Scantide Local PC Security Check

Computer: EXAMPLE-PC-001 | User: EXAMPLE\analyst | Generated: 2026-06-16 12:14:59 | v3.5.175
Local Risk Score
100
Findings
79
Installed Software
138
Software CVE Matches
19
Listening Ports
35
Shares
3
Shared Printers
1
Pending Reboot
Yes
Admin Context
Limited
Completeness of local checks
Check Level
Advanced
Preset plus selected modules
Total Runtime
52.6 s
43 ran, 0 skipped, 0 failed
External IP
Skipped
Blacklist: Skipped
Endpoint Posture
144
Remote/firewall/PATH review items
Certificates
111
Expired/soon expiring
Click a summary card, tab, or quick filter.
Anonymized example report:Hostnames, usernames, organization names, serial numbers, local paths, IP addresses, Wi-Fi profile names and device instance identifiers have been replaced for publication. Findings, layout, CVE examples and Scantide report behavior are preserved as representative sample data.

Important Disclaimer

Read this first: Important disclaimer: Scantide Local Check and Scantide Local Watch are assessment and awareness tools. They are not an EDR, antivirus, patch manager, compliance certification, or proof of compromise. Installed-software CVE matches are review leads based on local inventory display names and versions; verify the exact product, edition, build and exposure before treating a match as confirmed. Public IP blacklist checks are indicators only and can be affected by NAT, VPNs, proxies, shared ISP addresses and stale DNSBL data. Missing or unknown data means not checked or not available, not clean.

Executive Findings

Scan scope: Limited local check - not running as Administrator
The script is not running elevated. The report is still useful, but several checks may be incomplete, unavailable, or shown as Unknown. Do not treat missing data as clean.
Checks that may be incomplete: Firewall policy details; Defender/AV internals; SMB server/client configuration; BitLocker; local users/admins; some shares/printers; some listening-process ownership; protected registry policy keys
Local endpoint posture check. Installed software CVE matching is queried against both Scantide CVE API and NOTCVE and should be treated as a review item unless exact product/version matching is confirmed. CVE status: Combined CVE results loaded from local cache for all 100 product/version pair(s). Cache freshness: <= 30 minutes. Matches with CVEs: 19. False-positive suppressions applied: 1.
SeverityAreaFinding / EvidenceRecommendation
HighServicesService runs from user-writable path: ZoomCptService
"C:\Program Files\Common Files\Zoom\Support\CptService.exe" -user_path "C:\Users\example.user\AppData\Roaming\Zoom"
Move service binaries to protected paths and verify permissions.
HighUsersPassword not required: ExampleBuiltInAccount
PasswordRequired=False
Require local account passwords.
HighUsersPassword not required: ExampleExampleGuestAccount
PasswordRequired=False
Require local account passwords.
InfoAntivirusMicrosoft Defender appears disabled/passive because another AV/EDR is registered
Registered AV/EDR: Example EDR Sensor
Verify the third-party AV/EDR is managed and healthy.
InfoBitLockerBitLocker was not fully checked
Admin required; Run elevated to query BitLocker
Run elevated to check BitLocker protection state.
InfoDevice ControlUSB storage appears enabled
USBSTOR Start=3
Confirm removable media policy matches the organization policy.
InfoEvent LogsRecent Application error: C:\ProgramData\Azure\AzCopy\azcopy.exe / 0
Review if the error repeats, affects security controls, or maps to failed services, drivers, updates or authentication.
InfoEvent LogsRecent Application error: HCP Port Monitor / 0
Review if the error repeats, affects security controls, or maps to failed services, drivers, updates or authentication.
InfoEvent LogsRecent Application error: HCP Port Monitor / 0
Review if the error repeats, affects security controls, or maps to failed services, drivers, updates or authentication.
InfoEvent LogsRecent Application error: VSS / 13
Volume Shadow Copy Service information: The COM Server with CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} and name Coordinator cannot be started. [0x80070005, Access is denied. ]
Review if the error repeats, affects security controls, or maps to failed services, drivers, updates or authentication.
InfoGhost DevicesNon-present device: Generic volume shadow copy
Class=VolumeSnapshot; InstanceId=REDACTED-DEVICE-ID
Review if stale devices are unexpected, especially old NICs, storage, VPN, security or remote access devices.
InfoGhost DevicesNon-present device: HID-compliant consumer control device
Class=HIDClass; InstanceId=REDACTED-DEVICE-ID;PID_030B&MI_03&COL03\8&35AECF77&0&0002
Review if stale devices are unexpected, especially old NICs, storage, VPN, security or remote access devices.
InfoGhost DevicesNon-present device: Integrated Monitor
Class=Monitor; InstanceId=REDACTED-DEVICE-ID;997B8A0&2&UID8388688
Review if stale devices are unexpected, especially old NICs, storage, VPN, security or remote access devices.
InfoGhost DevicesNon-present device: Example Bluetooth Headset
Class=MEDIA; InstanceId=REDACTED-DEVICE-ID;PID_030B&MI_00\7&30FD822B&0&0000
Review if stale devices are unexpected, especially old NICs, storage, VPN, security or remote access devices.
InfoGhost DevicesNon-present device: MIDI 2.0 Service Tests
Class=SoftwareDevice; InstanceId=REDACTED-DEVICE-ID
Review if stale devices are unexpected, especially old NICs, storage, VPN, security or remote access devices.
InfoGhost DevicesNon-present device: PS/2 Compatible Mouse
Class=Mouse; InstanceId=REDACTED-DEVICE-ID;77AFA20&0
Review if stale devices are unexpected, especially old NICs, storage, VPN, security or remote access devices.
InfoGhost DevicesNon-present device: Service Test Loopback A
Class=SoftwareDevice; InstanceId=REDACTED-DEVICE-ID
Review if stale devices are unexpected, especially old NICs, storage, VPN, security or remote access devices.
InfoGhost DevicesNon-present device: Service Test Loopback B
Class=SoftwareDevice; InstanceId=REDACTED-DEVICE-ID
Review if stale devices are unexpected, especially old NICs, storage, VPN, security or remote access devices.
InfoGhost DevicesNon-present device: USB Composite Device
Class=USB; InstanceId=REDACTED-DEVICE-ID;PID_030B\50C2ED067EBE
Review if stale devices are unexpected, especially old NICs, storage, VPN, security or remote access devices.
InfoGhost DevicesNon-present device: USB Input Device
Class=HIDClass; InstanceId=REDACTED-DEVICE-ID;PID_0311\50C2ED067EBE
Review if stale devices are unexpected, especially old NICs, storage, VPN, security or remote access devices.
InfoInstalled Software CVE ReviewReview signal: AD Info Free Edition 1.7.92
1 CVE(s); highest=MEDIUM 6.8; top=CVE-2021-20876. Local installed-software matching is weaker evidence than service/banner matching.
Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability.
InfoInstalled Software CVE ReviewReview signal: Intel(R) LMS 1.0.0.0
1 CVE(s); highest=MEDIUM 6.4; top=CVE-2020-8704. Local installed-software matching is weaker evidence than service/banner matching.
Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability.
InfoInstalled Software CVE ReviewReview signal: Intel(R) Management Engine Driver 1.0.0.0
1 CVE(s); highest=MEDIUM 5.5; top=CVE-2021-33087. Local installed-software matching is weaker evidence than service/banner matching.
Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability.
InfoUSB StorageUSB mass storage appears enabled
USBSTOR Start=3
Confirm removable media policy matches the organization policy.
LowCertificatesExpired certificate: CN=AddTrust External CA Root, OU=AddTrust External TTP Network, O=AddTrust AB, C=SE
Store=Cert:\LocalMachine\Root; NotAfter=05/30/2020 12:48:38
Remove expired/unneeded certificates or renew if still used.
LowCertificatesExpired certificate: CN=AddTrust External CA Root, OU=AddTrust External TTP Network, O=AddTrust AB, C=SE
Store=Cert:\CurrentUser\Root; NotAfter=05/30/2020 12:48:38
Remove expired/unneeded certificates or renew if still used.
LowCertificatesExpired certificate: CN=Microsoft Authenticode(tm) Root Authority, O=MSFT, C=US
Store=Cert:\LocalMachine\Root; NotAfter=01/01/2000 00:59:59
Remove expired/unneeded certificates or renew if still used.
LowCertificatesExpired certificate: CN=Microsoft Authenticode(tm) Root Authority, O=MSFT, C=US
Store=Cert:\CurrentUser\Root; NotAfter=01/01/2000 00:59:59
Remove expired/unneeded certificates or renew if still used.
LowCertificatesExpired certificate: CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US
Store=Cert:\CurrentUser\Root; NotAfter=07/09/2019 20:40:36
Remove expired/unneeded certificates or renew if still used.
LowCertificatesExpired certificate: CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US
Store=Cert:\LocalMachine\Root; NotAfter=07/09/2019 20:40:36
Remove expired/unneeded certificates or renew if still used.
LowCertificatesExpired certificate: OU="NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.", OU=VeriSign Time Stamping Service Root, OU="VeriSign, Inc.", O=VeriSign Trust Network
Store=Cert:\CurrentUser\Root; NotAfter=01/08/2004 00:59:59
Remove expired/unneeded certificates or renew if still used.
LowCertificatesExpired certificate: OU="NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.", OU=VeriSign Time Stamping Service Root, OU="VeriSign, Inc.", O=VeriSign Trust Network
Store=Cert:\LocalMachine\Root; NotAfter=01/08/2004 00:59:59
Remove expired/unneeded certificates or renew if still used.
LowCertificatesExpired certificate: OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Time Stamping Service Root, OU=Microsoft Corporation, O=Microsoft Trust Network
Store=Cert:\LocalMachine\Root; NotAfter=12/31/1999 00:59:59
Remove expired/unneeded certificates or renew if still used.
LowCertificatesExpired certificate: OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Time Stamping Service Root, OU=Microsoft Corporation, O=Microsoft Trust Network
Store=Cert:\CurrentUser\Root; NotAfter=12/31/1999 00:59:59
Remove expired/unneeded certificates or renew if still used.
LowInstalled Software CVE ReviewReview signal: Example Display and Peripheral Manager 2.1.0.24
2 CVE(s); highest=HIGH 7.3; top=CVE-2025-46430, CVE-2026-21419. Local installed-software matching is weaker evidence than service/banner matching.
Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability.
LowInstalled Software CVE ReviewReview signal: Fiddler 4.4.9.2
2 CVE(s); highest=HIGH 8.8; top=CVE-2019-12097, CVE-2020-13661. Local installed-software matching is weaker evidence than service/banner matching.
Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability.
LowInstalled Software CVE ReviewReview signal: GlobalProtect 6.3.3
2 CVE(s); highest=HIGH 8.1; top=CVE-2017-7409, CVE-2019-1579. Local installed-software matching is weaker evidence than service/banner matching.
Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability.
LowInstalled Software CVE ReviewReview signal: Intel(R) Wireless Bluetooth(R) 23.30.0.3
5 CVE(s); highest=HIGH 7.8; top=CVE-2019-14620, CVE-2020-0555, CVE-2023-45845, CVE-2023-47859, CVE-2024-24984. Local installed-software matching is weaker evidence than service/banner matching.
Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability.
LowInstalled Software CVE ReviewReview signal: ISS_Drivers_x64 3.10.100.4446
1 CVE(s); highest=HIGH 7.1; top=CVE-2024-50035. Local installed-software matching is weaker evidence than service/banner matching.
Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability.
LowInstalled Software CVE ReviewReview signal: Microsoft Intune Management Extension 1.101.111.0
1 CVE(s); highest=HIGH 8.1; top=CVE-2021-31980. Local installed-software matching is weaker evidence than service/banner matching.
Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability.
LowInstalled Software CVE ReviewReview signal: Notepad++ 8.9.6.4
4 CVE(s); highest=HIGH 8.4; top=CVE-2007-5145, CVE-2025-49144, CVE-2025-56383, CVE-2026-25866. Local installed-software matching is weaker evidence than service/banner matching.
Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability.
LowListening PortsListening RPC Endpoint Mapper / 135
Address=0.0.0.0; Process=svchost; Context=Common local listening service. Confirm it is expected and firewall-scoped.
Confirm the service is expected, patched, and restricted by host firewall or network policy.
LowListening PortsListening RPC Endpoint Mapper / 135
Address=::; Process=svchost; Context=Common local listening service. Confirm it is expected and firewall-scoped.
Confirm the service is expected, patched, and restricted by host firewall or network policy.
LowPrintersShared printer:
Share=; Driver=
Confirm the printer share and driver are required.
LowRemote AccessRemote access indicator: Example Remote Support Tool
Installed software; Example Remote Tool
Confirm this remote access tool/service is expected and managed.
LowUpdatesPending reboot detected
Pending file rename
Reboot during maintenance.
LowWindows Security BaselineLSASS protection is not clearly enabled
RunAsPPL=2
Consider enabling LSA protection where compatible.
MediumFirewall RulesRisky inbound allow rule: @{Microsoft.LockApp_10.0.26100.8655_neutral__cw5n1h2txyewy?ms-resource://Microsoft.LockApp/resources/AppDisplayName}
Ports=; Remote=*; Profile=Domain,Private
Confirm the rule is required and scope it to trusted networks.
MediumFirewall RulesRisky inbound allow rule: @{MicrosoftWindows.Client.CBS_1000.26100.315.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.CBS/resources/ProductPkgDisplayName}
Ports=; Remote=*; Profile=Domain,Private,Public
Confirm the rule is required and scope it to trusted networks.
MediumFirewall RulesRisky inbound allow rule: @{MicrosoftWindows.Client.Core_1000.26100.94.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.Core/Resources/ProductPkgDisplayName}
Ports=; Remote=*; Profile=Domain,Private
Confirm the rule is required and scope it to trusted networks.
MediumFirewall RulesRisky inbound allow rule: @{MicrosoftWindows.Client.OOBE_1000.26100.45.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.OOBE/resources/ProductPkgDisplayName}
Ports=; Remote=*; Profile=Domain,Private,Public
Confirm the rule is required and scope it to trusted networks.
MediumFirewall RulesRisky inbound allow rule: Core Networking - Teredo (ICMPv6-In)
Ports=; Remote=*; Profile=Domain,Private,Public
Confirm the rule is required and scope it to trusted networks.
MediumFirewall RulesRisky inbound allow rule: Microsoft 365 Copilot
Ports=; Remote=*; Profile=Domain,Private,Public
Confirm the rule is required and scope it to trusted networks.
MediumFirewall RulesRisky inbound allow rule: Microsoft Edge WebView2 mDNS [UDP]
Ports=5353; Remote=LocalSubnet; Profile=Domain,Private,Public
Confirm the rule is required and scope it to trusted networks.
MediumFirewall RulesRisky inbound allow rule: Microsoft Store
Ports=; Remote=*; Profile=Domain,Private,Public
Confirm the rule is required and scope it to trusted networks.
MediumFirewall RulesRisky inbound allow rule: ms-resource:ProductPkgDisplayName
Ports=7000; Remote=*; Profile=Private
Confirm the rule is required and scope it to trusted networks.
MediumFirewall RulesRisky inbound allow rule: ms-resource:ProductPkgDisplayName
Ports=7000; Remote=*; Profile=Public
Confirm the rule is required and scope it to trusted networks.
MediumInstalled Software CVE ReviewReview signal: 7-Zip 26.01.00.0
5 CVE(s); highest=CRITICAL 9.3; top=CVE-2002-0370, CVE-2004-2348, CVE-2008-3075, CVE-2009-1782, CVE-2016-3646. Local installed-software matching is weaker evidence than service/banner matching.
Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability.
MediumInstalled Software CVE ReviewReview signal: AD Info 1.8.2
4 CVE(s); highest=CRITICAL 10; top=CVE-2000-1023, CVE-2001-1011, CVE-2001-1431, CVE-2001-1434. Local installed-software matching is weaker evidence than service/banner matching.
Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability.
MediumInstalled Software CVE ReviewReview signal: Google Chrome 149.0.7827.115
2 CVE(s); highest=CRITICAL 9.3; top=CVE-2008-5915, CVE-2009-1598. Local installed-software matching is weaker evidence than service/banner matching.
Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability.
MediumInstalled Software CVE ReviewReview signal: Microsoft OneDrive 26.095.0519.0003
5 CVE(s); highest=CRITICAL 9.1; top=CVE-2018-0592, CVE-2018-0593, CVE-2020-0654, CVE-2020-1465, CVE-2022-23255. Local installed-software matching is weaker evidence than service/banner matching.
Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability.
MediumInstalled Software CVE ReviewReview signal: Mozilla Firefox 151.0.4
2 CVE(s); highest=CRITICAL 10; top=CVE-2004-0904, CVE-2004-0905. Local installed-software matching is weaker evidence than service/banner matching.
Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability.
MediumInstalled Software CVE ReviewReview signal: OpenSSL 3.4.1
10 CVE(s); highest=CRITICAL 9.8; top=CVE-2003-0851, CVE-2004-0079, CVE-2004-0081, CVE-2004-0112, CVE-2025-15467, CVE-2025-15469, CVE-2026-2673, CVE-2026-28386. Local installed-software matching is weaker evidence than service/banner matching.
Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability.
MediumInstalled Software CVE ReviewReview signal: PowerShell 7.4.7.0
5 CVE(s); highest=CRITICAL 9.8; top=CVE-2017-8565, CVE-2018-7890, CVE-2023-48795, CVE-2025-49734, CVE-2026-26143. Local installed-software matching is weaker evidence than service/banner matching.
Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability.
MediumInstalled Software CVE ReviewReview signal: PowerShell 7.6.2.0
3 CVE(s); highest=CRITICAL 9.8; top=CVE-2017-8565, CVE-2018-7890, CVE-2023-48795. Local installed-software matching is weaker evidence than service/banner matching.
Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability.
MediumInstalled Software CVE ReviewReview signal: PuTTY 0.81.0.0
4 CVE(s); highest=CRITICAL 9.8; top=CVE-2013-4206, CVE-2013-4207, CVE-2013-4852, CVE-2017-17131. Local installed-software matching is weaker evidence than service/banner matching.
Verify exact product, edition, build and exposure before treating this as a confirmed vulnerability.
MediumListening PortsListening SMB / 445
Address=::; Process=System; Context=Common local listening service. Confirm it is expected and firewall-scoped.
Confirm the service is expected, patched, and restricted by host firewall or network policy.
MediumLock ScreenAutomatic lock / screensaver posture needs review
Screensaver is enabled but password on resume is not required.
Require automatic lock and password on resume. Recommended maximum timeout is 15 minutes or less.
MediumPATH HijackWritable PATH directory: C:\Users\example.user\AppData\Local\Microsoft\WindowsApps
User-writable-looking PATH directory
Remove writable directories from PATH or harden permissions.
MediumPATH HijackWritable PATH directory: C:\Users\example.user\AppData\Local\Microsoft\WindowsApps
User-writable-looking PATH directory
Remove writable directories from PATH or harden permissions.
MediumPATH HijackWritable PATH directory: C:\Users\example.user\AppData\Local\Programs\Fiddler
User-writable-looking PATH directory
Remove writable directories from PATH or harden permissions.
MediumScan ScopeLocal check was not run as Administrator
The script is not running elevated. The report is still useful, but several checks may be incomplete, unavailable, or shown as Unknown. Do not treat missing data as clean.
Re-run from an elevated PowerShell session for complete checks. Limited areas: Firewall policy details; Defender/AV internals; SMB server/client configuration; BitLocker; local users/admins; some shares/printers; some listening-process ownership; protected registry policy keys
MediumScheduled TasksTask runs from user-writable path: CleanupTemporaryState
%windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Review task action and remove if not required.
MediumWi-FiWeak Wi-Fi profile: Example Open Wi-Fi 1
Authentication=Open; Cipher=None
Remove old weak Wi-Fi profiles and prefer WPA2/WPA3.
MediumWi-FiWeak Wi-Fi profile: Example Open Wi-Fi 2
Authentication=Open; Cipher=None
Remove old weak Wi-Fi profiles and prefer WPA2/WPA3.
MediumWi-FiWeak Wi-Fi profile: Example Open Wi-Fi 3
Authentication=Open; Cipher=None
Remove old weak Wi-Fi profiles and prefer WPA2/WPA3.
MediumWi-FiWeak Wi-Fi profile: Example Open Wi-Fi 4
Authentication=Open; Cipher=None
Remove old weak Wi-Fi profiles and prefer WPA2/WPA3.
MediumWi-FiWeak Wi-Fi profile: Example Open Wi-Fi 5
Authentication=Open; Cipher=None
Remove old weak Wi-Fi profiles and prefer WPA2/WPA3.
MediumWi-FiWeak Wi-Fi profile: Example Open Wi-Fi 6
Authentication=Open; Cipher=None
Remove old weak Wi-Fi profiles and prefer WPA2/WPA3.

