Summary
- Total Checks: 158
- Positive Checks: 20
- Penalties: 137
- Maximum Possible Points: 100
Forensics Questions
Question 1
File Path: C:\Users\benjamin\Desktop\Forensics Question 1.txt
Content:
An external network scan identified an unauthorized web server running on this
machine and management has asked you to investigate it. The typical file path
for the web server files is C:\inetpub\wwwroot\, however, that directory is
empty.
What is the absolute file path of the configured root directory for the web
server?
( HINT: You can use inetmgr to view the web server configuration. )
( EXAMPLE: C:\Windows\System32\ )
ANSWER: <Type Answer Here>
Question 2
File Path: C:\Users\benjamin\Desktop\Forensics Question 2.txt
Content:
Remote Desktop access is determined by the local or domain security policy
called "Allow log on through Remote Desktop Services." This setting defines
which groups or users are permitted to connect using Remote Desktop Protocol.
By default, this policy usually includes two groups: Administrators and Remote
Desktop Users. However, additional groups or individual accounts can be added
manually through Group Policy or local security settings.
To find out who actually has RDP access, it is not enough to just look at the
Remote Desktop Users group. You must enumerate all users and nested groups
within the above permission to see who effectively can log in via RDP.
Based on the above information, please list all user accounts that can log in
via Remote Desktop Protocol (RDP) on this machine.
( HINT: The Administrators group does NOT currently have the permission. )
( HINT: You will NOT gain any points for removing anyone's RDP permission
as RDP is not a critical service and should be disabled. )
( EXAMPLE: Guest )
ANSWER: <Type Answer Here>
ANSWER: <Type Answer Here>
ANSWER: <Type Answer Here>
ANSWER: <Type Answer Here>
ANSWER: <Type Answer Here>
Category: Account policy (F) (ACT)
✅ Passwords are not stored using reversible encryption +4
Specific Conditions:
HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Fhas Exists equal totrueHKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Fmatches pattern^(..){76}0.
ID: REV
✅ A secure account lockout duration exists +4
Specific Conditions:
- Account Lockout Policy has Exists equal to
true - Account Lockout Policy has LockoutThreshold greater than
4 - Account Lockout Policy has LockoutThreshold less than
51 - Account Lockout Policy has LockoutDuration greater than
240
ID: DUR
Category: Application update (F) (AUP)
✅ 7-Zip has been updated +5
Specific Conditions:
C:\Program Files\7-Zip\7z.exehas Exists equal totrueC:\Program Files\7-Zip\7z.exehas FileVersionMajor greater than25-
OR
C:\Program Files\7-Zip\7z.exehas Exists equal totrueC:\Program Files\7-Zip\7z.exehas FileVersionMajor equal to25C:\Program Files\7-Zip\7z.exehas FileVersionMinor greater than0-
OR
C:\Program Files\7-Zip\7z.exehas Exists equal totrueC:\Program Files\7-Zip\7z.exehas FileVersionMajor equal to23C:\Program Files\7-Zip\7z.exehas FileVersionMinor greater than0-
OR
C:\Program Files\7-Zip\7z.exehas Exists equal totrueC:\Program Files\7-Zip\7z.exehas FileVersionMajor equal to19-
OR
C:\Program Files\7-Zip\7z.exehas Exists equal totrueC:\Program Files\7-Zip\7z.exehas FileVersionMajor equal to16C:\Program Files\7-Zip\7z.exehas FileVersionMinor greater than3-
OR
C:\Program Files\7-Zip\7z.exehas Exists equal totrueC:\Program Files\7-Zip\7z.exehas FileVersionMajor equal to9C:\Program Files\7-Zip\7z.exehas FileVersionMinor greater than19-
OR
C:\Program Files (x86)\7-Zip\7z.exehas Exists equal totrueC:\Program Files (x86)\7-Zip\7z.exehas FileVersionMajor greater than25-
OR
C:\Program Files (x86)\7-Zip\7z.exehas Exists equal totrueC:\Program Files (x86)\7-Zip\7z.exehas FileVersionMajor equal to25C:\Program Files (x86)\7-Zip\7z.exehas FileVersionMinor greater than0-
OR
C:\Program Files (x86)\7-Zip\7z.exehas Exists equal totrueC:\Program Files (x86)\7-Zip\7z.exehas FileVersionMajor equal to23C:\Program Files (x86)\7-Zip\7z.exehas FileVersionMinor greater than0-
OR
C:\Program Files (x86)\7-Zip\7z.exehas Exists equal totrueC:\Program Files (x86)\7-Zip\7z.exehas FileVersionMajor equal to19-
OR
C:\Program Files (x86)\7-Zip\7z.exehas Exists equal totrueC:\Program Files (x86)\7-Zip\7z.exehas FileVersionMajor equal to16C:\Program Files (x86)\7-Zip\7z.exehas FileVersionMinor greater than3-
OR
C:\Program Files (x86)\7-Zip\7z.exehas Exists equal totrueC:\Program Files (x86)\7-Zip\7z.exehas FileVersionMajor equal to9C:\Program Files (x86)\7-Zip\7z.exehas FileVersionMinor greater than19
ID: 7ZIP
✅ LibreOffice has been updated +5
Specific Conditions:
C:\Program Files\LibreOffice\program\swriter.exehas Exists equal totrueC:\Program Files\LibreOffice\program\swriter.exehas FileVersionMajor equal to25C:\Program Files\LibreOffice\program\swriter.exehas FileVersionMinor greater than2-
OR
C:\Program Files\LibreOffice\program\swriter.exehas Exists equal totrueC:\Program Files\LibreOffice\program\swriter.exehas FileVersionMajor greater than25-
OR
C:\Program Files (x86)\LibreOffice\program\swriter.exehas Exists equal totrueC:\Program Files (x86)\LibreOffice\program\swriter.exehas FileVersionMajor equal to25C:\Program Files (x86)\LibreOffice\program\swriter.exehas FileVersionMinor greater than2-
OR
C:\Program Files (x86)\LibreOffice\program\swriter.exehas Exists equal totrueC:\Program Files (x86)\LibreOffice\program\swriter.exehas FileVersionMajor greater than25-
OR
