| Severity | Area | Finding / Evidence | Recommendation |
|---|---|---|---|
| High | Services | Service runs from user-writable path: ZoomCptService "C:\Program Files\Common Files\Zoom\Support\CptService.exe" -user_path "C:\Users\Default\AppData\Roaming\Zoom" | Move service binaries to protected paths and verify permissions. |
| High | Users | Password not required: DefaultAccount PasswordRequired=False | Require local account passwords. |
| High | Users | Password not required: CorpGuest.REDACTED PasswordRequired=False | Require local account passwords. |
| Info | Antivirus | Microsoft Defender appears disabled/passive because another AV/EDR is registered Registered AV/EDR: CrowdStrike Falcon Sensor | Verify the third-party AV/EDR is managed and healthy. |
| Info | BitLocker | BitLocker was not fully checked Admin required; Run elevated to query BitLocker | Run elevated to check BitLocker protection state. |
| Info | Device Control | USB storage appears enabled USBSTOR Start=3 | Confirm removable media policy matches the organization policy. |
| Info | Event Logs | Recent Application error: C:\ProgramData\Azure\AzCopy\azcopy.exe / 0 | Review if the error repeats, affects security controls, or maps to failed services, drivers, updates or authentication. |
| Info | Event Logs | Recent Application error: HCP Port Monitor / 0 | Review if the error repeats, affects security controls, or maps to failed services, drivers, updates or authentication. |
| Info | Event Logs | Recent Application error: HCP Port Monitor / 0 | Review if the error repeats, affects security controls, or maps to failed services, drivers, updates or authentication. |
| Info | Event Logs | Recent Application error: VSS / 13 Volume Shadow Copy Service information: The COM Server with CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} and name Coordinator cannot be started. [0x80070005, Access is denied. ] | Review if the error repeats, affects security controls, or maps to failed services, drivers, updates or authentication. |
| Info | Ghost Devices | Non-present device: Generic volume shadow copy Class=VolumeSnapshot; InstanceId=STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2 | Review if stale devices are unexpected, especially old NICs, storage, VPN, security or remote access devices. |
| Info | Ghost Devices | Non-present device: HID-compliant consumer control device Class=HIDClass; InstanceId=HID\VID_0B0E&PID_030B&MI_03&COL03\8&35AECF77&0&0002 | Review if stale devices are unexpected, especially old NICs, storage, VPN, security or remote access devices. |
| Info | Ghost Devices | Non-present device: Jabra Evolve 65 Class=MEDIA; InstanceId=USB\VID_0B0E&PID_030B&MI_00\7&30FD822B&0&0000 | Review if stale devices are unexpected, especially old NICs, storage, VPN, security or remote access devices. |
| Info | Ghost Devices | Non-present device: MIDI 2.0 Service Tests Class=SoftwareDevice; InstanceId=SWD\MIDISRV\MIDIU_DIAG_TRANSPORT | Review if stale devices are unexpected, especially old NICs, storage, VPN, security or remote access devices. |
| Info | Ghost Devices | Non-present device: PS/2 Compatible Mouse Class=Mouse; InstanceId=ACPI\DLL0A5B\4&77AFA20&0 | Review if stale devices are unexpected, especially old NICs, storage, VPN, security or remote access devices. |
| Info | Ghost Devices | Non-present device: Service Test Loopback A Class=SoftwareDevice; InstanceId=SWD\MIDISRV\MIDIU_DIAG_LOOPBACK_A | Review if stale devices are unexpected, especially old NICs, storage, VPN, security or remote access devices. |
| Info | Ghost Devices | Non-present device: Service Test Loopback B Class=SoftwareDevice; InstanceId=SWD\MIDISRV\MIDIU_DIAG_LOOPBACK_B | Review if stale devices are unexpected, especially old NICs, storage, VPN, security or remote access devices. |
| Info | Ghost Devices | Non-present device: Speakers (Jabra Evolve 65) Class=AudioEndpoint; InstanceId=SWD\MMDEVAPI\{0.0.0.00000000}.{D9EA0B81-ABB1-4919-929A-D798006EC989} | Review if stale devices are unexpected, especially old NICs, storage, VPN, security or remote access devices. |
| Info | Ghost Devices | Non-present device: USB Composite Device Class=USB; InstanceId=USB\VID_0B0E&PID_030B\50C2ED067EBE | Review if stale devices are unexpected, especially old NICs, storage, VPN, security or remote access devices. |
| Info | Ghost Devices | Non-present device: USB Input Device Class=HIDClass; InstanceId=USB\VID_0B0E&PID_0311\50C2ED067EBE | Review if stale devices are unexpected, especially old NICs, storage, VPN, security or remote access devices. |
| Info | Installed Software CVE Review | Review signal: AD Info Free Edition 1.7.92 1 CVE(s); highest=MEDIUM 6.8; top=CVE-2021-20876. Local installed-software matching is weaker evidence than service/banner matching. | Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability. |
| Info | Installed Software CVE Review | Review signal: Intel(R) LMS 1.0.0.0 1 CVE(s); highest=MEDIUM 6.4; top=CVE-2020-8704. Local installed-software matching is weaker evidence than service/banner matching. | Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability. |
| Info | Installed Software CVE Review | Review signal: Intel(R) Management Engine Driver 1.0.0.0 1 CVE(s); highest=MEDIUM 5.5; top=CVE-2021-33087. Local installed-software matching is weaker evidence than service/banner matching. | Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability. |
| Info | Installed Software CVE Review | Review signal: Microsoft Edge 149.0.4022.62 2 CVE(s); highest=MEDIUM 5; top=CVE-2015-6057, CVE-2015-6058. Local installed-software matching is weaker evidence than service/banner matching. | Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability. |
| Info | USB Storage | USB mass storage appears enabled USBSTOR Start=3 | Confirm removable media policy matches the organization policy. |
| Low | Certificates | Expired certificate: CN=AddTrust External CA Root, OU=AddTrust External TTP Network, O=AddTrust AB, C=SE Store=Cert:\LocalMachine\Root; NotAfter=05/30/2020 12:48:38 | Remove expired/unneeded certificates or renew if still used. |
| Low | Certificates | Expired certificate: CN=AddTrust External CA Root, OU=AddTrust External TTP Network, O=AddTrust AB, C=SE Store=Cert:\CurrentUser\Root; NotAfter=05/30/2020 12:48:38 | Remove expired/unneeded certificates or renew if still used. |
| Low | Certificates | Expired certificate: CN=Microsoft Authenticode(tm) Root Authority, O=MSFT, C=US Store=Cert:\CurrentUser\Root; NotAfter=01/01/2000 00:59:59 | Remove expired/unneeded certificates or renew if still used. |
| Low | Certificates | Expired certificate: CN=Microsoft Authenticode(tm) Root Authority, O=MSFT, C=US Store=Cert:\LocalMachine\Root; NotAfter=01/01/2000 00:59:59 | Remove expired/unneeded certificates or renew if still used. |
| Low | Certificates | Expired certificate: CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US Store=Cert:\LocalMachine\Root; NotAfter=07/09/2019 20:40:36 | Remove expired/unneeded certificates or renew if still used. |
| Low | Certificates | Expired certificate: CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US Store=Cert:\CurrentUser\Root; NotAfter=07/09/2019 20:40:36 | Remove expired/unneeded certificates or renew if still used. |
| Low | Certificates | Expired certificate: OU="NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.", OU=VeriSign Time Stamping Service Root, OU="VeriSign, Inc.", O=VeriSign Trust Network Store=Cert:\LocalMachine\Root; NotAfter=01/08/2004 00:59:59 | Remove expired/unneeded certificates or renew if still used. |
| Low | Certificates | Expired certificate: OU="NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.", OU=VeriSign Time Stamping Service Root, OU="VeriSign, Inc.", O=VeriSign Trust Network Store=Cert:\CurrentUser\Root; NotAfter=01/08/2004 00:59:59 | Remove expired/unneeded certificates or renew if still used. |
| Low | Certificates | Expired certificate: OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Time Stamping Service Root, OU=Microsoft Corporation, O=Microsoft Trust Network Store=Cert:\LocalMachine\Root; NotAfter=12/31/1999 00:59:59 | Remove expired/unneeded certificates or renew if still used. |
| Low | Certificates | Expired certificate: OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Time Stamping Service Root, OU=Microsoft Corporation, O=Microsoft Trust Network Store=Cert:\CurrentUser\Root; NotAfter=12/31/1999 00:59:59 | Remove expired/unneeded certificates or renew if still used. |
| Low | Installed Software CVE Review | Review signal: Dell Display and Peripheral Manager 2.1.0.24 2 CVE(s); highest=HIGH 7.3; top=CVE-2025-46430, CVE-2026-21419. Local installed-software matching is weaker evidence than service/banner matching. | Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability. |
| Low | Installed Software CVE Review | Review signal: Fiddler 4.4.9.2 1 CVE(s); highest=HIGH 8.8; top=CVE-2020-13661. Local installed-software matching is weaker evidence than service/banner matching. | Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability. |
| Low | Installed Software CVE Review | Review signal: Intel(R) Wireless Bluetooth(R) 23.30.0.3 5 CVE(s); highest=HIGH 7.8; top=CVE-2020-0555, CVE-2019-14620, CVE-2024-24984, CVE-2023-47859, CVE-2023-45845. Local installed-software matching is weaker evidence than service/banner matching. | Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability. |
| Low | Installed Software CVE Review | Review signal: ISS_Drivers_x64 3.10.100.4446 1 CVE(s); highest=HIGH 7.1; top=CVE-2024-50035. Local installed-software matching is weaker evidence than service/banner matching. | Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability. |
| Low | Installed Software CVE Review | Review signal: Microsoft Intune Management Extension 1.101.111.0 1 CVE(s); highest=HIGH 8.1; top=CVE-2021-31980. Local installed-software matching is weaker evidence than service/banner matching. | Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability. |
| Low | Installed Software CVE Review | Review signal: Notepad++ 8.9.6.4 4 CVE(s); highest=HIGH 8.4; top=CVE-2025-56383, CVE-2026-25866, CVE-2025-49144, CVE-2007-5145. Local installed-software matching is weaker evidence than service/banner matching. | Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability. |
| Low | Installed Software CVE Review | Review signal: OpenSSL 3.4.1 4 CVE(s); highest=HIGH 7.5; top=CVE-2004-0079, CVE-2003-0851, CVE-2004-0081, CVE-2004-0112. Local installed-software matching is weaker evidence than service/banner matching. | Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability. |
| Low | Listening Ports | Listening RPC Endpoint Mapper / 135 Address=0.0.0.0; Process=svchost; Context=Common local listening service. Confirm it is expected and firewall-scoped. | Confirm the service is expected, patched, and restricted by host firewall or network policy. |
| Low | Listening Ports | Listening RPC Endpoint Mapper / 135 Address=::; Process=svchost; Context=Common local listening service. Confirm it is expected and firewall-scoped. | Confirm the service is expected, patched, and restricted by host firewall or network policy. |
| Low | Printers | Shared printer: Share=; Driver= | Confirm the printer share and driver are required. |
| Low | Remote Access | Remote access indicator: TeamViewer Host Installed software; TeamViewer | Confirm this remote access tool/service is expected and managed. |
| Low | Updates | Pending reboot detected Pending file rename | Reboot during maintenance. |
| Low | Windows Security Baseline | LSASS protection is not clearly enabled RunAsPPL=2 | Consider enabling LSA protection where compatible. |
| Medium | Firewall Rules | Risky inbound allow rule: Core Networking - Teredo (ICMPv6-In) Ports=; Remote=*; Profile=Domain,Private,Public | Confirm the rule is required and scope it to trusted networks. |
| Medium | Firewall Rules | Risky inbound allow rule: Microsoft 365 Copilot Ports=; Remote=*; Profile=Domain,Private,Public | Confirm the rule is required and scope it to trusted networks. |
| Medium | Firewall Rules | Risky inbound allow rule: Microsoft Edge (mDNS-In) Ports=5353; Remote=*; Profile=Domain,Private,Public | Confirm the rule is required and scope it to trusted networks. |
| Medium | Firewall Rules | Risky inbound allow rule: Microsoft Edge (mDNS-In) Ports=5353; Remote=*; Profile=Domain,Private,Public | Confirm the rule is required and scope it to trusted networks. |
| Medium | Firewall Rules | Risky inbound allow rule: Teamviewer Remote Control Application Ports=*; Remote=*; Profile=Private | Confirm the rule is required and scope it to trusted networks. |
| Medium | Firewall Rules | Risky inbound allow rule: Teamviewer Remote Control Application Ports=*; Remote=*; Profile=Private | Confirm the rule is required and scope it to trusted networks. |
| Medium | Firewall Rules | Risky inbound allow rule: Teamviewer Remote Control Service Ports=*; Remote=*; Profile=Private | Confirm the rule is required and scope it to trusted networks. |
| Medium | Firewall Rules | Risky inbound allow rule: Teamviewer Remote Control Service Ports=*; Remote=*; Profile=Private | Confirm the rule is required and scope it to trusted networks. |
| Medium | Firewall Rules | Risky inbound allow rule: Windows App Ports=*; Remote=*; Profile=Domain,Private,Public | Confirm the rule is required and scope it to trusted networks. |
| Medium | Firewall Rules | Risky inbound allow rule: Windows App Ports=*; Remote=*; Profile=Domain,Private,Public | Confirm the rule is required and scope it to trusted networks. |
| Medium | Installed Software CVE Review | Review signal: 7-Zip 24.08 5 CVE(s); highest=CRITICAL 9.3; top=CVE-2008-3075, CVE-2016-3646, CVE-2002-0370, CVE-2009-1782, CVE-2004-2348. Local installed-software matching is weaker evidence than service/banner matching. | Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability. |
| Medium | Installed Software CVE Review | Review signal: 7-Zip 26.01.00.0 5 CVE(s); highest=CRITICAL 9.3; top=CVE-2008-3075, CVE-2016-3646, CVE-2002-0370, CVE-2009-1782, CVE-2004-2348. Local installed-software matching is weaker evidence than service/banner matching. | Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability. |
| Medium | Installed Software CVE Review | Review signal: GlobalProtect 6.2.8 10 CVE(s); highest=CRITICAL 9.8; top=CVE-2016-3657, CVE-2017-7945, CVE-2017-9458, CVE-2016-3656, CVE-2017-7409. Local installed-software matching is weaker evidence than service/banner matching. | Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability. |
| Medium | Installed Software CVE Review | Review signal: Mozilla Firefox 151.0.4 2 CVE(s); highest=CRITICAL 10; top=CVE-2004-0904, CVE-2004-0905. Local installed-software matching is weaker evidence than service/banner matching. | Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability. |
| Medium | Listening Ports | Listening SMB / 445 Address=::; Process=System; Context=Common local listening service. Confirm it is expected and firewall-scoped. | Confirm the service is expected, patched, and restricted by host firewall or network policy. |
| Medium | Lock Screen | Automatic lock / screensaver posture needs review Screensaver is enabled but password on resume is not required. | Require automatic lock and password on resume. Recommended maximum timeout is 15 minutes or less. |
| Medium | PATH Hijack | Writable PATH directory: C:\Users\user.redacted\AppData\Local\Microsoft\WindowsApps User-writable-looking PATH directory | Remove writable directories from PATH or harden permissions. |
| Medium | PATH Hijack | Writable PATH directory: C:\Users\user.redacted\AppData\Local\Microsoft\WindowsApps User-writable-looking PATH directory | Remove writable directories from PATH or harden permissions. |
| Medium | PATH Hijack | Writable PATH directory: C:\Users\user.redacted\AppData\Local\Programs\Fiddler User-writable-looking PATH directory | Remove writable directories from PATH or harden permissions. |
| Medium | Scan Scope | Local check was not run as Administrator The script is not running elevated. The report is still useful, but several checks may be incomplete, unavailable, or shown as Unknown. Do not treat missing data as clean. | Re-run from an elevated PowerShell session for complete checks. Limited areas: Firewall policy details; Defender/AV internals; SMB server/client configuration; BitLocker; local users/admins; some shares/printers; some listening-process ownership; protected registry policy keys |
| Medium | Scheduled Tasks | Task runs from user-writable path: CleanupTemporaryState %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState | Review task action and remove if not required. |
| Medium | Wi-Fi | Weak Wi-Fi profile: BSMH-Guest Authentication=Open; Cipher=None | Remove old weak Wi-Fi profiles and prefer WPA2/WPA3. |
| Medium | Wi-Fi | Weak Wi-Fi profile: CARE4U Authentication=Open; Cipher=None | Remove old weak Wi-Fi profiles and prefer WPA2/WPA3. |
| Medium | Wi-Fi | Weak Wi-Fi profile: Hyatt_Guest Authentication=Open; Cipher=None | Remove old weak Wi-Fi profiles and prefer WPA2/WPA3. |
| Medium | Wi-Fi | Weak Wi-Fi profile: IHG ONE REWARDS Free WI-FI Authentication=Open; Cipher=None | Remove old weak Wi-Fi profiles and prefer WPA2/WPA3. |
| Medium | Wi-Fi | Weak Wi-Fi profile: PowhatanWiFi Authentication=Open; Cipher=None | Remove old weak Wi-Fi profiles and prefer WPA2/WPA3. |
| Medium | Wi-Fi | Weak Wi-Fi profile: Qualityguest Authentication=Open; Cipher=None | Remove old weak Wi-Fi profiles and prefer WPA2/WPA3. |
| Computer | DESKTOP-REDACTED | User | CORP\\user.redacted |
|---|---|---|---|
| Domain / Workgroup | WORKGROUP | Part of domain | False |