System Overview

P26-03-31 00:00:00P26-02-01 09:00:00P26-06-15 09:00:00
ComputerEXAMPLE-PC-001UserEXAMPLE\analyst
Domain / WorkgroupEXAMPLEPart of domainFalse
ManufacturerExample VendorModelExample Laptop Model
Serial numberEXAMPLE-SERIALSystem typex64-based PC
BIOS version1.46.0
BaseboardExample Vendor EXAMPLE-BOARDBaseboard serial/EXAMPLE-SERIAL/EXAMPLE-BOARD-SERIAL/
Operating systemMicrosoft Windows 11 EnterpriseOS version / build10.0.26200 / 26200
Architecture64-bit
Time zone(UTC+01:00) Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna
CPUExample CPU ModelCores / logical processors4 / 8
Total RAM15.7 GBMemory slots used8
Memory modules2.0 GB / 4267 MHz / EXAMPLE-MEMORY-MODULE | 2.0 GB / 4267 MHz / EXAMPLE-MEMORY-MODULE | 2.0 GB / 4267 MHz / EXAMPLE-MEMORY-MODULE | 2.0 GB / 4267 MHz / EXAMPLE-MEMORY-MODULE | 2.0 GB / 4267 MHz / EXAMPLE-MEMORY-MODULE | 2.0 GB / 4267 MHz / EXAMPLE-MEMORY-MODULE | 2.0 GB / 4267 MHz / EXAMPLE-MEMORY-MODULE | 2.0 GB / 4267 MHz / EXAMPLE-MEMORY-MODULE
Local disksC: 474.7 GB total, 245.2 GB free
AdminFalsePending rebootPending file rename

Scan Completeness / Privilege

Running as AdministratorFalseStatusLimited local check - not running as Administrator
ImpactThe script is not running elevated. The report is still useful, but several checks may be incomplete, unavailable, or shown as Unknown. Do not treat missing data as clean.
Checks that may be incompleteFirewall policy details; Defender/AV internals; SMB server/client configuration; BitLocker; local users/admins; some shares/printers; some listening-process ownership; protected registry policy keys

Check Modules and Runtime

Runtime explanation:This table shows which modules ran, which were skipped or failed, and where time was spent. Long runtimes are usually caused by SoftwareCve because it queries the Scantide CVE API and NOTCVE in parallel batches. Total scan runtime: 52.6 seconds.
CheckStatusSecondsNote
SystemInfoOK2.15
UpdatePolicyOK0.39
RemoteAccessToolsOK2.75
NetworkOK5.37
AntivirusOK0.96
BrowserPostureOK0.31
CredentialExposureOK0.49
RiskyFirewallRulesOK0.35
RecoveryPostureOK0.96
AuditLoggingOK0.31
DeviceControlOK0.26
UpdatesOK2.68
DeveloperAdminToolsOK3.82
UsbStorageOK0.36
RemoteManagementOK5.79
ScheduledTasksOK4.76
TimeSyncOK2.84
ExternalIpOK0.08
WritableServicesOK7.15
ProxyVpnOK4.25
UACOK0.51
UsersOK2.55
LockScreenOK1.13
PathHijackOK0.44
BrowserExtensionsOK0.86
SMBOK4.12
SharesOK3.99
SoftwareInventoryOK1.89
WindowsSecurityBaselineOK0.53
GhostDevicesOK5.72
CertificatesOK1.34
SoftwareCveOK4.51
LapsOK0.73
BitLockerOK0.06
ListeningPortsOK13.03
FirewallOK6.96
RDPOK0.39
PowerShellOK0.66
SecureBootTpmOK0.65
StartupOK0.3
EventLogErrorsOK0.56
PrintersOK1.71
WifiProfilesOK4.85

Network and External IP

Network explanation:This section shows local adapters, DNS servers, default routes and public IP reputation when enabled. Treat public IP blacklist data as an indicator only; VPNs, NAT and shared ISP addresses can affect it.

External IP / Reputation

External IPCountryRegionCityOrgSourceBlacklistedListed onNote
SkippedSkippedSkippedExternal IP/reputation check skipped by user setting.

Adapters

InterfaceDescriptionIPv4IPv6GatewayDNS servers
Wi-FiExample Wi-Fi Adapter192.168.10.10192.168.10.11192.168.10.12, 192.168.10.13
Ethernet 7Example USB Ethernet Adapter192.168.10.14fd00:10::53, fd00:10::53, fd00:10::53
Bluetooth Network ConnectionExample Bluetooth PAN Adapter192.168.10.15fd00:10::53, fd00:10::53, fd00:10::53

DNS Servers

InterfaceAddress familyDNS servers
Ethernet 72
Local Area Connection* 92
Local Area Connection* 102
Wi-Fi2192.168.10.12, 192.168.10.13
Bluetooth Network Connection2
Loopback Pseudo-Interface 12
Teredo Tunneling Pseudo-Interface2

Default Routes

InterfaceNext hopMetric
Wi-Fi192.168.10.110

Firewall

NameEnabledDefault InDefault Out
DomainTrueNotConfiguredNotConfigured
PrivateTrueNotConfiguredNotConfigured
PublicTrueNotConfiguredNotConfigured

Antivirus / EDR

NameSourceEnabledRealtimeSig AgeStateDetails
Example EDR Sensorroot\SecurityCenter2266240C:\Program Files\CrowdStrike\ExampleEDRController.exe
Microsoft DefenderGet-MpComputerStatusFalseFalse65535AMService=False; Behavior=False
Windows Defenderroot\SecurityCenter2393472windowsdefender://

SMB

SMB1 ServerSMB1 ClientRequire SigningSigning EnabledInsecure ExampleGuest
FalseUnknownTrueFalseFalse

RDP / BitLocker / UAC

CheckValue
RDP EnabledFalse/Unknown
NLA RequiredFalse/Unknown
UAC EnableLUA1

Listening TCP Ports

Listening port explanation:These are services accepting TCP connections. A listening port is not automatically bad, but it should be expected, patched and scoped by firewall policy. Localhost-only listeners are usually lower risk than 0.0.0.0 or :: listeners.
ProtocolAddressPortPIDProcessUsuallyCategoryRiskExplanationGuidance
::135svchostRPC Endpoint MapperFallbackLowCommon local listening service. Confirm it is expected and firewall-scoped.Confirm the service is expected, patched, and restricted by host firewall or network policy.
0.0.0.0135svchostRPC Endpoint MapperFallbackLowCommon local listening service. Confirm it is expected and firewall-scoped.Confirm the service is expected, patched, and restricted by host firewall or network policy.
::445SystemSMBFallbackMediumCommon local listening service. Confirm it is expected and firewall-scoped.Confirm the service is expected, patched, and restricted by host firewall or network policy.
::623LMSIntel AMT / IPMI RMCPFallbackInfoCommon local listening service. Confirm it is expected and firewall-scoped.Confirm the service is expected, patched, and restricted by host firewall or network policy.
0.0.0.0623LMSIntel AMT / IPMI RMCPFallbackInfoCommon local listening service. Confirm it is expected and firewall-scoped.Confirm the service is expected, patched, and restricted by host firewall or network policy.
127.0.0.14767PanGPSUnknown / customFallbackInfoNo curated helper metadata was available for this port. Confirm the owning process and whether it should listen.Confirm the service is expected, patched, and restricted by host firewall or network policy.
0.0.0.05040svchostUnknown / customFallbackInfoNo curated helper metadata was available for this port. Confirm the owning process and whether it should listen.Confirm the service is expected, patched, and restricted by host firewall or network policy.
::5357SystemWSDAPIFallbackInfoCommon local listening service. Confirm it is expected and firewall-scoped.Confirm the service is expected, patched, and restricted by host firewall or network policy.
127.0.0.15939Example Remote Tool_ServiceUnknown / customFallbackInfoNo curated helper metadata was available for this port. Confirm the owning process and whether it should listen.Confirm the service is expected, patched, and restricted by host firewall or network policy.
127.0.0.17311hcpclientcoreUnknown / customFallbackInfoNo curated helper metadata was available for this port. Confirm the owning process and whether it should listen.Confirm the service is expected, patched, and restricted by host firewall or network policy.
::7680svchostWindows Delivery OptimizationFallbackInfoCommon local listening service. Confirm it is expected and firewall-scoped.Confirm the service is expected, patched, and restricted by host firewall or network policy.
127.0.0.18883SystemUnknown / customFallbackInfoNo curated helper metadata was available for this port. Confirm the owning process and whether it should listen.Confirm the service is expected, patched, and restricted by host firewall or network policy.
127.0.0.18884SystemUnknown / customFallbackInfoNo curated helper metadata was available for this port. Confirm the owning process and whether it should listen.Confirm the service is expected, patched, and restricted by host firewall or network policy.
192.168.10.1010001agentid-serviceUnknown / customFallbackInfoNo curated helper metadata was available for this port. Confirm the owning process and whether it should listen.Confirm the service is expected, patched, and restricted by host firewall or network policy.
127.0.0.110001agentid-serviceUnknown / customFallbackInfoNo curated helper metadata was available for this port. Confirm the owning process and whether it should listen.Confirm the service is expected, patched, and restricted by host firewall or network policy.
::16992LMSIntel AMT / LMSFallbackInfoCommon local listening service. Confirm it is expected and firewall-scoped.Confirm the service is expected, patched, and restricted by host firewall or network policy.
0.0.0.016992LMSIntel AMT / LMSFallbackInfoCommon local listening service. Confirm it is expected and firewall-scoped.Confirm the service is expected, patched, and restricted by host firewall or network policy.
127.0.0.128385SystemUnknown / customFallbackInfoNo curated helper metadata was available for this port. Confirm the owning process and whether it should listen.Confirm the service is expected, patched, and restricted by host firewall or network policy.
127.0.0.128390SystemUnknown / customFallbackInfoNo curated helper metadata was available for this port. Confirm the owning process and whether it should listen.Confirm the service is expected, patched, and restricted by host firewall or network policy.
::142050OneDrive.Sync.ServiceUnknown / customFallbackInfoNo curated helper metadata was available for this port. Confirm the owning process and whether it should listen.Confirm the service is expected, patched, and restricted by host firewall or network policy.
127.0.0.149350esrv_svcUnknown / customFallbackInfoNo curated helper metadata was available for this port. Confirm the owning process and whether it should listen.Confirm the service is expected, patched, and restricted by host firewall or network policy.
127.0.0.149351esrvUnknown / customFallbackInfoNo curated helper metadata was available for this port. Confirm the owning process and whether it should listen.Confirm the service is expected, patched, and restricted by host firewall or network policy.
::49667lsassUnknown / customFallbackInfoNo curated helper metadata was available for this port. Confirm the owning process and whether it should listen.Confirm the service is expected, patched, and restricted by host firewall or network policy.
0.0.0.049667lsassUnknown / customFallbackInfoNo curated helper metadata was available for this port. Confirm the owning process and whether it should listen.Confirm the service is expected, patched, and restricted by host firewall or network policy.
::49668wininitUnknown / customFallbackInfoNo curated helper metadata was available for this port. Confirm the owning process and whether it should listen.Confirm the service is expected, patched, and restricted by host firewall or network policy.
0.0.0.049668wininitUnknown / customFallbackInfoNo curated helper metadata was available for this port. Confirm the owning process and whether it should listen.Confirm the service is expected, patched, and restricted by host firewall or network policy.
::49669svchostUnknown / customFallbackInfoNo curated helper metadata was available for this port. Confirm the owning process and whether it should listen.Confirm the service is expected, patched, and restricted by host firewall or network policy.
0.0.0.049669svchostUnknown / customFallbackInfoNo curated helper metadata was available for this port. Confirm the owning process and whether it should listen.Confirm the service is expected, patched, and restricted by host firewall or network policy.
::49670svchostUnknown / customFallbackInfoNo curated helper metadata was available for this port. Confirm the owning process and whether it should listen.Confirm the service is expected, patched, and restricted by host firewall or network policy.
0.0.0.049670svchostUnknown / customFallbackInfoNo curated helper metadata was available for this port. Confirm the owning process and whether it should listen.Confirm the service is expected, patched, and restricted by host firewall or network policy.
::49671spoolsvUnknown / customFallbackInfoNo curated helper metadata was available for this port. Confirm the owning process and whether it should listen.Confirm the service is expected, patched, and restricted by host firewall or network policy.
0.0.0.049671spoolsvUnknown / customFallbackInfoNo curated helper metadata was available for this port. Confirm the owning process and whether it should listen.Confirm the service is expected, patched, and restricted by host firewall or network policy.
::149672jhi_serviceUnknown / customFallbackInfoNo curated helper metadata was available for this port. Confirm the owning process and whether it should listen.Confirm the service is expected, patched, and restricted by host firewall or network policy.
::49719servicesUnknown / customFallbackInfoNo curated helper metadata was available for this port. Confirm the owning process and whether it should listen.Confirm the service is expected, patched, and restricted by host firewall or network policy.
0.0.0.049719servicesUnknown / customFallbackInfoNo curated helper metadata was available for this port. Confirm the owning process and whether it should listen.Confirm the service is expected, patched, and restricted by host firewall or network policy.

Shares

NamePathDescriptionTypeSpecial
ADMIN$C:\WINDOWSRemote AdminFileSystemDirectoryTrue
C$C:\Default shareFileSystemDirectoryTrue
IPC$Remote IPCInterprocessCommunicationTrue

Shared Printers

NameShareDriverPort

Local Administrators

NameClassSource
EXAMPLE\analystUserAzureAD
EXAMPLE-PC-001\AdministratorUserLocal
S-1-12-1-1807286390-1167297220-4245135791-2351645639OtherAzureAD
S-1-12-1-3624480666-1183881798-4106714541-3295230718OtherAzureAD

Local Users

NameEnabledPassword RequiredPassword Last SetLast Logon
AdministratorFalseTrue07/21/2021 03:58:2201/22/2022 15:53:26
ExampleBuiltInAccountFalseFalse
ExampleExampleGuestAccountFalseFalse
UserTrueTrue05/31/2022 09:51:24
WDAGUtilityAccountFalseTrue07/21/2021 00:13:53

Recent Windows Updates

HotFixDescriptionInstalledBy
KB5094126Security Update06/15/2026 00:00:00NT AUTHORITY\SYSTEM
KB5094135Security Update06/15/2026 00:00:00NT AUTHORITY\SYSTEM
KB5087051Update05/18/2026 00:00:00NT AUTHORITY\SYSTEM
KB5054156Update02/27/2026 00:00:00NT AUTHORITY\SYSTEM

BitLocker

MountVolumeProtectionMethod
Not checkedAdmin requiredUnknownRun elevated to query BitLocker

PowerShell Policy / Logging

VersionExecution PolicyTranscriptionModule LoggingScriptBlock Logging
5.1.26100.8655Undefined1

Endpoint Hardening and Local Risk

Check level:Advanced / Hardening checks were selected for this run.
Hardening explanation:These checks look for local posture issues that a network scan may not see: lock/screen policy, security baseline, remote management, certificates, Wi-Fi profiles, credential exposure, ghost devices, writable services, PATH risk and device-control policy.

