue-
OR
C:\Windows\Mediahas Exists equal tofalse
ID: WNUO
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
C:\Windows\PolicyDefinitions\DnsClient.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: KMKE
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
C:\Windows\Media\flourish.midhas Exists equal totrue-
OR
C:\Windows\Mediahas Exists equal tofalse
ID: JXQM
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
C:\Windows\PolicyDefinitions\EdgeUI.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: MIFC
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
C:\Windows\PolicyDefinitions\WindowsSandbox.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: WOPC
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
C:\Windows\Media\trojan.dllhas Exists equal totrue-
OR
C:\Windows\Mediahas Exists equal tofalse
ID: PNZL
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
C:\Windows\PolicyDefinitions\AllowBuildPreview.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: DTKZ
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
C:\Program Files\Windows Media Player\wmpnetwk.exehas Exists equal totrue-
OR
C:\Program Files\Windows Media Playerhas Exists equal tofalse
ID: BQMX
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
C:\Windows\PolicyDefinitions\WindowsProducts.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: ZZNJ
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\PolicyDefinitions\TabletShell.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: DOGP
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\Media\Ring06.wavhas Exists equal totrue-
OR
C:\Windows\Mediahas Exists equal tofalse
ID: CTQU
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\mytrojan.dllhas Exists equal totrue-
OR
C:\Windowshas Exists equal tofalse
ID: USKD
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Program Files\Windows NT\Accessories\IrisProtocol.dllhas Exists equal totrue-
OR
C:\Program Files\Windows NT\Accessorieshas Exists equal tofalse
ID: JPRN
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\PolicyDefinitions\LanmanWorkstation.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: XFQZ
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Program Files\Windows Defender\ProtectionManagement_Uninstall.mofhas Exists equal totrue-
OR
C:\Program Files\Windows Defenderhas Exists equal tofalse
ID: VMJV
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Server Manager.lnkhas Exists equal totrue-
OR
C:\ProgramData\Microsoft\Windows\Start Menu\Programshas Exists equal tofalse
ID: IAAQ
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\System32\GroupPolicy\User\has Exists equal totrue-
OR
C:\Windows\System32\GroupPolicy\Userhas Exists equal tofalse
ID: EZUS
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\PolicyDefinitions\WindowsMediaDRM.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: BBHV
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\PolicyDefinitions\WPN.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: DADW
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\Media\Windows Proximity Connection.wavhas Exists equal totrue-
OR
C:\Windows\Mediahas Exists equal tofalse
ID: VNKA
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\PolicyDefinitions\WindowsInkWorkspace.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: GYAT
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Windows\PolicyDefinitions\EAIME.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: GFBF
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Windows\PolicyDefinitions\AppXRuntime.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: FCQY
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Windows\Media\Windows Menu Command.wavhas Exists equal totrue-
OR
C:\Windows\Mediahas Exists equal tofalse
ID: BWDP
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Program Files\Windows Media Player\WMPNSSUI.dllhas Exists equal totrue-
OR
C:\Program Files\Windows Media Playerhas Exists equal tofalse
ID: TXXT
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Windows\PolicyDefinitions\InkWatson.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: UAUE
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Windows\Media\Alarm05.wavhas Exists equal totrue-
OR
C:\Windows\Mediahas Exists equal tofalse
ID: KGDP
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Windows\Media\Windows Error.wavhas Exists equal totrue-
OR
C:\Windows\Mediahas Exists equal tofalse
ID: NPQG
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Windows\PolicyDefinitions\FileHistory.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: XYXO
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Program Files\Windows Defender\MpEvMsg.dllhas Exists equal totrue-
OR
C:\Program Files\Windows Defenderhas Exists equal tofalse
ID: ANAC
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Windows\PolicyDefinitions\WinLogon.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: FRAI
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Windows\PolicyDefinitions\PeerToPeerCaching.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: DQEA
Category: Uncategorized operating system setting (F) (SYS)
✅ File sharing disabled for hidden share Private$ +4
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanServer\Shares\Private$has Exists equal tofalse
ID: SHHDN
✅ Created Executive SMB Share +4
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanServer\Shares\EXEChas Exists equal totrue-
OR
C:\EXEChas Exists equal totrue
ID: SMB_EXEC
Category: User auditing (F) (USR)
✅ Created group Exec SMB Users +4
Specific Conditions:
- Group
Exec SMB Usershas Exists equal totrue
ID: SMB_GRP1
✅ Added users to group Exec SMB Users +4
Specific Conditions:
- Group
Exec SMB Usershas Exists equal totrue - Group
Exec SMB Usershas Member equal tojpearson - Group
Exec SMB Usershas Member equal toedarby - Group
Exec SMB Usershas Member equal todpaulsen
ID: SMB_GRP2
✅ Removed unauthorized user ttanner +3
Specific Conditions:
ttannerhas Exists equal tofalse-
OR
ttannerhas Exists equal totruettannerhas Enabled equal tofalse
ID: TTAN
✅ Removed unauthorized user tgianopolous +3
Specific Conditions:
tgianopoloushas Exists equal tofalse-
OR
tgianopoloushas Exists equal totruetgianopoloushas Enabled equal tofalse
ID: TGIA
✅ User kbennett is not an administrator +3
Specific Conditions:
kbennetthas Exists equal totruekbennetthas Admin equal tofalse
ID: KBEN
✅ User rzane is not an administrator +3
Specific Conditions:
rzanehas Exists equal totruerzanehas Admin equal tofalse
ID: RZAN
✅ Changed insecure password for user dscott +3
Specific Conditions:
dscotthas Exists equal totruedscotthas Password not equal toharvey123