C:\Program Files\LibreOffice\program\scalc.exehas Exists equal totrueC:\Program Files\LibreOffice\program\scalc.exehas FileVersionMajor equal to25C:\Program Files\LibreOffice\program\scalc.exehas FileVersionMinor greater than2-
OR
C:\Program Files\LibreOffice\program\scalc.exehas Exists equal totrueC:\Program Files\LibreOffice\program\scalc.exehas FileVersionMajor greater than25-
OR
C:\Program Files (x86)\LibreOffice\program\scalc.exehas Exists equal totrueC:\Program Files (x86)\LibreOffice\program\scalc.exehas FileVersionMajor equal to25C:\Program Files (x86)\LibreOffice\program\scalc.exehas FileVersionMinor greater than2-
OR
C:\Program Files (x86)\LibreOffice\program\scalc.exehas Exists equal totrueC:\Program Files (x86)\LibreOffice\program\scalc.exehas FileVersionMajor greater than25-
OR
C:\Program Files\LibreOffice\program\simpress.exehas Exists equal totrueC:\Program Files\LibreOffice\program\simpress.exehas FileVersionMajor equal to25C:\Program Files\LibreOffice\program\simpress.exehas FileVersionMinor greater than2-
OR
C:\Program Files\LibreOffice\program\simpress.exehas Exists equal totrueC:\Program Files\LibreOffice\program\simpress.exehas FileVersionMajor greater than25-
OR
C:\Program Files (x86)\LibreOffice\program\simpress.exehas Exists equal totrueC:\Program Files (x86)\LibreOffice\program\simpress.exehas FileVersionMajor equal to25C:\Program Files (x86)\LibreOffice\program\simpress.exehas FileVersionMinor greater than2-
OR
C:\Program Files (x86)\LibreOffice\program\simpress.exehas Exists equal totrueC:\Program Files (x86)\LibreOffice\program\simpress.exehas FileVersionMajor greater than25
ID: LOFF
Category: Defensive countermeasure (F) (DEF)
✅ Firewall protection has been enabled +5
Specific Conditions:
- Firewall has Exists equal to
true - Firewall has Enabled equal to
true -
OR
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\EnableFirewallhas Exists equal totrueHKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\EnableFirewallhas Value equal to1-
OR
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\PrivateProfile\EnableFirewallhas Exists equal totrueHKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\PrivateProfile\EnableFirewallhas Value equal to1-
OR
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\PublicProfile\EnableFirewallhas Exists equal totrueHKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\PublicProfile\EnableFirewallhas Value equal to1
ID: FWALL
Category: Prohibited file (F) (FIL)
✅ Removed prohibited MP3 files +4
Specific Conditions:
C:\Users\sthomas\Music\01-05- Vertigo Delight.mp3has Exists equal tofalse-
OR
C:\Users\sthomas\Music\01-02- Fall Festival.mp3has Exists equal tofalse-
OR
C:\Users\sthomas\Desktop\has Exists equal totrue
ID: MP3
Category: Forensic Question (F) (FOR)
✅ Forensics Question 1 correct +10
Specific Conditions:
C:\Users\benjamin\Desktop\Forensics Question 1.txthas Exists equal totrue- Data of
C:\Users\benjamin\Desktop\Forensics Question 1.txtmatches patternANSWER: C:\Users\llitt\Documents\Personal\
ID: Q1
✅ Forensics Question 2 correct +10
Specific Conditions:
C:\Users\benjamin\Desktop\Forensics Question 2.txthas Exists equal totrue- Data of
C:\Users\benjamin\Desktop\Forensics Question 2.txtmatches patternANSWER: benjamin - Data of
C:\Users\benjamin\Desktop\Forensics Question 2.txtmatches patternANSWER: jpearson - Data of
C:\Users\benjamin\Desktop\Forensics Question 2.txtmatches patternANSWER: kbennett - Data of
C:\Users\benjamin\Desktop\Forensics Question 2.txtmatches patternANSWER: jquelling - Data of
C:\Users\benjamin\Desktop\Forensics Question 2.txtmatches patternANSWER: dscott
ID: Q2
Category: Malware (F) (MAL)
✅ Removed Tini backdoor +6
Specific Conditions:
C:\tini.exehas Exists equal tofalse-
OR
C:\Windows\has Exists equal totrue-
OR
- Process
\tini.exedoes not exists
ID: TINI
Category: Penalty (F) (PEN)
➖ WARNING: VirtualBox is unsupported 0
Specific Conditions:
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\VideoBiosVersionhas Exists equal totrueHKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\VideoBiosVersionmatches patternVirtualBox-
OR
HKEY_LOCAL_MACHINE\HARDWARE\ACPI\RSDT\VBOX__\Nonehas Exists equal totrue
ID: VBX
❌ Account lockout threshold less than 5 is deprecated -3
Specific Conditions:
- Account Lockout Policy has Exists equal to
true - Account Lockout Policy has LockoutThreshold greater than
0 - Account Lockout Policy has LockoutThreshold less than
5
ID: LOCK
❌ Google Chrome is not installed at the default location -5
Specific Conditions:
C:\Program Files\Google\Chrome\Application\chrome.exehas Exists not equal totrue-
OR
C:\Program Files (x86)\Google\Chrome\Application\chrome.exehas Exists not equal totrue
ID: SFT_GCHR
❌ Notepad++ is not installed at the default location -5
Specific Conditions:
C:\Program Files\Notepad++\notepad++.exehas Exists not equal totrue-
OR
C:\Program Files (X86)\Notepad++\notepad++.exehas Exists not equal totrue
ID: SFT_NPP
❌ 7-Zip is not installed at the default location -5
Specific Conditions:
C:\Program Files\7-Zip\7z.exehas Exists not equal totrue-
OR
C:\Program Files (x86)\7-Zip\7z.exehas Exists not equal totrue
ID: SFT_7ZIP
❌ Removed one or more authorized administrators -5
Specific Conditions:
benjaminhas Admin equal tofalse-
OR
benjaminhas Exists equal tofalse-
OR
edarbyhas Admin equal tofalse-
OR
edarbyhas Exists equal tofalse-
OR
jpearsonhas Admin equal tofalse-
OR
jpearsonhas Exists equal tofalse-
OR
hspecterhas Admin equal tofalse-
OR
hspecterhas Exists equal tofalse-
OR
llitthas Admin equal tofalse-
OR
llitthas Exists equal tofalse
ID: USRA
❌ Removed one or more authorized users -5