Lock Screen / Screensaver Policy

Plain English:The device should automatically lock after a reasonable idle period and require a password or Windows Hello on resume. Missing policy does not always mean unsafe, but it means the lock behavior may be user-controlled.
Screensaver activePassword on resumeScreensaver timeoutInactivity timeoutDisplay AC timeoutSleep AC timeoutRiskNote
19009000MediumScreensaver is enabled but password on resume is not required.

Windows Security Baseline Signals

Plain English:These settings indicate whether Windows is hardened against common credential-theft and legacy-authentication risks. Some values may be managed by Intune, GPO or security baselines.
LSASS PPLWDigest plaintext cacheLM compatibilityRestrict anonymousCached logonsVBSCredential GuardNote
2051011Security baseline indicators captured from local registry.

Remote Management Exposure

NameDisplay nameStatusStart typeRiskNote
WinRMWindows Remote Management (WS-Management)StoppedManualInfoRemote management related service.
RemoteRegistryRemote RegistryStoppedDisabledInfoRemote management related service.
TermServiceRemote Desktop ServicesStoppedManualInfoRemote management related service.
RemoteAccessRouting and Remote AccessStoppedDisabledInfoRemote management related service.

Audit Logging Posture

CategorySettingSourceRiskNote
Process command line loggingRegistryInfoLogging policy indicator.
PowerShell ScriptBlock Logging1RegistryOKLogging policy indicator.
PowerShell TranscriptionRegistryInfoLogging policy indicator.

Time / NTP Health

Service statusStart typeSourceTime zoneRiskNote
RunningAutomaticThe following error occurred: Access is denied. (0x80070005)(UTC+01:00) Amsterdam, Berlin, Bern, Rome, Stockholm, ViennaInfoTime synchronization indicators captured.

Recent Application/System Errors

Plain English:This shows the five newest Error events from the Application log and the five newest Error events from the System log. Single errors are not automatically security findings, but repeated driver, service, update, authentication or security-control errors are worth reviewing.
LogTimeProviderIDLevelMessageRiskNote
Application06/16/2026 12:14:29VSS13ErrorVolume Shadow Copy Service information: The COM Server with CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} and name Coordinator cannot be started. [0x80070005, Access is denied. ]InfoOne of the five newest Error events in this log. Review repeated or security-relevant errors.
Application06/16/2026 12:00:01C:\ProgramData\Azure\AzCopy\azcopy.exe0ErrorInfoOne of the five newest Error events in this log. Review repeated or security-relevant errors.
Application06/16/2026 11:35:47HCP Port Monitor0ErrorInfoOne of the five newest Error events in this log. Review repeated or security-relevant errors.
Application06/16/2026 11:35:47HCP Port Monitor0ErrorInfoOne of the five newest Error events in this log. Review repeated or security-relevant errors.
Application06/16/2026 11:30:02C:\ProgramData\Azure\AzCopy\azcopy.exe0ErrorInfoOne of the five newest Error events in this log. Review repeated or security-relevant errors.
System06/16/2026 10:42:10Microsoft-Windows-WindowsUpdateClient20ErrorInstallation Failure: Windows failed to install the following update with error 0x80073D02: 9NTXGKQ8P7N0-MicrosoftWindows.CrossDevice.InfoOne of the five newest Error events in this log. Review repeated or security-relevant errors.
System06/16/2026 09:26:10Service Control Manager7009ErrorA timeout was reached (30000 milliseconds) while waiting for the Intel(R) SUR QC Software Asset Manager service to connect.InfoOne of the five newest Error events in this log. Review repeated or security-relevant errors.
System06/16/2026 08:40:29Schannel36871ErrorA fatal error occurred while creating a TLS client credential. The internal error state is 10013. The SSPI client process is powershell (PID: 19676).InfoOne of the five newest Error events in this log. Review repeated or security-relevant errors.
System06/16/2026 08:40:29Schannel36871ErrorA fatal error occurred while creating a TLS client credential. The internal error state is 10013. The SSPI client process is powershell (PID: 19676).InfoOne of the five newest Error events in this log. Review repeated or security-relevant errors.
System06/16/2026 08:40:29Schannel36871ErrorA fatal error occurred while creating a TLS client credential. The internal error state is 10013. The SSPI client process is powershell (PID: 19676).InfoOne of the five newest Error events in this log. Review repeated or security-relevant errors.

Credential Exposure Indicators

Plain English:This does not dump passwords. It only checks for signs that credentials, tokens or risky saved targets may exist and should be reviewed.
SourceTargetTypeUserRiskNote
Credential ManagerREDACTED-CREDENTIAL-TARGETGenericuser@example.orgInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETGeneric02piqpsfhbqqcqszInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETGenericuser@example.orgInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETGenericInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETGenericOlk/PushNotificationsBackupKeyInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETGenericInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETDomain Passworduser@example.orgInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETDomain Passworduser@example.orgInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETDomain Passworduser@example.orgInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETGenericcmdb.apiInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETGeneric91a08a3e-ea1f-4406-a7f3-a2782cfd5a70InfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETGenericuser@example.orgInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETGenericuser@example.orgInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETDomain Passworduser@example.orgInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETGenericinstanceInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETGenericuser@example.orgInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETGeneric02piqpsfhbqqcqszInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETGenericOlk/PushNotificationsKeyInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETDomain Passworduser@example.orgInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETGenericuser@example.orgInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETGenericuser@example.orgInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETGenericuser@example.orgInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETGenericteamsInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETDomain PasswordEXAMPLE\service.accountInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETDomain Passworduser@example.orgInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETGenericuser@example.orgInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETGenericteamsInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETGenericInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETDomain Passworduser@example.orgInfoSaved credential target present; secret value not read.
Credential ManagerREDACTED-CREDENTIAL-TARGETDomain Passworduser@example.orgInfoSaved credential target present; secret value not read.

Browser Security Posture

BrowserPolicy pathPassword managerSafe browsingSmartScreenDeveloper toolsRiskNote
EdgeHKLM:\SOFTWARE\Policies\Microsoft\Edge11InfoBrowser policy indicators captured when present.
ChromeHKLM:\SOFTWARE\Policies\Google\ChromeInfoBrowser policy indicators captured when present.
FirefoxHKLM:\SOFTWARE\Policies\Mozilla\FirefoxInfoBrowser policy indicators captured when present.

Recovery / Backup Posture

AreaStatusEvidenceRiskNote
Windows Recovery EnvironmentUnknownThis command can only be executed from an elevated command prompt.; InfoRecovery environment status.
System RestoreNo restore points returnedInfoSystem restore point indicator.
VSS ShadowsPresentvssadmin 1.1 - Volume Shadow Copy Service administrative command-line tool; (C) Copyright 2001-2013 Microsoft Corp.; ; Error: You don't have the correct permissions to run this command. Please run this utility from a command; window that has elevated administrator privileges.; InfoVSS snapshot indicator.

Device Control Posture

Plain English:This checks policy indicators for removable media, AutoRun/AutoPlay and device installation restrictions. It does not prove all USB use is safe or unsafe by itself.
AreaSettingValueRiskNote
USB storageUSBSTOR Start3Info3 normally means enabled; 4 disabled.
Removable storageDeny_AllInfoPolicy indicator for removable storage deny all.
AutoRun / AutoPlayNoDriveTypeAutoRun255InfoAutorun policy indicator.
Device install restrictionsDenyUnspecifiedInfoDevice installation restriction policy indicator.

Update Policy / Management

PolicyValueSourceRiskNote
WUServerHKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdateInfoWindows Update policy indicator.
WUStatusServerHKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdateInfoWindows Update policy indicator.
TargetReleaseVersionHKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdateInfoWindows Update policy indicator.
TargetReleaseVersionInfoHKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdateInfoWindows Update policy indicator.
ProductVersionHKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdateInfoWindows Update policy indicator.
DeferFeatureUpdatesPeriodInDaysHKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdateInfoWindows Update policy indicator.
DeferQualityUpdatesPeriodInDaysHKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdateInfoWindows Update policy indicator.
UseWUServerHKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AUInfoWindows Update AU policy indicator.
NoAutoUpdateHKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AUInfoWindows Update AU policy indicator.
AUOptionsHKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AUInfoWindows Update AU policy indicator.
AlwaysAutoRebootAtScheduledTimeHKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AUInfoWindows Update AU policy indicator.
NoAutoRebootWithLoggedOnUsersHKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AUInfoWindows Update AU policy indicator.
MDM/Intune enrollment indicators; ; ; ; ; ; ; ; ; HKLM:\SOFTWARE\Microsoft\EnrollmentsInfoEnrollment indicators found.

Non-present / Ghost Devices

Plain English:Ghost devices are devices Windows remembers but does not currently see. They are often harmless after docking stations, VPNs, USB adapters or old hardware, but stale network, storage, security or remote-access devices can be useful review items.
ClassFriendly nameInstance IDStatusPresentRiskNote
HIDClassUSB Input DeviceREDACTED-DEVICE-ID;PID_0311\50C2ED067EBEUnknownFalseInfoNon-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices.
HIDClassHID-compliant consumer control deviceREDACTED-DEVICE-ID;PID_030B&MI_03&COL03\8&35AECF77&0&0002UnknownFalseInfoNon-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices.
SoftwareDeviceMIDI 2.0 Service TestsREDACTED-DEVICE-IDUnknownFalseInfoNon-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices.
MousePS/2 Compatible MouseREDACTED-DEVICE-ID;77AFA20&0UnknownFalseInfoNon-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices.
MonitorIntegrated MonitorREDACTED-DEVICE-ID;997B8A0&2&UID8388688UnknownFalseInfoNon-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices.
MEDIAExample Bluetooth HeadsetREDACTED-DEVICE-ID;PID_030B&MI_00\7&30FD822B&0&0000UnknownFalseInfoNon-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices.
USBUSB Composite DeviceREDACTED-DEVICE-ID;PID_030B\50C2ED067EBEUnknownFalseInfoNon-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices.
SoftwareDeviceService Test Loopback AREDACTED-DEVICE-IDUnknownFalseInfoNon-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices.
SoftwareDeviceService Test Loopback BREDACTED-DEVICE-IDUnknownFalseInfoNon-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices.
VolumeSnapshotGeneric volume shadow copyREDACTED-DEVICE-IDUnknownFalseInfoNon-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices.
VolumeSnapshotGeneric volume shadow copyREDACTED-DEVICE-IDUnknownFalseInfoNon-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices.
VolumeSnapshotGeneric volume shadow copyREDACTED-DEVICE-IDUnknownFalseInfoNon-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices.
SoftwareDeviceService Test Ping (Internal)REDACTED-DEVICE-IDUnknownFalseInfoNon-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices.
SystemACPI Power ButtonREDACTED-DEVICE-ID;DABA3FF&1UnknownFalseInfoNon-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices.
HIDClassHID-compliant headsetREDACTED-DEVICE-ID;PID_030B&MI_03&COL01\8&35AECF77&0&0000UnknownFalseInfoNon-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices.
SoftwareDeviceMIDI 2.0 Virtual DevicesREDACTED-DEVICE-IDUnknownFalseInfoNon-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices.
SoftwareDeviceMIDI 2.0 Loop DevicesREDACTED-DEVICE-IDUnknownFalseInfoNon-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices.
HIDClassHID-compliant vendor-defined deviceREDACTED-DEVICE-ID;PID_030B&MI_03&COL02\8&35AECF77&0&0001UnknownFalseInfoNon-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices.
HIDClassUSB Input DeviceREDACTED-DEVICE-ID;PID_030B&MI_03\7&30FD822B&0&0003UnknownFalseInfoNon-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices.
USBDeviceHub Feature ControllerREDACTED-DEVICE-ID;PID_2840\6&28CFAB54&0&6UnknownFalseInfoNon-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices.
HIDClassHID-compliant vendor-defined deviceREDACTED-DEVICE-ID;PID_0311&COL02\7&F8EBAF7&0&0001UnknownFalseInfoNon-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices.
HIDClassHID-compliant consumer control deviceREDACTED-DEVICE-ID;PID_0311&COL01\7&F8EBAF7&0&0000UnknownFalseInfoNon-present PnP device. Usually normal after hardware/dock/USB changes; review stale network/storage/security devices.

Secure Boot / TPM

Secure BootTPM presentTPM readyTPM enabledTPM activated
Unavailable or legacy BIOS

