POWERSTRUX WINDOWS AUDITOR REPORT

Report created on Oct 14, 2025 10:46 AM
Report: 10-14-2025
SourceLast Sync TimeLast Sync In Minutes
time.windows.com,0x9 10/14/2025 9:43:26 AM58
NameManufacturerModelArchitectureWindows EditionWindows Version
DESKTOP-NM6VC29Dell Inc.G3 3590x64-based PCMicrosoft Windows 11 Pro24H2
ManufacturerSerial NumberVersionRelease Date
Dell Inc.CDVKNT21.19.09/5/2022 8:00:00 PM
NameSerial NumberHealth StatusOperational StatusSize (GB)Partition Style
KBG40ZNS512G NVMe TOSHIBA 512GB0100_0000_0000_0000_8CE3_8E04_001A_9A0F.HealthyOnline477GPT
NameDrive LetterHealth StatusOperational StatusSize (GB)Size Remaining (GB)Percent Remaining
OSCHealthyOK458.9270.8859%
ESPHealthyOK0.630.5486%
ImageHealthyOK16.059.0957%
DELLSUPPORTHealthyOK1.210.3428%
Detection TimeRemediation TimeAction SuccessThreat IDResources
10/15/2025 9:37:16 AM10/15/2025 9:37:16 AMTrue2147912646behavior:_process: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, pid:12360:118419370780344,process:_pid:12360,ProcessStart:134050090357970435
10/15/2025 9:33:00 AM10/15/2025 9:33:14 AMTrue2147519003file:_C:\Users\powerstrux-webinar\eicar.com.txt
10/15/2025 9:37:16 AM10/15/2025 9:37:16 AMTrue2147912646behavior:_process: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, pid:17192:118419370780344,process:_pid:17192,ProcessStart:134050090362584159
Antivirus EnabledReal Time Protection EnabledBehavior Monitor EnabledIoav Protection EnabledOn Access Protection EnabledIs Tamper Protected
TrueTrueTrueTrueTrueTrue
Antivirus Signature VersionAntivirus Signature AgeAntivirus Signature Last Updated
1.439.193.0010/15/2025 4:37:46 AM
Full Scan Start TimeFull Scan End TimeFull Scan AgeQuick Scan Start TimeQuick Scan End TimeQuick Scan Age
9/17/2025 1:05:21 PM9/17/2025 1:43:01 PM2710/14/2025 12:52:51 PM10/14/2025 12:54:46 PM0
Mount PointEncryption MethodVolume StatusProtection StatusLock StatusEncryption PercentageKey Protector
C:NoneFullyDecryptedOffUnlocked0

Report: 10-14-2025
NameEnabledLast LogonPassword RequiredDays Since Last Logon
goodActorTrue9/14/2025 9:43:26 AMFalse30
powerstrux-webinarTrue10/14/2025 10:47:26 AMTrue0
TimeIDAudit TypeActionSubject AccountTarget Account
10/14/2025 9:06:05 AM4738Audit SuccessA user account was changedpowerstrux-webinargoodActor
10/14/2025 8:41:45 AM4724Audit SuccessAn attempt was made to reset an account's passwordpowerstrux-webinarbadActor
10/14/2025 8:41:45 AM4738Audit SuccessA user account was changedpowerstrux-webinarbadActor
10/14/2025 8:41:45 AM4738Audit SuccessA user account was changedpowerstrux-webinarbadActor
TimeIDActionSubject AccountOld Target AccountNew Target Account
10/14/2025 9:06:05 AM4781The name of an account was changedpowerstrux-webinarbadActorgoodActor
MemberGroup
powerstrux-webinardocker-users
X_AdminAdministrators
powerstrux-webinarAdministrators
S-1-5-21-1645087665-3375922359-1671035281-1034Administrators
powerstrux-webinarEvent Log Readers
VisitorGuests
IUSRIIS_IUSRS
DefaultAccountSystem Managed Accounts Group
INTERACTIVEUsers
Authenticated UsersUsers
powerstrux-webinarUsers
TimeIDActionSubject AccountMember SIDMember NameGroup Name
10/14/2025 8:42:01 AM4733Member Removedpowerstrux-webinarS-1-5-21-1645087665-3375922359-1671035281-1036goodActorAdministrators
10/14/2025 8:41:53 AM4732Member Addedpowerstrux-webinarS-1-5-21-1645087665-3375922359-1671035281-1036goodActorAdministrators
TimeIDActionUserGroup
10/14/2025 9:06:46 AM4734A security-enabled local group was deletedpowerstrux-webinarpowerstrux
10/14/2025 8:41:15 AM4731A security-enabled local group was createdpowerstrux-webinarpowerstrux

Report: 10-14-2025
TimeIDUserLogon IDLogon TypeIs Elevated?