Specific Conditions:
dscotthas Exists equal tofalse-
OR
nnesbitthas Exists equal tofalse-
OR
pporterhas Exists equal tofalse-
OR
kbennetthas Exists equal tofalse-
OR
mrosshas Exists equal tofalse-
OR
rzanehas Exists equal tofalse-
OR
dpaulsenhas Exists equal tofalse-
OR
shuntleyhas Exists equal tofalse-
OR
jpomavillehas Exists equal tofalse-
OR
sbandaruhas Exists equal tofalse-
OR
sthomashas Exists equal tofalse
ID: USRS
❌ Removed one or more authorized user directories -5
Specific Conditions:
C:\Users\benjaminhas Exists equal tofalse-
OR
C:\Users\edarbyhas Exists equal tofalse-
OR
C:\Users\jpearsonhas Exists equal tofalse-
OR
C:\Users\hspecterhas Exists equal tofalse-
OR
C:\Users\llitthas Exists equal tofalse-
OR
C:\Users\dscotthas Exists equal tofalse-
OR
C:\Users\nnesbitthas Exists equal tofalse-
OR
C:\Users\pporterhas Exists equal tofalse-
OR
C:\Users\kbennetthas Exists equal tofalse-
OR
C:\Users\mrosshas Exists equal tofalse-
OR
C:\Users\rzanehas Exists equal tofalse-
OR
C:\Users\dpaulsenhas Exists equal tofalse-
OR
C:\Users\shuntleyhas Exists equal tofalse-
OR
C:\Users\jpomavillehas Exists equal tofalse-
OR
C:\Users\sbandaruhas Exists equal tofalse-
OR
C:\Users\sthomashas Exists equal tofalse
ID: USRD
Category: Local policy (F) (POL)
✅ Do not require CTRL+ALT+DEL [disabled] +5
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableCADhas Exists equal totrueHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableCADhas Value equal to0-
OR
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\DisableCADhas Exists equal totrueHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\DisableCADhas Value equal to0
ID: IL_CAD
❌ Performed an unspecified action on the registry -2
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Keyboard Layouts\0001045c\Layout Filehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Keyboard Layouts\0001045c\Layout Filehas Value equal to1
ID: GAZZR
❌ Performed an unspecified action on the registry -2
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e97d-e325-11ce-bfc1-08002be10318}\0035\Nonehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e97d-e325-11ce-bfc1-08002be10318}\0035\Nonehas Value equal to1
ID: KQGUS
❌ Performed an unspecified action on the registry -2
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Diagtrack-Listener\{2B1488D0-4158-4F7B-B43A-7A0725E370D9}\EnableLevelhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Diagtrack-Listener\{2B1488D0-4158-4F7B-B43A-7A0725E370D9}\EnableLevelhas Value equal to1
ID: PVVDF
❌ Performed an unspecified action on the registry -2
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\EventLog-Application\{dcbe5aaa-16e2-457c-9337-366950045f0a}\Nonehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\EventLog-Application\{dcbe5aaa-16e2-457c-9337-366950045f0a}\Nonehas Value equal to1
ID: GCQBY
❌ Performed an unspecified action on the registry -2
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{08B0e5c0-4FCB-11CF-AAA5-00401C608501}\Compatibility Flagshas Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{08B0e5c0-4FCB-11CF-AAA5-00401C608501}\Compatibility Flagshas Value equal to1
ID: WLBEM
❌ Performed an unspecified action on the registry -2
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Turks And Caicos Standard Time\Displayhas Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Turks And Caicos Standard Time\Displayhas Value equal to1
ID: UMZEQ
❌ Performed an unspecified action on the registry -2
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDMANDK\DriverMajorVersionhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDMANDK\DriverMajorVersionhas Value equal to1
ID: WFJET
❌ Performed an unspecified action on the registry -2
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\GraphicsDrivers\AdditionalModeLists\COMPONENT\1440x576ix50Hz_4x3\Nonehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\GraphicsDrivers\AdditionalModeLists\COMPONENT\1440x576ix50Hz_4x3\Nonehas Value equal to1
ID: ZOXED
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3029224078\RolloutStatehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3029224078\RolloutStatehas Value equal to1
ID: TXUYV
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\Locale\0000082chas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\Locale\0000082chas Value equal to1
ID: ARNZQ
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1208has Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1208has Value equal to1
ID: NICRY
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderTypes\{20338b7b-531c-4aad-8011-f5b3db2123ec}\TopViews\{9ef125c2-d179-4d37-b37d-3c52e4735abf}\Orderhas Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderTypes\{20338b7b-531c-4aad-8011-f5b3db2123ec}\TopViews\{9ef125c2-d179-4d37-b37d-3c52e4735abf}\Orderhas Value equal to1
ID: BCIAA
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\238c9fa8-0aad-41ed-83f4-97be242c8f20\25dfa149-5dd1-4736-b5ab-e8a37b5b8187\DefaultPowerSchemeValues\Nonehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\238c9fa8-0aad-41ed-83f4-97be242c8f20\25dfa149-5dd1-4736-b5ab-e8a37b5b8187\DefaultPowerSchemeValues\Nonehas Value equal to1
ID: EMHCA
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{268c95a1-edfe-11d3-95c3-0010dc4050a5}\Classhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{268c95a1-edfe-11d3-95c3-0010dc4050a5}\Classhas Value equal to1
ID: HYIJE
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\credssp.dll\Commenthas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\credssp.dll\Commenthas Value equal to1