| Manufacturer | Dell Inc. | Model | Latitude 9420 |
| Serial number | 68SG3M3 | System type | x64-based PC |
| BIOS version | 1.46.0 | BIOS release date | 2026-03-31 02:00:00 |
| Baseboard | Dell Inc. 0CP3KM | Baseboard serial | /68SG3M3/CNCMK0021D0128/ |
| Operating system | Microsoft Windows 11 Enterprise | OS version / build | 10.0.26200 / 26200 |
| Architecture | 64-bit | Install date | 2026-02-27 16:00:31 |
| Last boot | 2026-06-09 08:37:44 | Time zone | (UTC+01:00) Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna |
| CPU | 11th Gen Intel(R) Core(TM) i7-1185G7 @ 3.00GHz | Cores / logical processors | 4 / 8 |
| Total RAM | 15.7 GB | Memory slots used | 8 |
| Memory modules | 2.0 GB / 4267 MHz / H9HCNNNCPMMLXR-NEE | 2.0 GB / 4267 MHz / H9HCNNNCPMMLXR-NEE | 2.0 GB / 4267 MHz / H9HCNNNCPMMLXR-NEE | 2.0 GB / 4267 MHz / H9HCNNNCPMMLXR-NEE | 2.0 GB / 4267 MHz / H9HCNNNCPMMLXR-NEE | 2.0 GB / 4267 MHz / H9HCNNNCPMMLXR-NEE | 2.0 GB / 4267 MHz / H9HCNNNCPMMLXR-NEE | 2.0 GB / 4267 MHz / H9HCNNNCPMMLXR-NEE | ||
| Local disks | C: 474.7 GB total, 253.6 GB free | ||
| Admin | False | Pending reboot | Pending file rename |
| Running as Administrator | False | Status | Limited local check - not running as Administrator |
|---|---|---|---|
| Impact | The script is not running elevated. The report is still useful, but several checks may be incomplete, unavailable, or shown as Unknown. Do not treat missing data as clean. | ||
| Checks that may be incomplete | Firewall policy details; Defender/AV internals; SMB server/client configuration; BitLocker; local users/admins; some shares/printers; some listening-process ownership; protected registry policy keys | ||
| Check | Status | Seconds | Note |
|---|---|---|---|
| SystemInfo | OK | 1.91 | |
| UpdatePolicy | OK | 0.28 | |
| RemoteAccessTools | OK | 2.21 | |
| Antivirus | OK | 0.96 | |
| Updates | OK | 2.39 | |
| BrowserPosture | OK | 0.35 | |
| RecoveryPosture | OK | 0.67 | |
| CredentialExposure | OK | 0.73 | |
| DeveloperAdminTools | OK | 5.55 | |
| RiskyFirewallRules | OK | 1.17 | |
| Network | OK | 12.23 | |
| AuditLogging | OK | 0.41 | |
| RemoteManagement | OK | 5.73 | |
| DeviceControl | OK | 0.23 | |
| UsbStorage | OK | 0.23 | |
| ProxyVpn | OK | 1.9 | |
| TimeSync | OK | 0.52 | |
| ScheduledTasks | OK | 4.47 | |
| WritableServices | OK | 4.28 | |
| ExternalIp | OK | 0.05 | |
| UAC | OK | 0.28 | |
| Users | OK | 2.07 | |
| LockScreen | OK | 0.39 | |
| PathHijack | OK | 0.24 | |
| SMB | OK | 3.21 | |
| BrowserExtensions | OK | 0.39 | |
| Shares | OK | 2.88 | |
| SoftwareInventory | OK | 0.8 | |
| ListeningPorts | OK | 11.12 | |
| Firewall | OK | 4.92 | |
| GhostDevices | OK | 5.69 | |
| WindowsSecurityBaseline | OK | 0.3 | |
| Laps | OK | 0.46 | |
| Certificates | OK | 0.76 | |
| BitLocker | OK | 0.04 | |
| RDP | OK | 0.32 | |
| PowerShell | OK | 0.59 | |
| SecureBootTpm | OK | 0.81 | |
| Startup | OK | 0.33 | |
| EventLogErrors | OK | 0.46 | |
| Printers | OK | 2.84 | |
| WifiProfiles | OK | 6.52 | |
| SoftwareCve | OK | 136.44 |
| External IP | Country | Region | City | Org | Source | Blacklisted | Listed on | Note |
|---|---|---|---|---|---|---|---|---|
| Skipped | Skipped | Skipped | External IP/reputation check skipped by user setting. |
| Interface | Description | IPv4 | IPv6 | Gateway | DNS servers |
|---|---|---|---|---|---|
| Wi-Fi | Intel(R) Wi-Fi 6E AX210 160MHz | 10.X.X.REDACTED | 10.X.X.REDACTED | 10.X.X.REDACTED, 10.X.X.REDACTED | |
| Ethernet 7 | Realtek USB GbE Family Controller #3 | 169.254.212.78 | fec0:0:0:ffff::1, fec0:0:0:ffff::2, fec0:0:0:ffff::3 | ||
| Bluetooth Network Connection | Bluetooth Device (Personal Area Network) | 169.254.188.231 | fec0:0:0:ffff::1, fec0:0:0:ffff::2, fec0:0:0:ffff::3 |
| Interface | Address family | DNS servers |
|---|---|---|
| Ethernet 7 | 2 | |
| Local Area Connection* 9 | 2 | |
| Local Area Connection* 10 | 2 | |
| Wi-Fi | 2 | 10.X.X.REDACTED, 10.X.X.REDACTED |
| Bluetooth Network Connection | 2 | |
| Loopback Pseudo-Interface 1 | 2 | |
| Teredo Tunneling Pseudo-Interface | 2 |
| Interface | Next hop | Metric |
|---|---|---|
| Wi-Fi | 10.X.X.REDACTED | 0 |
| Name | Enabled | Default In | Default Out |
|---|---|---|---|
| Domain | True | NotConfigured | NotConfigured |
| Private | True | NotConfigured | NotConfigured |
| Public | True | NotConfigured | NotConfigured |
| Name | Source | Enabled | Realtime | Sig Age | State | Details |
|---|---|---|---|---|---|---|
| CrowdStrike Falcon Sensor | root\SecurityCenter2 | 266240 | C:\Program Files\CrowdStrike\CSFalconController.exe | |||
| Microsoft Defender | Get-MpComputerStatus | False | False | 65535 | AMService=False; Behavior=False | |
| Windows Defender | root\SecurityCenter2 | 393472 | windowsdefender:// |
| SMB1 Server | SMB1 Client | Require Signing | Signing Enabled | Insecure Guest |
|---|---|---|---|---|
| False | Unknown | True | False | False |
| Check | Value |
|---|---|
| RDP Enabled | False/Unknown |
| NLA Required | False/Unknown |
| UAC EnableLUA | 1 |
| Protocol | Address | Port | PID | Process | Usually | Category | Risk | Explanation | Guidance |
|---|---|---|---|---|---|---|---|---|---|
| :: | 135 | svchost | RPC Endpoint Mapper | Fallback | Low | Common local listening service. Confirm it is expected and firewall-scoped. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| 0.0.0.0 | 135 | svchost | RPC Endpoint Mapper | Fallback | Low | Common local listening service. Confirm it is expected and firewall-scoped. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| :: | 445 | System | SMB | Fallback | Medium | Common local listening service. Confirm it is expected and firewall-scoped. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| :: | 623 | LMS | Intel AMT / IPMI RMCP | Fallback | Info | Common local listening service. Confirm it is expected and firewall-scoped. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| 0.0.0.0 | 623 | LMS | Intel AMT / IPMI RMCP | Fallback | Info | Common local listening service. Confirm it is expected and firewall-scoped. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| 0.0.0.0 | 5040 | svchost | Unknown / custom | Fallback | Info | No curated helper metadata was available for this port. Confirm the owning process and whether it should listen. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| :: | 5357 | System | WSDAPI | Fallback | Info | Common local listening service. Confirm it is expected and firewall-scoped. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| 127.0.0.1 | 5939 | TeamViewer_Service | Unknown / custom | Fallback | Info | No curated helper metadata was available for this port. Confirm the owning process and whether it should listen. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| 127.0.0.1 | 7311 | hcpclientcore | Unknown / custom | Fallback | Info | No curated helper metadata was available for this port. Confirm the owning process and whether it should listen. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| :: | 7680 | svchost | Windows Delivery Optimization | Fallback | Info | Common local listening service. Confirm it is expected and firewall-scoped. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| 127.0.0.1 | 8884 | System | Unknown / custom | Fallback | Info | No curated helper metadata was available for this port. Confirm the owning process and whether it should listen. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| 10.X.X.REDACTED | 10001 | agentid-service | Unknown / custom | Fallback | Info | No curated helper metadata was available for this port. Confirm the owning process and whether it should listen. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| 127.0.0.1 | 10001 | agentid-service | Unknown / custom | Fallback | Info | No curated helper metadata was available for this port. Confirm the owning process and whether it should listen. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| :: | 16992 | LMS | Intel AMT / LMS | Fallback | Info | Common local listening service. Confirm it is expected and firewall-scoped. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| 0.0.0.0 | 16992 | LMS | Intel AMT / LMS | Fallback | Info | Common local listening service. Confirm it is expected and firewall-scoped. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| 127.0.0.1 | 28385 | System | Unknown / custom | Fallback | Info | No curated helper metadata was available for this port. Confirm the owning process and whether it should listen. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| 127.0.0.1 | 28390 | System | Unknown / custom | Fallback | Info | No curated helper metadata was available for this port. Confirm the owning process and whether it should listen. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| ::1 | 42050 | OneDrive.Sync.Service | Unknown / custom | Fallback | Info | No curated helper metadata was available for this port. Confirm the owning process and whether it should listen. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| 127.0.0.1 | 49350 | esrv_svc | Unknown / custom | Fallback | Info | No curated helper metadata was available for this port. Confirm the owning process and whether it should listen. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| 127.0.0.1 | 49351 | esrv | Unknown / custom | Fallback | Info | No curated helper metadata was available for this port. Confirm the owning process and whether it should listen. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| :: | 49667 | lsass | Unknown / custom | Fallback | Info | No curated helper metadata was available for this port. Confirm the owning process and whether it should listen. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| 0.0.0.0 | 49667 | lsass | Unknown / custom | Fallback | Info | No curated helper metadata was available for this port. Confirm the owning process and whether it should listen. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| :: | 49668 | wininit | Unknown / custom | Fallback | Info | No curated helper metadata was available for this port. Confirm the owning process and whether it should listen. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| 0.0.0.0 | 49668 | wininit | Unknown / custom | Fallback | Info | No curated helper metadata was available for this port. Confirm the owning process and whether it should listen. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| :: | 49669 | svchost | Unknown / custom | Fallback | Info | No curated helper metadata was available for this port. Confirm the owning process and whether it should listen. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| 0.0.0.0 | 49669 | svchost | Unknown / custom | Fallback | Info | No curated helper metadata was available for this port. Confirm the owning process and whether it should listen. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| :: | 49670 | svchost | Unknown / custom | Fallback | Info | No curated helper metadata was available for this port. Confirm the owning process and whether it should listen. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| 0.0.0.0 | 49670 | svchost | Unknown / custom | Fallback | Info | No curated helper metadata was available for this port. Confirm the owning process and whether it should listen. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| :: | 49672 | spoolsv | Unknown / custom | Fallback | Info | No curated helper metadata was available for this port. Confirm the owning process and whether it should listen. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| 0.0.0.0 | 49672 | spoolsv | Unknown / custom | Fallback | Info | No curated helper metadata was available for this port. Confirm the owning process and whether it should listen. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| ::1 | 49673 | jhi_service | Unknown / custom | Fallback | Info | No curated helper metadata was available for this port. Confirm the owning process and whether it should listen. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| :: | 49723 | services | Unknown / custom | Fallback | Info | No curated helper metadata was available for this port. Confirm the owning process and whether it should listen. | Confirm the service is expected, patched, and restricted by host firewall or network policy. | ||
| 0.0.0.0 | 49723 | services | Unknown / custom | Fallback | Info | No curated helper metadata was available for this port. Confirm the owning process and whether it should listen. | Confirm the service is expected, patched, and restricted by host firewall or network policy. |
| Name | Path | Description | Type | Special |
|---|---|---|---|---|
| ADMIN$ | C:\WINDOWS | Remote Admin | FileSystemDirectory | True |
| C$ | C:\ | Default share | FileSystemDirectory | True |
| IPC$ | Remote IPC | InterprocessCommunication | True |
| Name | Share | Driver | Port |
|---|---|---|---|
| Name | Class | Source |
|---|---|---|
| CORP\\user.redacted | User | AzureAD |
| DESKTOP-REDACTED\Administrator | User | Local |
| S-1-12-1-REDACTED | Other | AzureAD |
| S-1-12-1-REDACTED | Other | AzureAD |
| Name | Enabled | Password Required | Password Last Set | Last Logon |
|---|---|---|---|---|
| Administrator | False | True | 07/21/2021 03:58:22 | 01/22/2022 15:53:26 |
| DefaultAccount | False | False | ||
| CorpGuest.REDACTED | False | False | ||
| Juffe | True | True | 05/31/2022 09:51:24 | |
| WDAGUtilityAccount | False | True | 07/21/2021 00:13:53 |
| HotFix | Description | Installed | By |
|---|---|---|---|
| KB5092762 | Security Update | 05/18/2026 00:00:00 | NT AUTHORITY\SYSTEM |
| KB5089466 | Security Update | 05/18/2026 00:00:00 | NT AUTHORITY\SYSTEM |
| KB5087051 | Update | 05/18/2026 00:00:00 | NT AUTHORITY\SYSTEM |
| KB5083769 | Security Update | 04/20/2026 00:00:00 | NT AUTHORITY\SYSTEM |
| KB5054156 | Update | 02/27/2026 00:00:00 | NT AUTHORITY\SYSTEM |
| Mount | Volume | Protection | Method |
|---|---|---|---|
| Not checked | Admin required | Unknown | Run elevated to query BitLocker |
| Version | Execution Policy | Transcription | Module Logging | ScriptBlock Logging |
|---|---|---|---|---|
| 5.1.26100.8115 | Undefined | 1 |
| Screensaver active | Password on resume | Screensaver timeout | Inactivity timeout | Display AC timeout | Sleep AC timeout | Risk | Note |
|---|---|---|---|---|---|---|---|
| 1 | 900 | 900 | 0 | Medium | Screensaver is enabled but password on resume is not required. |
| LSASS PPL | WDigest plaintext cache | LM compatibility | Restrict anonymous | Cached logons | VBS | Credential Guard | Note |
|---|---|---|---|---|---|---|---|
| 2 | 0 | 5 | 1 | 0 | 1 | 1 | Security baseline indicators captured from local registry. |
| Name | Display name | Status | Start type | Risk | Note |
|---|---|---|---|---|---|
| WinRM | Windows Remote Management (WS-Management) | Stopped | Manual | Info | Remote management related service. |
| RemoteRegistry | Remote Registry | Stopped | Disabled | Info | Remote management related service. |
| TermService | Remote Desktop Services | Stopped | Manual | Info | Remote management related service. |
| RemoteAccess | Routing and Remote Access | Stopped | Disabled | Info | Remote management related service. |
| Category | Setting | Source | Risk | Note |
|---|---|---|---|---|
| Process command line logging | Registry | Info | Logging policy indicator. | |
| PowerShell ScriptBlock Logging | 1 | Registry | OK | Logging policy indicator. |
| PowerShell Transcription | Registry | Info | Logging policy indicator. |
| Service status | Start type | Source | Time zone | Risk | Note |
|---|---|---|---|---|---|
| Running | Automatic | The following error occurred: Access is denied. (0x80070005) | (UTC+01:00) Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna | Info | Time synchronization indicators captured. |
| Log | Time | Provider | ID | Level | Message | Risk | Note |
|---|---|---|---|---|---|---|---|
| Application | 06/11/2026 17:28:26 | VSS | 13 | Error | Volume Shadow Copy Service information: The COM Server with CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} and name Coordinator cannot be started. [0x80070005, Access is denied. ] | Info | One of the five newest Error events in this log. Review repeated or security-relevant errors. |
| Application | 06/11/2026 17:19:40 | HCP Port Monitor | 0 | Error | Info | One of the five newest Error events in this log. Review repeated or security-relevant errors. | |
| Application | 06/11/2026 16:19:40 | HCP Port Monitor | 0 | Error | Info | One of the five newest Error events in this log. Review repeated or security-relevant errors. | |
| Application | 06/11/2026 16:00:01 | C:\ProgramData\Azure\AzCopy\azcopy.exe | 0 | Error | Info | One of the five newest Error events in this log. Review repeated or security-relevant errors. | |
| Application | 06/11/2026 15:52:55 | VSS | 13 | Error | Volume Shadow Copy Service information: The COM Server with CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} and name Coordinator cannot be started. [0x80070005, Access is denied. ] | Info | One of the five newest Error events in this log. Review repeated or security-relevant errors. |
| System | 06/11/2026 11:41:44 | Microsoft-Windows-HAL | 21 | Error | The hardware real-time clock was not set because evaluation of the ACPI Time and Alarm Device method failed. Status: 0xC00000BB. | Info | One of the five newest Error events in this log. Review repeated or security-relevant errors. |
| System | 06/11/2026 11:41:44 | Microsoft-Windows-HAL | 20 | Error | The hardware real-time clock was not queried because evaluation of the ACPI Time and Alarm Device method failed. Status: 0xC00000BB. | Info | One of the five newest Error events in this log. Review repeated or security-relevant errors. |