10/14/2025 9:38:28 AM4624powerstrux-webinar1057879UnlockNo
10/14/2025 9:38:28 AM4624powerstrux-webinar1057820UnlockYes
10/14/2025 9:38:28 AM4624powerstrux-webinar1056418CachedInteractiveNo
10/14/2025 9:38:28 AM4624powerstrux-webinar1056359CachedInteractiveYes
10/14/2025 9:19:09 AM4624powerstrux-webinar1509499UnlockNo
10/14/2025 9:19:09 AM4624powerstrux-webinar1509394UnlockYes
10/14/2025 9:19:09 AM4624powerstrux-webinar1507137CachedInteractiveNo
10/14/2025 9:19:09 AM4624powerstrux-webinar1507071CachedInteractiveYes
10/14/2025 8:44:05 AM4624powerstrux-webinar408860317UnlockNo
10/14/2025 8:44:05 AM4624powerstrux-webinar408860174UnlockYes
10/14/2025 8:44:05 AM4624powerstrux-webinar408858842CachedInteractiveNo
10/14/2025 8:44:05 AM4624powerstrux-webinar408858768CachedInteractiveYes
TimeIDUserLogon ID
10/14/2025 9:37:37 AM4647powerstrux-webinar1507137
10/14/2025 9:14:31 AM4647powerstrux-webinar408858842
10/14/2025 8:43:58 AM4647powerstrux-webinar318113020
TimeIDAccountWorkstationAddress
10/14/2025 8:40:55 AM4625BadActorDESKTOP-NM6VC29::1
10/14/2025 8:40:55 AM4625BadActorDESKTOP-NM6VC29::1
10/14/2025 8:40:55 AM4625BadActorDESKTOP-NM6VC29::1
10/14/2025 8:40:55 AM4625BadActorDESKTOP-NM6VC29::1
10/14/2025 8:40:55 AM4625BadActorDESKTOP-NM6VC29::1
10/14/2025 8:40:55 AM4625BadActorDESKTOP-NM6VC29::1
10/14/2025 8:40:55 AM4625BadActorDESKTOP-NM6VC29::1
10/14/2025 8:40:55 AM4625BadActorDESKTOP-NM6VC29::1
10/14/2025 8:40:55 AM4625BadActorDESKTOP-NM6VC29::1
10/14/2025 8:40:55 AM4625BadActorDESKTOP-NM6VC29::1
TimeIDUserLogon IDPrivileges
10/14/2025 9:38:28 AM4672powerstrux-webinar1057820SeSecurityPrivilege, SeTakeOwnershipPrivilege, SeLoadDriverPrivilege, SeBackupPrivilege, SeRestorePrivilege, SeDebugPrivilege, SeSystemEnvironmentPrivilege, SeImpersonatePrivilege, SeDelegateSessionUserImpersonatePrivilege
10/14/2025 9:38:28 AM4672powerstrux-webinar1056359SeSecurityPrivilege, SeTakeOwnershipPrivilege, SeLoadDriverPrivilege, SeBackupPrivilege, SeRestorePrivilege, SeDebugPrivilege, SeSystemEnvironmentPrivilege, SeImpersonatePrivilege, SeDelegateSessionUserImpersonatePrivilege
10/14/2025 9:19:09 AM4672powerstrux-webinar1509394SeSecurityPrivilege, SeTakeOwnershipPrivilege, SeLoadDriverPrivilege, SeBackupPrivilege, SeRestorePrivilege, SeDebugPrivilege, SeSystemEnvironmentPrivilege, SeImpersonatePrivilege, SeDelegateSessionUserImpersonatePrivilege
10/14/2025 9:19:09 AM4672powerstrux-webinar1507071SeSecurityPrivilege, SeTakeOwnershipPrivilege, SeLoadDriverPrivilege, SeBackupPrivilege, SeRestorePrivilege, SeDebugPrivilege, SeSystemEnvironmentPrivilege, SeImpersonatePrivilege, SeDelegateSessionUserImpersonatePrivilege
10/14/2025 8:44:05 AM4672powerstrux-webinar408860174SeSecurityPrivilege, SeTakeOwnershipPrivilege, SeLoadDriverPrivilege, SeBackupPrivilege, SeRestorePrivilege, SeDebugPrivilege, SeSystemEnvironmentPrivilege, SeImpersonatePrivilege, SeDelegateSessionUserImpersonatePrivilege
10/14/2025 8:44:05 AM4672powerstrux-webinar408858768SeSecurityPrivilege, SeTakeOwnershipPrivilege, SeLoadDriverPrivilege, SeBackupPrivilege, SeRestorePrivilege, SeDebugPrivilege, SeSystemEnvironmentPrivilege, SeImpersonatePrivilege, SeDelegateSessionUserImpersonatePrivilege

Report: 10-14-2025
TimeIDActionUserVolume LabelVolume SerialMessageTotal Transfer Size (KB)Log LocationFileFile Size (KB)
10/19/2025 9:47:15 AM1021WriteToUsbDESKTOP-NM6VC29\powerstrux-webinarFortress3456186785Project includes 1 folder(s) and 4 file(s).17621 KBC:\Report Files\DESKTOP-NM6VC29.powerstrux-webinar_20251019094710.txt C:\Users\powerstrux-webinar\OneDrive\Desktop\Sysmon\Eula.txt7 KB