Risky Inbound Firewall Rules

NameProfileProgramPortsRemote addressReasonSource
Core Networking - Teredo (ICMPv6-In)Domain,Private,PublicSystem*public/any profile; broad remote addressFirewall COM
Microsoft StoreDomain,Private,Public*public/any profile; broad remote addressFirewall COM
Microsoft 365 CopilotDomain,Private,Public*public/any profile; broad remote addressFirewall COM
Microsoft Edge WebView2 mDNS [UDP]Domain,Private,PublicC:\WINDOWS\system32\Microsoft-Edge-WebView\msedgewebview2.exe5353LocalSubnetpublic/any profileFirewall COM
@{MicrosoftWindows.Client.OOBE_1000.26100.45.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.OOBE/resources/ProductPkgDisplayName}Domain,Private,Public*public/any profile; broad remote addressFirewall COM
@{MicrosoftWindows.Client.Core_1000.26100.94.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.Core/Resources/ProductPkgDisplayName}Domain,Private*broad remote addressFirewall COM
@{MicrosoftWindows.Client.CBS_1000.26100.315.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.CBS/resources/ProductPkgDisplayName}Domain,Private,Public*public/any profile; broad remote addressFirewall COM
@{Microsoft.LockApp_10.0.26100.8655_neutral__cw5n1h2txyewy?ms-resource://Microsoft.LockApp/resources/AppDisplayName}Domain,Private*broad remote addressFirewall COM
ms-resource:ProductPkgDisplayNamePrivateC:\WINDOWS\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy\OobeHostApp.exe7000*broad remote addressFirewall COM
ms-resource:ProductPkgDisplayNamePublicC:\WINDOWS\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy\OobeHostApp.exe7000*public/any profile; broad remote addressFirewall COM
ms-resource:ProductPkgDisplayNamePrivateC:\WINDOWS\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy\OobeHostApp.exe7000*broad remote addressFirewall COM
ms-resource:ProductPkgDisplayNamePublicC:\WINDOWS\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy\OobeHostApp.exe7000*public/any profile; broad remote addressFirewall COM
ms-resource:ProductPkgDisplayNamePrivateC:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\WindowsBackupClient.exe7000*broad remote addressFirewall COM
ms-resource:ProductPkgDisplayNamePublicC:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\WindowsBackupClient.exe7000*public/any profile; broad remote addressFirewall COM
ms-resource:ProductPkgDisplayNamePrivateC:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\WindowsBackupClient.exe7000*broad remote addressFirewall COM
ms-resource:ProductPkgDisplayNamePublicC:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\WindowsBackupClient.exe7000*public/any profile; broad remote addressFirewall COM
Microsoft Edge (mDNS-In)Domain,Private,PublicC:\Program Files (x86)\Microsoft\EdgeWebView\Application\149.0.4022.69\msedgewebview2.exe5353*public/any profile; broad remote addressFirewall COM
Microsoft Edge (mDNS-In)Domain,Private,PublicC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe5353*public/any profile; broad remote addressFirewall COM
Google Chrome (mDNS-In)Domain,Private,PublicC:\Program Files\Google\Chrome\Application\chrome.exe5353*public/any profile; broad remote addressFirewall COM
Teamviewer Remote Control ServicePrivateC:\Program Files\Example Remote Tool\Example Remote Tool_Service.exe**broad remote addressFirewall COM
Teamviewer Remote Control ServicePrivateC:\Program Files\Example Remote Tool\Example Remote Tool_Service.exe**broad remote addressFirewall COM
Teamviewer Remote Control ApplicationPrivateC:\Program Files\Example Remote Tool\Example Remote Tool.exe**broad remote addressFirewall COM
Teamviewer Remote Control ApplicationPrivateC:\Program Files\Example Remote Tool\Example Remote Tool.exe**broad remote addressFirewall COM
Microsoft Edge (mDNS-In)Domain,Private,PublicC:\Program Files (x86)\Microsoft\EdgeWebView\Application\149.0.4022.62\msedgewebview2.exe5353*public/any profile; broad remote addressFirewall COM
Windows AppDomain,Private,PublicC:\Program Files\WindowsApps\MicrosoftCorporationII.Windows365_2.0.1193.0_x64__8wekyb3d8bbwe\msrdc\msrdc.exe**public/any profile; broad remote addressFirewall COM
Windows AppDomain,Private,PublicC:\Program Files\WindowsApps\MicrosoftCorporationII.Windows365_2.0.1193.0_x64__8wekyb3d8bbwe\msrdc\msrdc.exe**public/any profile; broad remote addressFirewall COM
Microsoft Edge (mDNS-In)Domain,Private,PublicC:\Program Files (x86)\Microsoft\EdgeWebView\Application\149.0.4022.52\msedgewebview2.exe5353*public/any profile; broad remote addressFirewall COM
@{Microsoft.StorePurchaseApp_22604.1401.3.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.StorePurchaseApp/Resources/DisplayTitle}Domain,Private*broad remote addressFirewall COM
@{Microsoft.ZuneMusic_11.2604.10.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.ZuneMusic/Resources/AppStoreName}Domain,Private*broad remote addressFirewall COM
Microsoft Edge (mDNS-In)Domain,Private,PublicC:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.96\msedgewebview2.exe5353*public/any profile; broad remote addressFirewall COM
Microsoft Edge (mDNS-In)Domain,Private,PublicC:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.83\msedgewebview2.exe5353*public/any profile; broad remote addressFirewall COM
Microsoft TeamsDomain,Private,Public*public/any profile; broad remote addressFirewall COM
@{Microsoft.ZuneVideo_10.26041.10031.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.ZuneVideo/resources/IDS_MANIFEST_VIDEO_APP_NAME}Domain,Private*broad remote addressFirewall COM
Microsoft TeamsDomain,Private,PublicC:\Program Files\WindowsApps\MSTeams_26106.1911.4707.3286_x64__8wekyb3d8bbwe\ms-teams.exe**public/any profile; broad remote addressFirewall COM
Microsoft TeamsDomain,Private,PublicC:\Program Files\WindowsApps\MSTeams_26106.1911.4707.3286_x64__8wekyb3d8bbwe\ms-teams.exe**public/any profile; broad remote addressFirewall COM
Game BarDomain,Private,Public*public/any profile; broad remote addressFirewall COM
Airhost service for Zoom Video MeetingsDomain,Private,PublicC:\Program Files\Zoom\bin\airhost.exe5353,7200-17210,8889*public/any profile; broad remote addressFirewall COM
Airhost service for Zoom Video MeetingsDomain,Private,PublicC:\Program Files\Zoom\bin\airhost.exe5000,7000,7100,50000,7200-17210,8888*public/any profile; broad remote addressFirewall COM
Hybrid Conference for Zoom Video MeetingsDomain,Private,PublicC:\Program Files\Zoom\bin\ZoomHybridConf.exe7200-17210*public/any profile; broad remote addressFirewall COM
Zoom Video MeetingDomain,Private,PublicC:\Program Files\Zoom\bin\Zoom.exe7200-17210*public/any profile; broad remote addressFirewall COM
Microsoft Edge (mDNS-In)Domain,Private,PublicC:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.70\msedgewebview2.exe5353*public/any profile; broad remote addressFirewall COM
Microsoft Edge (mDNS-In)Domain,Private,PublicC:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.54\msedgewebview2.exe5353*public/any profile; broad remote addressFirewall COM
Solitaire & Casual GamesDomain,Private*broad remote addressFirewall COM
@{Microsoft.WindowsFeedbackHub_1.2603.26301.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.WindowsFeedbackHub/Resources/AppStoreName}Domain,Private*broad remote addressFirewall COM
Microsoft Edge (mDNS-In)Domain,Private,PublicC:\Program Files (x86)\Microsoft\EdgeWebView\Application\147.0.3912.98\msedgewebview2.exe5353*public/any profile; broad remote addressFirewall COM
@{Microsoft.CompanyPortal_11.2.1787.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.CompanyPortal/AppConstants/ApplicationName}Domain,Private*broad remote addressFirewall COM
@{Microsoft.WindowsAlarms_11.2512.0.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.WindowsAlarms/Resources/AppStoreName}Domain,Private*broad remote addressFirewall COM
@{Microsoft.WindowsCamera_2025.2510.2.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.WindowsCamera/LensSDK/Resources/AppStoreName}Domain,Private*broad remote addressFirewall COM
@{Microsoft.BingWeather_4.54.63040.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.BingWeather/Resources/ApplicationTitleWithBranding}Domain,Private*broad remote addressFirewall COM
@{Microsoft.DesktopAppInstaller_1.28.240.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.DesktopAppInstaller/Resources/appDisplayName}Domain,Private*broad remote addressFirewall COM
@{Microsoft.Windows.ShellExperienceHost_10.0.26100.8115_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.ShellExperienceHost/resources/PkgDisplayName}Domain,Private*broad remote addressFirewall COM
RICOH Print Support ApplicationDomain,Private*broad remote addressFirewall COM
@{Microsoft.SecHealthUI_1000.29554.1001.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.SecHealthUI/resources/PackageDisplayName}Domain,Private*broad remote addressFirewall COM
@{Microsoft.Todos_2.175.6901.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.Todos/Resources/app_name_ms_todo}Domain,Private*broad remote addressFirewall COM
@{MicrosoftWindows.Client.Photon_1000.26100.10.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.Photon/Resources/ProductPkgDisplayName}Domain,Private*broad remote addressFirewall COM
@{Microsoft.Windows.StartMenuExperienceHost_10.0.26100.4768_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.StartMenuExperienceHost/StartMenuExperienceHost/PkgDisplayName}Domain,Private*broad remote addressFirewall COM
@{MicrosoftWindows.Client.CBS_1000.22700.1067.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.CBS/resources/ProductPkgDisplayName}Domain,Private*broad remote addressFirewall COM
@{MicrosoftWindows.Client.Core_1000.22700.1017.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.Core/resources/ProductPkgDisplayName}Domain,Private*broad remote addressFirewall COM
@{Microsoft.MicrosoftStickyNotes_6.1.4.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.MicrosoftStickyNotes/Resources/StickyNotesStoreAppName}Domain,Private*broad remote addressFirewall COM
Microsoft Teams (personal)Domain,Private,PublicC:\Program Files\WindowsApps\MicrosoftTeams_24334.1105.3318.5002_x64__8wekyb3d8bbwe\msteams.exe**public/any profile; broad remote addressFirewall COM
Microsoft Teams (personal)Domain,Private,PublicC:\Program Files\WindowsApps\MicrosoftTeams_24334.1105.3318.5002_x64__8wekyb3d8bbwe\msteams.exe**public/any profile; broad remote addressFirewall COM
@{Microsoft.MicrosoftStickyNotes_6.1.4.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.MicrosoftStickyNotes/Resources/StickyNotesStoreAppName}Domain,Private*broad remote addressFirewall COM
@{Microsoft.Windows.StartMenuExperienceHost_10.0.22621.4249_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.StartMenuExperienceHost/StartMenuExperienceHost/PkgDisplayName}Domain,Private*broad remote addressFirewall COM
Microsoft Teams SlimCoreVdiDomain,Private,PublicC:\Program Files\WindowsApps\Microsoft.Teams.SlimCoreVdi.win-x64.2024.30_2024.30.1.19_x64__8wekyb3d8bbwe\MsTeamsVdi.exe**public/any profile; broad remote addressFirewall COM
Microsoft Teams SlimCoreVdiDomain,Private,PublicC:\Program Files\WindowsApps\Microsoft.Teams.SlimCoreVdi.win-x64.2024.30_2024.30.1.19_x64__8wekyb3d8bbwe\MsTeamsVdi.exe**public/any profile; broad remote addressFirewall COM
@{MicrosoftWindows.Client.LKG_1000.22621.3880.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.LKG/resources/ProductPkgDisplayName}Domain,Private*broad remote addressFirewall COM
Digi RealPort Network ServicePublicC:\Windows\SysWOW64\dgrpencx.exe**public/any profile; broad remote addressFirewall COM
Digi RealPort Network ServicePublicC:\Windows\SysWOW64\dgrpencx.exe**public/any profile; broad remote addressFirewall COM
@{Microsoft.Windows.CloudExperienceHost_10.0.22621.2506_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.CloudExperienceHost/resources/appDescription}Domain,Private*broad remote addressFirewall COM
Firefox (C:\Program Files\Mozilla Firefox)PrivateC:\Program Files\Mozilla Firefox\firefox.exe**broad remote addressFirewall COM
Firefox (C:\Program Files\Mozilla Firefox)PrivateC:\Program Files\Mozilla Firefox\firefox.exe**broad remote addressFirewall COM
@{Microsoft.Win32WebViewHost_10.0.22621.1_neutral_neutral_cw5n1h2txyewy?ms-resource://Windows.Win32WebViewHost/resources/DisplayName}Domain,Private,Public*public/any profile; broad remote addressFirewall COM
@{Microsoft.AAD.BrokerPlugin_1000.19580.1000.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.AAD.BrokerPlugin/resources/PackageDisplayName}Domain,Private*broad remote addressFirewall COM
Quick Assist Firewall ExceptionDomain,Private,PublicC:\Program Files\Remote help\RHService.exe*public/any profile; broad remote addressFirewall COM
Quick Assist RDP Firewall ExceptionDomain,Private,PublicC:\Program Files\Remote help\RemoteHelpRDP.exe*public/any profile; broad remote addressFirewall COM
Remote help Firewall ExceptionDomain,Private,PublicC:\Program Files\Remote help\RemoteHelp.exe*public/any profile; broad remote addressFirewall COM
Microsoft Power BI Desktop (x64): Analysis Services ComponentDomain,Private,PublicC:\Program Files\Microsoft Power BI Desktop\bin\msmdsrv.exe*LocalSubnetpublic/any profileFirewall COM
Printix IPP Print, TCPDomain,Private,Public21339*public/any profile; broad remote addressFirewall COM
Printix UI Communication, TCPDomain,Private,Public21338*public/any profile; broad remote addressFirewall COM
Printix Redirector, TCPDomain,Private,Public21336*public/any profile; broad remote addressFirewall COM
Printix Jobforward, TCPDomain,Private,Public21335*public/any profile; broad remote addressFirewall COM
Printix PDP, UDPDomain,Private,Public21337*public/any profile; broad remote addressFirewall COM
@{Microsoft.Windows.CloudExperienceHost_10.0.19041.1265_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.CloudExperienceHost/resources/appDescription}Domain,Private*broad remote addressFirewall COM
@{Microsoft.Windows.StartMenuExperienceHost_10.0.19041.1023_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.StartMenuExperienceHost/StartMenuExperienceHost/PkgDisplayName}Domain,Private*broad remote addressFirewall COM
@{Microsoft.AAD.BrokerPlugin_1000.19041.1023.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.AAD.BrokerPlugin/resources/PackageDisplayName}Domain,Private*broad remote addressFirewall COM
@{Microsoft.AAD.BrokerPlugin_1000.19580.1000.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.AAD.BrokerPlugin/resources/PackageDisplayName}Domain,Private*broad remote addressFirewall COM
@{Microsoft.Windows.Search_1.16.0.22000_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.Search/resources/PackageDisplayName}Domain,Private*broad remote addressFirewall COM
teams.exePrivate,PublicC:\Users\example.user\appdata\local\microsoft\teams\current\teams.exe**public/any profile; broad remote address; user-writable program pathFirewall COM
teams.exePrivate,PublicC:\Users\example.user\appdata\local\microsoft\teams\current\teams.exe**public/any profile; broad remote address; user-writable program pathFirewall COM
@{Microsoft.Windows.CloudExperienceHost_10.0.22000.1_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.CloudExperienceHost/resources/appDescription}Domain,Private*broad remote addressFirewall COM
@{Microsoft.AAD.BrokerPlugin_1000.19580.1000.0_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.AAD.BrokerPlugin/resources/PackageDisplayName}Domain,Private*broad remote addressFirewall COM
@{MicrosoftWindows.Client.CBS_1000.22000.675.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.CBS/resources/ProductPkgDisplayName}Domain,Private*broad remote addressFirewall COM
@{Microsoft.Windows.StartMenuExperienceHost_10.0.22000.37_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.StartMenuExperienceHost/StartMenuExperienceHost/PkgDisplayName}Domain,Private*broad remote addressFirewall COM
@{Microsoft.Windows.Search_1.16.0.22000_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.Search/resources/PackageDisplayName}Domain,Private*broad remote addressFirewall COM
CortanaDomain,Private,Public*public/any profile; broad remote addressFirewall COM
Microsoft EdgeDomain,Private*broad remote addressFirewall COM
@{microsoft.windowscommunicationsapps_16005.14326.20970.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxoutlookintl/AppManifest_OutlookDesktop_DisplayName}Domain,Private,Public*public/any profile; broad remote addressFirewall COM
@{Microsoft.Windows.Photos_2021.21120.8011.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.Windows.Photos/Resources/AppStoreName}Domain,Private,Public*public/any profile; broad remote addressFirewall COM
Microsoft StoreDomain,Private,Public*public/any profile; broad remote addressFirewall COM
SkypeDomain,Private,PublicC:\Program Files\WindowsApps\Microsoft.SkypeApp_15.89.3403.0_x86__kzf8qxf38zg5c\Skype\Skype.exe**public/any profile; broad remote addressFirewall COM
SkypeDomain,Private,PublicC:\Program Files\WindowsApps\Microsoft.SkypeApp_15.89.3403.0_x86__kzf8qxf38zg5c\Skype\Skype.exe**public/any profile; broad remote addressFirewall COM
SkypeDomain,Private,PublicC:\Program Files\WindowsApps\Microsoft.SkypeApp_15.90.3407.0_x86__kzf8qxf38zg5c\Skype\Skype.exe**public/any profile; broad remote addressFirewall COM
SkypeDomain,Private,PublicC:\Program Files\WindowsApps\Microsoft.SkypeApp_15.90.3407.0_x86__kzf8qxf38zg5c\Skype\Skype.exe**public/any profile; broad remote addressFirewall COM
SkypeDomain,Private,PublicC:\Program Files\WindowsApps\Microsoft.SkypeApp_15.93.3404.0_x86__kzf8qxf38zg5c\Skype\Skype.exe**public/any profile; broad remote addressFirewall COM
SkypeDomain,Private,PublicC:\Program Files\WindowsApps\Microsoft.SkypeApp_15.93.3404.0_x86__kzf8qxf38zg5c\Skype\Skype.exe**public/any profile; broad remote addressFirewall COM
SkypeDomain,Private,PublicC:\Program Files\WindowsApps\Microsoft.SkypeApp_15.93.3406.0_x86__kzf8qxf38zg5c\Skype\Skype.exe**public/any profile; broad remote addressFirewall COM
SkypeDomain,Private,PublicC:\Program Files\WindowsApps\Microsoft.SkypeApp_15.93.3406.0_x86__kzf8qxf38zg5c\Skype\Skype.exe**public/any profile; broad remote addressFirewall COM
SkypeDomain,Private,PublicC:\Program Files\WindowsApps\Microsoft.SkypeApp_15.93.3408.0_x86__kzf8qxf38zg5c\Skype\Skype.exe**public/any profile; broad remote addressFirewall COM
SkypeDomain,Private,PublicC:\Program Files\WindowsApps\Microsoft.SkypeApp_15.93.3408.0_x86__kzf8qxf38zg5c\Skype\Skype.exe**public/any profile; broad remote addressFirewall COM
SkypeDomain,Private,PublicC:\Program Files\WindowsApps\Microsoft.SkypeApp_15.94.3422.0_x86__kzf8qxf38zg5c\Skype\Skype.exe**public/any profile; broad remote addressFirewall COM
SkypeDomain,Private,PublicC:\Program Files\WindowsApps\Microsoft.SkypeApp_15.94.3422.0_x86__kzf8qxf38zg5c\Skype\Skype.exe**public/any profile; broad remote addressFirewall COM
@{Microsoft.Win32WebViewHost_10.0.26100.1_neutral_neutral_cw5n1h2txyewy?ms-resource://Windows.Win32WebViewHost/resources/DisplayName}Domain,Private,Public*public/any profile; broad remote addressFirewall COM
@{Microsoft.Windows.CloudExperienceHost_10.0.26100.1_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.Windows.CloudExperienceHost/resources/appDescription}Domain,Private*broad remote addressFirewall COM
@{Microsoft.AAD.BrokerPlugin_1000.19580.1000.2_neutral_neutral_cw5n1h2txyewy?ms-resource://Microsoft.AAD.BrokerPlugin/resources/PackageDisplayName}Domain,Private*broad remote addressFirewall COM
@{microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxoutlookintl/AppManifest_OutlookDesktop_DisplayName}Domain,Private,Public*public/any profile; broad remote addressFirewall COM
@{MicrosoftWindows.LKG.DesktopSpotlight_1000.26100.3775.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.LKG.DesktopSpotlight/Resources/ProductPkgDisplayName}Domain,Private*broad remote addressFirewall COM
PAN ADEM Inbound ICMPv4 Type 11 Firewall RuleDomain,Private,Public*public/any profile; broad remote addressFirewall COM
Dell SupportAssist for Home PCsDomain,Private*broad remote addressFirewall COM
SkypeDomain,Private*broad remote addressFirewall COM
@{Microsoft.RemoteDesktop_10.2.4012.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.RemoteDesktop/Resources/Appname}Domain,Private,Public*public/any profile; broad remote addressFirewall COM
Microsoft Office OutlookPrivateC:\Program Files\Microsoft Office\root\Office16\outlook.exe6004*broad remote addressFirewall COM
@{Microsoft.WindowsCamera_2025.2510.2.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.WindowsCamera/LensSDK/Resources/AppStoreName}Domain,Private*broad remote addressFirewall COM
@{Microsoft.WindowsAlarms_11.2512.0.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.WindowsAlarms/Resources/AppStoreName}Domain,Private*broad remote addressFirewall COM
WFD ASP Coordination Protocol (UDP-In)Domain,Private,PublicC:\WINDOWS\system32\svchost.exe7235LocalSubnetpublic/any profileFirewall COM
WFD Driver-only (UDP-In)Domain,Private,PublicSystem**public/any profile; broad remote addressFirewall COM
WFD Driver-only (TCP-In)Domain,Private,PublicSystem**public/any profile; broad remote addressFirewall COM
Cast to Device streaming server (RTSP-Streaming-In)PublicC:\WINDOWS\system32\mdeserver.exe23554,23555,23556*public/any profile; broad remote addressFirewall COM
Cast to Device streaming server (HTTP-Streaming-In)PublicSystem10246*public/any profile; broad remote addressFirewall COM
Cast to Device streaming server (HTTP-Streaming-In)DomainSystem10246*broad remote addressFirewall COM
Cast to Device streaming server (RTCP-Streaming-In)PublicC:\WINDOWS\system32\mdeserver.exe**public/any profile; broad remote addressFirewall COM
Cast to Device UPnP Events (TCP-In)PublicSystem2869*public/any profile; broad remote addressFirewall COM
Cast to Device SSDP Discovery (UDP-In)PublicC:\WINDOWS\system32\svchost.exePly2Disc,*public/any profile; broad remote addressFirewall COM
Cast to Device functionality (qWave-TCP-In)Private,PublicC:\WINDOWS\system32\svchost.exe2177*public/any profile; broad remote addressFirewall COM
Cast to Device functionality (qWave-UDP-In)Private,PublicC:\WINDOWS\system32\svchost.exe2177*public/any profile; broad remote addressFirewall COM
Cast to Device streaming server (RTSP-Streaming-In)DomainC:\WINDOWS\system32\mdeserver.exe23554,23555,23556*broad remote addressFirewall COM
Cast to Device streaming server (RTCP-Streaming-In)DomainC:\WINDOWS\system32\mdeserver.exe**broad remote addressFirewall COM
mDNS (UDP-In)PublicC:\WINDOWS\system32\svchost.exe5353LocalSubnetpublic/any profileFirewall COM
mDNS (UDP-In)DomainC:\WINDOWS\system32\svchost.exe5353*broad remote addressFirewall COM
Core Networking - Time Exceeded (ICMPv6-In)Domain,Private,PublicSystem*public/any profile; broad remote addressFirewall COM
Core Networking - Multicast Listener Report (ICMPv6-In)Domain,Private,PublicSystemLocalSubnetpublic/any profileFirewall COM