ID: UICUM
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NtVdm64\ACMSETUP301\Nonehas Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NtVdm64\ACMSETUP301\Nonehas Value equal to1
ID: LHVEJ
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\LwtNetLog\{315a8872-923e-4ea2-9889-33cd4754bf64}\Enabledhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\LwtNetLog\{315a8872-923e-4ea2-9889-33cd4754bf64}\Enabledhas Value equal to1
ID: JPEXO
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Logging\LogDroppedPacketshas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Logging\LogDroppedPacketshas Value equal to1
ID: AAFMG
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\EventLog-System\{8507cd07-f18b-54f0-b871-23c43a5bf118}\EnablePropertyhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\EventLog-System\{8507cd07-f18b-54f0-b871-23c43a5bf118}\EnablePropertyhas Value equal to1
ID: STMNG
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Cryptography\Configuration\Local\Default\00010002\TLS_DHE_RSA_WITH_AES_256_CBC_SHA\Providershas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Cryptography\Configuration\Local\Default\00010002\TLS_DHE_RSA_WITH_AES_256_CBC_SHA\Providershas Value equal to1
ID: BKTQL
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetTcpPortSharing\ImagePathhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetTcpPortSharing\ImagePathhas Value equal to1
ID: YVRMJ
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\US Eastern Standard Time\TZIhas Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\US Eastern Standard Time\TZIhas Value equal to1
ID: SPSCZ
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\CodePage\ACPhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\CodePage\ACPhas Value equal to1
ID: XPUVT
❌ Performed an unspecified action on the registry -3
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GenPass\Starthas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GenPass\Starthas Value equal to1
ID: ICFQF
❌ Performed an unspecified action on the registry -4
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ScDeviceEnum\TriggerInfo\Nonehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ScDeviceEnum\TriggerInfo\Nonehas Value equal to1
ID: UMWTI
❌ Performed an unspecified action on the registry -4
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\North Asia Standard Time\MUI_Dlthas Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\North Asia Standard Time\MUI_Dlthas Value equal to1
ID: QIRDZ
❌ Performed an unspecified action on the registry -4
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Notifications\02821B2CA3BC2075has Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Notifications\02821B2CA3BC2075has Value equal to1
ID: CLJUI
❌ Performed an unspecified action on the registry -4
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\Nonehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\Nonehas Value equal to1
ID: HMYMN
❌ Performed an unspecified action on the registry -4
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinHttpAutoProxySvc\Parameters\Nonehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinHttpAutoProxySvc\Parameters\Nonehas Value equal to1
ID: VUXMC
❌ Performed an unspecified action on the registry -4
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedLow\DisplayNamehas Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedLow\DisplayNamehas Value equal to1
ID: UHOEM
❌ Performed an unspecified action on the registry -4
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderTypes\{fbb3477e-c9e4-4b3b-a2ba-d3f5d3cd46f9}\TopViews\{a34fce31-1399-42a7-b445-2a27e88f85f8}\ColumnListhas Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderTypes\{fbb3477e-c9e4-4b3b-a2ba-d3f5d3cd46f9}\TopViews\{a34fce31-1399-42a7-b445-2a27e88f85f8}\ColumnListhas Value equal to1
ID: GSGZW
❌ Performed an unspecified action on the registry -4
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\238c9fa8-0aad-41ed-83f4-97be242c8f20\bd3b718a-0680-4d9d-8ab2-e1d2b4ac806d\2\FriendlyNamehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\238c9fa8-0aad-41ed-83f4-97be242c8f20\bd3b718a-0680-4d9d-8ab2-e1d2b4ac806d\2\FriendlyNamehas Value equal to1
ID: VLUYI
❌ Performed an unspecified action on the registry -4
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\Locale\0000044ahas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\Locale\0000044ahas Value equal to1
ID: WUEBI
❌ Performed an unspecified action on the registry -4
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ldap\ldapclientintegrityhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ldap\ldapclientintegrityhas Value equal to1
ID: VRMKX
❌ Performed an unspecified action on the registry -4
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.EraseDisc.Action\ActionIdhas Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.EraseDisc.Action\ActionIdhas Value equal to1
ID: LSIEF
❌ Performed an unspecified action on the registry -4
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\54533251-82be-4824-96c1-47b60b740d00\75b0ae3f-bce0-45a7-8c89-c9611c25e101\DefaultPowerSchemeValues\8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c\DCSettingIndexhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\54533251-82be-4824-96c1-47b60b740d00\75b0ae3f-bce0-45a7-8c89-c9611c25e101\DefaultPowerSchemeValues\8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c\DCSettingIndexhas Value equal to1
ID: SVWZG
❌ Performed an unspecified action on the registry -5