10/19/2025 9:47:15 AM1021WriteToUsbDESKTOP-NM6VC29\powerstrux-webinarFortress3456186785Project includes 1 folder(s) and 4 file(s).17621 KBC:\Report Files\DESKTOP-NM6VC29.powerstrux-webinar_20251019094710.txt C:\Users\powerstrux-webinar\OneDrive\Desktop\Sysmon\Sysmon.exe8282 KB
10/19/2025 9:47:15 AM1021WriteToUsbDESKTOP-NM6VC29\powerstrux-webinarFortress3456186785Project includes 1 folder(s) and 4 file(s).17621 KBC:\Report Files\DESKTOP-NM6VC29.powerstrux-webinar_20251019094710.txt C:\Users\powerstrux-webinar\OneDrive\Desktop\Sysmon\Sysmon64.exe4456 KB
10/19/2025 9:47:15 AM1021WriteToUsbDESKTOP-NM6VC29\powerstrux-webinarFortress3456186785Project includes 1 folder(s) and 4 file(s).17621 KBC:\Report Files\DESKTOP-NM6VC29.powerstrux-webinar_20251019094710.txt C:\Users\powerstrux-webinar\OneDrive\Desktop\Sysmon\Sysmon64a.exe4876 KB
10/19/2025 9:39:29 AM1004WriteToDiskDESKTOP-NM6VC29\powerstrux-webinar\??\Volume{4c7a68e4-a85a-11ef-9555-b068e6773ab6}0Project includes 0 folder(s) and 1 file(s).1683 KBC:\Report Files\DESKTOP-NM6VC29.powerstrux-webinar_20251019093742.txt C:\Users\powerstrux-webinar\OneDrive\Desktop\2025, June 9, Smarter, Not Harder Using PowerShell for Security and Automation.pptx1684 KB
TimeIDDetailsAction
10/14/2025 9:11:35 AM307Document 2, SecretFile.txt - Notepad owned by powerstrux-webinar on \\DESKTOP-NM6VC29 was printed on HP3F0148 (HP ENVY 6400 series) through port WSD-eb5958a4-3043-40b0-954d-eaba22af0f8d. Size in bytes: 55517. Pages printed: 1. No user action is required.Printing a document
TimeIDDevice NameClass Name
10/19/2025 9:46:05 AM6416FortressWPD
10/19/2025 9:46:04 AM6416VolumeVolume
10/19/2025 9:46:04 AM6416Apricorn Fortress USB DeviceDiskDrive
10/19/2025 9:46:04 AM6416Apricorn Aegis FortressUSB
10/19/2025 9:44:29 AM6416SEC560WPD
10/19/2025 9:44:29 AM6416VolumeVolume
10/19/2025 9:44:29 AM6416Generic Mass Storage USB DeviceDiskDrive
10/19/2025 9:44:29 AM6416USB Mass Storage DeviceUSB
10/19/2025 9:43:37 AM6416SEC560WPD
10/19/2025 9:43:37 AM6416VolumeVolume
10/19/2025 9:43:37 AM6416Generic Mass Storage USB DeviceDiskDrive
10/19/2025 9:43:37 AM6416USB Mass Storage DeviceUSB
10/19/2025 9:41:26 AM6416HID-compliant mouseMouse
10/19/2025 9:41:26 AM6416USB Input DeviceHIDClass
10/19/2025 9:40:57 AM6416SEC560WPD
10/19/2025 9:40:57 AM6416VolumeVolume
10/19/2025 9:40:57 AM6416Generic Mass Storage USB DeviceDiskDrive
10/19/2025 9:40:56 AM6416USB Mass Storage DeviceUSB
10/19/2025 9:24:36 AM6416HL-DT-ST DVDRAM SP80NB80 USB DeviceCDROM
10/19/2025 9:24:35 AM6416USB Mass Storage DeviceUSB
10/19/2025 8:49:04 AM6416OneNote (Desktop)PrintQueue
TimeIDUserOperationObject NameObject Value NameOld Object ValueNew Object Value
10/14/2025 10:38:53 AM4657powerstrux-webinarRegistry value deleted\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\RemovableStorageDevicesNew Value #10-
10/14/2025 10:38:53 AM4657powerstrux-webinarRegistry value created\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\RemovableStorageDevicesnewKey-0
10/14/2025 10:38:48 AM4657powerstrux-webinarRegistry value created\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\RemovableStorageDevicesNew Value #1-0
10/14/2025 8:50:49 AM4657DESKTOP-NM6VC29$Registry value created\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\WinRM\ClientAllowBasic-0
10/14/2025 8:50:49 AM4657DESKTOP-NM6VC29$Registry value created\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\WinRM\ClientAllowCredSSP-0