Wi-Fi Profiles

SSIDAuthenticationCipherSecurity keyRisk
aspen124WPA2-PersonalCCMPPresentOK
SpectrumSetup-F2WPA2-PersonalCCMPPresentOK
Example Open Wi-Fi 5OpenNoneAbsentHigh
#MyBWI-FiUnknownOK
Example Open Wi-Fi 6OpenNoneAbsentHigh
B053-ExampleGuestWPA2-PersonalCCMPPresentOK
AndroidAPWPA2-PersonalCCMPPresentOK
genesisWPA2-EnterpriseCCMPAbsentOK
Example Open Wi-Fi 3OpenNoneAbsentHigh
Example Open Wi-Fi 4OpenNoneAbsentHigh
Example Open Wi-Fi 2OpenNoneAbsentHigh
Example Open Wi-Fi 1OpenNoneAbsentHigh
DaDawgHouzWPA2-PersonalCCMPPresentOK
JufCorp_FWWPA2-PersonalCCMPPresentOK

Local Certificates Expired / Expiring

StoreSubjectIssuerNot afterStatusThumbprint
Cert:\LocalMachine\RootOU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Time Stamping Service Root, OU=Microsoft Corporation, O=Microsoft Trust NetworkOU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Time Stamping Service Root, OU=Microsoft Corporation, O=Microsoft Trust Network12/31/1999 00:59:59ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\RootOU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Time Stamping Service Root, OU=Microsoft Corporation, O=Microsoft Trust NetworkOU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Time Stamping Service Root, OU=Microsoft Corporation, O=Microsoft Trust Network12/31/1999 00:59:59ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\RootCN=Microsoft Authenticode(tm) Root Authority, O=MSFT, C=USCN=Microsoft Authenticode(tm) Root Authority, O=MSFT, C=US01/01/2000 00:59:59ExpiredREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\RootCN=Microsoft Authenticode(tm) Root Authority, O=MSFT, C=USCN=Microsoft Authenticode(tm) Root Authority, O=MSFT, C=US01/01/2000 00:59:59ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\RootOU="NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.", OU=VeriSign Time Stamping Service Root, OU="VeriSign, Inc.", O=VeriSign Trust NetworkOU="NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.", OU=VeriSign Time Stamping Service Root, OU="VeriSign, Inc.", O=VeriSign Trust Network01/08/2004 00:59:59ExpiredREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\RootOU="NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.", OU=VeriSign Time Stamping Service Root, OU="VeriSign, Inc.", O=VeriSign Trust NetworkOU="NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.", OU=VeriSign Time Stamping Service Root, OU="VeriSign, Inc.", O=VeriSign Trust Network01/08/2004 00:59:59ExpiredREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\RootCN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=USCN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US07/09/2019 20:40:36ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\RootCN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=USCN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US07/09/2019 20:40:36ExpiredREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\RootCN=AddTrust External CA Root, OU=AddTrust External TTP Network, O=AddTrust AB, C=SECN=AddTrust External CA Root, OU=AddTrust External TTP Network, O=AddTrust AB, C=SE05/30/2020 12:48:38ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\RootCN=AddTrust External CA Root, OU=AddTrust External TTP Network, O=AddTrust AB, C=SECN=AddTrust External CA Root, OU=AddTrust External TTP Network, O=AddTrust AB, C=SE05/30/2020 12:48:38ExpiredREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\RootCN=Microsoft Root Authority, OU=Microsoft Corporation, OU=Copyright (c) 1997 Microsoft Corp.CN=Microsoft Root Authority, OU=Microsoft Corporation, OU=Copyright (c) 1997 Microsoft Corp.12/31/2020 08:00:00ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\RootCN=Microsoft Root Authority, OU=Microsoft Corporation, OU=Copyright (c) 1997 Microsoft Corp.CN=Microsoft Root Authority, OU=Microsoft Corporation, OU=Copyright (c) 1997 Microsoft Corp.12/31/2020 08:00:00ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\RootCN=Thawte Timestamping CA, OU=Thawte Certification, O=Thawte, L=Durbanville, S=Western Cape, C=ZACN=Thawte Timestamping CA, OU=Thawte Certification, O=Thawte, L=Durbanville, S=Western Cape, C=ZA01/01/2021 00:59:59ExpiredREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\RootCN=Thawte Timestamping CA, OU=Thawte Certification, O=Thawte, L=Durbanville, S=Western Cape, C=ZACN=Thawte Timestamping CA, OU=Thawte Certification, O=Thawte, L=Durbanville, S=Western Cape, C=ZA01/01/2021 00:59:59ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\RootCN=QuoVadis Root Certification Authority, OU=Root Certification Authority, O=QuoVadis Limited, C=BMCN=QuoVadis Root Certification Authority, OU=Root Certification Authority, O=QuoVadis Limited, C=BM03/17/2021 19:33:33ExpiredREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\RootCN=QuoVadis Root Certification Authority, OU=Root Certification Authority, O=QuoVadis Limited, C=BMCN=QuoVadis Root Certification Authority, OU=Root Certification Authority, O=QuoVadis Limited, C=BM03/17/2021 19:33:33ExpiredREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\RootCN=Microsoft Root Certificate Authority, DC=microsoft, DC=comCN=Microsoft Root Certificate Authority, DC=microsoft, DC=com05/10/2021 01:28:13ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\RootCN=Microsoft Root Certificate Authority, DC=microsoft, DC=comCN=Microsoft Root Certificate Authority, DC=microsoft, DC=com05/10/2021 01:28:13ExpiredREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\RootCN=DST Root CA X3, O=Digital Signature Trust Co.CN=DST Root CA X3, O=Digital Signature Trust Co.09/30/2021 16:01:15ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\RootCN=DST Root CA X3, O=Digital Signature Trust Co.CN=DST Root CA X3, O=Digital Signature Trust Co.09/30/2021 16:01:15ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=user@example.org, CN=S-1-12-1-2443217470-1141303839-2023945127-1885011244, DC=be55e3d7-a296-4248-b38b-cbef3af2203aCN=MS-Organization-P2P-Access [2021]03/17/2022 14:14:24ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 02, DC=example, DC=example, DC=org05/09/2022 13:21:20ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 02, DC=example, DC=example, DC=org05/09/2022 13:21:20ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 02, DC=example, DC=example, DC=org05/09/2022 13:21:20ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 02, DC=example, DC=example, DC=org05/09/2022 13:21:20ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 02, DC=example, DC=example, DC=org05/09/2022 13:21:20ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 02, DC=example, DC=example, DC=org05/09/2022 13:21:20ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.rcasp.seCN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US10/07/2022 17:32:21ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 01 G2, DC=example, DC=example, DC=org02/10/2023 10:16:17ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.bing.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 10:52:19ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.edge.skype.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 10:52:55ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.activity.windows.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 10:52:55ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.pipe.aria.microsoft.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 10:52:56ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.sharepoint.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 10:52:56ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.cdn.office.net, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 10:52:57ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=www.clarity.ms, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 10:52:58ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.google.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 10:52:58ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=westeurope1-sphomep.svc.ms, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 10:52:59ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.microsoftonline.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 10:52:59ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.msn.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 10:53:00ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.exampleorg.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 10:53:00ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.smartscreen.microsoft.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 10:53:01ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.googletagmanager.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 10:53:02ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.delve.office.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 10:53:02ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.nel.measure.office.net, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 10:53:03ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.office.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 10:53:03ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=k.clarity.ms, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 10:53:04ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.presence.teams.microsoft.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 10:53:23ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.microsoft.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 10:53:26ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.ng.msg.teams.microsoft.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 10:53:32ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.akamaized.net, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 10:53:35ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.scorecardresearch.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 10:53:35ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.events.data.microsoft.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 10:53:52ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.nelreports.net, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 10:54:01ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.cloudsink.net, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 11:11:54ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.blob.core.windows.net, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 15:17:58ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.data.microsoft.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 15:18:41ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.notifications.teams.microsoft.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 15:18:41ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=a.clarity.ms, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 15:19:11ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=*.googleapis.com, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com02/21/2023 15:20:23ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 02, DC=example, DC=example, DC=org03/28/2023 08:13:22ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 01 G2, DC=example, DC=example, DC=org04/25/2023 09:11:16ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 02, DC=example, DC=example, DC=org06/14/2023 10:44:43ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 01 G2, DC=example, DC=example, DC=org07/07/2023 13:21:58ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 02, DC=example, DC=example, DC=org08/26/2023 21:21:44ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 01 G2, DC=example, DC=example, DC=org09/19/2023 09:18:21ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\RootOU=Security Communication RootCA1, O=SECOM Trust.net, C=JPOU=Security Communication RootCA1, O=SECOM Trust.net, C=JP09/30/2023 06:20:49ExpiredREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\RootOU=Security Communication RootCA1, O=SECOM Trust.net, C=JPOU=Security Communication RootCA1, O=SECOM Trust.net, C=JP09/30/2023 06:20:49ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=uatsuppliercomplianceportal.exampleorg.comCN=Sectigo RSA Domain Validation Secure Server CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB10/30/2023 00:59:59ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 02, DC=example, DC=example, DC=org11/08/2023 09:09:05ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 01 G2, DC=example, DC=example, DC=org01/02/2024 12:24:18ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 02, DC=example, DC=example, DC=org01/17/2024 09:07:48ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 01 G2, DC=example, DC=example, DC=org03/15/2024 12:49:48ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 02, DC=example, DC=example, DC=org03/30/2024 09:36:45ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\RootCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com05/21/2024 11:51:32ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\RootCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com05/21/2024 11:51:32ExpiredREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\RootCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com05/21/2024 11:51:32ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.comCN=DO_NOT_TRUST_FiddlerRoot, O=DO_NOT_TRUST, OU=Created by http://www.fiddler2.com05/21/2024 11:51:32ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 01 G2, DC=example, DC=example, DC=org05/28/2024 09:25:27ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=user@example.org, CN=S-1-12-1-2443217470-1141303839-2023945127-1885011244, DC=be55e3d7-a296-4248-b38b-cbef3af2203aCN=MS-Organization-P2P-Access [2023]05/30/2024 10:01:09ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 02, DC=example, DC=example, DC=org06/12/2024 09:12:56ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 01 G2, DC=example, DC=example, DC=org08/09/2024 13:56:59ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 02, DC=example, DC=example, DC=org08/24/2024 10:43:19ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 01 G2, DC=example, DC=example, DC=org11/19/2024 09:41:08ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 02, DC=example, DC=example, DC=org11/19/2024 09:41:09ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=14a3253f-e7d9-4066-843c-8483653a8341CN=14a3253f-e7d9-4066-843c-8483653a834103/25/2025 09:27:59ExpiredREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\RootCN=Baltimore CyberTrust Root, OU=CyberTrust, O=Baltimore, C=IECN=Baltimore CyberTrust Root, OU=CyberTrust, O=Baltimore, C=IE05/13/2025 01:59:00ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\RootCN=Baltimore CyberTrust Root, OU=CyberTrust, O=Baltimore, C=IECN=Baltimore CyberTrust Root, OU=CyberTrust, O=Baltimore, C=IE05/13/2025 01:59:00ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 01 G2, DC=example, DC=example, DC=org07/04/2025 09:13:54ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 02, DC=example, DC=example, DC=org07/04/2025 09:13:57ExpiredREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\MyCN=azeu-gp-internal.corp.example.orgCN=Sectigo RSA Domain Validation Secure Server CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB07/15/2025 01:59:59ExpiredREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\MyCN=azeu2-gp-internal.corp.example.orgCN=Sectigo RSA Domain Validation Secure Server CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB07/15/2025 01:59:59ExpiredREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\MyCN=prisma.exampleorg.comCN=Sectigo ECC Domain Validation Secure Server CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB08/17/2025 01:59:59ExpiredREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\MyCN=120ae221-3914-4721-ad0a-5aa00a1b27aeCN=ExampleOrg.com Issuing CA 01 G2, DC=example, DC=example, DC=org10/15/2025 11:52:24ExpiredREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\MyCN=120ae221-3914-4721-ad0a-5aa00a1b27aeCN=ExampleOrg.com Issuing CA 01 G2, DC=example, DC=example, DC=org10/15/2025 11:52:24ExpiredREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\MyCN=ExampleOrg.com Issuing CA 01 G2, DC=example, DC=example, DC=orgCN=ExampleOrg.com Root CA G210/15/2025 11:52:24ExpiredREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\MyCN=120ae221-3914-4721-ad0a-5aa00a1b27aeCN=ExampleOrg.com Issuing CA 01 G2, DC=example, DC=example, DC=org10/15/2025 11:52:24ExpiredREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\MyCN=120ae221-3914-4721-ad0a-5aa00a1b27aeCN=ExampleOrg.com Issuing CA 01 G2, DC=example, DC=example, DC=org10/15/2025 11:52:24ExpiredREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\MyCN=120ae221-3914-4721-ad0a-5aa00a1b27aeCN=ExampleOrg.com Issuing CA 01 G2, DC=example, DC=example, DC=org10/15/2025 11:52:24ExpiredREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\MyCN=120ae221-3914-4721-ad0a-5aa00a1b27aeCN=ExampleOrg.com Issuing CA 01 G2, DC=example, DC=example, DC=org10/15/2025 11:52:24ExpiredREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\MyCN=exampleorg-Client-Cert, O=exampleorg International AB, L=Tumba, S=Stockholm, C=SECN=ExampleOrg.com Issuing CA 01 G2, DC=example, DC=example, DC=org10/15/2025 11:52:24ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 01 G2, DC=example, DC=example, DC=org10/15/2025 11:52:24ExpiredREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\MyCN=120ae221-3914-4721-ad0a-5aa00a1b27aeCN=ExampleOrg.com Issuing CA 01 G2, DC=example, DC=example, DC=org10/15/2025 11:52:24ExpiredREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\MyCN=120ae221-3914-4721-ad0a-5aa00a1b27aeCN=ExampleOrg.com Issuing CA 01 G2, DC=example, DC=example, DC=org10/15/2025 11:52:24ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=user@example.org, CN=S-1-12-1-2443217470-1141303839-2023945127-1885011244, DC=be55e3d7-a296-4248-b38b-cbef3af2203aCN=MS-Organization-P2P-Access [2025]12/11/2025 10:57:36ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 02, DC=example, DC=example, DC=org02/26/2026 09:22:19ExpiredREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyOID.1.3.6.1.4.1.25461.4.49.2=834782572, OID.1.3.6.1.4.1.25461.4.49.1=01790025991, C=US, S=CA, L=Santa Clara, O=Palo Alto Networks, CN=01790025991C=US, O=Palo-Alto-Networks-Inc., CN=USW-Client-Issuing-CA2-G503/21/2026 13:50:19ExpiredREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\MyCN=120ae221-3914-4721-ad0a-5aa00a1b27ae, DC=be55e3d7-a296-4248-b38b-cbef3af2203aCN=MS-Organization-P2P-Access [2026]06/16/2026 16:42:02Expiring <=30dREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\MyCN=Example UserCN=ExampleOrg.com Issuing CA 02, DC=example, DC=example, DC=org06/24/2026 17:18:10Expiring <=30dREDACTED-CERT-THUMBPRINT
Cert:\CurrentUser\RootCN=Microsoft Intune Root Certification AuthorityCN=Microsoft Intune Root Certification Authority08/12/2026 02:00:00Expiring <=90dREDACTED-CERT-THUMBPRINT
Cert:\LocalMachine\RootCN=Microsoft Intune Root Certification AuthorityCN=Microsoft Intune Root Certification Authority08/12/2026 02:00:00Expiring <=90dREDACTED-CERT-THUMBPRINT

Remote Access Indicators

SourceNameVersionEvidenceRisk
Installed softwareExample Remote Support Tool15.78.4Example Remote ToolReview

Developer / Admin Tools

ToolVersionPublisherWhy it matters
Npcap1.79Nmap ProjectUseful admin/developer tool; confirm expected and patched.
OpenSSL 3.4.1 Light (64-bit)3.4.1OpenSSL Win64 Installer TeamUseful admin/developer tool; confirm expected and patched.
PowerShell 7.4.7.0-x647.4.7.0Microsoft CorporationUseful admin/developer tool; confirm expected and patched.
PowerShell 7-x647.6.2.0Microsoft CorporationUseful admin/developer tool; confirm expected and patched.
PuTTY release 0.81 (64-bit)0.81.0.0Simon TathamUseful admin/developer tool; confirm expected and patched.
USBPcap 1.5.4.01.5.4.0Tomasz MonUseful admin/developer tool; confirm expected and patched.
Windows Subsystem for Linux2.4.12.0Microsoft CorporationUseful admin/developer tool; confirm expected and patched.
Windows Subsystem for Linux Update5.10.102.1Microsoft CorporationUseful admin/developer tool; confirm expected and patched.
Windows Subsystem for Linux WSLg Preview1.0.27Microsoft CorporationUseful admin/developer tool; confirm expected and patched.
Wireshark 4.6.6 x644.6.6The Wireshark developer community, https://www.wireshark.orgUseful admin/developer tool; confirm expected and patched.