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\UsageSubscriptions\1363780748\{ADA99BC0-C044-496A-B47D-A776D04FBC95}\ReportingKindhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\UsageSubscriptions\1363780748\{ADA99BC0-C044-496A-B47D-A776D04FBC95}\ReportingKindhas Value equal to1
ID: YCHHB
❌ Performed an unspecified action on the registry -5
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DmaSecurity\Default\AllowedBuses\Intel(R) PCI Express Root Port #5 - A294has Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DmaSecurity\Default\AllowedBuses\Intel(R) PCI Express Root Port #5 - A294has Value equal to1
ID: HMFBT
❌ Performed an unspecified action on the registry -5
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000\VidPNSource0Heighthas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000\VidPNSource0Heighthas Value equal to1
ID: MVRUA
❌ Performed an unspecified action on the registry -5
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\629057167\VariantPayloadKindhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\629057167\VariantPayloadKindhas Value equal to1
ID: QDNMA
❌ Performed an unspecified action on the registry -5
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\0012ee47-9041-4b5d-9b77-535fba8b1442\0b2d69d7-a2a1-449c-9680-f91c70521c60\DefaultPowerSchemeValues\a1841308-3541-4fab-bc81-f71556f20b4a\DCSettingIndexhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\0012ee47-9041-4b5d-9b77-535fba8b1442\0b2d69d7-a2a1-449c-9680-f91c70521c60\DefaultPowerSchemeValues\a1841308-3541-4fab-bc81-f71556f20b4a\DCSettingIndexhas Value equal to1
ID: OQMND
❌ Performed an unspecified action on the registry -5
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System\Microsoft-Windows-Kernel-Tm\Nonehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System\Microsoft-Windows-Kernel-Tm\Nonehas Value equal to1
ID: BFPQN
❌ Performed an unspecified action on the registry -5
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\EventLog-Application\{36c23e18-0e66-11d9-bbeb-505054503030}\MatchAllKeywordhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\EventLog-Application\{36c23e18-0e66-11d9-bbeb-505054503030}\MatchAllKeywordhas Value equal to1
ID: INCBM
❌ Performed an unspecified action on the registry -5
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HwNClx0101\ImagePathhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HwNClx0101\ImagePathhas Value equal to1
ID: HOCKL
❌ Performed an unspecified action on the registry -5
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WUDFWpdFs\Typehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WUDFWpdFs\Typehas Value equal to1
ID: HDOZQ
❌ Performed an unspecified action on the registry -5
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\180Ehas Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\180Ehas Value equal to1
ID: PPNFC
❌ Performed an unspecified action on the registry -5
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Notifications\41840B3EA3BD0875has Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Notifications\41840B3EA3BD0875has Value equal to1
ID: RODGC
❌ Performed an unspecified action on the registry -5
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\EventLog-Application\{72d211e1-4c54-4a93-9520-4901681b2271}\EnableLevelhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\EventLog-Application\{72d211e1-4c54-4a93-9520-4901681b2271}\EnableLevelhas Value equal to1
ID: UNORP
❌ Performed an unspecified action on the registry -5
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Video\{BFFD05D8-5655-11EF-AAA2-806E6F6E6963}\0002\VidPNSource0Heighthas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Video\{BFFD05D8-5655-11EF-AAA2-806E6F6E6963}\0002\VidPNSource0Heighthas Value equal to1
ID: LHMJT
❌ Performed an unspecified action on the registry -5
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Syria Standard Time\Dynamic DST\2021has Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Syria Standard Time\Dynamic DST\2021has Value equal to1
ID: WUKEQ
❌ Performed an unspecified action on the registry -5
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ebdrv\DisplayNamehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ebdrv\DisplayNamehas Value equal to1
ID: AJZVR
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MDCoreSvc\LaunchProtectedhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MDCoreSvc\LaunchProtectedhas Value equal to1
ID: QRQVD
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\8619b916-e004-4dd8-9b66-dae86f806698\c763ee92-71e8-4127-84eb-f6ed043a3e3d\DefaultPowerSchemeValues\381b4222-f694-41f0-9685-ff5bb260df2e\DCSettingIndexhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\8619b916-e004-4dd8-9b66-dae86f806698\c763ee92-71e8-4127-84eb-f6ed043a3e3d\DefaultPowerSchemeValues\381b4222-f694-41f0-9685-ff5bb260df2e\DCSettingIndexhas Value equal to1
ID: CJRXK
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\EnergyEstimation\CPU\EfficiencyClass\0\PowerCurve\4\PowerEnvelopehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\EnergyEstimation\CPU\EfficiencyClass\0\PowerCurve\4\PowerEnvelopehas Value equal to1
ID: ENCKZ
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WDI\Scenarios\{7AFB026E-9A24-4f4f-B193-CEB850EA611B}\DisplayResources\SourceNameResourcehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WDI\Scenarios\{7AFB026E-9A24-4f4f-B193-CEB850EA611B}\DisplayResources\SourceNameResourcehas Value equal to1
ID: OVWKO