| System | 06/11/2026 11:07:43 | Service Control Manager | 7009 | Error | A timeout was reached (30000 milliseconds) while waiting for the Intel(R) SUR QC Software Asset Manager service to connect. | Info | One of the five newest Error events in this log. Review repeated or security-relevant errors. |
| System | 06/11/2026 09:21:14 | Microsoft-Windows-Security-Kerberos | 11 | Error | The Distinguished Name in the subject field of your smart card logon certificate does not contain enough information to identify the appropriate domain on an non-domain joined computer. Contact your system administrator. | Info | One of the five newest Error events in this log. Review repeated or security-relevant errors. |
| System | 06/11/2026 09:17:03 | Microsoft-Windows-NDIS | 10317 | Error | Miniport Microsoft Wi-Fi Direct Virtual Adapter #2, {be6e2561-4c3e-4eb3-96c9-93e81cbe9447}, had event Fatal error: The miniport has failed a power transition to operational power | Info | One of the five newest Error events in this log. Review repeated or security-relevant errors. |
| Source | Target | Type | User | Risk | Note |
|---|---|---|---|---|---|
| Credential Manager | MicrosoftAccount:target=SSO_POP_User:user=user@corp-redacted.com | Generic | user@corp-redacted.com | Info | Saved credential target present; secret value not read. |
| Credential Manager | MicrosoftAccount:target=SSO_POP_Device | Generic | 02piqpsfhbqqcqsz | Info | Saved credential target present; secret value not read. |
| Credential Manager | LegacyGeneric:target=WindowsLive:(token):name=user@corp-redacted.com;serviceuri=http://passport.net/purpose | Generic | user@corp-redacted.com | Info | Saved credential target present; secret value not read. |
| Credential Manager | LegacyGeneric:target=Microsoft_OneDrive_Cookies_v2_Business1_https://corp-redacted-my.sharepoint.com/ | Generic | Info | Saved credential target present; secret value not read. | |
| Credential Manager | LegacyGeneric:target=Olk/PushNotificationsBackupKey | Generic | Olk/PushNotificationsBackupKey | Info | Saved credential target present; secret value not read. |
| Credential Manager | LegacyGeneric:target=Microsoft_OneDrive_Cookies_v2_Business1_https://corp-redacted.sharepoint.com/ | Generic | Info | Saved credential target present; secret value not read. | |
| Credential Manager | Domain:target=autodiscover.corp-redacted.se | Domain Password | user@corp-redacted.com | Info | Saved credential target present; secret value not read. |
| Credential Manager | Domain:name=user@corp-redacted.com | Domain Password | user@corp-redacted.com | Info | Saved credential target present; secret value not read. |
| Credential Manager | Domain:target=TERMSRV/SRV-REDACTED.CORP.REDACTED.COM | Domain Password | user@corp-redacted.com | Info | Saved credential target present; secret value not read. |
| Credential Manager | LegacyGeneric:target=ScantideAuditor.ServiceNow | Generic | cmdb.api | Info | Saved credential target present; secret value not read. |
| Credential Manager | LegacyGeneric:target=OneDrive Cached Credential Business - Business1 | Generic | 91a08a3e-ea1f-4406-a7f3-a2782cfd5a70 | Info | Saved credential target present; secret value not read. |
| Credential Manager | LegacyGeneric:target=MS.Outlook.15:user@corp-redacted.com:PUT | Generic | user@corp-redacted.com | Info | Saved credential target present; secret value not read. |
| Credential Manager | LegacyGeneric:target=MicrosoftAccount:user=user@corp-redacted.com | Generic | user@corp-redacted.com | Info | Saved credential target present; secret value not read. |
| Credential Manager | Domain:target=defrsrv294.corp.corp-redacted.com | Domain Password | user@corp-redacted.com | Info | Saved credential target present; secret value not read. |
| Credential Manager | LegacyGeneric:target=ScantideAuditor.ServiceNow.Instance | Generic | instance | Info | Saved credential target present; secret value not read. |
| Credential Manager | LegacyGeneric:target=ScantideAuditor.Api | Generic | helpdesk@corp-redacted.se | Info | Saved credential target present; secret value not read. |
| Credential Manager | WindowsLive:target=virtualapp/didlogical | Generic | 02piqpsfhbqqcqsz | Info | Saved credential target present; secret value not read. |
| Credential Manager | LegacyGeneric:target=Olk/PushNotificationsKey | Generic | Olk/PushNotificationsKey | Info | Saved credential target present; secret value not read. |
| Credential Manager | Domain:target=TERMSRV/RDWEB.CORP-REDACTED.SE | Domain Password | user@corp-redacted.com | Info | Saved credential target present; secret value not read. |
| Credential Manager | LegacyGeneric:target=TERMSRV/europa.corp-redacted.com | Generic | user@corp-redacted.com | Info | Saved credential target present; secret value not read. |
| Credential Manager | LegacyGeneric:target=crushftp.corp-redacted.se | Generic | user@corp-redacted.com | Info | Saved credential target present; secret value not read. |
| Credential Manager | LegacyGeneric:target=TERMSRV/*.corp-redacted.se | Generic | user@corp-redacted.com | Info | Saved credential target present; secret value not read. |
| Credential Manager | LegacyGeneric:target=teamsIv/teams | Generic | teams | Info | Saved credential target present; secret value not read. |
| Credential Manager | Domain:target=*.CORP.CORP-REDACTED.COM | Domain Password | CORP.CORP-REDACTED.COM\admuser.redacted | Info | Saved credential target present; secret value not read. |
| Credential Manager | Domain:target=autodiscover.redcloud-redacted.se | Domain Password | user@corp-redacted.com | Info | Saved credential target present; secret value not read. |
| Credential Manager | LegacyGeneric:target=rdweb.corp-redacted.se | Generic | user@corp-redacted.com | Info | Saved credential target present; secret value not read. |
| Credential Manager | LegacyGeneric:target=teamsKey/teams | Generic | teams | Info | Saved credential target present; secret value not read. |
| Credential Manager | LegacyGeneric:target=MicrosoftOffice16_Data:SSPI:user@corp-redacted.com | Generic | Info | Saved credential target present; secret value not read. | |
| Credential Manager | Domain:target=mail.corp-redacted.se | Domain Password | user@corp-redacted.com | Info | Saved credential target present; secret value not read. |
| Credential Manager | Domain:target=EXCHANGE.corp-redacted.se | Domain Password | user@corp-redacted.com | Info | Saved credential target present; secret value not read. |
| Browser | Policy path | Password manager | Safe browsing | SmartScreen | Developer tools | Risk | Note |
|---|---|---|---|---|---|---|---|
| Edge | HKLM:\SOFTWARE\Policies\Microsoft\Edge | 1 | 1 | Info | Browser policy indicators captured when present. | ||
| Chrome | HKLM:\SOFTWARE\Policies\Google\Chrome | Info | Browser policy indicators captured when present. | ||||
| Firefox | HKLM:\SOFTWARE\Policies\Mozilla\Firefox | Info | Browser policy indicators captured when present. |
| Area | Status | Evidence | Risk | Note |
|---|---|---|---|---|
| Windows Recovery Environment | Unknown | This command can only be executed from an elevated command prompt.; | Info | Recovery environment status. |
| System Restore | No restore points returned | Info | System restore point indicator. | |
| VSS Shadows | Present | vssadmin 1.1 - Volume Shadow Copy Service administrative command-line tool; (C) Copyright 2001-2013 Microsoft Corp.; ; Error: You don't have the correct permissions to run this command. Please run this utility from a command; window that has elevated administrator privileges.; | Info | VSS snapshot indicator. |
| Area | Setting | Value | Risk | Note |
|---|---|---|---|---|
| USB storage | USBSTOR Start | 3 | Info | 3 normally means enabled; 4 disabled. |
| Removable storage | Deny_All | Info | Policy indicator for removable storage deny all. | |
| AutoRun / AutoPlay | NoDriveTypeAutoRun | 255 | Info | Autorun policy indicator. |
| Device install restrictions | DenyUnspecified | Info | Device installation restriction policy indicator. |
| Policy | Value | Source | Risk | Note |
|---|---|---|---|---|
| WUServer | HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate | Info | Windows Update policy indicator. | |
| WUStatusServer | HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate | Info | Windows Update policy indicator. | |
| TargetReleaseVersion | HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate | Info | Windows Update policy indicator. | |
| TargetReleaseVersionInfo | HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate | Info | Windows Update policy indicator. | |
| ProductVersion | HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate | Info | Windows Update policy indicator. | |
| DeferFeatureUpdatesPeriodInDays | HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate | Info | Windows Update policy indicator. | |
| DeferQualityUpdatesPeriodInDays | HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate | Info | Windows Update policy indicator. | |
| UseWUServer | HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU | Info | Windows Update AU policy indicator. | |
| NoAutoUpdate | HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU | Info | Windows Update AU policy indicator. | |
| AUOptions | HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU | Info | Windows Update AU policy indicator. | |
| AlwaysAutoRebootAtScheduledTime | HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU | Info | Windows Update AU policy indicator. | |
| NoAutoRebootWithLoggedOnUsers | HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU | Info | Windows Update AU policy indicator. | |
| MDM/Intune enrollment indicators | ; ; ; ; ; ; ; ; ; | HKLM:\SOFTWARE\Microsoft\Enrollments | Info | Enrollment indicators found. |
| Class | Friendly name | Instance ID | Status | Present | Risk | Note |
|---|---|---|---|---|---|---|
| HIDClass | USB Input Device | USB\VID_0B0E&PID_0311\50C2ED067EBE | Unknown | False | Info | Non-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices. |
| HIDClass | HID-compliant consumer control device | HID\VID_0B0E&PID_030B&MI_03&COL03\8&35AECF77&0&0002 | Unknown | False | Info | Non-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices. |
| SoftwareDevice | MIDI 2.0 Service Tests | SWD\MIDISRV\MIDIU_DIAG_TRANSPORT | Unknown | False | Info | Non-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices. |
| Mouse | PS/2 Compatible Mouse | ACPI\DLL0A5B\4&77AFA20&0 | Unknown | False | Info | Non-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices. |
| AudioEndpoint | Speakers (Jabra Evolve 65) | SWD\MMDEVAPI\{0.0.0.00000000}.{D9EA0B81-ABB1-4919-929A-D798006EC989} | Unknown | False | Info | Non-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices. |
| MEDIA | Jabra Evolve 65 | USB\VID_0B0E&PID_030B&MI_00\7&30FD822B&0&0000 | Unknown | False | Info | Non-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices. |
| USB | USB Composite Device | USB\VID_0B0E&PID_030B\50C2ED067EBE | Unknown | False | Info | Non-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices. |
| SoftwareDevice | Service Test Loopback A | SWD\MIDISRV\MIDIU_DIAG_LOOPBACK_A | Unknown | False | Info | Non-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices. |
| SoftwareDevice | Service Test Loopback B | SWD\MIDISRV\MIDIU_DIAG_LOOPBACK_B | Unknown | False | Info | Non-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices. |
| VolumeSnapshot | Generic volume shadow copy | STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2 | Unknown | False | Info | Non-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices. |
| VolumeSnapshot | Generic volume shadow copy | STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3 | Unknown | False | Info | Non-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices. |
| VolumeSnapshot | Generic volume shadow copy | STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4 | Unknown | False | Info | Non-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices. |
| VolumeSnapshot | Generic volume shadow copy | STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5 | Unknown | False | Info | Non-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices. |
| SoftwareDevice | Service Test Ping (Internal) | SWD\MIDISRV\MIDIU_DIAG_PING | Unknown | False | Info | Non-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices. |
| System | ACPI Power Button | ACPI\PNP0C0C\2&DABA3FF&1 | Unknown | False | Info | Non-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices. |
| AudioEndpoint | Microphone (Jabra Evolve 65) | SWD\MMDEVAPI\{0.0.1.00000000}.{8B266551-A131-4C9A-8C6A-C0DA41E02C39} | Unknown | False | Info | Non-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices. |
| HIDClass | HID-compliant headset | HID\VID_0B0E&PID_030B&MI_03&COL01\8&35AECF77&0&0000 | Unknown | False | Info | Non-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices. |
| SoftwareDevice | MIDI 2.0 Virtual Devices | SWD\MIDISRV\MIDIU_APP_TRANSPORT | Unknown | False | Info | Non-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices. |
| SoftwareDevice | MIDI 2.0 Loop Devices | SWD\MIDISRV\MIDIU_LOOP_TRANSPORT | Unknown | False | Info | Non-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices. |
| HIDClass | HID-compliant vendor-defined device | HID\VID_0B0E&PID_030B&MI_03&COL02\8&35AECF77&0&0001 | Unknown | False | Info | Non-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices. |
| HIDClass | USB Input Device | USB\VID_0B0E&PID_030B&MI_03\7&30FD822B&0&0003 | Unknown | False | Info | Non-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices. |
| USBDevice | Hub Feature Controller | USB\VID_0424&PID_2840\6&28CFAB54&0&6 | Unknown | False | Info | Non-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices. |
| HIDClass | HID-compliant vendor-defined device | HID\VID_0B0E&PID_0311&COL02\7&F8EBAF7&0&0001 | Unknown | False | Info | Non-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices. |
| HIDClass | HID-compliant consumer control device | HID\VID_0B0E&PID_0311&COL01\7&F8EBAF7&0&0000 | Unknown | False | Info | Non-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices. |
| Secure Boot | TPM present | TPM ready | TPM enabled | TPM activated |
|---|---|---|---|---|
| Unavailable or legacy BIOS |
| Name | Profile | Program | Ports | Remote address | Reason | Source |
|---|---|---|---|---|---|---|
| Core Networking - Teredo (ICMPv6-In) | Domain,Private,Public | System | * | public/any profile; broad remote address | Firewall COM | |
| Teamviewer Remote Control Service | Private | C:\Program Files\TeamViewer\TeamViewer_Service.exe | * | * | broad remote address | Firewall COM |
| Teamviewer Remote Control Service | Private | C:\Program Files\TeamViewer\TeamViewer_Service.exe | * | * | broad remote address | Firewall COM |
| Teamviewer Remote Control Application | Private | C:\Program Files\TeamViewer\TeamViewer.exe | * | * | broad remote address | Firewall COM |
| Teamviewer Remote Control Application | Private | C:\Program Files\TeamViewer\TeamViewer.exe | * | * | broad remote address | Firewall COM |
| Microsoft Edge (mDNS-In) | Domain,Private,Public | C:\Program Files (x86)\Microsoft\EdgeWebView\Application\149.0.4022.62\msedgewebview2.exe | 5353 | * | public/any profile; broad remote address | Firewall COM |
| Microsoft Edge (mDNS-In) | Domain,Private,Public | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | 5353 | * | public/any profile; broad remote address | Firewall COM |
| Microsoft 365 Copilot | Domain,Private,Public | * | public/any profile; broad remote address | Firewall COM | ||
| Windows App | Domain,Private,Public | C:\Program Files\WindowsApps\MicrosoftCorporationII.Windows365_2.0.1193.0_x64__8wekyb3d8bbwe\msrdc\msrdc.exe | * | * | public/any profile; broad remote address | Firewall COM |
| Windows App | Domain,Private,Public | C:\Program Files\WindowsApps\MicrosoftCorporationII.Windows365_2.0.1193.0_x64__8wekyb3d8bbwe\msrdc\msrdc.exe | * | * | public/any profile; broad remote address | Firewall COM |
| Microsoft Edge (mDNS-In) | Domain,Private,Public | C:\Program Files (x86)\Microsoft\EdgeWebView\Application\149.0.4022.52\msedgewebview2.exe | 5353 | * | public/any profile; broad remote address | Firewall COM |
| Google Chrome (mDNS-In) | Domain,Private,Public | C:\Program Files\Google\Chrome\Application\chrome.exe | 5353 | * | public/any profile; broad remote address | Firewall COM |
| @{Microsoft.StorePurchaseApp_22604.1401.3.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.StorePurchaseApp/Resources/DisplayTitle} | Domain,Private | * | broad remote address | Firewall COM | ||
| @{Microsoft.ZuneMusic_11.2604.10.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.ZuneMusic/Resources/AppStoreName} | Domain,Private | * | broad remote address | Firewall COM | ||
| Microsoft Edge (mDNS-In) | Domain,Private,Public | C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.96\msedgewebview2.exe | 5353 | * | public/any profile; broad remote address | Firewall COM |
| Microsoft Store | Domain,Private,Public | * | public/any profile; broad remote address | Firewall COM | ||
| Microsoft Edge (mDNS-In) | Domain,Private,Public | C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.83\msedgewebview2.exe | 5353 | * | public/any profile; broad remote address | Firewall COM |
| Microsoft Teams | Domain,Private,Public | * | public/any profile; broad remote address | Firewall COM | ||
| @{Microsoft.ZuneVideo_10.26041.10031.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.ZuneVideo/resources/IDS_MANIFEST_VIDEO_APP_NAME} | Domain,Private | * | broad remote address | Firewall COM | ||
| Microsoft Teams | Domain,Private,Public | C:\Program Files\WindowsApps\MSTeams_26106.1911.4707.3286_x64__8wekyb3d8bbwe\ms-teams.exe | * | * | public/any profile; broad remote address | Firewall COM |