Scheduled Tasks for Review

TaskPathStateActionRisk
OneDrive Per-Machine Standalone Update Task\ReadyC:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe Review
OneDrive Reporting Task-S-1-12-1-2443217470-1141303839-2023945127-1885011244\ReadyC:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe /reportingReview
OneDrive Startup Task-S-1-12-1-2443217470-1141303839-2023945127-1885011244\ReadyC:\Program Files\Microsoft OneDrive\26.095.0519.0003\OneDriveLauncher.exe /startInstancesReview
Cloud Managed Desktop Extension Health Evaluation\Microsoft\CMD\ReadyC:\Program Files\Microsoft Cloud Managed Desktop Extension\CMDExtension\ClientHealth\Microsoft.Management.Services.CloudManagedDesktop.Agent.ClientHealth.exe Review
Intune Management Extension Health Evaluation\Microsoft\Intune\ReadyC:\Program Files (x86)\Microsoft Intune Management Extension\ClientHealthEval.exe Review
Office Actions Server\Microsoft\Office\ReadyC:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\ActionsServer\ActionsServer.exe availabilitycheckReview
Office Automatic Updates 2.0\Microsoft\Office\ReadyC:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /frequentupdate SCHEDULEDTASK displaylevel=FalseReview
Office Background Push Maintenance\Microsoft\Office\ReadyC:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\opushutil.exe /pushregistrationReview
Office ClickToRun Service Monitor\Microsoft\Office\ReadyC:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /WatchServiceReview
Office Feature Updates\Microsoft\Office\ReadyC:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe Review
Office Feature Updates Logon\Microsoft\Office\ReadyC:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe /onlogonReview
Office Performance Monitor\Microsoft\Office\ReadyC:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe Review
Office Serviceability Manager\Microsoft\Office\ReadyC:\Program Files\Common Files\Microsoft Shared\ClickToRun\officesvcmgr.exe /checkinReview
Office Startup Maintenance\Microsoft\Office\ReadyC:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\ActionsServer\ActionsServer.exe wacheckReview
.NET Framework NGEN v4.0.30319\Microsoft\Windows\.NET Framework\Ready Review
.NET Framework NGEN v4.0.30319 64\Microsoft\Windows\.NET Framework\Ready Review
RecoverabilityToastTask\Microsoft\Windows\AccountHealth\Ready Review
AD RMS Rights Policy Template Management (Manual)\Microsoft\Windows\Active Directory Rights Management Services Client\Ready Review
MareBackup\Microsoft\Windows\Application Experience\Ready%windir%\system32\compattelrunner.exe -m:aeinv.dll -f:UpdateSoftwareInventoryW invsvc | %windir%\system32\compattelrunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun | %windir%\system32\compattelrunner.exe -m:aemarebackup.dll -f:BackupMareDataReview
Microsoft Compatibility Appraiser Exp\Microsoft\Windows\Application Experience\Ready%windir%\system32\compattelrunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun expressReview
PcaPatchDbTask\Microsoft\Windows\Application Experience\Ready%windir%\system32\rundll32.exe %windir%\system32\PcaSvc.dll,PcaPatchSdbTaskReview
SdbinstMergeDbTask\Microsoft\Windows\Application Experience\Ready%windir%\system32\sdbinst.exe -mmReview
StartupAppTask\Microsoft\Windows\Application Experience\Ready%windir%\system32\rundll32.exe Startupscan.dll,SusRunTaskReview
appuriverifierdaily\Microsoft\Windows\ApplicationData\Ready%windir%\system32\AppHostRegistrationVerifier.exe Review
appuriverifierinstall\Microsoft\Windows\ApplicationData\Ready%windir%\system32\AppHostRegistrationVerifier.exe Review
CleanupTemporaryState\Microsoft\Windows\ApplicationData\Ready%windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryStateHigh
DsSvcCleanup\Microsoft\Windows\ApplicationData\Ready%windir%\system32\dstokenclean.exe Review
Backup\Microsoft\Windows\AppListBackup\Ready Review
BackupNonMaintenance\Microsoft\Windows\AppListBackup\Ready Review
Proxy\Microsoft\Windows\Autochk\Ready%windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperationsReview
BitLocker Encrypt All Drives\Microsoft\Windows\BitLocker\Ready Review
BitLocker MDM policy Refresh\Microsoft\Windows\BitLocker\Ready Review
UninstallDeviceTask\Microsoft\Windows\Bluetooth\ReadyBthUdTask.exe $(Arg0)Review
BgTaskRegistrationMaintenanceTask\Microsoft\Windows\BrokerInfrastructure\Ready Review
maintenancetasks\Microsoft\Windows\capabilityaccessmanager\Ready%windir%\system32\rundll32.exe %windir%\system32\CapabilityAccessManager.dll,CapabilityAccessManagerDoStoreMaintenanceReview
UserTask\Microsoft\Windows\CertificateServicesClient\Ready Review
UserTask-Roam\Microsoft\Windows\CertificateServicesClient\Ready Review
ProactiveScan\Microsoft\Windows\Chkdsk\Ready Review
SyspartRepair\Microsoft\Windows\Chkdsk\Ready%windir%\system32\bcdboot.exe %windir% /sysrepairReview
CreateObjectTask\Microsoft\Windows\CloudExperienceHost\Ready Review
Backup\Microsoft\Windows\CloudRestore\Ready Review
Restore\Microsoft\Windows\CloudRestore\Ready Review
UnifiedConsentSyncTask\Microsoft\Windows\ConsentUX\UnifiedConsent\Ready Review
CmCleanup\Microsoft\Windows\Containers\Ready Review
Consolidator\Microsoft\Windows\Customer Experience Improvement Program\Ready%SystemRoot%\System32\wsqmcons.exe Review
UsbCeip\Microsoft\Windows\Customer Experience Improvement Program\Ready Review
Data Integrity Check And Scan\Microsoft\Windows\Data Integrity Scan\Ready Review
Data Integrity Scan\Microsoft\Windows\Data Integrity Scan\Ready Review
Data Integrity Scan for Crash Recovery\Microsoft\Windows\Data Integrity Scan\Ready Review
ScheduledDefrag\Microsoft\Windows\Defrag\Ready%windir%\system32\defrag.exe -c -h -o -$Review
Device\Microsoft\Windows\Device Information\Ready%windir%\system32\devicecensus.exe SystemCxtReview
Device User\Microsoft\Windows\Device Information\Ready%windir%\system32\devicecensus.exe UserCxtReview
RecommendedTroubleshootingScanner\Microsoft\Windows\Diagnosis\Ready Review
Scheduled\Microsoft\Windows\Diagnosis\Ready Review
UnexpectedCodepath\Microsoft\Windows\Diagnosis\Ready%windir%\system32\UCConfigTask.exe Review
DirectXDatabaseUpdater\Microsoft\Windows\DirectX\Ready%windir%\system32\directxdatabaseupdater.exe Review
DXGIAdapterCache\Microsoft\Windows\DirectX\Ready%windir%\system32\dxgiadaptercache.exe Review
SilentCleanup\Microsoft\Windows\DiskCleanup\Ready%windir%\system32\cleanmgr.exe /autocleanstoragesense /d %systemdrive%Review
Diagnostics\Microsoft\Windows\DiskFootprint\Ready%windir%\system32\disksnapshot.exe -zReview
StorageSense\Microsoft\Windows\DiskFootprint\Ready Review
dusmtask\Microsoft\Windows\DUSM\Ready%SystemRoot%\System32\dusmtask.exe Review
EDP App Launch Task\Microsoft\Windows\EDP\Ready Review
EDP Auth Task\Microsoft\Windows\EDP\Ready Review
EDP Inaccessible Credentials Task\Microsoft\Windows\EDP\Ready Review
StorageCardEncryption Task\Microsoft\Windows\EDP\Ready Review
Login Schedule created by enrollment client\Microsoft\Windows\EnterpriseMgmt\88EECD34-0B9A-4941-87A5-318825AD21BA\Ready%windir%\system32\deviceenroller.exe /o "88EECD34-0B9A-4941-87A5-318825AD21BA" /c /lfReview
PushLaunch\Microsoft\Windows\EnterpriseMgmt\88EECD34-0B9A-4941-87A5-318825AD21BA\Ready%windir%\system32\deviceenroller.exe /o "88EECD34-0B9A-4941-87A5-318825AD21BA" /c /zReview
PushRenewal\Microsoft\Windows\EnterpriseMgmt\88EECD34-0B9A-4941-87A5-318825AD21BA\Ready%windir%\system32\deviceenroller.exe /o "88EECD34-0B9A-4941-87A5-318825AD21BA" /c /yReview
PushUpgrade\Microsoft\Windows\EnterpriseMgmt\88EECD34-0B9A-4941-87A5-318825AD21BA\Ready%windir%\system32\deviceenroller.exe /o "88EECD34-0B9A-4941-87A5-318825AD21BA" /c /PushUpgradeReview
Login Schedule created by enrollment client\Microsoft\Windows\EnterpriseMgmt\FC5071E4-D929-4FA6-945C-A699D2DB51B6\Ready%windir%\system32\deviceenroller.exe /o "FC5071E4-D929-4FA6-945C-A699D2DB51B6" /c /lfReview
PushLaunch\Microsoft\Windows\EnterpriseMgmt\FC5071E4-D929-4FA6-945C-A699D2DB51B6\Ready%windir%\system32\deviceenroller.exe /o "FC5071E4-D929-4FA6-945C-A699D2DB51B6" /c /zReview
PushRenewal\Microsoft\Windows\EnterpriseMgmt\FC5071E4-D929-4FA6-945C-A699D2DB51B6\Ready%windir%\system32\deviceenroller.exe /o "FC5071E4-D929-4FA6-945C-A699D2DB51B6" /c /yReview
PushUpgrade\Microsoft\Windows\EnterpriseMgmt\FC5071E4-D929-4FA6-945C-A699D2DB51B6\Ready%windir%\system32\deviceenroller.exe /o "FC5071E4-D929-4FA6-945C-A699D2DB51B6" /c /PushUpgradeReview
Retry Schedule created for incomplete session {B3E20F4B-F23F-4871-8196-17605577F151}\Microsoft\Windows\EnterpriseMgmt\SessionRetry\88EECD34-0B9A-4941-87A5-318825AD21BA\Ready%windir%\system32\deviceenroller.exe /o "88EECD34-0B9A-4941-87A5-318825AD21BA" /InitiationID "{B3E20F4B-F23F-4871-8196-17605577F151}" /c /vReview
ExploitGuard MDM policy Refresh\Microsoft\Windows\ExploitGuard\Ready Review
DmClient\Microsoft\Windows\Feedback\Siuf\Ready%windir%\system32\dmclient.exe Review
DmClientOnScenarioDownload\Microsoft\Windows\Feedback\Siuf\Ready%windir%\system32\dmclient.exe utcwnfReview
File History (maintenance mode)\Microsoft\Windows\FileHistory\Ready Review
GovernedFeatureUsageProcessing\Microsoft\Windows\Flighting\FeatureConfig\Ready Review
ReconcileConfigs\Microsoft\Windows\Flighting\FeatureConfig\Ready Review
ReconcileFeatures\Microsoft\Windows\Flighting\FeatureConfig\Ready Review
SafeguardsReconciliation\Microsoft\Windows\Flighting\FeatureConfig\Ready Review
UsageDataFlushing\Microsoft\Windows\Flighting\FeatureConfig\Ready Review
UsageDataReceiver\Microsoft\Windows\Flighting\FeatureConfig\Ready Review
UsageDataReporting\Microsoft\Windows\Flighting\FeatureConfig\Ready Review
RefreshCache\Microsoft\Windows\Flighting\OneSettings\Ready Review
Monitoring\Microsoft\Windows\Hotpatch\Ready%systemroot%\system32\cmd.exe /d /c %systemroot%\system32\hpatchmonTask.cmdReview
InputSettingsRestoreDataAvailable\Microsoft\Windows\input\Ready Review
LocalUserSyncDataAvailable\Microsoft\Windows\input\Ready Review
MouseSyncDataAvailable\Microsoft\Windows\input\Ready Review
PenSyncDataAvailable\Microsoft\Windows\input\Ready Review
RemoteMouseSyncDataAvailable\Microsoft\Windows\input\Ready Review
RemotePenSyncDataAvailable\Microsoft\Windows\input\Ready Review
RemoteTouchpadSyncDataAvailable\Microsoft\Windows\input\Ready Review
syncpensettings\Microsoft\Windows\input\Ready Review
TouchpadSyncDataAvailable\Microsoft\Windows\input\Ready Review
RestoreDevice\Microsoft\Windows\InstallService\Ready Review
ScanForUpdates\Microsoft\Windows\InstallService\Ready Review
ScanForUpdatesAsUser\Microsoft\Windows\InstallService\Ready Review
Synchronize Language Settings\Microsoft\Windows\International\Ready Review
La57Cleanup\Microsoft\Windows\Kernel\Ready%windir%\system32\la57setup.exe Review
Installation\Microsoft\Windows\LanguageComponentsInstaller\Ready Review
ReconcileLanguageResources\Microsoft\Windows\LanguageComponentsInstaller\Ready Review
Notifications\Microsoft\Windows\Location\Ready%windir%\System32\LocationNotificationWindows.exe Review
WindowsActionDialog\Microsoft\Windows\Location\Ready%windir%\System32\WindowsActionDialog.exe Review
WinSAT\Microsoft\Windows\Maintenance\Ready Review
Cellular\Microsoft\Windows\Management\Provisioning\Ready%windir%\system32\ProvTool.exe /turn 7 /source CellStateChangeTaskReview
Logon\Microsoft\Windows\Management\Provisioning\Ready%windir%\system32\ProvTool.exe /turn 5 /source LogonIdleTaskReview
MapsToastTask\Microsoft\Windows\Maps\Ready Review
AutomaticOfflineMemoryDiagnostic\Microsoft\Windows\MemoryDiagnostic\Ready Review
ProcessMemoryDiagnosticEvents\Microsoft\Windows\MemoryDiagnostic\Ready Review
MNO Metadata Parser\Microsoft\Windows\Mobile Broadband Accounts\Ready%SystemRoot%\System32\MbaeParserTask.exe Review
LPRemove\Microsoft\Windows\MUI\Ready%windir%\system32\lpremove.exe Review
SystemSoundsService\Microsoft\Windows\Multimedia\Running Review
NcsiIdentifyUserProxies\Microsoft\Windows\Network Connectivity Status Indicator\Ready Review
WiFiTask\Microsoft\Windows\NlaSvc\Ready%SystemRoot%\System32\WiFiTask.exe nlaReview
PCR Prediction Framework Firmware Update Task\Microsoft\Windows\PCRPF\Ready%windir%\system32\rundll32.exe %windir%\system32\pcrpf.dll,NotifyFirmwareUpdateStagedReview
RequestTrace\Microsoft\Windows\PerformanceTrace\Ready Review
ShowFeedbackToast\Microsoft\Windows\PerformanceTrace\Ready Review
WhesvcToast\Microsoft\Windows\PerformanceTrace\Ready Review
Device Install Group Policy\Microsoft\Windows\Plug and Play\Ready Review
Device Install Reboot Required\Microsoft\Windows\Plug and Play\Ready Review
Sysprep Generalize Drivers\Microsoft\Windows\Plug and Play\Ready%SystemRoot%\System32\drvinst.exe 6Review
AnalyzeSystem\Microsoft\Windows\Power Efficiency Diagnostics\Ready Review
EduPrintProv\Microsoft\Windows\Printing\Ready%windir%\system32\eduprintprov.exe Review
PrinterCleanupTask\Microsoft\Windows\Printing\Ready Review
Initialization\Microsoft\Windows\ReFsDedupSvc\Ready Review
RegIdleBackup\Microsoft\Windows\Registry\Ready Review
Report update status\Microsoft\Windows\RemoteApp and Desktop Connections Update\user@example.org\Ready%SYSTEMROOT%\System32\RUNDLL32 tsworkspace,WorkspaceStatusNotify2Review
Start Workspace Runtime at logon\Microsoft\Windows\RemoteApp and Desktop Connections Update\user@example.org\Ready Review
Update connections\Microsoft\Windows\RemoteApp and Desktop Connections Update\user@example.org\Ready%SYSTEMROOT%\System32\RUNDLL32 tsworkspace,TaskUpdateWorkspaces2Review
IntelligentPwdlessTask\Microsoft\Windows\Security\Pwdless\Ready Review
StartComponentCleanup\Microsoft\Windows\Servicing\Ready Review
PITRTask\Microsoft\Windows\Setup\Ready Review
SetupRecoveryDataTask\Microsoft\Windows\Setup\Ready Review
CreateObjectTask\Microsoft\Windows\Shell\Ready Review
FamilySafetyMonitor\Microsoft\Windows\Shell\Ready%windir%\System32\wpcmon.exe Review
FamilySafetyRefreshTask\Microsoft\Windows\Shell\Ready Review
IndexerAutomaticMaintenance\Microsoft\Windows\Shell\Ready Review
ThemesSyncedImageDownload\Microsoft\Windows\Shell\Ready Review
UninstallSMB1ClientTask\Microsoft\Windows\SMB\Ready%windir%\system32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& %windir%\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Client"Review
UninstallSMB1ServerTask\Microsoft\Windows\SMB\Ready%windir%\system32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& %windir%\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Server"Review
SpaceAgentTask\Microsoft\Windows\SpacePort\Ready%windir%\system32\SpaceAgent.exe Review
SpaceManagerTask\Microsoft\Windows\SpacePort\Ready%windir%\system32\spaceman.exe /WorkReview
MaintenanceTasks\Microsoft\Windows\StateRepository\Ready%windir%\system32\rundll32.exe %windir%\system32\Windows.StateRepositoryClient.dll,StateRepositoryDoMaintenanceTasksReview
Storage Tiers Management Initialization\Microsoft\Windows\Storage Tiers Management\Ready Review
EnableLicenseAcquisition\Microsoft\Windows\Subscription\Ready%SystemRoot%\system32\ClipRenew.exe -eReview
LicenseAcquisition\Microsoft\Windows\Subscription\Ready%SystemRoot%\system32\ClipRenew.exe Review
PowerGridForecastTask\Microsoft\Windows\Sustainability\Ready Review
SustainabilityTelemetry\Microsoft\Windows\Sustainability\Ready Review
ResPriStaticDbSync\Microsoft\Windows\Sysmain\Ready Review
WsSwapAssessmentTask\Microsoft\Windows\Sysmain\Ready%windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTaskReview
SR\Microsoft\Windows\SystemRestore\Ready%windir%\system32\srtasks.exe ExecuteScheduledSPPCreationReview
Interactive\Microsoft\Windows\Task Manager\Ready Review
MsCtfMonitor\Microsoft\Windows\TextServicesFramework\Ready Review
ForceSynchronizeTime\Microsoft\Windows\Time Synchronization\Ready Review
SynchronizeTime\Microsoft\Windows\Time Synchronization\Ready%windir%\system32\sc.exe start w32time task_startedReview
SynchronizeTimeZone\Microsoft\Windows\Time Zone\Ready%windir%\system32\tzsync.exe Review
UPnPHostConfig\Microsoft\Windows\UPnP\Readysc.exe config upnphost start= autoReview
Usb-Notifications\Microsoft\Windows\USB\Ready Review
WiFiTask\Microsoft\Windows\WCM\Ready%SystemRoot%\System32\WiFiTask.exe Review
ResolutionHost\Microsoft\Windows\WDI\Ready Review
Windows Defender Cache Maintenance\Microsoft\Windows\Windows Defender\Ready%ProgramFiles%\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdCacheMaintenanceReview
Windows Defender Cleanup\Microsoft\Windows\Windows Defender\Ready%ProgramFiles%\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdCleanupReview
Windows Defender Scheduled Scan\Microsoft\Windows\Windows Defender\Ready%ProgramFiles%\Windows Defender\MpCmdRun.exe Scan -ScheduleJobReview
Windows Defender Verification\Microsoft\Windows\Windows Defender\Ready%ProgramFiles%\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdVerificationReview
QueueReporting\Microsoft\Windows\Windows Error Reporting\Ready%windir%\system32\wermgr.exe -uploadReview
BfeOnServiceStartTypeChange\Microsoft\Windows\Windows Filtering Platform\Ready%windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChangeReview
UpdateLibrary\Microsoft\Windows\Windows Media Sharing\Ready"%ProgramFiles%\Windows Media Player\wmpnscfg.exe" Review
Calibration Loader\Microsoft\Windows\WindowsColorSystem\Ready Review
Scheduled Start\Microsoft\Windows\WindowsUpdate\Ready%systemroot%\System32\sc.exe start wuauservReview
CacheTask\Microsoft\Windows\Wininet\Running Review
CDSSync\Microsoft\Windows\WlanSvc\Ready Review
MoProfileManagement\Microsoft\Windows\WlanSvc\Ready Review
Work Folders Logon Synchronization\Microsoft\Windows\Work Folders\Ready Review
Work Folders Maintenance Work\Microsoft\Windows\Work Folders\Ready Review
Device-Sync\Microsoft\Windows\Workplace Join\Ready Review
NotificationTask\Microsoft\Windows\WwanSvc\Ready%SystemRoot%\System32\WiFiTask.exe wwanReview
OobeDiscovery\Microsoft\Windows\WwanSvc\Ready Review
XblGameSaveTask\Microsoft\XblGameSave\Ready%windir%\System32\XblGameSaveTask.exe standbyReview
Firefox Background Update S-1-12-1-2443217470-1141303839-2023945127-1885011244 308046B0AF4A39CB\Mozilla\ReadyC:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdateReview
SoftLandingCreativeManagementTask\SoftLanding\S-1-12-1-2443217470-1141303839-2023945127-1885011244\Ready Review