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Diagtrack-Listener\{2504BC27-0E8B-5FED-7A9F-D86972086285}\MatchAnyKeywordhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Diagtrack-Listener\{2504BC27-0E8B-5FED-7A9F-D86972086285}\MatchAnyKeywordhas Value equal to1
ID: UJLNM
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\GraphicsDrivers\AdditionalModeLists\DVI\1280x720px59.94Hz_16x9\TimingIdhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\GraphicsDrivers\AdditionalModeLists\DVI\1280x720px59.94Hz_16x9\TimingIdhas Value equal to1
ID: ONUXU
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap\.mpv2has Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap\.mpv2has Value equal to1
ID: YFFRI
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\Low\TemplateIndexhas Exists equal tofalseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\Low\TemplateIndexhas Value equal to1
ID: NJJAA
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\EventLog-Application\{595f33ea-d4af-4f4d-b4dd-9dacdd17fc6e}\LoggerNamehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\EventLog-Application\{595f33ea-d4af-4f4d-b4dd-9dacdd17fc6e}\LoggerNamehas Value equal to1
ID: QCDPS
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\23\Requestshas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\23\Requestshas Value equal to1
ID: JSCBW
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetDiagFx\Microsoft\HostDLLs\ScenarioDependencies\HelperClasses\nid\Providers\{60523747-6516-48B7-84B1-3264FA2CB359}\Namehas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetDiagFx\Microsoft\HostDLLs\ScenarioDependencies\HelperClasses\nid\Providers\{60523747-6516-48B7-84B1-3264FA2CB359}\Namehas Value equal to1
ID: FWTHE
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vds\Security\Securityhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vds\Security\Securityhas Value equal to1
ID: EQJOS
❌ Performed an unspecified action on the registry -6
Specific Conditions:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdiSystemHost\Security\Securityhas Exists equal tofalseHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdiSystemHost\Security\Securityhas Value equal to1
ID: MFTGD
Category: Penalty (F) (SCR)
❌ Removed multiple authorized users -6
Specific Conditions:
dscotthas Exists equal tofalse-
OR
nnesbitthas Exists equal tofalse-
OR
pporterhas Exists equal tofalse-
OR
kbennetthas Exists equal tofalse-
OR
mrosshas Exists equal tofalse-
OR
rzanehas Exists equal tofalse-
OR
dpaulsenhas Exists equal tofalse-
OR
shuntleyhas Exists equal tofalse-
OR
jpomavillehas Exists equal tofalse-
OR
sbandaruhas Exists equal tofalse-
OR
sthomashas Exists equal tofalse-
OR
benjaminhas Exists equal tofalse-
OR
edarbyhas Exists equal tofalse-
OR
jpearsonhas Exists equal tofalse-
OR
hspecterhas Exists equal tofalse-
OR
llitthas Exists equal tofalse
ID: SCRU
❌ Removed multiple authorized user directories -6
Specific Conditions:
C:\Users\benjaminhas Exists equal tofalse-
OR
C:\Users\edarbyhas Exists equal tofalse-
OR
C:\Users\jpearsonhas Exists equal tofalse-
OR
C:\Users\hspecterhas Exists equal tofalse-
OR
C:\Users\llitthas Exists equal tofalse-
OR
C:\Users\dscotthas Exists equal tofalse-
OR
C:\Users\nnesbitthas Exists equal tofalse-
OR
C:\Users\pporterhas Exists equal tofalse-
OR
C:\Users\kbennetthas Exists equal tofalse-
OR
C:\Users\mrosshas Exists equal tofalse-
OR
C:\Users\rzanehas Exists equal tofalse-
OR
C:\Users\dpaulsenhas Exists equal tofalse-
OR
C:\Users\shuntleyhas Exists equal tofalse-
OR
C:\Users\jpomavillehas Exists equal tofalse-
OR
C:\Users\sbandaruhas Exists equal tofalse-
OR
C:\Users\sthomashas Exists equal tofalse
ID: SCRD
Category: Unwanted software (F) (SFT)
✅ Removed TicTacToe +4
Specific Conditions:
C:\Users\llitt\Documents\Personal\index.htmlhas Exists equal tofalse-
OR
C:\Users\llitt\Documents\has Exists equal totrue
ID: TICTAC
✅ Removed Cursor +4
Specific Conditions:
C:\Program Files\cursor\Cursor.exehas Exists equal tofalse-
OR
C:\Program Files\has Exists equal totrue
ID: CURSOR
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
C:\Windows\Media\Windows Logon.wavhas Exists equal totrue-
OR
C:\Windows\Mediahas Exists equal tofalse
ID: FNOI
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
C:\Windows\PolicyDefinitions\VolumeEncryption.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: FQLN
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
C:\Windows\PolicyDefinitions\SettingSync.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: NXGP
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
C:\Program Files\Windows Defender\MpDlp.dllhas Exists equal totrue-
OR
C:\Program Files\Windows Defenderhas Exists equal tofalse
ID: USGY
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
C:\Windows\Prefetch\WMIPRVSE.EXE-1628051C.pfhas Exists equal totrue-
OR
C:\Windows\Prefetchhas Exists equal tofalse
ID: AXCU
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
C:\Windows\PolicyDefinitions\msched.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: GWOZ
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
C:\Program Files\Windows Defender\MpClient.dllhas Exists equal totrue-
OR
C:\Program Files\Windows Defenderhas Exists equal tofalse
ID: SAIP
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
C:\Windows\Prefetch\CCSCLIENTDEBUG.EXE-61093714.pfhas Exists equal totrue-
OR
C:\Windows\Prefetchhas Exists equal tofalse
ID: WRSZ
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
C:\Windows\PolicyDefinitions\IIS.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: KEPB
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