| Microsoft Teams | Domain,Private,Public | C:\Program Files\WindowsApps\MSTeams_26106.1911.4707.3286_x64__8wekyb3d8bbwe\ms-teams.exe | * | * | public/any profile; broad remote address | Firewall COM |
| Game Bar | Domain,Private,Public | * | public/any profile; broad remote address | Firewall COM | ||
| Airhost service for Zoom Video Meetings | Domain,Private,Public | C:\Program Files\Zoom\bin\airhost.exe | 5353,7200-17210,8889 | * | public/any profile; broad remote address | Firewall COM |
| Airhost service for Zoom Video Meetings | Domain,Private,Public | C:\Program Files\Zoom\bin\airhost.exe | 5000,7000,7100,50000,7200-17210,8888 | * | public/any profile; broad remote address | Firewall COM |
| Hybrid Conference for Zoom Video Meetings | Domain,Private,Public | C:\Program Files\Zoom\bin\ZoomHybridConf.exe | 7200-17210 | * | public/any profile; broad remote address | Firewall COM |
| Zoom Video Meeting | Domain,Private,Public | C:\Program Files\Zoom\bin\Zoom.exe | 7200-17210 | * | public/any profile; broad remote address | Firewall COM |
| Microsoft Edge (mDNS-In) | Domain,Private,Public | C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.70\msedgewebview2.exe | 5353 | * | public/any profile; broad remote address | Firewall COM |
| Microsoft Edge (mDNS-In) | Domain,Private,Public | C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.54\msedgewebview2.exe | 5353 | * | public/any profile; broad remote address | Firewall COM |
| Solitaire & Casual Games | Domain,Private | * | broad remote address | Firewall COM | ||
| @{Microsoft.WindowsFeedbackHub_1.2603.26301.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.WindowsFeedbackHub/Resources/AppStoreName} | Domain,Private | * | broad remote address | Firewall COM | ||
| Microsoft Edge (mDNS-In) | Domain,Private,Public | C:\Program Files (x86)\Microsoft\EdgeWebView\Application\147.0.3912.98\msedgewebview2.exe | 5353 | * | public/any profile; broad remote address | Firewall COM |
| @{Microsoft.CompanyPortal_11.2.1787.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.CompanyPortal/AppConstants/ApplicationName} | Domain,Private | * | broad remote address | Firewall COM | ||
| @{Microsoft.WindowsAlarms_11.2512.0.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.WindowsAlarms/Resources/AppStoreName} | Domain,Private | * | broad remote address | Firewall COM | ||
| @{Microsoft.WindowsCamera_2025.2510.2.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.WindowsCamera/LensSDK/Resources/AppStoreName} | Domain,Private | * | broad remote address | Firewall COM | ||
| @{Microsoft.BingWeather_4.54.63040.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.BingWeather/Resources/ApplicationTitleWithBranding} | Domain,Private | * | broad remote address | Firewall COM | ||
| @{Microsoft.DesktopAppInstaller_1.28.240.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.DesktopAppInstaller/Resources/appDisplayName} | Domain,Private | * | broad remote address | Firewall COM | ||
| @{MicrosoftWindows.Client.OOBE_1000.26100.40.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.OOBE/resources/ProductPkgDisplayName} | Domain,Private,Public | * | public/any profile; broad remote address | Firewall COM | ||
| @{MicrosoftWindows.Client.Core_1000.26100.86.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.Core/Resources/ProductPkgDisplayName} | Domain,Private | * | broad remote address | Firewall COM | ||
| @{MicrosoftWindows.Client.CBS_1000.26100.297.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.CBS/resources/ProductPkgDisplayName} | Domain,Private,Public | * | public/any profile; broad remote address | Firewall COM | ||
| @{Microsoft.Windows.ShellExperienceHost_10.0.26100.8115_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.ShellExperienceHost/resources/PkgDisplayName} | Domain,Private | * | broad remote address | Firewall COM | ||
| ms-resource:ProductPkgDisplayName | Private | C:\WINDOWS\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy\OobeHostApp.exe | 7000 | * | broad remote address | Firewall COM |
| ms-resource:ProductPkgDisplayName | Public | C:\WINDOWS\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy\OobeHostApp.exe | 7000 | * | public/any profile; broad remote address | Firewall COM |
| ms-resource:ProductPkgDisplayName | Private | C:\WINDOWS\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy\OobeHostApp.exe | 7000 | * | broad remote address | Firewall COM |
| ms-resource:ProductPkgDisplayName | Public | C:\WINDOWS\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy\OobeHostApp.exe | 7000 | * | public/any profile; broad remote address | Firewall COM |
| ms-resource:ProductPkgDisplayName | Private | C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\WindowsBackupClient.exe | 7000 | * | broad remote address | Firewall COM |
| ms-resource:ProductPkgDisplayName | Public | C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\WindowsBackupClient.exe | 7000 | * | public/any profile; broad remote address | Firewall COM |
| ms-resource:ProductPkgDisplayName | Private | C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\WindowsBackupClient.exe | 7000 | * | broad remote address | Firewall COM |
| ms-resource:ProductPkgDisplayName | Public | C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\WindowsBackupClient.exe | 7000 | * | public/any profile; broad remote address | Firewall COM |
| RICOH Print Support Application | Domain,Private | * | broad remote address | Firewall COM | ||
| @{Microsoft.SecHealthUI_1000.29554.1001.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.SecHealthUI/resources/PackageDisplayName} | Domain,Private | * | broad remote address | Firewall COM | ||
| @{Microsoft.Todos_2.175.6901.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.Todos/Resources/app_name_ms_todo} | Domain,Private | * | broad remote address | Firewall COM | ||
| @{MicrosoftWindows.Client.Photon_1000.26100.10.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.Photon/Resources/ProductPkgDisplayName} | Domain,Private | * | broad remote address | Firewall COM | ||
| @{Microsoft.Windows.StartMenuExperienceHost_10.0.26100.4768_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.StartMenuExperienceHost/StartMenuExperienceHost/PkgDisplayName} | Domain,Private | * | broad remote address | Firewall COM | ||
| @{MicrosoftWindows.Client.CBS_1000.22700.1067.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.CBS/resources/ProductPkgDisplayName} | Domain,Private | * | broad remote address | Firewall COM | ||
| @{MicrosoftWindows.Client.Core_1000.22700.1017.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.Core/resources/ProductPkgDisplayName} | Domain,Private | * | broad remote address | Firewall COM | ||
| @{Microsoft.MicrosoftStickyNotes_6.1.4.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.MicrosoftStickyNotes/Resources/StickyNotesStoreAppName} | Domain,Private | * | broad remote address | Firewall COM | ||
| Microsoft Teams (personal) | Domain,Private,Public | C:\Program Files\WindowsApps\MicrosoftTeams_24334.1105.3318.5002_x64__8wekyb3d8bbwe\msteams.exe | * | * | public/any profile; broad remote address | Firewall COM |
| Microsoft Teams (personal) | Domain,Private,Public | C:\Program Files\WindowsApps\MicrosoftTeams_24334.1105.3318.5002_x64__8wekyb3d8bbwe\msteams.exe | * | * | public/any profile; broad remote address | Firewall COM |
| @{Microsoft.MicrosoftStickyNotes_6.1.4.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.MicrosoftStickyNotes/Resources/StickyNotesStoreAppName} | Domain,Private | * | broad remote address | Firewall COM | ||
| @{Microsoft.Windows.StartMenuExperienceHost_10.0.22621.4249_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.StartMenuExperienceHost/StartMenuExperienceHost/PkgDisplayName} | Domain,Private | * | broad remote address | Firewall COM | ||
| Microsoft Teams SlimCoreVdi | Domain,Private,Public | C:\Program Files\WindowsApps\Microsoft.Teams.SlimCoreVdi.win-x64.2024.30_2024.30.1.19_x64__8wekyb3d8bbwe\MsTeamsVdi.exe | * | * | public/any profile; broad remote address | Firewall COM |
| Microsoft Teams SlimCoreVdi | Domain,Private,Public | C:\Program Files\WindowsApps\Microsoft.Teams.SlimCoreVdi.win-x64.2024.30_2024.30.1.19_x64__8wekyb3d8bbwe\MsTeamsVdi.exe | * | * | public/any profile; broad remote address | Firewall COM |
| @{MicrosoftWindows.Client.LKG_1000.22621.3880.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.LKG/resources/ProductPkgDisplayName} | Domain,Private | * | broad remote address | Firewall COM | ||
| Digi RealPort Network Service | Public | C:\Windows\SysWOW64\dgrpencx.exe | * | * | public/any profile; broad remote address | Firewall COM |
| Digi RealPort Network Service | Public | C:\Windows\SysWOW64\dgrpencx.exe | * | * | public/any profile; broad remote address | Firewall COM |
| @{Microsoft.Windows.CloudExperienceHost_10.0.22621.2506_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.CloudExperienceHost/resources/appDescription} | Domain,Private | * | broad remote address | Firewall COM | ||
| Firefox (C:\Program Files\Mozilla Firefox) | Private | C:\Program Files\Mozilla Firefox\firefox.exe | * | * | broad remote address | Firewall COM |
| Firefox (C:\Program Files\Mozilla Firefox) | Private | C:\Program Files\Mozilla Firefox\firefox.exe | * | * | broad remote address | Firewall COM |
| @{Microsoft.Win32WebViewHost_10.0.22621.1_neutral_neutral_cw5n1h2txyewy?ms-resource://Windows.Win32WebViewHost/resources/DisplayName} | Domain,Private,Public | * | public/any profile; broad remote address | Firewall COM | ||
| @{Microsoft.AAD.BrokerPlugin_1000.19580.1000.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.AAD.BrokerPlugin/resources/PackageDisplayName} | Domain,Private | * | broad remote address | Firewall COM | ||
| Quick Assist Firewall Exception | Domain,Private,Public | C:\Program Files\Remote help\RHService.exe | * | public/any profile; broad remote address | Firewall COM | |
| Quick Assist RDP Firewall Exception | Domain,Private,Public | C:\Program Files\Remote help\RemoteHelpRDP.exe | * | public/any profile; broad remote address | Firewall COM | |
| Remote help Firewall Exception | Domain,Private,Public | C:\Program Files\Remote help\RemoteHelp.exe | * | public/any profile; broad remote address | Firewall COM | |
| Microsoft Power BI Desktop (x64): Analysis Services Component | Domain,Private,Public | C:\Program Files\Microsoft Power BI Desktop\bin\msmdsrv.exe | * | LocalSubnet | public/any profile | Firewall COM |
| Printix IPP Print, TCP | Domain,Private,Public | 21339 | * | public/any profile; broad remote address | Firewall COM | |
| Printix UI Communication, TCP | Domain,Private,Public | 21338 | * | public/any profile; broad remote address | Firewall COM | |
| Printix Redirector, TCP | Domain,Private,Public | 21336 | * | public/any profile; broad remote address | Firewall COM | |
| Printix Jobforward, TCP | Domain,Private,Public | 21335 | * | public/any profile; broad remote address | Firewall COM | |
| Printix PDP, UDP | Domain,Private,Public | 21337 | * | public/any profile; broad remote address | Firewall COM | |
| @{Microsoft.Windows.CloudExperienceHost_10.0.19041.1265_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.CloudExperienceHost/resources/appDescription} | Domain,Private | * | broad remote address | Firewall COM | ||
| @{Microsoft.Windows.StartMenuExperienceHost_10.0.19041.1023_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.StartMenuExperienceHost/StartMenuExperienceHost/PkgDisplayName} | Domain,Private | * | broad remote address | Firewall COM | ||
| @{Microsoft.AAD.BrokerPlugin_1000.19041.1023.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.AAD.BrokerPlugin/resources/PackageDisplayName} | Domain,Private | * | broad remote address | Firewall COM | ||
| @{Microsoft.AAD.BrokerPlugin_1000.19580.1000.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.AAD.BrokerPlugin/resources/PackageDisplayName} | Domain,Private | * | broad remote address | Firewall COM | ||
| @{Microsoft.Windows.Search_1.16.0.22000_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.Search/resources/PackageDisplayName} | Domain,Private | * | broad remote address | Firewall COM | ||
| teams.exe | Private,Public | C:\users\user.redacted\appdata\local\microsoft\teams\current\teams.exe | * | * | public/any profile; broad remote address; user-writable program path | Firewall COM |
| teams.exe | Private,Public | C:\users\user.redacted\appdata\local\microsoft\teams\current\teams.exe | * | * | public/any profile; broad remote address; user-writable program path | Firewall COM |
| @{Microsoft.Windows.CloudExperienceHost_10.0.22000.1_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.CloudExperienceHost/resources/appDescription} | Domain,Private | * | broad remote address | Firewall COM | ||
| @{Microsoft.AAD.BrokerPlugin_1000.19580.1000.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.AAD.BrokerPlugin/resources/PackageDisplayName} | Domain,Private | * | broad remote address | Firewall COM | ||
| @{MicrosoftWindows.Client.CBS_1000.22000.675.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.CBS/resources/ProductPkgDisplayName} | Domain,Private | * | broad remote address | Firewall COM | ||
| @{Microsoft.Windows.StartMenuExperienceHost_10.0.22000.37_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.StartMenuExperienceHost/StartMenuExperienceHost/PkgDisplayName} | Domain,Private | * | broad remote address | Firewall COM | ||
| @{Microsoft.Windows.Search_1.16.0.22000_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.Search/resources/PackageDisplayName} | Domain,Private | * | broad remote address | Firewall COM | ||
| Cortana | Domain,Private,Public | * | public/any profile; broad remote address | Firewall COM | ||
| Microsoft Edge | Domain,Private | * | broad remote address | Firewall COM | ||
| @{microsoft.windowscommunicationsapps_16005.14326.20970.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxoutlookintl/AppManifest_OutlookDesktop_DisplayName} | Domain,Private,Public | * | public/any profile; broad remote address | Firewall COM | ||
| @{Microsoft.Windows.Photos_2021.21120.8011.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.Windows.Photos/Resources/AppStoreName} | Domain,Private,Public | * | public/any profile; broad remote address | Firewall COM | ||
| Microsoft Store | Domain,Private,Public | * | public/any profile; broad remote address | Firewall COM | ||
| Skype | Domain,Private,Public | C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.89.3403.0_x86__kzf8qxf38zg5c\Skype\Skype.exe | * | * | public/any profile; broad remote address | Firewall COM |
| Skype | Domain,Private,Public | C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.89.3403.0_x86__kzf8qxf38zg5c\Skype\Skype.exe | * | * | public/any profile; broad remote address | Firewall COM |
| Skype | Domain,Private,Public | C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.90.3407.0_x86__kzf8qxf38zg5c\Skype\Skype.exe | * | * | public/any profile; broad remote address | Firewall COM |
| Skype | Domain,Private,Public | C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.90.3407.0_x86__kzf8qxf38zg5c\Skype\Skype.exe | * | * | public/any profile; broad remote address | Firewall COM |
| Skype | Domain,Private,Public | C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.93.3404.0_x86__kzf8qxf38zg5c\Skype\Skype.exe | * | * | public/any profile; broad remote address | Firewall COM |
| Skype | Domain,Private,Public | C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.93.3404.0_x86__kzf8qxf38zg5c\Skype\Skype.exe | * | * | public/any profile; broad remote address | Firewall COM |
| Skype | Domain,Private,Public | C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.93.3406.0_x86__kzf8qxf38zg5c\Skype\Skype.exe | * | * | public/any profile; broad remote address | Firewall COM |
| Skype | Domain,Private,Public | C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.93.3406.0_x86__kzf8qxf38zg5c\Skype\Skype.exe | * | * | public/any profile; broad remote address | Firewall COM |
| Skype | Domain,Private,Public | C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.93.3408.0_x86__kzf8qxf38zg5c\Skype\Skype.exe | * | * | public/any profile; broad remote address | Firewall COM |
| Skype | Domain,Private,Public | C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.93.3408.0_x86__kzf8qxf38zg5c\Skype\Skype.exe | * | * | public/any profile; broad remote address | Firewall COM |
| Skype | Domain,Private,Public | C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.94.3422.0_x86__kzf8qxf38zg5c\Skype\Skype.exe | * | * | public/any profile; broad remote address | Firewall COM |
| Skype | Domain,Private,Public | C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.94.3422.0_x86__kzf8qxf38zg5c\Skype\Skype.exe | * | * | public/any profile; broad remote address | Firewall COM |
| @{Microsoft.Win32WebViewHost_10.0.26100.1_neutral_neutral_cw5n1h2txyewy?ms-resource://Windows.Win32WebViewHost/resources/DisplayName} | Domain,Private,Public | * | public/any profile; broad remote address | Firewall COM | ||
| @{Microsoft.Windows.CloudExperienceHost_10.0.26100.1_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.CloudExperienceHost/resources/appDescription} | Domain,Private | * | broad remote address | Firewall COM | ||
| @{Microsoft.AAD.BrokerPlugin_1000.19580.1000.2_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.AAD.BrokerPlugin/resources/PackageDisplayName} | Domain,Private | * | broad remote address | Firewall COM | ||
| @{microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxoutlookintl/AppManifest_OutlookDesktop_DisplayName} | Domain,Private,Public | * | public/any profile; broad remote address | Firewall COM | ||