Services Running From Writable/Suspicious Paths

NameDisplay nameStateStart modePathRisk
hcpclientcoreHCP client core serviceRunningAuto"C:\Program Files\Ricoh\PMC Client\hcpclientcore.exe" run --service --config \\?\C:\ProgramData\hcpclientcore\hcpclientcore.confReview - ProgramData path
ZoomCptServiceZoom Sharing ServiceRunningAuto"C:\Program Files\Common Files\Zoom\Support\CptService.exe" -user_path "C:\Users\example.user\AppData\Roaming\Zoom"High - user-writable path

PATH Hijack Risk

PathRiskReason
C:\Users\example.user\AppData\Local\Microsoft\WindowsAppsHighUser-writable-looking PATH directory
C:\Users\example.user\AppData\Local\Programs\FiddlerHighUser-writable-looking PATH directory
C:\Users\example.user\AppData\Local\Microsoft\WindowsAppsHighUser-writable-looking PATH directory

USB Storage Policy

USBSTOR StartUSB storage enabledRemovable storage deny allNote
3TrueNot configuredUSBSTOR Start=4 usually means USB mass storage disabled.

Proxy / VPN

Proxy enabledProxy server
0
NameServerTunnel typeSplit tunnelingAll-user
No data captured.

Domain / LAPS

Domain joinedDomainLAPS policy
FalseWORKGROUPConfigured/Policy present

Browser Extensions

Mild suggestion: Browser extension inventory only shows what is installed locally. For browser-side website risk review, Scantide Observe can complement this by checking cookies, headers, scripts, iframes, forms and tracking beacons while browsing. It does not replace endpoint security, patching, or browser extension governance.
BrowserProfileExtension IDNameVersion
ChromeDefaultblojlgglhfcmpigjbkllcgjmhincdjhbSnow Web Application Metering1.0.8_0
ChromeDefaultcdblaggcibgbankgilackljdpdhhcine__MSG_appName__6.1.14_0
ChromeDefaultghbmnnjooekpmoecnnnilnnbdlolhkhi__MSG_extName__1.104.1_0
ChromeDefaulthaofejeafnajjfidaekiaejelpompjknScantide Observe3.1.10_0
ChromeDefaultmiinajhilmmkpdoaimnoncdiliaejpdkNexthink26.5.1_0
ChromeDefaultnmmhkkegccagdldgiimedpiccmgmieda__MSG_APP_NAME__1.0.0.6_0
ChromeDefaultTemp
EdgeDefaultcgjgjfacjflmgphhhepmbhhbgjieaecnMicrosoft Edge Unminification Extension135.0.3176.0_0
EdgeDefaultfmammgdlmljodabkafnkpagekcigmabkSnow Web Application Metering1.0.8_0
EdgeDefaulthigleibocjmgcnbikjneplkibiopjnkpNexthink26.5.1_0
EdgeDefaultjmjflgjpcpepeafmmgdpfkogkghcpihaEdge relevant text changes1.2.1_0
EdgeDefaultkfbdpdaobnofkbopebjglnaadopfikhhMicrosoft Edge DevTools Enhancements113.0.1765.0_0
EdgeProfile 1jmjflgjpcpepeafmmgdpfkogkghcpihaEdge relevant text changes1.2.1_0
EdgeProfile 2jmjflgjpcpepeafmmgdpfkogkghcpihaEdge relevant text changes1.2.1_0
Firefoxidjefsxd.default-releaseuser@example.orgScantide Observe3.1.11
Firefoxidjefsxd.default-releaseuser@example.orgSnow Web Application Metering1.2.5
Firefoxidjefsxd.default-releaseuser@example.orgForm Autofill1.0.1
Firefoxidjefsxd.default-releaseuser@example.orgPicture-In-Picture1.0.0
Firefoxidjefsxd.default-releaseuser@example.orgAdd-ons Search Detection3.0.0
Firefoxidjefsxd.default-releaseuser@example.orgWeb Compatibility Interventions151.6.0
Firefoxidjefsxd.default-releaseuser@example.orgNew Tab151.4.0
Firefoxidjefsxd.default-releaseuser@example.orgIPP Activator0.1
Firefoxidjefsxd.default-releaseuser@example.orgData Leak Blocker144.0.0
Firefoxidjefsxd.default-releaseuser@example.orgSystem theme — auto1.4.2
Firefoxidjefsxd.default-releaseuser@example.orgAdd-ons Search Detection3.0.0
Firefoxidjefsxd.default-releaseuser@example.orgLight1.3.4
Firefoxidjefsxd.default-releaseuser@example.orgDark1.3.4
Firefoxidjefsxd.default-releaseuser@example.orgFirefox Alpenglow1.5.2
Firefoxidjefsxd.default-releaseuser@example.orgNew Tab153.3.20260605.21338

Installed Software CVE Review

What this means: Installed software names from Windows are less precise than service banners. Scantide queries both the Scantide CVE API and NOTCVE, shows per-source success badges, merges/de-duplicates the review evidence, and treats these as review leads only. Do not treat old CVEs returned for a modern product name as confirmed without checking exact affected version ranges, product edition and exposure.
Combined CVE results loaded from local cache for all 100 product/version pair(s). Cache freshness: <= 30 minutes. Matches with CVEs: 19. False-positive suppressions applied: 1. Results are based on installed-software display names and versions, so treat them as review evidence unless the product/version match is exact.
False positives: Click Add to exclusion to suppress only that exact product + exact version. This requires the Scantide local protocol helper to be installed from the Launcher. The PowerShell command is still shown and can be copied as a fallback. Saved suppressions are stored in C:\ProgramData\Scantide\ScantideLocalCveFalsePositives.json.
ProductVersionInstalled display nameCVE ReviewHighest severityHighest scoreTop CVEsScantide CVENOTCVEFalse positive
OpenSSL3.4.1OpenSSL 3.4.1 Light (64-bit)Possible Critical CVE signal (10)CRITICAL9.8CVE-2003-0851, CVE-2004-0079, CVE-2004-0081, CVE-2004-0112, CVE-2025-15467, CVE-2025-15469, CVE-2026-2673, CVE-2026-28386CachedCachedAdd to exclusion

Command:
powershell.exe -ExecutionPolicy Bypass -File 'C:\Scantide\ScantideLocalCheck.ps1' -AddCveFalsePositive 'OpenSSL|3.4.1'
7-Zip26.01.00.07-Zip 26.01 (x64 edition)Possible Critical CVE signal (5)CRITICAL9.3CVE-2002-0370, CVE-2004-2348, CVE-2008-3075, CVE-2009-1782, CVE-2016-3646CachedCachedAdd to exclusion

Command:
powershell.exe -ExecutionPolicy Bypass -File 'C:\Scantide\ScantideLocalCheck.ps1' -AddCveFalsePositive '7-Zip|26.01.00.0'
Intel(R) Wireless Bluetooth(R)23.30.0.3Intel(R) Wireless Bluetooth(R)Possible High CVE signal (5)HIGH7.8CVE-2019-14620, CVE-2020-0555, CVE-2023-45845, CVE-2023-47859, CVE-2024-24984CachedCachedAdd to exclusion

Command:
powershell.exe -ExecutionPolicy Bypass -File 'C:\Scantide\ScantideLocalCheck.ps1' -AddCveFalsePositive 'Intel(R) Wireless Bluetooth(R)|23.30.0.3'
Microsoft OneDrive26.095.0519.0003Microsoft OneDrivePossible Critical CVE signal (5)CRITICAL9.1CVE-2018-0592, CVE-2018-0593, CVE-2020-0654, CVE-2020-1465, CVE-2022-23255CachedCachedAdd to exclusion

Command:
powershell.exe -ExecutionPolicy Bypass -File 'C:\Scantide\ScantideLocalCheck.ps1' -AddCveFalsePositive 'Microsoft OneDrive|26.095.0519.0003'
PowerShell7.4.7.0PowerShell 7.4.7.0-x64Possible Critical CVE signal (5)CRITICAL9.8CVE-2017-8565, CVE-2018-7890, CVE-2023-48795, CVE-2025-49734, CVE-2026-26143CachedCachedAdd to exclusion

Command:
powershell.exe -ExecutionPolicy Bypass -File 'C:\Scantide\ScantideLocalCheck.ps1' -AddCveFalsePositive 'PowerShell|7.4.7.0'
AD Info1.8.2AD InfoPossible Critical CVE signal (4)CRITICAL10CVE-2000-1023, CVE-2001-1011, CVE-2001-1431, CVE-2001-1434CachedCachedAdd to exclusion

Command:
powershell.exe -ExecutionPolicy Bypass -File 'C:\Scantide\ScantideLocalCheck.ps1' -AddCveFalsePositive 'AD Info|1.8.2'
Notepad++8.9.6.4Notepad++ (64-bit x64)Possible High CVE signal (4)HIGH8.4CVE-2007-5145, CVE-2025-49144, CVE-2025-56383, CVE-2026-25866CachedCachedAdd to exclusion

Command:
powershell.exe -ExecutionPolicy Bypass -File 'C:\Scantide\ScantideLocalCheck.ps1' -AddCveFalsePositive 'Notepad++|8.9.6.4'
PuTTY0.81.0.0PuTTY release 0.81 (64-bit)Possible Critical CVE signal (4)CRITICAL9.8CVE-2013-4206, CVE-2013-4207, CVE-2013-4852, CVE-2017-17131CachedCachedAdd to exclusion

Command:
powershell.exe -ExecutionPolicy Bypass -File 'C:\Scantide\ScantideLocalCheck.ps1' -AddCveFalsePositive 'PuTTY|0.81.0.0'
PowerShell7.6.2.0PowerShell 7-x64Possible Critical CVE signal (3)CRITICAL9.8CVE-2017-8565, CVE-2018-7890, CVE-2023-48795CachedCachedAdd to exclusion

Command:
powershell.exe -ExecutionPolicy Bypass -File 'C:\Scantide\ScantideLocalCheck.ps1' -AddCveFalsePositive 'PowerShell|7.6.2.0'
Example Display and Peripheral Manager2.1.0.24Example Display and Peripheral ManagerPossible High CVE signal (2)HIGH7.3CVE-2025-46430, CVE-2026-21419CachedCachedAdd to exclusion

Command:
powershell.exe -ExecutionPolicy Bypass -File 'C:\Scantide\ScantideLocalCheck.ps1' -AddCveFalsePositive 'Example Display and Peripheral Manager|2.1.0.24'
Fiddler4.4.9.2FiddlerPossible High CVE signal (2)HIGH8.8CVE-2019-12097, CVE-2020-13661CachedCachedAdd to exclusion

Command:
powershell.exe -ExecutionPolicy Bypass -File 'C:\Scantide\ScantideLocalCheck.ps1' -AddCveFalsePositive 'Fiddler|4.4.9.2'
GlobalProtect6.3.3GlobalProtectPossible High CVE signal (2)HIGH8.1CVE-2017-7409, CVE-2019-1579CachedCachedAdd to exclusion

Command:
powershell.exe -ExecutionPolicy Bypass -File 'C:\Scantide\ScantideLocalCheck.ps1' -AddCveFalsePositive 'GlobalProtect|6.3.3'
Google Chrome149.0.7827.115Google ChromePossible Critical CVE signal (2)CRITICAL9.3CVE-2008-5915, CVE-2009-1598CachedCachedAdd to exclusion

Command:
powershell.exe -ExecutionPolicy Bypass -File 'C:\Scantide\ScantideLocalCheck.ps1' -AddCveFalsePositive 'Google Chrome|149.0.7827.115'
Mozilla Firefox151.0.4Mozilla Firefox (x64 en-US)Possible Critical CVE signal (2)CRITICAL10CVE-2004-0904, CVE-2004-0905CachedCachedAdd to exclusion

Command:
powershell.exe -ExecutionPolicy Bypass -File 'C:\Scantide\ScantideLocalCheck.ps1' -AddCveFalsePositive 'Mozilla Firefox|151.0.4'
AD Info Free Edition1.7.92AD Info Free EditionPossible Medium CVE signal (1)MEDIUM6.8CVE-2021-20876CachedCachedAdd to exclusion