C:\Windows\PolicyDefinitions\DeviceCredential.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: YICB
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
C:\Windows\PolicyDefinitions\CEIPEnable.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: UOOV
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
C:\Windows\Media\Invoke_48000Hz.rawhas Exists equal totrue-
OR
C:\Windows\Mediahas Exists equal tofalse
ID: TBKV
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
C:\Windows\PolicyDefinitions\Taskbar.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: SRAU
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
C:\Windows\PolicyDefinitions\LanmanServer.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: WARS
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
C:\Windows\nc.exehas Exists equal totrue-
OR
C:\Windowshas Exists equal tofalse
ID: HMJA
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
C:\Windows\Prefetch\VMTOOLSD.EXE-CD82EC13.pfhas Exists equal totrue-
OR
C:\Windows\Prefetchhas Exists equal tofalse
ID: CQYY
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
C:\Windows\Media\Windows Minimize.wavhas Exists equal totrue-
OR
C:\Windows\Mediahas Exists equal tofalse
ID: CFDV
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
C:\Windows\Prefetch\SVCHOST.EXE-EBA34E64.pfhas Exists equal totrue-
OR
C:\Windows\Prefetchhas Exists equal tofalse
ID: JCGH
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
C:\Windows\Prefetch\SVCHOST.EXE-C9CCCC35.pfhas Exists equal totrue-
OR
C:\Windows\Prefetchhas Exists equal tofalse
ID: QGRC
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
C:\Windows\Prefetch\WLRMDR.EXE-C2B47318.pfhas Exists equal totrue-
OR
C:\Windows\Prefetchhas Exists equal tofalse
ID: KMMG
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
C:\Windows\PolicyDefinitions\Explorer.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: GSGP
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
C:\Windows\PolicyDefinitions\AttachmentManager.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: QQHH
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
C:\Windows\PolicyDefinitions\inetres.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: WWLW
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
C:\Windows\Media\tada.wavhas Exists equal totrue-
OR
C:\Windows\Mediahas Exists equal tofalse
ID: JEFS
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
C:\Windows\Microsoft.NET\Framework\sbs_system.enterpriseservices.dllhas Exists equal totrue-
OR
C:\Windows\Microsoft.NET\Frameworkhas Exists equal tofalse
ID: MOTK
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
C:\Windows\PolicyDefinitions\WindowsAnytimeUpgrade.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: FOPU
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
C:\Windows\Media\Ring04.wavhas Exists equal totrue-
OR
C:\Windows\Mediahas Exists equal tofalse
ID: NWGT
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
C:\Windows\PolicyDefinitions\TenantRestrictions.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: VVWL
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\PolicyDefinitions\Thumbnails.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: UYTR
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\PolicyDefinitions\ShellWelcomeCenter.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: XHIN
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Program Files\Windows Media Player\wmprph.exehas Exists equal totrue-
OR
C:\Program Files\Windows Media Playerhas Exists equal tofalse
ID: GKEU
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\PolicyDefinitions\DWM.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: YQNB
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\Prefetch\SETUP.EXE-9ABFCE17.pfhas Exists equal totrue-
OR
C:\Windows\Prefetchhas Exists equal tofalse
ID: ZNWP
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\PolicyDefinitions\SmartScreen.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: QQAK
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\PolicyDefinitions\chrome.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: BVDU
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\PolicyDefinitions\WindowsExplorer.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: WJMM
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\Media\Speech Sleep.wavhas Exists equal totrue-
OR
C:\Windows\Mediahas Exists equal tofalse
ID: LAFU
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\PolicyDefinitions\fthsvc.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: IEAK
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\Prefetch\DLLHOST.EXE-0AD6AC16.pfhas Exists equal totrue-
OR
C:\Windows\Prefetchhas Exists equal tofalse
ID: MFPF
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\Media\GoBack_48000Hz.rawhas Exists equal totrue-
OR
C:\Windows\Mediahas Exists equal tofalse
ID: RAMX
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\PolicyDefinitions\WindowsRemoteManagement.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: XYZM
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\PolicyDefinitions\EventLog.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: SXYV
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\PolicyDefinitions\ReAgent.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: RTJV
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\System32\setup\tssysprep.dllhas Exists equal totrue-
OR
C:\Windows\System32\setuphas Exists equal tofalse
ID: GFSG