| @{MicrosoftWindows.LKG.DesktopSpotlight_1000.26100.3775.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.LKG.DesktopSpotlight/Resources/ProductPkgDisplayName} | Domain,Private | * | broad remote address | Firewall COM | ||
| PAN ADEM Inbound ICMPv4 Type 11 Firewall Rule | Domain,Private,Public | * | public/any profile; broad remote address | Firewall COM | ||
| Dell SupportAssist for Home PCs | Domain,Private | * | broad remote address | Firewall COM | ||
| Skype | Domain,Private | * | broad remote address | Firewall COM | ||
| @{Microsoft.RemoteDesktop_10.2.4012.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.RemoteDesktop/Resources/Appname} | Domain,Private,Public | * | public/any profile; broad remote address | Firewall COM | ||
| Microsoft Office Outlook | Private | C:\Program Files\Microsoft Office\root\Office16\outlook.exe | 6004 | * | broad remote address | Firewall COM |
| @{Microsoft.WindowsCamera_2025.2510.2.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.WindowsCamera/LensSDK/Resources/AppStoreName} | Domain,Private | * | broad remote address | Firewall COM | ||
| @{Microsoft.WindowsAlarms_11.2512.0.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.WindowsAlarms/Resources/AppStoreName} | Domain,Private | * | broad remote address | Firewall COM | ||
| WFD ASP Coordination Protocol (UDP-In) | Domain,Private,Public | C:\WINDOWS\system32\svchost.exe | 7235 | LocalSubnet | public/any profile | Firewall COM |
| WFD Driver-only (UDP-In) | Domain,Private,Public | System | * | * | public/any profile; broad remote address | Firewall COM |
| WFD Driver-only (TCP-In) | Domain,Private,Public | System | * | * | public/any profile; broad remote address | Firewall COM |
| Cast to Device streaming server (RTSP-Streaming-In) | Public | C:\WINDOWS\system32\mdeserver.exe | 23554,23555,23556 | * | public/any profile; broad remote address | Firewall COM |
| Cast to Device streaming server (HTTP-Streaming-In) | Public | System | 10246 | * | public/any profile; broad remote address | Firewall COM |
| Cast to Device streaming server (HTTP-Streaming-In) | Domain | System | 10246 | * | broad remote address | Firewall COM |
| Cast to Device streaming server (RTCP-Streaming-In) | Public | C:\WINDOWS\system32\mdeserver.exe | * | * | public/any profile; broad remote address | Firewall COM |
| Cast to Device UPnP Events (TCP-In) | Public | System | 2869 | * | public/any profile; broad remote address | Firewall COM |
| Cast to Device SSDP Discovery (UDP-In) | Public | C:\WINDOWS\system32\svchost.exe | Ply2Disc, | * | public/any profile; broad remote address | Firewall COM |
| Cast to Device functionality (qWave-TCP-In) | Private,Public | C:\WINDOWS\system32\svchost.exe | 2177 | * | public/any profile; broad remote address | Firewall COM |
| Cast to Device functionality (qWave-UDP-In) | Private,Public | C:\WINDOWS\system32\svchost.exe | 2177 | * | public/any profile; broad remote address | Firewall COM |
| Cast to Device streaming server (RTSP-Streaming-In) | Domain | C:\WINDOWS\system32\mdeserver.exe | 23554,23555,23556 | * | broad remote address | Firewall COM |
| Cast to Device streaming server (RTCP-Streaming-In) | Domain | C:\WINDOWS\system32\mdeserver.exe | * | * | broad remote address | Firewall COM |
| mDNS (UDP-In) | Public | C:\WINDOWS\system32\svchost.exe | 5353 | LocalSubnet | public/any profile | Firewall COM |
| mDNS (UDP-In) | Domain | C:\WINDOWS\system32\svchost.exe | 5353 | * | broad remote address | Firewall COM |
| Core Networking - Time Exceeded (ICMPv6-In) | Domain,Private,Public | System | * | public/any profile; broad remote address | Firewall COM | |
| Core Networking - Multicast Listener Report (ICMPv6-In) | Domain,Private,Public | System | LocalSubnet | public/any profile | Firewall COM | |
| Core Networking - Multicast Listener Query (ICMPv6-In) | Domain,Private,Public | System | LocalSubnet | public/any profile | Firewall COM | |
| Core Networking - Multicast Listener Report v2 (ICMPv6-In) | Domain,Private,Public | System | LocalSubnet | public/any profile | Firewall COM |
| SSID | Authentication | Cipher | Security key | Risk |
|---|---|---|---|---|
| HomeNetwork2-Redacted | WPA2-Personal | CCMP | Present | OK |
| SpectrumSetup-F2 | WPA2-Personal | CCMP | Present | OK |
| PowhatanWiFi | Open | None | Absent | High |
| #MyBWI-Fi | Unknown | OK | ||
| Qualityguest | Open | None | Absent | High |
| B053-Guest | WPA2-Personal | CCMP | Present | OK |
| AndroidAP | WPA2-Personal | CCMP | Present | OK |
| genesis | WPA2-Enterprise | CCMP | Absent | OK |
| Hyatt_Guest | Open | None | Absent | High |
| IHG ONE REWARDS Free WI-FI | Open | None | Absent | High |
| CARE4U | Open | None | Absent | High |
| BSMH-Guest | Open | None | Absent | High |
| HomeNetwork-Redacted | WPA2-Personal | CCMP | Present | OK |
| CorpNet_FW | WPA2-Personal | CCMP | Present | OK |
| Store | Subject | Issuer | Not after | Status | Thumbprint |
|---|---|---|---|---|---|
| Cert:\LocalMachine\Root | OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Time Stamping Service Root, OU=Microsoft Corporation, O=Microsoft Trust Network | OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Time Stamping Service Root, OU=Microsoft Corporation, O=Microsoft Trust Network | 12/31/1999 00:59:59 | Expired | 245C97DF7514E7CF2DF8BE72AE957B9E04741E85 |
| Cert:\CurrentUser\Root | OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Time Stamping Service Root, OU=Microsoft Corporation, O=Microsoft Trust Network | OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Time Stamping Service Root, OU=Microsoft Corporation, O=Microsoft Trust Network | 12/31/1999 00:59:59 | Expired | 245C97DF7514E7CF2DF8BE72AE957B9E04741E85 |
| Cert:\CurrentUser\Root | CN=Microsoft Authenticode(tm) Root Authority, O=MSFT, C=US | CN=Microsoft Authenticode(tm) Root Authority, O=MSFT, C=US | 01/01/2000 00:59:59 | Expired | 7F88CD7223F3C813818C994614A89C99FA3B5247 |
| Cert:\LocalMachine\Root | CN=Microsoft Authenticode(tm) Root Authority, O=MSFT, C=US | CN=Microsoft Authenticode(tm) Root Authority, O=MSFT, C=US | 01/01/2000 00:59:59 | Expired | 7F88CD7223F3C813818C994614A89C99FA3B5247 |
| Cert:\CurrentUser\Root | OU="NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.", OU=VeriSign Time Stamping Service Root, OU="VeriSign, Inc.", O=VeriSign Trust Network | OU="NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.", OU=VeriSign Time Stamping Service Root, OU="VeriSign, Inc.", O=VeriSign Trust Network | 01/08/2004 00:59:59 | Expired | 18F7C1FCC3090203FD5BAA2F861A754976C8DD25 |
| Cert:\LocalMachine\Root | OU="NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.", OU=VeriSign Time Stamping Service Root, OU="VeriSign, Inc.", O=VeriSign Trust Network | OU="NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.", OU=VeriSign Time Stamping Service Root, OU="VeriSign, Inc.", O=VeriSign Trust Network | 01/08/2004 00:59:59 | Expired | 18F7C1FCC3090203FD5BAA2F861A754976C8DD25 |
| Cert:\LocalMachine\Root | CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US | CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US | 07/09/2019 20:40:36 | Expired | E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46 |
| Cert:\CurrentUser\Root | CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US | CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US | 07/09/2019 20:40:36 | Expired | E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46 |
| Cert:\LocalMachine\Root | CN=AddTrust External CA Root, OU=AddTrust External TTP Network, O=AddTrust AB, C=SE | CN=AddTrust External CA Root, OU=AddTrust External TTP Network, O=AddTrust AB, C=SE | 05/30/2020 12:48:38 | Expired | 02FAF3E291435468607857694DF5E45B68851868 |
| Cert:\CurrentUser\Root | CN=AddTrust External CA Root, OU=AddTrust External TTP Network, O=AddTrust AB, C=SE | CN=AddTrust External CA Root, OU=AddTrust External TTP Network, O=AddTrust AB, C=SE | 05/30/2020 12:48:38 | Expired | 02FAF3E291435468607857694DF5E45B68851868 |
| Cert:\LocalMachine\Root | CN=Microsoft Root Authority, OU=Microsoft Corporation, OU=Copyright (c) 1997 Microsoft Corp. | CN=Microsoft Root Authority, OU=Microsoft Corporation, OU=Copyright (c) 1997 Microsoft Corp. | 12/31/2020 08:00:00 | Expired | A43489159A520F0D93D032CCAF37E7FE20A8B419 |
| Cert:\CurrentUser\Root | CN=Microsoft Root Authority, OU=Microsoft Corporation, OU=Copyright (c) 1997 Microsoft Corp. | CN=Microsoft Root Authority, OU=Microsoft Corporation, OU=Copyright (c) 1997 Microsoft Corp. | 12/31/2020 08:00:00 | Expired | A43489159A520F0D93D032CCAF37E7FE20A8B419 |
| Cert:\CurrentUser\Root | CN=Thawte Timestamping CA, OU=Thawte Certification, O=Thawte, L=Durbanville, S=Western Cape, C=ZA | CN=Thawte Timestamping CA, OU=Thawte Certification, O=Thawte, L=Durbanville, S=Western Cape, C=ZA | 01/01/2021 00:59:59 | Expired | BE36A4562FB2EE05DBB3D32323ADF445084ED656 |
| Cert:\LocalMachine\Root | CN=Thawte Timestamping CA, OU=Thawte Certification, O=Thawte, L=Durbanville, S=Western Cape, C=ZA | CN=Thawte Timestamping CA, OU=Thawte Certification, O=Thawte, L=Durbanville, S=Western Cape, C=ZA | 01/01/2021 00:59:59 | Expired | BE36A4562FB2EE05DBB3D32323ADF445084ED656 |
| Cert:\CurrentUser\Root | CN=QuoVadis Root Certification Authority, OU=Root Certification Authority, O=QuoVadis Limited, C=BM | CN=QuoVadis Root Certification Authority, OU=Root Certification Authority, O=QuoVadis Limited, C=BM | 03/17/2021 19:33:33 | Expired | DE3F40BD5093D39B6C60F6DABC076201008976C9 |
| Cert:\LocalMachine\Root | CN=QuoVadis Root Certification Authority, OU=Root Certification Authority, O=QuoVadis Limited, C=BM | CN=QuoVadis Root Certification Authority, OU=Root Certification Authority, O=QuoVadis Limited, C=BM | 03/17/2021 19:33:33 | Expired | DE3F40BD5093D39B6C60F6DABC076201008976C9 |
| Cert:\LocalMachine\Root | CN=Microsoft Root Certificate Authority, DC=microsoft, DC=com | CN=Microsoft Root Certificate Authority, DC=microsoft, DC=com | 05/10/2021 01:28:13 | Expired | CDD4EEAE6000AC7F40C3802C171E30148030C072 |
| Cert:\CurrentUser\Root | CN=Microsoft Root Certificate Authority, DC=microsoft, DC=com | CN=Microsoft Root Certificate Authority, DC=microsoft, DC=com | 05/10/2021 01:28:13 | Expired | CDD4EEAE6000AC7F40C3802C171E30148030C072 |
| Cert:\LocalMachine\Root | CN=DST Root CA X3, O=Digital Signature Trust Co. | CN=DST Root CA X3, O=Digital Signature Trust Co. | 09/30/2021 16:01:15 | Expired | DAC9024F54D8F6DF94935FB1732638CA6AD77C13 |
| Cert:\CurrentUser\Root | CN=DST Root CA X3, O=Digital Signature Trust Co. | CN=DST Root CA X3, O=Digital Signature Trust Co. | 09/30/2021 16:01:15 | Expired | DAC9024F54D8F6DF94935FB1732638CA6AD77C13 |
| Cert:\CurrentUser\My | CN=user@corp-redacted.com, CN=S-1-12-1-REDACTED, DC=xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx | CN=MS-Organization-P2P-Access [2021] | 03/17/2022 14:14:24 | Expired | 7D62CBE5C81546A608C997AA341A25DE3FB7D9C2 |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 02, DC=corp, DC=corp-redacted, DC=com | 05/09/2022 13:21:20 | Expired | 7E78E721F45E7D828EEDDC007AFB0C72C443C779 |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 02, DC=corp, DC=corp-redacted, DC=com | 05/09/2022 13:21:20 | Expired | 72BB500E2613AE652D81001A58CED0759F963505 |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 02, DC=corp, DC=corp-redacted, DC=com | 05/09/2022 13:21:20 | Expired | AF3ACBA1394F65C0C807FAE7F5D3BD77C426F2C6 |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 02, DC=corp, DC=corp-redacted, DC=com | 05/09/2022 13:21:20 | Expired | 83292A32FE8B318A3411EB6DEEDDD79BE3799F6B |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 02, DC=corp, DC=corp-redacted, DC=com | 05/09/2022 13:21:20 | Expired | 467C625F25D9C220EA260EDEF6A042DFAB3326E7 |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 02, DC=corp, DC=corp-redacted, DC=com | 05/09/2022 13:21:20 | Expired | 6142EC0B80640231846657DEEB580BCFEDC94330 |
| Cert:\CurrentUser\My | CN=*.corp-redacted.se | CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US | 10/07/2022 17:32:21 | Expired | 4B00EC9033645BAC0D9334FF17DB01B1AAE8F0F9 |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 01 G2, DC=corp, DC=corp-redacted, DC=com | 02/10/2023 10:16:17 | Expired | 45BC39A3248126F048A9C9EB04747103EA47DFD4 |
| Cert:\CurrentUser\My | CN=*.bing.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 10:52:19 | Expired | E174F6733A9B34F9B5753902D72E865CC3C517B7 |
| Cert:\CurrentUser\My | CN=*.edge.skype.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 10:52:55 | Expired | 9BA485B2DCF05B7B3B1051230E70611E8ACF2933 |
| Cert:\CurrentUser\My | CN=*.activity.windows.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 10:52:55 | Expired | 2D30C1753C0AC1D29943E2BDCFB0A488067F1EBE |
| Cert:\CurrentUser\My | CN=*.pipe.aria.microsoft.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 10:52:56 | Expired | C0F39C88C90DDCD21FDCF472DA781C9A33870D13 |
| Cert:\CurrentUser\My | CN=*.sharepoint.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 10:52:56 | Expired | 079CB14167F023BE0CE152E649694C31293E6241 |
| Cert:\CurrentUser\My | CN=*.cdn.office.net, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 10:52:57 | Expired | 3BE3AF1EEE08F12E182319CCED767E514BD9615B |
| Cert:\CurrentUser\My | CN=www.clarity.ms, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 10:52:58 | Expired | C2F3467B9E86F12D7C392E19CF9F53C06405E313 |
| Cert:\CurrentUser\My | CN=*.google.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 10:52:58 | Expired | 7195330EF2B834669F863AA98D0DF3B9455D579C |
| Cert:\CurrentUser\My | CN=westeurope1-sphomep.svc.ms, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 10:52:59 | Expired | C042D35A29CD9DDA92E5E35838990BDD1B306678 |
| Cert:\CurrentUser\My | CN=*.microsoftonline.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 10:52:59 | Expired | 4CE49E867512F4081E3EBE860FCB9922540D929F |
| Cert:\CurrentUser\My | CN=*.msn.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 10:53:00 | Expired | 3F52836BF101664BC736DE1986C4BC8FEF042DAB |
| Cert:\CurrentUser\My | CN=*.corp-redacted.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 10:53:00 | Expired | 9EB50E8FCD3E512BE1DDD019963C73D8E4BFA2E5 |
| Cert:\CurrentUser\My | CN=*.smartscreen.microsoft.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 10:53:01 | Expired | 822F86BE815626205A255B789418C12E03F2EFD0 |
| Cert:\CurrentUser\My | CN=*.googletagmanager.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 10:53:02 | Expired | 7C081D950641E319BD41601168FD43B91DF92F8D |
| Cert:\CurrentUser\My | CN=*.delve.office.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 10:53:02 | Expired | 88F82449CC292C603145235C6F783A5AC0FAD416 |
| Cert:\CurrentUser\My | CN=*.nel.measure.office.net, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 10:53:03 | Expired | DAC9BF2F94909C9EBFB35355C98A9B016D0D6ECC |
| Cert:\CurrentUser\My | CN=*.office.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 10:53:03 | Expired | B153538D1495EE4271E3C9A12F2B928B12430CD4 |
| Cert:\CurrentUser\My | CN=k.clarity.ms, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 10:53:04 | Expired | 97C1B3BE76722B97E88728B64A1CED3E57D8F83E |
| Cert:\CurrentUser\My | CN=*.presence.teams.microsoft.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 10:53:23 | Expired | E90B16BB2E01DB839875B61674D11A04448831CD |
| Cert:\CurrentUser\My | CN=*.microsoft.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 10:53:26 | Expired | C73DB440BE35408455152A0D83E6209EADE2FF6A |
| Cert:\CurrentUser\My | CN=*.ng.msg.teams.microsoft.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 10:53:32 | Expired | AAE03A1BBB8BFEC9198E1F66DCCE03F4D0541B2E |
| Cert:\CurrentUser\My | CN=*.akamaized.net, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 10:53:35 | Expired | 6DD7EB937F0412B398A3B19821A186FE2CEE8FCF |
| Cert:\CurrentUser\My | CN=*.scorecardresearch.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 10:53:35 | Expired | 11BDE9809278E29C65B8430B9A7A4E814FE0F569 |
| Cert:\CurrentUser\My | CN=*.events.data.microsoft.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 10:53:52 | Expired | C19E673CB17EE3F4CD668A9C3FABACE6E57EA2CD |
| Cert:\CurrentUser\My | CN=*.nelreports.net, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 10:54:01 | Expired | 309C14C50029C72CE8F3BF173E9439F2F2EB5F2C |
| Cert:\CurrentUser\My | CN=*.cloudsink.net, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 11:11:54 | Expired | C26A0873A5E9864AB28B8FE6817EC3CFC8E06706 |
| Cert:\CurrentUser\My | CN=*.blob.core.windows.net, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 15:17:58 | Expired | 980F186C882C2D12AC681376FC69057209D5DC5C |
| Cert:\CurrentUser\My | CN=*.data.microsoft.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 15:18:41 | Expired | B339E362E3A3AEE9E5FF46916A7A47C7F95C7AF6 |
| Cert:\CurrentUser\My | CN=*.notifications.teams.microsoft.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 15:18:41 | Expired | 6209253C704F00DE8702807EC05AF6C25CFF0148 |
| Cert:\CurrentUser\My | CN=a.clarity.ms, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 15:19:11 | Expired | 19E9C349290EA7E049E6832A14051425D7CF3919 |