Command:
powershell.exe -ExecutionPolicy Bypass -File 'C:\Scantide\ScantideLocalCheck.ps1' -AddCveFalsePositive 'AD Info Free Edition|1.7.92'
Intel(R) LMS1.0.0.0Intel(R) LMSPossible Medium CVE signal (1)MEDIUM6.4CVE-2020-8704CachedCachedAdd to exclusion

Command:
powershell.exe -ExecutionPolicy Bypass -File 'C:\Scantide\ScantideLocalCheck.ps1' -AddCveFalsePositive 'Intel(R) LMS|1.0.0.0'
Intel(R) Management Engine Driver1.0.0.0Intel(R) Management Engine DriverPossible Medium CVE signal (1)MEDIUM5.5CVE-2021-33087CachedCachedAdd to exclusion

Command:
powershell.exe -ExecutionPolicy Bypass -File 'C:\Scantide\ScantideLocalCheck.ps1' -AddCveFalsePositive 'Intel(R) Management Engine Driver|1.0.0.0'
ISS_Drivers_x643.10.100.4446ISS_Drivers_x64Possible High CVE signal (1)HIGH7.1CVE-2024-50035CachedCachedAdd to exclusion

Command:
powershell.exe -ExecutionPolicy Bypass -File 'C:\Scantide\ScantideLocalCheck.ps1' -AddCveFalsePositive 'ISS_Drivers_x64|3.10.100.4446'
Microsoft Intune Management Extension1.101.111.0Microsoft Intune Management ExtensionPossible High CVE signal (1)HIGH8.1CVE-2021-31980CachedCachedAdd to exclusion

Command:
powershell.exe -ExecutionPolicy Bypass -File 'C:\Scantide\ScantideLocalCheck.ps1' -AddCveFalsePositive 'Microsoft Intune Management Extension|1.101.111.0'
7-Zip26.017-Zip 26.01 (x64)False positive suppressedSuppressedCVE-2002-0370, CVE-2004-2348, CVE-2008-3075, CVE-2009-1782, CVE-2016-3646CachedCachedAlready suppressed for this exact product/version

Installed Software Inventory

What this means: This is the registry-based installed software inventory used for local review and CVE matching. Rows with a light red/orange background have possible local CVE review signals and should be verified against exact affected version ranges before being treated as confirmed.
NameVersionPublisherInstall DateCVE Review
„Microsoft 365“ programos įmonėms - lt-lt.proof16.0.20026.20168Microsoft CorporationNot matched
7-Zip 26.01 (x64 edition)26.01.00.0Igor Pavlov20260428Possible Critical CVE signal (5)
7-Zip 26.01 (x64)26.01Igor PavlovFalse positive suppressed
AD Info1.8.2Cjwdev20260615Possible Critical CVE signal (4)
AD Info Free Edition1.7.92Cjwdev20220414Possible Medium CVE signal (1)
Angry IP Scanner3.8.2Angry IP ScannerNot matched
Aplicaciones de Microsoft 365 para empresas - es-es.proof16.0.20026.20168Microsoft CorporationNot matched
Aplicații Microsoft 365 pentru întreprindere - ro-ro.proof16.0.20026.20168Microsoft CorporationNot matched
Aplikacje Microsoft 365 dla przedsiębiorstw - pl-pl.proof16.0.20026.20168Microsoft CorporationNot matched
Citrix XenCenter7.0.1Citrix Systems, Inc.20231006Not matched
CPU Speed Pro version 33CPU Speed Pro20240416Not matched
CrowdStrike Device Control7.35.20865.0CrowdStrike, Inc.20260609Not matched
CrowdStrike Firmware Analysis7.14.18456.0CrowdStrike, Inc.20241003Not matched
CrowdStrike Sensor Platform7.36.20805.0CrowdStrike, Inc.20260609Not matched
CrowdStrike Windows Sensor7.36.20805.0CrowdStrike, Inc.20260609Not matched
Dell Active Pen Service7.7.1.117Wacom Technology Corp.Not matched
Dell Command | Update for Windows Universal5.7.0Example Vendor20260415Not matched
Dell ControlVault Host Components Installer 64 bit5.15.14.19Broadcom Limited20250916Not matched
Dell Core Services1.14.149.0Dell, Inc.20260415Not matched
Example Display and Peripheral Manager2.1.0.24Dell Technologies20260122Possible High CVE signal (2)
Dell Peripheral Core2.1.0.356Example VendorNot matched
Dell SupportAssist5.1.1.3567Example Vendor20260609Not matched
Dell SupportAssist OS Recovery Plugin for Dell Update5.5.16.1Example Vendor20260519Not matched
Digi Device DiscoveryNot matched
Documentation Manager23.30.0.6Intel Corporation20240325Not matched
Dynamic Application Loader Host Interface Service1.0.0.0Intel Corporation20250820Not matched
eM Client10.0.3530.0eM Client Inc.20241008Not matched
Fiddler4.4.9.2TelerikPossible High CVE signal (2)
GlobalProtect6.3.3Palo Alto Networks20260615Possible High CVE signal (2)
Google Chrome149.0.7827.115Google LLC20260612Possible Critical CVE signal (2)
Intel Driver && Support Assistant26.1.0.2Intel20260401Not matched
Intel(R) Computing Improvement Program2.4.10965Intel Corporation20250214Not matched
Intel(R) Graphics Software & Drivers1.0.1168.2Intel(R) CorporationNot matched
Intel(R) LMS1.0.0.0Intel Corporation20250820Possible Medium CVE signal (1)
Intel(R) Management Engine Components1.0.0.0Intel Corporation20250820Not matched
Intel(R) Management Engine Components2514.7.16.0Intel CorporationNot matched
Intel(R) Management Engine Driver1.0.0.0Intel Corporation20250820Possible Medium CVE signal (1)
Intel(R) ME WMI Provider1.0.0.0Intel Corporation20250820Not matched
Intel(R) SOL LMS Extension1.0.0.0Intel Corporation20250820Not matched
Intel(R) Wireless Bluetooth(R)23.30.0.3Intel Corporation20240325Possible High CVE signal (5)
Intel(R) Wireless Manageability Driver1.0.0.0Intel Corporation20250820Not matched
Intel(R) Wireless Manageability Driver Extension1.0.0.0Intel Corporation20250820Not matched
Intel® Driver & Support Assistant26.1.0.2Intel20260401Not matched
Intel® Integrated Sensor Solution3.10.100.4446Intel CorporationNot matched
Intel® Software Installer23.30.0.6Intel CorporationNot matched
ISS_Drivers_x643.10.100.4446Intel Corporation20220427Possible High CVE signal (1)
Kurumlar için Microsoft 365 Uygulamaları - tr-tr.proof16.0.20026.20168Microsoft CorporationNot matched
Microsoft .NET Host - 8.0.28 (x64)64.112.53549Microsoft Corporation20260611Not matched
Microsoft .NET Host - 8.0.28 (x86)64.112.53549Microsoft Corporation20260615Not matched
Microsoft .NET Host - 9.0.17 (x64)72.68.53536Microsoft Corporation20260615Not matched
Microsoft .NET Host FX Resolver - 8.0.28 (x64)64.112.53549Microsoft Corporation20260611Not matched
Microsoft .NET Host FX Resolver - 8.0.28 (x86)64.112.53549Microsoft Corporation20260615Not matched
Microsoft .NET Host FX Resolver - 9.0.17 (x64)72.68.53536Microsoft Corporation20260615Not matched
Microsoft .NET Runtime - 8.0.28 (x64)64.112.53549Microsoft Corporation20260611Not matched
Microsoft .NET Runtime - 8.0.28 (x86)64.112.53549Microsoft Corporation20260615Not matched
Microsoft .NET Runtime - 9.0.17 (x64)72.68.53536Microsoft Corporation20260615Not matched
Microsoft 365 Apps for enterprise - da-dk.proof16.0.20026.20168Microsoft CorporationNot matched
Microsoft 365 Apps for Enterprise - de-de.proof16.0.20026.20168Microsoft CorporationNot matched
Microsoft 365 Apps for enterprise - en-us16.0.20026.20168Microsoft CorporationNot matched
Microsoft 365 Apps for enterprise - en-us.proof16.0.20026.20168Microsoft CorporationNot matched
Microsoft 365 Apps for enterprise - fr-fr.proof16.0.20026.20168Microsoft CorporationNot matched
Microsoft 365 Apps for enterprise - it-it.proof16.0.20026.20168Microsoft CorporationNot matched
Microsoft 365 Apps for enterprise - ja-jp.proof16.0.20026.20168Microsoft CorporationNot matched
Microsoft 365 Apps for enterprise - nb-no.proof16.0.20026.20168Microsoft CorporationNot matched
Microsoft 365 Apps para Grandes Empresas - pt-pt.proof16.0.20026.20168Microsoft CorporationNot matched
Microsoft 365 Apps pro velké organizace - cs-cz.proof16.0.20026.20168Microsoft CorporationNot matched
Microsoft 365 programmas lieluzņēmumiem - lv-lv.proof16.0.20026.20168Microsoft CorporationNot matched
Microsoft 365 -sovellukset suuryrityksille - fi-fi.proof16.0.20026.20168Microsoft CorporationNot matched
Microsoft 365 suurettevõtterakendused - et-ee.proof16.0.20026.20168Microsoft CorporationNot matched
Microsoft 365 企业应用版 - zh-cn.proof16.0.20026.20168Microsoft CorporationNot matched
Microsoft 365-appar för företag - sv-se.proof16.0.20026.20168Microsoft CorporationNot matched
Microsoft 365-apps voor ondernemingen - nl-nl.proof16.0.20026.20168Microsoft CorporationNot matched
Microsoft ASP.NET Core 8.0.28 - Shared Framework (x86)8.0.28.26269Microsoft CorporationNot matched
Microsoft ASP.NET Core 8.0.28 Shared Framework (x86)8.0.28.26269Microsoft Corporation20260615Not matched
Microsoft Cloud Managed Desktop Extension1.2.02664.211Microsoft Corporation20240626Not matched
Microsoft Device Inventory Agent26.5.24.2000Microsoft Corporation20260609Not matched
Microsoft Edge149.0.4022.69Microsoft Corporation20260615Not matched
Microsoft Edge WebView2 Runtime149.0.4022.69Microsoft Corporation20260615Not matched
Microsoft Intune Management Extension1.101.111.0Microsoft Corporation20260522Possible High CVE signal (1)
Microsoft OneDrive26.095.0519.0003Microsoft CorporationPossible Critical CVE signal (5)
Microsoft Power BI Desktop (x64)2.102.845.0Microsoft Corporation20220303Not matched
Microsoft PowerBI Desktop (x64)2.102.845.0Microsoft CorporationNot matched
Microsoft Purview Information Protection3.2.92.0Microsoft CorporationNot matched
Microsoft Teams Meeting Add-in for Microsoft Office1.26.08901Microsoft20260506Not matched
Microsoft Update Health Tools5.72.0.0Microsoft Corporation20231106Not matched
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.51.3624714.51.36247Microsoft Corporation20260611Not matched
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.51.3624714.51.36247Microsoft Corporation20260611Not matched
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.51.3624714.51.36247Microsoft Corporation20260611Not matched
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.51.3624714.51.36247Microsoft Corporation20260611Not matched
Microsoft Visual C++ v14 Redistributable (x64) - 14.51.3624714.51.36247.0Microsoft CorporationNot matched
Microsoft Visual C++ v14 Redistributable (x86) - 14.51.3624714.51.36247.0Microsoft CorporationNot matched
Microsoft Windows Desktop Runtime - 8.0.28 (x64)64.112.53617Microsoft Corporation20260611Not matched
Microsoft Windows Desktop Runtime - 8.0.28 (x64)8.0.28.36119Microsoft CorporationNot matched
Microsoft Windows Desktop Runtime - 8.0.28 (x86)64.112.53617Microsoft Corporation20260615Not matched
Microsoft Windows Desktop Runtime - 8.0.28 (x86)8.0.28.36119Microsoft CorporationNot matched
Microsoft Windows Desktop Runtime - 9.0.17 (x64)72.68.53601Microsoft Corporation20260615Not matched
Microsoft Windows Desktop Runtime - 9.0.17 (x64)9.0.17.36118Microsoft CorporationNot matched
Mozilla Firefox (x64 en-US)151.0.4MozillaPossible Critical CVE signal (2)
Mozilla Maintenance Service151.0.4MozillaNot matched
Mozilla Thunderbird ESR (x64 en-US)140.11.1MozillaNot matched
Nagyvállalati Microsoft 365-alkalmazások - hu-hu.proof16.0.20026.20168Microsoft CorporationNot matched
Nexthink Finder6.30.14.1Nexthink S.A.20230320Not matched
Notepad++ (64-bit x64)8.9.6.4Notepad++ TeamPossible High CVE signal (4)
Novabench5.5.1Novabench Inc.20240325Not matched
Npcap1.79Nmap ProjectNot matched
NTFS Permissions Reporter2.3.5Cjwdev20260615Not matched
NTP Query ToolNot matched
NTP ScanNot matched
Office 16 Click-to-Run Extensibility Component16.0.20026.20076Microsoft Corporation20260520Not matched
OpenSSL 3.4.1 Light (64-bit)3.4.1OpenSSL Win64 Installer Team20250311Possible Critical CVE signal (10)
PerformanceTest v11.011.0.1014.0Passmark Software20240416Not matched
PhotoPad Image Editor11.67NCH SoftwareNot matched
PMC Client3.31.0RicohNot matched
PowerShell 7.4.7.0-x647.4.7.0Microsoft CorporationPossible Critical CVE signal (5)
PowerShell 7-x647.6.2.0Microsoft Corporation20260525Possible Critical CVE signal (3)
PuTTY release 0.81 (64-bit)0.81.0.0Simon Tatham20260615Possible Critical CVE signal (4)
Qualys Cloud Security Agent6.4.1.22Qualys, Inc.20260409Not matched
Realtek Audio Driver192.168.10.16Realtek Semiconductor Corp.20250304Not matched
Realtek Card Reader10.0.26100.21374Realtek Semiconductor Corp.20250121Not matched
Realtek USB Ethernet Controller All-In-One Windows Driver11.17.20.1030Realtek20250414Not matched
Remote help3.8.0.12Microsoft Corporation20220308Not matched
Scripting Tools for Windows PowerShell: iLO Cmdlets1.5.1.0Hewlett Packard Enterprise20241107Not matched
Scripting Tools for Windows PowerShell: iLO Cmdlets4.0.0.0Hewlett Packard Enterprise20241022Not matched
Snow Inventory Agent for Windows7.5.0Snow Software20260310Not matched
Example Remote Support Tool15.78.4Example Remote ToolNot matched
TreeSize Free V4.5.34.5.3JAM Software20220509Not matched
Uninstall UUByte DMG Editor1.5.8UUByte20220629Not matched
USBPcap 1.5.4.01.5.4.0Tomasz MonNot matched
Webex43.6.0.26407Cisco Systems, Inc20240126Not matched
Win32DiskImager version 1.0.01.0.0ImageWriter Developers20220629Not matched
Windows Subsystem for Linux2.4.12.0Microsoft Corporation20250320Not matched
Windows Subsystem for Linux Update5.10.102.1Microsoft Corporation20220428Not matched
Windows Subsystem for Linux WSLg Preview1.0.27Microsoft Corporation20230320Not matched
Wireshark 4.6.6 x644.6.6The Wireshark developer community, https://www.wireshark.orgNot matched
Zoom Workplace (64-bit)7.0.38856Zoom20260519Not matched
Приложения Microsoft 365 для предприятий - ru-ru.proof16.0.20026.20168Microsoft CorporationNot matched
Програми Microsoft 365 для підприємств - uk-ua.proof16.0.20026.20168Microsoft CorporationNot matched
엔터프라이즈용 Microsoft 365 앱 - ko-kr.proof16.0.20026.20168Microsoft CorporationNot matched

Startup Items

SourceNameCommand
HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\RunSecurityHealthC:\WINDOWS\system32\SecurityHealthSystray.exe
HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\RunRtkAudUService"C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_babf1584c40a3d53\RtkAudUService64.exe" -background
HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\RunWavesSvc"C:\WINDOWS\System32\DriverStore\FileRepository\wavesapo10de.inf_amd64_db3f3288eba6a142\WavesSvc64.exe" -Jack
HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\RunPMC ClientC:\Program Files\Ricoh\PMC Client\hcpclient.exe
HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\RunGlobalProtect"C:\Program Files\Palo Alto Networks\GlobalProtect\PanGPA.exe" -fromWindows
HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOneDrive"C:\Program Files\Microsoft OneDrive\OneDrive.exe" /background
HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\RunCiscoMeetingDaemon"C:\Users\example.user\AppData\Local\WebEx\WebexHost.exe" /daemon /runFrom=autorun
HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\RunMicrosoft.ListsC:\Program Files\Microsoft OneDrive\26.095.0519.0003\OneDrive.Sync.Service.exe
HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Runcom.squirrel.Postman-Agent.PostmanAgentC:\Users\example.user\AppData\Local\Postman-Agent\Postman Agent.exe
HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\RunCiscoSparkC:\Users\example.user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Webex\Webex.lnk /minimized /autostartedWithWindows=true
HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\RunBlueMailC:\WINDOWS\explorer.exe me.blueone.win:noopt:hidden
HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\RunTeams"C:\Users\example.user\AppData\Local\Microsoft\WindowsApps\MSTeams_8wekyb3d8bbwe\ms-teams.exe" msteams:system-initiated
HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\RunMicrosoftEdgeAutoLaunch_996CAB29764A7E71C494B428A956D1DD"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start
Generated by Scantide Local PC Security Check v3.5.175