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\PolicyDefinitions\UserProfiles.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: XEPJ
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\PolicyDefinitions\Sensors.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: GEOT
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
C:\Windows\PolicyDefinitions\StorageHealth.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: ZTLH
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Program Files\Windows Defender\MpRtp.dllhas Exists equal totrue-
OR
C:\Program Files\Windows Defenderhas Exists equal tofalse
ID: TLXN
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Windows\PolicyDefinitions\NewsAndInterests.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: FNPG
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Windows\PolicyDefinitions\WindowsMediaPlayer.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: YXHX
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Program Files\Windows Defender\AmStatusInstall.mofhas Exists equal totrue-
OR
C:\Program Files\Windows Defenderhas Exists equal tofalse
ID: WGRJ
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Windows\PolicyDefinitions\AllowBuildPreview.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: TKFR
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Windows\PolicyDefinitions\Help.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: HKND
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Windows\Prefetch\CONHOST.EXE-1F3E9D7E.pfhas Exists equal totrue-
OR
C:\Windows\Prefetchhas Exists equal tofalse
ID: AZNL
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Windows\PolicyDefinitions\WindowsUpdate.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: SMKF
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Program Files\Internet Explorer\ExtExport.exehas Exists equal totrue-
OR
C:\Program Files\Internet Explorerhas Exists equal tofalse
ID: XWEE
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Windows\PolicyDefinitions\DCOM.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: HFZK
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Windows\PolicyDefinitions\Display.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: VFES
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Program Files\Windows Defender\ProtectionManagement_Uninstall.mofhas Exists equal totrue-
OR
C:\Program Files\Windows Defenderhas Exists equal tofalse
ID: VLPW
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Windows\PolicyDefinitions\ActiveXInstallService.admxhas Exists equal totrue-
OR
C:\Windows\PolicyDefinitionshas Exists equal tofalse
ID: OHUK
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Windows\Media\Windows Balloon.wavhas Exists equal totrue-
OR
C:\Windows\Mediahas Exists equal tofalse
ID: PBUJ
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Windows\Microsoft.NET\Framework\sbscmp10.dllhas Exists equal totrue-
OR
C:\Windows\Microsoft.NET\Frameworkhas Exists equal tofalse
ID: XYWB
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Windows\Media\Windows Notify System Generic.wavhas Exists equal totrue-
OR
C:\Windows\Mediahas Exists equal tofalse
ID: RPTB
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
C:\Windows\servicing\wrpintapi.dllhas Exists equal totrue-
OR
C:\Windows\servicinghas Exists equal tofalse
ID: GTAQ
Category: Service auditing (F) (SRV)
✅ World Wide Web Publishing service has been stopped and disabled +5
Specific Conditions:
- Service
W3SVChas Exists equal totrue - Service
W3SVChas State not equal toRunning -
OR
- Service
W3SVChas Exists equal tofalse -
OR
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC\Starthas Exists equal totrueHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC\Starthas Value greater than2-
OR
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC\Starthas Exists equal tofalse
ID: W3PUB
Category: Uncategorized operating system setting (F) (SYS)
✅ Remote desktop sharing is turned off +5
Specific Conditions:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\fDenyTSConnectionshas Exists equal tofalse-
OR
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\fDenyTSConnectionshas Exists equal totrueHKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\fDenyTSConnectionshas Value equal to1HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\fDenyTSConnectionshas Exists equal tofalse-
OR
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\fDenyTSConnectionshas Exists equal tofalse-
OR
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\fDenyTSConnectionshas Exists equal totrueHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\fDenyTSConnectionshas Value equal to1
ID: RDSK
Category: User auditing (F) (USR)
✅ Removed unauthorized user aholt +4
Specific Conditions:
aholthas Exists equal tofalse-
OR
aholthas Exists equal totrueaholthas Enabled equal tofalse
ID: AHOL
✅ Removed unauthorized user jquelling +4
Specific Conditions:
jquellinghas Exists equal tofalse-
OR
jquellinghas Exists equal totruejquellinghas Enabled equal tofalse
ID: JQUE
✅ User dscott is not an administrator +4
Specific Conditions:
dscotthas Exists equal totruedscotthas Admin equal tofalse
ID: DSCO
✅ User shuntley is not an administrator +4
Specific Conditions:
shuntleyhas Exists equal totrueshuntleyhas Admin equal tofalse
ID: SHUN
✅ Changed insecure password for user llitt +4
Specific Conditions:
llitthas Exists equal totruellitthas Password not equal tougotlittup
ID: LLIT
✅ User sbandaru has a password +4
Specific Conditions:
sbandaruhas Exists equal totruesbandaruhas Password not equal toNone