| Cert:\CurrentUser\My | CN=*.googleapis.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 02/21/2023 15:20:23 | Expired | 63B92B53B64F54B59DBDD52F0161BB454DE1F752 |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 02, DC=corp, DC=corp-redacted, DC=com | 03/28/2023 08:13:22 | Expired | 21F2FAD6689D979F67B67E6469C6424FC58062EC |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 01 G2, DC=corp, DC=corp-redacted, DC=com | 04/25/2023 09:11:16 | Expired | 8865870AF74BC0578A709B68DCC3B7658C50D9DA |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 02, DC=corp, DC=corp-redacted, DC=com | 06/14/2023 10:44:43 | Expired | E4A1444534C38A6CF25D8D5DE309FF849EF59848 |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 01 G2, DC=corp, DC=corp-redacted, DC=com | 07/07/2023 13:21:58 | Expired | 92082D10F91D7203261EC048BFC384AB84BA232B |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 02, DC=corp, DC=corp-redacted, DC=com | 08/26/2023 21:21:44 | Expired | 6C0489AA7311CEFA6B62458E353F1AE2307F6F07 |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 01 G2, DC=corp, DC=corp-redacted, DC=com | 09/19/2023 09:18:21 | Expired | 3C644767E519B72C848F553A5774573B318DB37D |
| Cert:\CurrentUser\Root | OU=Security Communication RootCA1, O=SECOM Trust.net, C=JP | OU=Security Communication RootCA1, O=SECOM Trust.net, C=JP | 09/30/2023 06:20:49 | Expired | 36B12B49F9819ED74C9EBC380FC6568F5DACB2F7 |
| Cert:\LocalMachine\Root | OU=Security Communication RootCA1, O=SECOM Trust.net, C=JP | OU=Security Communication RootCA1, O=SECOM Trust.net, C=JP | 09/30/2023 06:20:49 | Expired | 36B12B49F9819ED74C9EBC380FC6568F5DACB2F7 |
| Cert:\CurrentUser\My | CN=uatsuppliercomplianceportal.corp-redacted.com | CN=Sectigo RSA Domain Validation Secure Server CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB | 10/30/2023 00:59:59 | Expired | B7413D98DCD9EC5D68847E90E70B9AA4FCC796D0 |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 02, DC=corp, DC=corp-redacted, DC=com | 11/08/2023 09:09:05 | Expired | D5C6FA2AD251CF3F3845B3AA3C015EE6E1EF404A |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 01 G2, DC=corp, DC=corp-redacted, DC=com | 01/02/2024 12:24:18 | Expired | 0804ABAA94757B6AAB371A6EC08DDC419DC21AE3 |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 02, DC=corp, DC=corp-redacted, DC=com | 01/17/2024 09:07:48 | Expired | 0AA3F4EBE4472723D90F47FC01613F7B98E3F7D6 |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 01 G2, DC=corp, DC=corp-redacted, DC=com | 03/15/2024 12:49:48 | Expired | 5D60FCA6BE2A343AD60257092531741ECAE93785 |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 02, DC=corp, DC=corp-redacted, DC=com | 03/30/2024 09:36:45 | Expired | 1D28BC2810569A89533885CECD681CCB49C39B0E |
| Cert:\CurrentUser\Root | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 05/21/2024 11:51:32 | Expired | 1E633DEC18D7E84DB59527912EDB685B3B1B034D |
| Cert:\CurrentUser\Root | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 05/21/2024 11:51:32 | Expired | 1E633DEC18D7E84DB59527912EDB685B3B1B034D |
| Cert:\LocalMachine\Root | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 05/21/2024 11:51:32 | Expired | 1E633DEC18D7E84DB59527912EDB685B3B1B034D |
| Cert:\CurrentUser\My | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | CN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com | 05/21/2024 11:51:32 | Expired | 1E633DEC18D7E84DB59527912EDB685B3B1B034D |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 01 G2, DC=corp, DC=corp-redacted, DC=com | 05/28/2024 09:25:27 | Expired | 9F9BEF12662519CC5175815344FAD3B976942756 |
| Cert:\CurrentUser\My | CN=user@corp-redacted.com, CN=S-1-12-1-REDACTED, DC=xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx | CN=MS-Organization-P2P-Access [2023] | 05/30/2024 10:01:09 | Expired | 8045A761EF24EAE2DE3D21777990C540BC5BC39C |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 02, DC=corp, DC=corp-redacted, DC=com | 06/12/2024 09:12:56 | Expired | 831E88E200BFDA42AD4FB14D1AFD4F956848BE4E |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 01 G2, DC=corp, DC=corp-redacted, DC=com | 08/09/2024 13:56:59 | Expired | B1CA3D90043816D0AFC7EF170F0227E039986237 |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 02, DC=corp, DC=corp-redacted, DC=com | 08/24/2024 10:43:19 | Expired | E89308EEED6EF783BEF00DAE1D9CA7DD6DC20B3E |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 01 G2, DC=corp, DC=corp-redacted, DC=com | 11/19/2024 09:41:08 | Expired | 3FC2B659C645A31C520FD8E642D86EE8A4BA4834 |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 02, DC=corp, DC=corp-redacted, DC=com | 11/19/2024 09:41:09 | Expired | 56031FAF712AFE60DCB0BB13E134F15F9DDFAEAB |
| Cert:\CurrentUser\My | CN=14a3253f-e7d9-4066-843c-8483653a8341 | CN=14a3253f-e7d9-4066-843c-8483653a8341 | 03/25/2025 09:27:59 | Expired | D14C2683E81C24F03476E94F8A39CE19CE326C95 |
| Cert:\LocalMachine\Root | CN=Baltimore CyberTrust Root, OU=CyberTrust, O=Baltimore, C=IE | CN=Baltimore CyberTrust Root, OU=CyberTrust, O=Baltimore, C=IE | 05/13/2025 01:59:00 | Expired | D4DE20D05E66FC53FE1A50882C78DB2852CAE474 |
| Cert:\CurrentUser\Root | CN=Baltimore CyberTrust Root, OU=CyberTrust, O=Baltimore, C=IE | CN=Baltimore CyberTrust Root, OU=CyberTrust, O=Baltimore, C=IE | 05/13/2025 01:59:00 | Expired | D4DE20D05E66FC53FE1A50882C78DB2852CAE474 |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 01 G2, DC=corp, DC=corp-redacted, DC=com | 07/04/2025 09:13:54 | Expired | 611CECF33943EDB86B2DF41137EC105CB77DBD89 |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 02, DC=corp, DC=corp-redacted, DC=com | 07/04/2025 09:13:57 | Expired | 90180B6E125B3EB17B9C61C36427749E89747189 |
| Cert:\LocalMachine\My | CN=azeu-gp-internal.corp.corp-redacted.com | CN=Sectigo RSA Domain Validation Secure Server CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB | 07/15/2025 01:59:59 | Expired | 68E1E46A8A810CC82F5F0DE5F77CAE4F4F7C7734 |
| Cert:\LocalMachine\My | CN=azeu2-gp-internal.corp.corp-redacted.com | CN=Sectigo RSA Domain Validation Secure Server CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB | 07/15/2025 01:59:59 | Expired | 67BCD438A033F26260F82350853725CEA77E956F |
| Cert:\LocalMachine\My | CN=prisma.corp-redacted.com | CN=Sectigo ECC Domain Validation Secure Server CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB | 08/17/2025 01:59:59 | Expired | 8382D2680683306DB2786EEA458EED0D680688AA |
| Cert:\LocalMachine\My | CN=120ae221-3914-4721-ad0a-5aa00a1b27ae | CN=Corp-Redacted.com Issuing CA 01 G2, DC=corp, DC=corp-redacted, DC=com | 10/15/2025 11:52:24 | Expired | BA3DA1DD2A3EAFDE9E47DD8BCE57B8149CF292A9 |
| Cert:\LocalMachine\My | CN=120ae221-3914-4721-ad0a-5aa00a1b27ae | CN=Corp-Redacted.com Issuing CA 01 G2, DC=corp, DC=corp-redacted, DC=com | 10/15/2025 11:52:24 | Expired | F7B1AE4DB953F20DDDFD10EFE428D846B44F883D |
| Cert:\LocalMachine\My | CN=120ae221-3914-4721-ad0a-5aa00a1b27ae | CN=Corp-Redacted.com Issuing CA 01 G2, DC=corp, DC=corp-redacted, DC=com | 10/15/2025 11:52:24 | Expired | EEFBA4A284ED53CD6660E580745CE8CB8335E005 |
| Cert:\LocalMachine\My | CN=120ae221-3914-4721-ad0a-5aa00a1b27ae | CN=Corp-Redacted.com Issuing CA 01 G2, DC=corp, DC=corp-redacted, DC=com | 10/15/2025 11:52:24 | Expired | EE36A9F7EBCFD927B3BA6700E0387DAB5B40BE44 |
| Cert:\LocalMachine\My | CN=120ae221-3914-4721-ad0a-5aa00a1b27ae | CN=Corp-Redacted.com Issuing CA 01 G2, DC=corp, DC=corp-redacted, DC=com | 10/15/2025 11:52:24 | Expired | E6A6224E834CFF4A39F2ABDF7C222F3E3E7CFD11 |
| Cert:\LocalMachine\My | CN=Corp-Redacted.com Issuing CA 01 G2, DC=corp, DC=corp-redacted, DC=com | CN=Corp-Redacted.com Root CA G2 | 10/15/2025 11:52:24 | Expired | CFF8DFB87E8BA3F93E6DB17923453BDAA2FED750 |
| Cert:\LocalMachine\My | CN=120ae221-3914-4721-ad0a-5aa00a1b27ae | CN=Corp-Redacted.com Issuing CA 01 G2, DC=corp, DC=corp-redacted, DC=com | 10/15/2025 11:52:24 | Expired | 84FC898510F3C8B42AF383738FEE2655993EB0F9 |
| Cert:\LocalMachine\My | CN=120ae221-3914-4721-ad0a-5aa00a1b27ae | CN=Corp-Redacted.com Issuing CA 01 G2, DC=corp, DC=corp-redacted, DC=com | 10/15/2025 11:52:24 | Expired | 9512F1A68866722332C461149695B47140751CD2 |
| Cert:\LocalMachine\My | CN=120ae221-3914-4721-ad0a-5aa00a1b27ae | CN=Corp-Redacted.com Issuing CA 01 G2, DC=corp, DC=corp-redacted, DC=com | 10/15/2025 11:52:24 | Expired | 76168FB3CDB851B5ADB5FDE9345DDFBACE0993B5 |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 01 G2, DC=corp, DC=corp-redacted, DC=com | 10/15/2025 11:52:24 | Expired | EB61154C226D523272B82FA57655CC506306D181 |
| Cert:\LocalMachine\My | CN=Corp-Client-Cert, O=Corp-Redacted International AB, L=REDACTED, S=REDACTED, C=SE | CN=Corp-Redacted.com Issuing CA 01 G2, DC=corp, DC=corp-redacted, DC=com | 10/15/2025 11:52:24 | Expired | 81838B31571EEB1F8D5DA3CAE5C7D0000D2C6D46 |
| Cert:\CurrentUser\My | CN=user@corp-redacted.com, CN=S-1-12-1-REDACTED, DC=xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx | CN=MS-Organization-P2P-Access [2025] | 12/11/2025 10:57:36 | Expired | 5197A1ACBA53DF74E82AD38E0D1B0332493BD5EE |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 02, DC=corp, DC=corp-redacted, DC=com | 02/26/2026 09:22:19 | Expired | 12D17940AAD7DEE5F7CC590E5A95C263B2DB39BA |
| Cert:\CurrentUser\My | OID.1.3.6.1.4.1.25461.4.49.2=834782572, OID.1.3.6.1.4.1.25461.4.49.1=01790025991, C=US, S=CA, L=Santa Clara, O=Palo Alto Networks, CN=01790025991 | C=US, O=Palo-Alto-Networks-Inc., CN=USW-Client-Issuing-CA2-G5 | 03/21/2026 13:50:19 | Expired | 5A87B4C4FF8F718ED2B285490DBC01F08BE985C1 |
| Cert:\LocalMachine\My | CN=120ae221-3914-4721-ad0a-5aa00a1b27ae, DC=xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx | CN=MS-Organization-P2P-Access [2025] | 06/12/2026 13:54:43 | Expiring <=30d | 4D5CDBADE2A166AEDB4C064E4B49DE5B5E81931B |
| Cert:\CurrentUser\My | CN=User.Redacted | CN=Corp-Redacted.com Issuing CA 02, DC=corp, DC=corp-redacted, DC=com | 06/24/2026 17:18:10 | Expiring <=30d | 6C59287CB544D064CF8B3A514AA6E91741BE7856 |
| Cert:\CurrentUser\Root | CN=Microsoft Intune Root Certification Authority | CN=Microsoft Intune Root Certification Authority | 08/12/2026 02:00:00 | Expiring <=90d | 9EA77BA6D30BB2AB2DECE2DFDC2470429DCC3677 |
| Cert:\LocalMachine\Root | CN=Microsoft Intune Root Certification Authority | CN=Microsoft Intune Root Certification Authority | 08/12/2026 02:00:00 | Expiring <=90d | 9EA77BA6D30BB2AB2DECE2DFDC2470429DCC3677 |
| Source | Name | Version | Evidence | Risk |
|---|---|---|---|---|
| Installed software | TeamViewer Host | 15.78.4 | TeamViewer | Review |
| Tool | Version | Publisher | Why it matters |
|---|---|---|---|
| Npcap | 1.79 | Nmap Project | Useful admin/developer tool; confirm expected and patched. |
| OpenSSL 3.4.1 Light (64-bit) | 3.4.1 | OpenSSL Win64 Installer Team | Useful admin/developer tool; confirm expected and patched. |
| PowerShell 7.4.7.0-x64 | 7.4.7.0 | Microsoft Corporation | Useful admin/developer tool; confirm expected and patched. |
| PowerShell 7-x64 | 7.6.2.0 | Microsoft Corporation | Useful admin/developer tool; confirm expected and patched. |
| PuTTY release 0.81 (64-bit) | 0.81.0.0 | Simon Tatham | Useful admin/developer tool; confirm expected and patched. |
| USBPcap 1.5.4.0 | 1.5.4.0 | Tomasz Mon | Useful admin/developer tool; confirm expected and patched. |
| Windows Subsystem for Linux | 2.4.12.0 | Microsoft Corporation | Useful admin/developer tool; confirm expected and patched. |
| Windows Subsystem for Linux Update | 5.10.102.1 | Microsoft Corporation | Useful admin/developer tool; confirm expected and patched. |
| Windows Subsystem for Linux WSLg Preview | 1.0.27 | Microsoft Corporation | Useful admin/developer tool; confirm expected and patched. |
| Wireshark 4.6.6 x64 | 4.6.6 | The Wireshark developer community, https://www.wireshark.org | Useful admin/developer tool; confirm expected and patched. |
| Task | Path | State | Action | Risk |
|---|---|---|---|---|
| OneDrive Per-Machine Standalone Update Task | \ | Ready | C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe | Review |
| OneDrive Reporting Task-S-1-12-1-REDACTED | \ | Ready | C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe /reporting | Review |
| OneDrive Startup Task-S-1-12-1-REDACTED | \ | Ready | C:\Program Files\Microsoft OneDrive\26.088.0510.0004\OneDriveLauncher.exe /startInstances | Review |
| Cloud Managed Desktop Extension Health Evaluation | \Microsoft\CMD\ | Ready | C:\Program Files\Microsoft Cloud Managed Desktop Extension\CMDExtension\ClientHealth\Microsoft.Management.Services.CloudManagedDesktop.Agent.ClientHealth.exe | Review |
| Intune Management Extension Health Evaluation | \Microsoft\Intune\ | Ready | C:\Program Files (x86)\Microsoft Intune Management Extension\ClientHealthEval.exe | Review |
| Office Actions Server | \Microsoft\Office\ | Ready | C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\ActionsServer\ActionsServer.exe availabilitycheck | Review |
| Office Automatic Updates 2.0 | \Microsoft\Office\ | Ready | C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /frequentupdate SCHEDULEDTASK displaylevel=False | Review |
| Office Background Push Maintenance | \Microsoft\Office\ | Ready | C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\opushutil.exe /pushregistration | Review |
| Office ClickToRun Service Monitor | \Microsoft\Office\ | Ready | C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /WatchService | Review |
| Office Feature Updates | \Microsoft\Office\ | Ready | C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe | Review |
| Office Feature Updates Logon | \Microsoft\Office\ | Ready | C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe /onlogon | Review |
| Office Performance Monitor | \Microsoft\Office\ | Ready | C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe | Review |
| Office Serviceability Manager | \Microsoft\Office\ | Ready | C:\Program Files\Common Files\Microsoft Shared\ClickToRun\officesvcmgr.exe /checkin | Review |
| Office Startup Maintenance | \Microsoft\Office\ | Ready | C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\ActionsServer\ActionsServer.exe wacheck | Review |
| .NET Framework NGEN v4.0.30319 | \Microsoft\Windows\.NET Framework\ | Ready | Review | |
| .NET Framework NGEN v4.0.30319 64 | \Microsoft\Windows\.NET Framework\ | Ready | Review | |
| RecoverabilityToastTask | \Microsoft\Windows\AccountHealth\ | Ready | Review | |
| AD RMS Rights Policy Template Management (Manual) | \Microsoft\Windows\Active Directory Rights Management Services Client\ | Ready | Review | |
| MareBackup | \Microsoft\Windows\Application Experience\ | Ready | %windir%\system32\compattelrunner.exe -m:aeinv.dll -f:UpdateSoftwareInventoryW invsvc | %windir%\system32\compattelrunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun | %windir%\system32\compattelrunner.exe -m:aemarebackup.dll -f:BackupMareData | Review |
| Microsoft Compatibility Appraiser Exp | \Microsoft\Windows\Application Experience\ | Ready | %windir%\system32\compattelrunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun express | Review |
| PcaPatchDbTask | \Microsoft\Windows\Application Experience\ | Ready | %windir%\system32\rundll32.exe %windir%\system32\PcaSvc.dll,PcaPatchSdbTask | Review |
| SdbinstMergeDbTask | \Microsoft\Windows\Application Experience\ | Ready | %windir%\system32\sdbinst.exe -mm | Review |
| StartupAppTask | \Microsoft\Windows\Application Experience\ | Ready | %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask | Review |
| appuriverifierdaily | \Microsoft\Windows\ApplicationData\ | Ready | %windir%\system32\AppHostRegistrationVerifier.exe | Review |
| appuriverifierinstall | \Microsoft\Windows\ApplicationData\ | Ready | %windir%\system32\AppHostRegistrationVerifier.exe | Review |
| CleanupTemporaryState | \Microsoft\Windows\ApplicationData\ | Ready | %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState | High |
| DsSvcCleanup | \Microsoft\Windows\ApplicationData\ | Ready | %windir%\system32\dstokenclean.exe | Review |
| Backup | \Microsoft\Windows\AppListBackup\ | Ready | Review | |
| BackupNonMaintenance | \Microsoft\Windows\AppListBackup\ | Ready | Review | |
| Proxy | \Microsoft\Windows\Autochk\ | Ready | %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations | Review |
| BitLocker Encrypt All Drives | \Microsoft\Windows\BitLocker\ | Ready | Review | |
| BitLocker MDM policy Refresh | \Microsoft\Windows\BitLocker\ | Ready | Review | |
| UninstallDeviceTask | \Microsoft\Windows\Bluetooth\ | Ready | BthUdTask.exe $(Arg0) | Review |
| BgTaskRegistrationMaintenanceTask | \Microsoft\Windows\BrokerInfrastructure\ | Ready | Review | |
| maintenancetasks | \Microsoft\Windows\capabilityaccessmanager\ | Ready | %windir%\system32\rundll32.exe %windir%\system32\CapabilityAccessManager.dll,CapabilityAccessManagerDoStoreMaintenance | Review |
| UserTask | \Microsoft\Windows\CertificateServicesClient\ | Ready | Review | |
| UserTask-Roam | \Microsoft\Windows\CertificateServicesClient\ | Ready | Review | |
| ProactiveScan | \Microsoft\Windows\Chkdsk\ | Ready | Review | |
| SyspartRepair | \Microsoft\Windows\Chkdsk\ | Ready | %windir%\system32\bcdboot.exe %windir% /sysrepair | Review |
| CreateObjectTask | \Microsoft\Windows\CloudExperienceHost\ | Ready | Review | |
| Backup | \Microsoft\Windows\CloudRestore\ | Ready | Review | |
| Restore | \Microsoft\Windows\CloudRestore\ | Ready | Review | |
| UnifiedConsentSyncTask | \Microsoft\Windows\ConsentUX\UnifiedConsent\ | Ready | Review | |
| CmCleanup | \Microsoft\Windows\Containers\ | Ready | Review | |
| Consolidator | \Microsoft\Windows\Customer Experience Improvement Program\ | Ready | %SystemRoot%\System32\wsqmcons.exe | Review |
| UsbCeip | \Microsoft\Windows\Customer Experience Improvement Program\ | Ready | Review | |
| Data Integrity Check And Scan | \Microsoft\Windows\Data Integrity Scan\ | Ready | Review | |
| Data Integrity Scan | \Microsoft\Windows\Data Integrity Scan\ | Ready | Review | |
| Data Integrity Scan for Crash Recovery | \Microsoft\Windows\Data Integrity Scan\ | Ready | Review | |
| ScheduledDefrag | \Microsoft\Windows\Defrag\ | Ready | %windir%\system32\defrag.exe -c -h -o -$ | Review |
| Device | \Microsoft\Windows\Device Information\ | Ready | %windir%\system32\devicecensus.exe SystemCxt | Review |
| Device User | \Microsoft\Windows\Device Information\ | Ready | %windir%\system32\devicecensus.exe UserCxt | Review |
| RecommendedTroubleshootingScanner | \Microsoft\Windows\Diagnosis\ | Ready | Review | |
| Scheduled | \Microsoft\Windows\Diagnosis\ | Ready | Review | |
| UnexpectedCodepath | \Microsoft\Windows\Diagnosis\ | Ready | %windir%\system32\UCConfigTask.exe | Review |
| DirectXDatabaseUpdater | \Microsoft\Windows\DirectX\ | Ready | %windir%\system32\directxdatabaseupdater.exe | Review |
| DXGIAdapterCache | \Microsoft\Windows\DirectX\ | Ready | %windir%\system32\dxgiadaptercache.exe | Review |
| SilentCleanup | \Microsoft\Windows\DiskCleanup\ | Ready | %windir%\system32\cleanmgr.exe /autocleanstoragesense /d %systemdrive% | Review |
| Diagnostics | \Microsoft\Windows\DiskFootprint\ | Ready | %windir%\system32\disksnapshot.exe -z | Review |
| StorageSense | \Microsoft\Windows\DiskFootprint\ | Ready | Review | |
| dusmtask | \Microsoft\Windows\DUSM\ | Ready | %SystemRoot%\System32\dusmtask.exe | Review |
| EDP App Launch Task | \Microsoft\Windows\EDP\ | Ready | Review | |
| EDP Auth Task | \Microsoft\Windows\EDP\ | Ready | Review | |
| EDP Inaccessible Credentials Task | \Microsoft\Windows\EDP\ | Ready | Review | |
| StorageCardEncryption Task | \Microsoft\Windows\EDP\ | Ready | Review | |
| Login Schedule created by enrollment client | \Microsoft\Windows\EnterpriseMgmt\88EECD34-0B9A-4941-87A5-318825AD21BA\ | Ready | %windir%\system32\deviceenroller.exe /o "88EECD34-0B9A-4941-87A5-318825AD21BA" /c /lf | Review |
| PushLaunch | \Microsoft\Windows\EnterpriseMgmt\88EECD34-0B9A-4941-87A5-318825AD21BA\ | Ready | %windir%\system32\deviceenroller.exe /o "88EECD34-0B9A-4941-87A5-318825AD21BA" /c /z | Review |
| PushRenewal | \Microsoft\Windows\EnterpriseMgmt\88EECD34-0B9A-4941-87A5-318825AD21BA\ | Ready | %windir%\system32\deviceenroller.exe /o "88EECD34-0B9A-4941-87A5-318825AD21BA" /c /y | Review |
| PushUpgrade | \Microsoft\Windows\EnterpriseMgmt\88EECD34-0B9A-4941-87A5-318825AD21BA\ | Ready | %windir%\system32\deviceenroller.exe /o "88EECD34-0B9A-4941-87A5-318825AD21BA" /c /PushUpgrade | Review |
| Login Schedule created by enrollment client | \Microsoft\Windows\EnterpriseMgmt\FC5071E4-D929-4FA6-945C-A699D2DB51B6\ | Ready | %windir%\system32\deviceenroller.exe /o "FC5071E4-D929-4FA6-945C-A699D2DB51B6" /c /lf | Review |
| PushLaunch | \Microsoft\Windows\EnterpriseMgmt\FC5071E4-D929-4FA6-945C-A699D2DB51B6\ | Ready | %windir%\system32\deviceenroller.exe /o "FC5071E4-D929-4FA6-945C-A699D2DB51B6" /c /z | Review |
| PushRenewal | \Microsoft\Windows\EnterpriseMgmt\FC5071E4-D929-4FA6-945C-A699D2DB51B6\ | Ready | %windir%\system32\deviceenroller.exe /o "FC5071E4-D929-4FA6-945C-A699D2DB51B6" /c /y | Review |
| PushUpgrade | \Microsoft\Windows\EnterpriseMgmt\FC5071E4-D929-4FA6-945C-A699D2DB51B6\ | Ready | %windir%\system32\deviceenroller.exe /o "FC5071E4-D929-4FA6-945C-A699D2DB51B6" /c /PushUpgrade | Review |
| ExploitGuard MDM policy Refresh | \Microsoft\Windows\ExploitGuard\ | Ready | Review | |
| DmClient | \Microsoft\Windows\Feedback\Siuf\ | Ready | %windir%\system32\dmclient.exe | Review |
| DmClientOnScenarioDownload | \Microsoft\Windows\Feedback\Siuf\ | Ready | %windir%\system32\dmclient.exe utcwnf | Review |
| File History (maintenance mode) | \Microsoft\Windows\FileHistory\ | Ready | Review | |
| GovernedFeatureUsageProcessing | \Microsoft\Windows\Flighting\FeatureConfig\ | Ready | Review | |
| ReconcileConfigs | \Microsoft\Windows\Flighting\FeatureConfig\ | Ready | Review | |
| ReconcileFeatures | \Microsoft\Windows\Flighting\FeatureConfig\ | Ready | Review | |
| UsageDataFlushing | \Microsoft\Windows\Flighting\FeatureConfig\ | Ready | Review | |
| UsageDataReceiver | \Microsoft\Windows\Flighting\FeatureConfig\ | Ready | Review | |
| UsageDataReporting | \Microsoft\Windows\Flighting\FeatureConfig\ | Ready | Review | |
| RefreshCache | \Microsoft\Windows\Flighting\OneSettings\ | Ready | Review | |
| Monitoring | \Microsoft\Windows\Hotpatch\ | Ready | %systemroot%\system32\cmd.exe /d /c %systemroot%\system32\hpatchmonTask.cmd | Review |
| InputSettingsRestoreDataAvailable | \Microsoft\Windows\input\ | Ready | Review | |
| LocalUserSyncDataAvailable | \Microsoft\Windows\input\ | Ready | Review | |
| MouseSyncDataAvailable | \Microsoft\Windows\input\ | Ready | Review | |
| PenSyncDataAvailable | \Microsoft\Windows\input\ | Ready | Review | |
| RemoteMouseSyncDataAvailable | \Microsoft\Windows\input\ | Ready | Review | |
| RemotePenSyncDataAvailable | \Microsoft\Windows\input\ | Ready | Review | |
| RemoteTouchpadSyncDataAvailable | \Microsoft\Windows\input\ | Ready | Review | |
| syncpensettings | \Microsoft\Windows\input\ | Ready | Review | |
| TouchpadSyncDataAvailable | \Microsoft\Windows\input\ | Ready | Review | |
| RestoreDevice | \Microsoft\Windows\InstallService\ | Ready | Review | |
| ScanForUpdates | \Microsoft\Windows\InstallService\ | Ready | Review | |
| ScanForUpdatesAsUser | \Microsoft\Windows\InstallService\ | Ready | Review | |
| Synchronize Language Settings | \Microsoft\Windows\International\ | Ready | Review | |
| La57Cleanup | \Microsoft\Windows\Kernel\ | Ready | %windir%\system32\la57setup.exe | Review |
| Installation | \Microsoft\Windows\LanguageComponentsInstaller\ | Ready | Review | |
| ReconcileLanguageResources | \Microsoft\Windows\LanguageComponentsInstaller\ | Ready | Review | |
| Notifications | \Microsoft\Windows\Location\ | Ready | %windir%\System32\LocationNotificationWindows.exe | Review |
| WindowsActionDialog | \Microsoft\Windows\Location\ | Ready | %windir%\System32\WindowsActionDialog.exe | Review |
| WinSAT | \Microsoft\Windows\Maintenance\ | Ready | Review | |
| Cellular | \Microsoft\Windows\Management\Provisioning\ | Ready | %windir%\system32\ProvTool.exe /turn 7 /source CellStateChangeTask | Review |
| Logon | \Microsoft\Windows\Management\Provisioning\ | Ready | %windir%\system32\ProvTool.exe /turn 5 /source LogonIdleTask | Review |
| MapsToastTask | \Microsoft\Windows\Maps\ | Ready | Review | |
| AutomaticOfflineMemoryDiagnostic | \Microsoft\Windows\MemoryDiagnostic\ | Ready | Review | |
| ProcessMemoryDiagnosticEvents | \Microsoft\Windows\MemoryDiagnostic\ | Ready | Review | |
| MNO Metadata Parser | \Microsoft\Windows\Mobile Broadband Accounts\ | Ready | %SystemRoot%\System32\MbaeParserTask.exe | Review |
| LPRemove | \Microsoft\Windows\MUI\ | Ready | %windir%\system32\lpremove.exe | Review |
| SystemSoundsService | \Microsoft\Windows\Multimedia\ | Running | Review | |
| NcsiIdentifyUserProxies | \Microsoft\Windows\Network Connectivity Status Indicator\ | Ready | Review | |
| WiFiTask | \Microsoft\Windows\NlaSvc\ | Ready | %SystemRoot%\System32\WiFiTask.exe nla | Review |
| PCR Prediction Framework Firmware Update Task | \Microsoft\Windows\PCRPF\ | Ready | %windir%\system32\rundll32.exe %windir%\system32\pcrpf.dll,NotifyFirmwareUpdateStaged | Review |
| RequestTrace | \Microsoft\Windows\PerformanceTrace\ | Ready | Review | |
| WhesvcToast | \Microsoft\Windows\PerformanceTrace\ | Ready | Review | |
| Device Install Group Policy | \Microsoft\Windows\Plug and Play\ | Ready | Review | |
| Device Install Reboot Required | \Microsoft\Windows\Plug and Play\ | Ready | Review | |
| Sysprep Generalize Drivers | \Microsoft\Windows\Plug and Play\ | Ready | %SystemRoot%\System32\drvinst.exe 6 | Review |
| AnalyzeSystem | \Microsoft\Windows\Power Efficiency Diagnostics\ | Ready | Review | |
| EduPrintProv | \Microsoft\Windows\Printing\ | Ready | %windir%\system32\eduprintprov.exe | Review |
| PrinterCleanupTask | \Microsoft\Windows\Printing\ | Ready | Review | |
| Initialization | \Microsoft\Windows\ReFsDedupSvc\ | Ready | Review | |
| RegIdleBackup | \Microsoft\Windows\Registry\ | Ready | Review | |
| Report update status | \Microsoft\Windows\RemoteApp and Desktop Connections Update\user@corp-redacted.com\ | Ready | %SYSTEMROOT%\System32\RUNDLL32 tsworkspace,WorkspaceStatusNotify2 | Review |
| Start Workspace Runtime at logon | \Microsoft\Windows\RemoteApp and Desktop Connections Update\user@corp-redacted.com\ | Ready | Review | |
| Update connections | \Microsoft\Windows\RemoteApp and Desktop Connections Update\user@corp-redacted.com\ | Ready | %SYSTEMROOT%\System32\RUNDLL32 tsworkspace,TaskUpdateWorkspaces2 | Review |
| IntelligentPwdlessTask | \Microsoft\Windows\Security\Pwdless\ | Ready | Review | |
| StartComponentCleanup | \Microsoft\Windows\Servicing\ | Ready | Review | |
| PITRTask | \Microsoft\Windows\Setup\ | Ready | Review | |
| SetupRecoveryDataTask | \Microsoft\Windows\Setup\ | Ready | Review | |
| CreateObjectTask | \Microsoft\Windows\Shell\ | Ready | Review | |
| FamilySafetyMonitor | \Microsoft\Windows\Shell\ | Ready | %windir%\System32\wpcmon.exe | Review |
| FamilySafetyRefreshTask | \Microsoft\Windows\Shell\ | Ready | Review | |
| IndexerAutomaticMaintenance | \Microsoft\Windows\Shell\ | Ready | Review | |
| ThemesSyncedImageDownload | \Microsoft\Windows\Shell\ | Ready | Review | |
| UninstallSMB1ClientTask | \Microsoft\Windows\SMB\ | Ready | %windir%\system32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& %windir%\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Client" | Review |
| UninstallSMB1ServerTask | \Microsoft\Windows\SMB\ | Ready | %windir%\system32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& %windir%\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Server" | Review |
| SpaceAgentTask | \Microsoft\Windows\SpacePort\ | Ready | %windir%\system32\SpaceAgent.exe | Review |
| SpaceManagerTask | \Microsoft\Windows\SpacePort\ | Ready | %windir%\system32\spaceman.exe /Work | Review |
| MaintenanceTasks | \Microsoft\Windows\StateRepository\ | Ready | %windir%\system32\rundll32.exe %windir%\system32\Windows.StateRepositoryClient.dll,StateRepositoryDoMaintenanceTasks | Review |
| Storage Tiers Management Initialization | \Microsoft\Windows\Storage Tiers Management\ | Ready | Review | |
| EnableLicenseAcquisition | \Microsoft\Windows\Subscription\ | Ready | %SystemRoot%\system32\ClipRenew.exe -e | Review |
| LicenseAcquisition | \Microsoft\Windows\Subscription\ | Ready | %SystemRoot%\system32\ClipRenew.exe | Review |
| PowerGridForecastTask | \Microsoft\Windows\Sustainability\ | Ready | Review | |
| SustainabilityTelemetry | \Microsoft\Windows\Sustainability\ | Ready | Review | |
| ResPriStaticDbSync | \Microsoft\Windows\Sysmain\ | Ready | Review | |
| WsSwapAssessmentTask | \Microsoft\Windows\Sysmain\ | Ready | %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask | Review |
| SR | \Microsoft\Windows\SystemRestore\ | Ready | %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation | Review |
| Interactive | \Microsoft\Windows\Task Manager\ | Ready | Review | |
| MsCtfMonitor | \Microsoft\Windows\TextServicesFramework\ | Ready | Review | |
| ForceSynchronizeTime | \Microsoft\Windows\Time Synchronization\ | Ready | Review | |
| SynchronizeTime | \Microsoft\Windows\Time Synchronization\ | Ready | %windir%\system32\sc.exe start w32time task_started | Review |
| SynchronizeTimeZone | \Microsoft\Windows\Time Zone\ | Ready | %windir%\system32\tzsync.exe | Review |
| UPnPHostConfig | \Microsoft\Windows\UPnP\ | Ready | sc.exe config upnphost start= auto | Review |
| Usb-Notifications | \Microsoft\Windows\USB\ | Ready | Review | |
| WiFiTask | \Microsoft\Windows\WCM\ | Ready | %SystemRoot%\System32\WiFiTask.exe | Review |
| ResolutionHost | \Microsoft\Windows\WDI\ | Ready | Review | |
| Windows Defender Cache Maintenance | \Microsoft\Windows\Windows Defender\ | Ready | %ProgramFiles%\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdCacheMaintenance | Review |
| Windows Defender Cleanup | \Microsoft\Windows\Windows Defender\ | Ready | %ProgramFiles%\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdCleanup | Review |
| Windows Defender Scheduled Scan | \Microsoft\Windows\Windows Defender\ | Ready | %ProgramFiles%\Windows Defender\MpCmdRun.exe Scan -ScheduleJob | Review |
| Windows Defender Verification | \Microsoft\Windows\Windows Defender\ | Ready | %ProgramFiles%\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdVerification | Review |
| QueueReporting | \Microsoft\Windows\Windows Error Reporting\ | Ready | %windir%\system32\wermgr.exe -upload | Review |
| BfeOnServiceStartTypeChange | \Microsoft\Windows\Windows Filtering Platform\ | Ready | %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange | Review |
| UpdateLibrary | \Microsoft\Windows\Windows Media Sharing\ | Ready | "%ProgramFiles%\Windows Media Player\wmpnscfg.exe" | Review |
| Calibration Loader | \Microsoft\Windows\WindowsColorSystem\ | Ready | Review | |
| Scheduled Start | \Microsoft\Windows\WindowsUpdate\ | Ready | %systemroot%\System32\sc.exe start wuauserv | Review |
| CacheTask | \Microsoft\Windows\Wininet\ | Running | Review | |
| CDSSync | \Microsoft\Windows\WlanSvc\ | Ready | Review | |
| MoProfileManagement | \Microsoft\Windows\WlanSvc\ | Ready | Review | |
| Work Folders Logon Synchronization | \Microsoft\Windows\Work Folders\ | Ready | Review | |
| Work Folders Maintenance Work | \Microsoft\Windows\Work Folders\ | Ready | Review | |
| Device-Sync | \Microsoft\Windows\Workplace Join\ | Ready | Review | |
| NotificationTask | \Microsoft\Windows\WwanSvc\ | Ready | %SystemRoot%\System32\WiFiTask.exe wwan | Review |
| OobeDiscovery | \Microsoft\Windows\WwanSvc\ | Ready | Review | |
| XblGameSaveTask | \Microsoft\XblGameSave\ | Ready | %windir%\System32\XblGameSaveTask.exe standby | Review |
| Firefox Background Update S-1-12-1-REDACTED 308046B0AF4A39CB | \Mozilla\ | Ready | C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate | Review |
| SoftLandingCreativeManagementTask | \SoftLanding\S-1-12-1-REDACTED\ | Ready | Review |
| Name | Display name | State | Start mode | Path | Risk |
|---|---|---|---|---|---|
| hcpclientcore | HCP client core service | Running | Auto | "C:\Program Files\Ricoh\PMC Client\hcpclientcore.exe" run --service --config \\?\C:\ProgramData\hcpclientcore\hcpclientcore.conf | Review - ProgramData path |
| ZoomCptService | Zoom Sharing Service | Running | Auto | "C:\Program Files\Common Files\Zoom\Support\CptService.exe" -user_path "C:\Users\Default\AppData\Roaming\Zoom" | High - user-writable path |
| Path | Risk | Reason |
|---|---|---|
| C:\Users\user.redacted\AppData\Local\Microsoft\WindowsApps | High | User-writable-looking PATH directory |
| C:\Users\user.redacted\AppData\Local\Programs\Fiddler | High | User-writable-looking PATH directory |
| C:\Users\user.redacted\AppData\Local\Microsoft\WindowsApps | High | User-writable-looking PATH directory |
| USBSTOR Start | USB storage enabled | Removable storage deny all | Note |
|---|---|---|---|
| 3 | True | Not configured | USBSTOR Start=4 usually means USB mass storage disabled. |
| Proxy enabled | Proxy server |
|---|---|
| 0 |
| Name | Server | Tunnel type | Split tunneling | All-user |
|---|---|---|---|---|
| No data captured. | ||||
| Domain joined | Domain | LAPS policy |
|---|---|---|
| False | WORKGROUP | Configured/Policy present |
| Browser | Profile | Extension ID | Name | Version |
|---|---|---|---|---|
| Chrome | Default | blojlgglhfcmpigjbkllcgjmhincdjhb | Snow Web Application Metering | 1.0.8_0 |
| Chrome | Default | cdblaggcibgbankgilackljdpdhhcine | __MSG_appName__ | 6.1.14_0 |
| Chrome | Default | ghbmnnjooekpmoecnnnilnnbdlolhkhi | __MSG_extName__ | 1.104.1_0 |
| Chrome | Default | haofejeafnajjfidaekiaejelpompjkn | Scantide Observe | 3.1.10_0 |
| Chrome | Default | miinajhilmmkpdoaimnoncdiliaejpdk | Nexthink | 26.4.4_0 |
| Chrome | Default | nmmhkkegccagdldgiimedpiccmgmieda | __MSG_APP_NAME__ | 1.0.0.6_0 |
| Edge | Default | cgjgjfacjflmgphhhepmbhhbgjieaecn | Microsoft Edge Unminification Extension | 135.0.3176.0_0 |
| Edge | Default | fmammgdlmljodabkafnkpagekcigmabk | Snow Web Application Metering | 1.0.8_0 |
| Edge | Default | higleibocjmgcnbikjneplkibiopjnkp | Nexthink | 26.5.1_0 |
| Edge | Default | jmjflgjpcpepeafmmgdpfkogkghcpiha | Edge relevant text changes | 1.2.1_0 |
| Edge | Default | kfbdpdaobnofkbopebjglnaadopfikhh | Microsoft Edge DevTools Enhancements | 113.0.1765.0_0 |
| Edge | Profile 1 | jmjflgjpcpepeafmmgdpfkogkghcpiha | Edge relevant text changes | 1.2.1_0 |
| Edge | Profile 2 | jmjflgjpcpepeafmmgdpfkogkghcpiha | Edge relevant text changes | 1.2.1_0 |
| Firefox | idjefsxd.default-release | scantide-observe@example.com | Scantide Observe | 3.1.11 |
| Firefox | idjefsxd.default-release | cloudmetering@snowsoftware.com | Snow Web Application Metering | 1.2.5 |
| Firefox | idjefsxd.default-release | formautofill@mozilla.org | Form Autofill | 1.0.1 |
| Firefox | idjefsxd.default-release | pictureinpicture@mozilla.org | Picture-In-Picture | 1.0.0 |
| Firefox | idjefsxd.default-release | addons-search-detection@mozilla.com | Add-ons Search Detection | 3.0.0 |
| Firefox | idjefsxd.default-release | webcompat@mozilla.org | Web Compatibility Interventions | 151.6.0 |
| Firefox | idjefsxd.default-release | newtab@mozilla.org | New Tab | 151.4.0 |
| Firefox | idjefsxd.default-release | ipp-activator@mozilla.com | IPP Activator | 0.1 |
| Firefox | idjefsxd.default-release | data-leak-blocker@mozilla.com | Data Leak Blocker | 144.0.0 |
| Firefox | idjefsxd.default-release | default-theme@mozilla.org | System theme — auto | 1.4.2 |
| Firefox | idjefsxd.default-release | addons-search-detection@mozilla.com | Add-ons Search Detection | 3.0.0 |
| Firefox | idjefsxd.default-release | firefox-compact-light@mozilla.org | Light | 1.3.4 |
| Firefox | idjefsxd.default-release | firefox-compact-dark@mozilla.org | Dark | 1.3.4 |
| Firefox | idjefsxd.default-release | firefox-alpenglow@mozilla.org | Firefox Alpenglow | 1.5.2 |
| Firefox | idjefsxd.default-release | newtab@mozilla.org | New Tab | 153.1.20260528.133333 |
| Product | Version | Installed display name | CVE Review | Highest severity | Highest score | Top CVEs | Status |
|---|---|---|---|---|---|---|---|
| GlobalProtect | 6.2.8 | GlobalProtect | Possible Critical CVE signal (10) | CRITICAL | 9.8 | CVE-2016-3657, CVE-2017-7945, CVE-2017-9458, CVE-2016-3656, CVE-2017-7409 | OK |
| 7-Zip | 26.01.00.0 | 7-Zip 26.01 (x64 edition) | Possible Critical CVE signal (5) | CRITICAL | 9.3 | CVE-2008-3075, CVE-2016-3646, CVE-2002-0370, CVE-2009-1782, CVE-2004-2348 | OK |
| 7-Zip | 24.08 | 7-Zip 24.08 (x64) | Possible Critical CVE signal (5) | CRITICAL | 9.3 | CVE-2008-3075, CVE-2016-3646, CVE-2002-0370, CVE-2009-1782, CVE-2004-2348 | OK |
| Intel(R) Wireless Bluetooth(R) | 23.30.0.3 | Intel(R) Wireless Bluetooth(R) | Possible High CVE signal (5) | HIGH | 7.8 | CVE-2020-0555, CVE-2019-14620, CVE-2024-24984, CVE-2023-47859, CVE-2023-45845 | OK |
| Notepad++ | 8.9.6.4 | Notepad++ (64-bit x64) | Possible High CVE signal (4) | HIGH | 8.4 | CVE-2025-56383, CVE-2026-25866, CVE-2025-49144, CVE-2007-5145 | OK |
| OpenSSL | 3.4.1 | OpenSSL 3.4.1 Light (64-bit) | Possible High CVE signal (4) | HIGH | 7.5 | CVE-2004-0079, CVE-2003-0851, CVE-2004-0081, CVE-2004-0112 | OK |
| Dell Display and Peripheral Manager | 2.1.0.24 | Dell Display and Peripheral Manager | Possible High CVE signal (2) | HIGH | 7.3 | CVE-2025-46430, CVE-2026-21419 | OK |
| Microsoft Edge | 149.0.4022.62 | Microsoft Edge | Possible Medium CVE signal (2) | MEDIUM | 5 | CVE-2015-6057, CVE-2015-6058 | OK |
| Mozilla Firefox | 151.0.4 | Mozilla Firefox (x64 en-US) | Possible Critical CVE signal (2) | CRITICAL | 10 | CVE-2004-0904, CVE-2004-0905 | OK |
| AD Info Free Edition | 1.7.92 | AD Info Free Edition | Possible Medium CVE signal (1) | MEDIUM | 6.8 | CVE-2021-20876 | OK |
| Fiddler | 4.4.9.2 | Fiddler | Possible High CVE signal (1) | HIGH | 8.8 | CVE-2020-13661 | OK |
| Intel(R) LMS | 1.0.0.0 | Intel(R) LMS | Possible Medium CVE signal (1) | MEDIUM | 6.4 | CVE-2020-8704 | OK |
| Intel(R) Management Engine Driver | 1.0.0.0 | Intel(R) Management Engine Driver | Possible Medium CVE signal (1) | MEDIUM | 5.5 | CVE-2021-33087 | OK |
| ISS_Drivers_x64 | 3.10.100.4446 | ISS_Drivers_x64 | Possible High CVE signal (1) | HIGH | 7.1 | CVE-2024-50035 | OK |
| Microsoft Intune Management Extension | 1.101.111.0 | Microsoft Intune Management Extension | Possible High CVE signal (1) | HIGH | 8.1 | CVE-2021-31980 | OK |
| Name | Version | Publisher | Install Date | CVE Review |
|---|---|---|---|---|
| „Microsoft 365“ programos įmonėms - lt-lt.proof | 16.0.20026.20168 | Microsoft Corporation | Not matched | |
| 7-Zip 24.08 (x64) | 24.08 | Igor Pavlov | Possible Critical CVE signal (5) | |
| 7-Zip 26.01 (x64 edition) | 26.01.00.0 | Igor Pavlov | 20260428 | Possible Critical CVE signal (5) |
| AD Info Free Edition | 1.7.92 | Cjwdev | 20220414 | Possible Medium CVE signal (1) |
| Angry IP Scanner | 3.8.2 | Angry IP Scanner | Not matched | |
| Aplicaciones de Microsoft 365 para empresas - es-es.proof | 16.0.20026.20168 | Microsoft Corporation | Not matched | |
| Aplicații Microsoft 365 pentru întreprindere - ro-ro.proof | 16.0.20026.20168 | Microsoft Corporation | Not matched | |
| Aplikacje Microsoft 365 dla przedsiębiorstw - pl-pl.proof | 16.0.20026.20168 | Microsoft Corporation | Not matched | |
| Citrix XenCenter | 7.0.1 | Citrix Systems, Inc. | 20231006 | Not matched |
| CPU Speed Pro version 3 | 3 | CPU Speed Pro | 20240416 | Not matched |
| CrowdStrike Device Control | 7.35.20865.0 | CrowdStrike, Inc. | 20260609 | Not matched |
| CrowdStrike Firmware Analysis | 7.14.18456.0 | CrowdStrike, Inc. | 20241003 | Not matched |
| CrowdStrike Sensor Platform | 7.36.20805.0 | CrowdStrike, Inc. | 20260609 | Not matched |
| CrowdStrike Windows Sensor | 7.36.20805.0 | CrowdStrike, Inc. | 20260609 | Not matched |
| Dell Active Pen Service | 7.7.1.117 | Wacom Technology Corp. | Not matched | |
| Dell Command | Update for Windows Universal | 5.7.0 | Dell Inc. | 20260415 | Not matched |
| Dell ControlVault Host Components Installer 64 bit | 5.15.14.19 | Broadcom Limited | 20250916 | Not matched |
| Dell Core Services | 1.14.149.0 | Dell, Inc. | 20260415 | Not matched |
| Dell Display and Peripheral Manager | 2.1.0.24 | Dell Technologies | 20260122 | Possible High CVE signal (2) |
| Dell Peripheral Core | 2.1.0.356 | Dell Inc. | Not matched | |
| Dell SupportAssist | 5.1.1.3567 | Dell Inc. | 20260609 | Not matched |
| Dell SupportAssist OS Recovery Plugin for Dell Update | 5.5.16.1 | Dell Inc. | 20260519 | Not matched |
| Digi Device Discovery | Not matched | |||
| Documentation Manager | 23.30.0.6 | Intel Corporation | 20240325 | Not matched |
| Dynamic Application Loader Host Interface Service | 1.0.0.0 | Intel Corporation | 20250820 | Not matched |
| eM Client | 10.0.3530.0 | eM Client Inc. | 20241008 | Not matched |
| Fiddler | 4.4.9.2 | Telerik | Possible High CVE signal (1) | |
| GlobalProtect | 6.2.8 | Palo Alto Networks | 20250806 | Possible Critical CVE signal (10) |
| Google Chrome | 149.0.7827.103 | Google LLC | 20260610 | Not matched |
| Intel Driver && Support Assistant | 26.1.0.2 | Intel | 20260401 | Not matched |
| Intel(R) Computing Improvement Program | 2.4.10965 | Intel Corporation | 20250214 | Not matched |
| Intel(R) Graphics Software & Drivers | 1.0.1168.2 | Intel(R) Corporation | Not matched | |
| Intel(R) LMS | 1.0.0.0 | Intel Corporation | 20250820 | Possible Medium CVE signal (1) |
| Intel(R) Management Engine Components | 1.0.0.0 | Intel Corporation | 20250820 | Not matched |
| Intel(R) Management Engine Components | 2514.7.16.0 | Intel Corporation | Not matched | |
| Intel(R) Management Engine Driver | 1.0.0.0 | Intel Corporation | 20250820 | Possible Medium CVE signal (1) |
| Intel(R) ME WMI Provider | 1.0.0.0 | Intel Corporation | 20250820 | Not matched |
| Intel(R) SOL LMS Extension | 1.0.0.0 | Intel Corporation | 20250820 | Not matched |
| Intel(R) Wireless Bluetooth(R) | 23.30.0.3 | Intel Corporation | 20240325 | Possible High CVE signal (5) |
| Intel(R) Wireless Manageability Driver | 1.0.0.0 | Intel Corporation | 20250820 | Not matched |
| Intel(R) Wireless Manageability Driver Extension | 1.0.0.0 | Intel Corporation | 20250820 | Not matched |
| Intel® Driver & Support Assistant | 26.1.0.2 | Intel | 20260401 | Not matched |
| Intel® Integrated Sensor Solution | 3.10.100.4446 | Intel Corporation | Not matched | |
| Intel® Software Installer | 23.30.0.6 | Intel Corporation | Not matched | |
| ISS_Drivers_x64 | 3.10.100.4446 | Intel Corporation | 20220427 | Possible High CVE signal (1) |
| Kurumlar için Microsoft 365 Uygulamaları - tr-tr.proof | 16.0.20026.20168 | Microsoft Corporation | Not matched | |
| Microsoft .NET Host - 8.0.27 (x86) | 64.108.52182 | Microsoft Corporation | 20260518 | Not matched |
| Microsoft .NET Host - 8.0.28 (x64) | 64.112.53549 | Microsoft Corporation | 20260611 | Not matched |
| Microsoft .NET Host - 9.0.16 (x64) | 72.64.52183 | Microsoft Corporation | 20260518 | Not matched |
| Microsoft .NET Host FX Resolver - 8.0.27 (x86) | 64.108.52182 | Microsoft Corporation | 20260518 | Not matched |
| Microsoft .NET Host FX Resolver - 8.0.28 (x64) | 64.112.53549 | Microsoft Corporation | 20260611 | Not matched |
| Microsoft .NET Host FX Resolver - 9.0.16 (x64) | 72.64.52183 | Microsoft Corporation | 20260518 | Not matched |
| Microsoft .NET Runtime - 8.0.27 (x86) | 64.108.52182 | Microsoft Corporation | 20260518 | Not matched |
| Microsoft .NET Runtime - 8.0.28 (x64) | 64.112.53549 | Microsoft Corporation | 20260611 | Not matched |
| Microsoft .NET Runtime - 9.0.16 (x64) | 72.64.52183 | Microsoft Corporation | 20260518 | Not matched |
| Microsoft 365 Apps for enterprise - da-dk.proof | 16.0.20026.20168 | Microsoft Corporation | Not matched | |
| Microsoft 365 Apps for Enterprise - de-de.proof | 16.0.20026.20168 | Microsoft Corporation | Not matched | |
| Microsoft 365 Apps for enterprise - en-us | 16.0.20026.20168 | Microsoft Corporation | Not matched | |
| Microsoft 365 Apps for enterprise - en-us.proof | 16.0.20026.20168 | Microsoft Corporation | Not matched | |
| Microsoft 365 Apps for enterprise - fr-fr.proof | 16.0.20026.20168 | Microsoft Corporation | Not matched | |
| Microsoft 365 Apps for enterprise - it-it.proof | 16.0.20026.20168 | Microsoft Corporation | Not matched | |
| Microsoft 365 Apps for enterprise - ja-jp.proof | 16.0.20026.20168 | Microsoft Corporation | Not matched | |
| Microsoft 365 Apps for enterprise - nb-no.proof | 16.0.20026.20168 | Microsoft Corporation | Not matched | |
| Microsoft 365 Apps para Grandes Empresas - pt-pt.proof | 16.0.20026.20168 | Microsoft Corporation | Not matched | |
| Microsoft 365 Apps pro velké organizace - cs-cz.proof | 16.0.20026.20168 | Microsoft Corporation | Not matched | |
| Microsoft 365 programmas lieluzņēmumiem - lv-lv.proof | 16.0.20026.20168 | Microsoft Corporation | Not matched | |
| Microsoft 365 -sovellukset suuryrityksille - fi-fi.proof | 16.0.20026.20168 | Microsoft Corporation | Not matched | |
| Microsoft 365 suurettevõtterakendused - et-ee.proof | 16.0.20026.20168 | Microsoft Corporation | Not matched | |
| Microsoft 365 企业应用版 - zh-cn.proof | 16.0.20026.20168 | Microsoft Corporation | Not matched | |
| Microsoft 365-appar för företag - sv-se.proof | 16.0.20026.20168 | Microsoft Corporation | Not matched | |
| Microsoft 365-apps voor ondernemingen - nl-nl.proof | 16.0.20026.20168 | Microsoft Corporation | Not matched | |
| Microsoft ASP.NET Core 8.0.27 - Shared Framework (x86) | 8.0.27.26230 | Microsoft Corporation | Not matched | |
| Microsoft ASP.NET Core 8.0.27 Shared Framework (x86) | 8.0.27.26230 | Microsoft Corporation | 20260518 | Not matched |
| Microsoft Cloud Managed Desktop Extension | 1.2.02664.211 | Microsoft Corporation | 20240626 | Not matched |
| Microsoft Device Inventory Agent | 26.5.24.2000 | Microsoft Corporation | 20260609 | Not matched |
| Microsoft Edge | 149.0.4022.62 | Microsoft Corporation | 20260611 | Possible Medium CVE signal (2) |
| Microsoft Edge WebView2 Runtime | 149.0.4022.62 | Microsoft Corporation | 20260611 | Not matched |
| Microsoft Intune Management Extension | 1.101.111.0 | Microsoft Corporation | 20260522 | Possible High CVE signal (1) |
| Microsoft OneDrive | 26.088.0510.0004 | Microsoft Corporation | Not matched | |
| Microsoft Power BI Desktop (x64) | 2.102.845.0 | Microsoft Corporation | 20220303 | Not matched |
| Microsoft PowerBI Desktop (x64) | 2.102.845.0 | Microsoft Corporation | Not matched | |
| Microsoft Purview Information Protection | 3.2.57.0 | Microsoft Corporation | 20260327 | Not matched |
| Microsoft Teams Meeting Add-in for Microsoft Office | 1.26.08901 | Microsoft | 20260506 | Not matched |
| Microsoft Update Health Tools | 5.72.0.0 | Microsoft Corporation | 20231106 | Not matched |
| Microsoft Visual C++ 2022 X64 Additional Runtime - 14.51.36247 | 14.51.36247 | Microsoft Corporation | 20260611 | Not matched |
| Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.51.36247 | 14.51.36247 | Microsoft Corporation | 20260611 | Not matched |
| Microsoft Visual C++ 2022 X86 Additional Runtime - 14.51.36247 | 14.51.36247 | Microsoft Corporation | 20260611 | Not matched |
| Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.51.36247 | 14.51.36247 | Microsoft Corporation | 20260611 | Not matched |
| Microsoft Visual C++ v14 Redistributable (x64) - 14.51.36247 | 14.51.36247.0 | Microsoft Corporation | Not matched | |
| Microsoft Visual C++ v14 Redistributable (x86) - 14.51.36247 | 14.51.36247.0 | Microsoft Corporation | Not matched | |
| Microsoft Windows Desktop Runtime - 8.0.27 (x86) | 64.108.52193 | Microsoft Corporation | 20260518 | Not matched |
| Microsoft Windows Desktop Runtime - 8.0.27 (x86) | 8.0.27.36030 | Microsoft Corporation | Not matched | |
| Microsoft Windows Desktop Runtime - 8.0.28 (x64) | 64.112.53617 | Microsoft Corporation | 20260611 | Not matched |
| Microsoft Windows Desktop Runtime - 8.0.28 (x64) | 8.0.28.36119 | Microsoft Corporation | Not matched | |
| Microsoft Windows Desktop Runtime - 9.0.16 (x64) | 72.64.52194 | Microsoft Corporation | 20260518 | Not matched |
| Microsoft Windows Desktop Runtime - 9.0.16 (x64) | 9.0.16.36030 | Microsoft Corporation | Not matched | |
| Mozilla Firefox (x64 en-US) | 151.0.4 | Mozilla | Possible Critical CVE signal (2) | |
| Mozilla Maintenance Service | 151.0.4 | Mozilla | Not matched | |
| Mozilla Thunderbird ESR (x64 en-US) | 140.11.1 | Mozilla | Not matched | |
| Nagyvállalati Microsoft 365-alkalmazások - hu-hu.proof | 16.0.20026.20168 | Microsoft Corporation | Not matched | |
| Nexthink Finder | 6.30.14.1 | Nexthink S.A. | 20230320 | Not matched |
| Notepad++ (64-bit x64) | 8.9.6.4 | Notepad++ Team | Possible High CVE signal (4) | |
| Novabench | 5.5.1 | Novabench Inc. | 20240325 | Not matched |
| Npcap | 1.79 | Nmap Project | Not matched | |
| NTP Query Tool | Not matched | |||
| NTP Scan | Not matched | |||
| Office 16 Click-to-Run Extensibility Component | 16.0.20026.20076 | Microsoft Corporation | 20260520 | Not matched |
| OpenSSL 3.4.1 Light (64-bit) | 3.4.1 | OpenSSL Win64 Installer Team | 20250311 | Possible High CVE signal (4) |
| PerformanceTest v11.0 | 11.0.1014.0 | Passmark Software | 20240416 | Not matched |
| PhotoPad Image Editor | 11.67 | NCH Software | Not matched | |
| PMC Client | 3.31.0 | Ricoh | Not matched | |
| PowerShell 7.4.7.0-x64 | 7.4.7.0 | Microsoft Corporation | Not matched | |
| PowerShell 7-x64 | 7.6.2.0 | Microsoft Corporation | 20260525 | Not matched |
| PuTTY release 0.81 (64-bit) | 0.81.0.0 | Simon Tatham | 20240614 | Not matched |
| Qualys Cloud Security Agent | 6.4.1.22 | Qualys, Inc. | 20260409 | Not matched |
| Realtek Audio Driver | 10.X.X.REDACTED | Realtek Semiconductor Corp. | 20250304 | Not matched |
| Realtek Card Reader | 10.0.26100.21374 | Realtek Semiconductor Corp. | 20250121 | Not matched |
| Realtek USB Ethernet Controller All-In-One Windows Driver | 11.17.20.1030 | Realtek | 20250414 | Not matched |
| Remote help | 3.8.0.12 | Microsoft Corporation | 20220308 | Not matched |
| Scripting Tools for Windows PowerShell: iLO Cmdlets | 1.5.1.0 | Hewlett Packard Enterprise | 20241107 | Not matched |
| Scripting Tools for Windows PowerShell: iLO Cmdlets | 4.0.0.0 | Hewlett Packard Enterprise | 20241022 | Not matched |
| Snow Inventory Agent for Windows | 7.5.0 | Snow Software | 20260310 | Not matched |
| TeamViewer Host | 15.78.4 | TeamViewer | Not matched | |
| TreeSize Free V4.5.3 | 4.5.3 | JAM Software | 20220509 | Not matched |
| Uninstall UUByte DMG Editor | 1.5.8 | UUByte | 20220629 | Not matched |
| USBPcap 1.5.4.0 | 1.5.4.0 | Tomasz Mon | Not matched | |
| Webex | 43.6.0.26407 | Cisco Systems, Inc | 20240126 | Not matched |
| Win32DiskImager version 1.0.0 | 1.0.0 | ImageWriter Developers | 20220629 | Not matched |
| Windows Subsystem for Linux | 2.4.12.0 | Microsoft Corporation | 20250320 | Not matched |
| Windows Subsystem for Linux Update | 5.10.102.1 | Microsoft Corporation | 20220428 | Not matched |
| Windows Subsystem for Linux WSLg Preview | 1.0.27 | Microsoft Corporation | 20230320 | Not matched |
| Wireshark 4.6.6 x64 | 4.6.6 | The Wireshark developer community, https://www.wireshark.org | Not matched | |
| Zoom Workplace (64-bit) | 7.0.38856 | Zoom | 20260519 | Not matched |
| Приложения Microsoft 365 для предприятий - ru-ru.proof | 16.0.20026.20168 | Microsoft Corporation | Not matched | |
| Програми Microsoft 365 для підприємств - uk-ua.proof | 16.0.20026.20168 | Microsoft Corporation | Not matched | |
| 엔터프라이즈용 Microsoft 365 앱 - ko-kr.proof | 16.0.20026.20168 | Microsoft Corporation | Not matched |
| Source | Name | Command |
|---|---|---|
| HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | SecurityHealth | C:\WINDOWS\system32\SecurityHealthSystray.exe |
| HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | RtkAudUService | "C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_babf1584c40a3d53\RtkAudUService64.exe" -background |
| HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | WavesSvc | "C:\WINDOWS\System32\DriverStore\FileRepository\wavesapo10de.inf_amd64_db3f3288eba6a142\WavesSvc64.exe" -Jack |
| HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | PMC Client | C:\Program Files\Ricoh\PMC Client\hcpclient.exe |
| HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | GlobalProtect | "C:\Program Files\Palo Alto Networks\GlobalProtect\PanGPA.exe" |
| HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | OneDrive | "C:\Program Files\Microsoft OneDrive\OneDrive.exe" /background |
| HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | CiscoMeetingDaemon | "C:\Users\user.redacted\AppData\Local\WebEx\WebexHost.exe" /daemon /runFrom=autorun |
| HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | Microsoft.Lists | C:\Program Files\Microsoft OneDrive\26.088.0510.0004\OneDrive.Sync.Service.exe |
| HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | com.squirrel.Postman-Agent.PostmanAgent | C:\Users\user.redacted\AppData\Local\Postman-Agent\Postman Agent.exe |
| HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | CiscoSpark | C:\Users\user.redacted\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Webex\Webex.lnk /minimized /autostartedWithWindows=true |
| HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | BlueMail | C:\WINDOWS\explorer.exe me.blueone.win:noopt:hidden |
| HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | Teams | "C:\Users\user.redacted\AppData\Local\Microsoft\WindowsApps\MSTeams_8wekyb3d8bbwe\ms-teams.exe" msteams:system-initiated |
| HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | MicrosoftEdgeAutoLaunch_996CAB29764A7E71C494B428A956D1DD | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start |