10/14/2025 8:50:49 AM4657DESKTOP-NM6VC29$Registry value created\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Windows SearchAllowIndexingEncryptedStoresOrItems-0
10/14/2025 8:50:49 AM4657DESKTOP-NM6VC29$Registry value created\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\WcmSvc\GroupPolicyfBlockNonDomain-1
10/14/2025 8:50:49 AM4657DESKTOP-NM6VC29$Registry value created\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\WcmSvc\GroupPolicyfMinimizeConnections-3
10/14/2025 8:50:49 AM4657DESKTOP-NM6VC29$Registry value created\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\SystemAllowDomainPINLogon-0
10/14/2025 8:50:49 AM4657DESKTOP-NM6VC29$Registry value created\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\SystemShellSmartScreenLevel-Block
10/14/2025 8:50:49 AM4657DESKTOP-NM6VC29$Registry value created\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\SystemEnableSmartScreen-1
10/14/2025 8:50:49 AM4657DESKTOP-NM6VC29$Registry value created\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\SystemEnumerateLocalUsers-0
10/14/2025 8:50:49 AM4657DESKTOP-NM6VC29$Registry value created\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\SystemDontDisplayNetworkSelectionUI-1
10/14/2025 8:50:49 AM4657DESKTOP-NM6VC29$Registry value created\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\PowerShell\TranscriptionOutputDirectory-C:\ProgramData\PS_Transcript
10/14/2025 8:50:49 AM4657DESKTOP-NM6VC29$Registry value created\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\PowerShell\TranscriptionEnableTranscripting-1
TimeIDUserObject TypeObject NameOld SDDLNew SDDL
10/14/2025 10:04:13 AM4670powerstrux-webinarFileC:\Users\powerstrux-webinar\OneDrive\Desktop\SecretFile.txtO:BAO:S-1-5-21-1645087665-3375922359-1671035281-1001
10/14/2025 10:04:05 AM4670powerstrux-webinarFileC:\Users\powerstrux-webinar\OneDrive\Desktop\SecretFile.txtO:S-1-5-21-1645087665-3375922359-1671035281-1001O:BA
TimeIDUserObject TypeObject NameOperation
10/14/2025 10:04:21 AM4663powerstrux-webinarFileC:\Users\powerstrux-webinar\OneDrive\Desktop\SecretFile.txtReadAttributes
10/14/2025 10:04:21 AM4663powerstrux-webinarFileC:\Users\powerstrux-webinar\OneDrive\Desktop\SecretFile.txtReadAttributes
10/14/2025 10:04:21 AM4663powerstrux-webinarFileC:\Users\powerstrux-webinar\OneDrive\Desktop\SecretFile.txtReadAttributes
10/14/2025 10:04:20 AM4663powerstrux-webinarFileC:\Users\powerstrux-webinar\OneDrive\Desktop\SecretFile.txtReadAttributes
10/14/2025 10:04:20 AM4663powerstrux-webinarFileC:\Users\powerstrux-webinar\OneDrive\Desktop\SecretFile.txtWRITE_OWNER
10/14/2025 10:04:13 AM4663powerstrux-webinarFileC:\Users\powerstrux-webinar\OneDrive\Desktop\SecretFile.txtReadAttributes
10/14/2025 10:04:13 AM4663powerstrux-webinarFileC:\Users\powerstrux-webinar\OneDrive\Desktop\SecretFile.txtReadAttributes
10/14/2025 10:04:13 AM4663powerstrux-webinarFileC:\Users\powerstrux-webinar\OneDrive\Desktop\SecretFile.txtReadAttributes

Report: 10-14-2025
TimeIDCreator AccountProcess NameToken TypeProcess Commandline
10/14/2025 10:44:44 AM4688powerstrux-webinarC:\Windows\System32\NETSTAT.EXEType 2"C:\WINDOWS\system32\NETSTAT.EXE" -nao
10/14/2025 10:44:43 AM4688powerstrux-webinarC:\Windows\System32\auditpol.exeType 2"C:\WINDOWS\system32\auditpol.exe" /get /category:*
TimeIDAudit TypeUserPrivilege
10/14/2025 10:44:43 AM4674Audit Successpowerstrux-webinarSeSecurityPrivilege
10/14/2025 10:41:48 AM4674Audit Successpowerstrux-webinarSeTakeOwnershipPrivilege
10/14/2025 10:41:48 AM4674Audit Successpowerstrux-webinarSeTakeOwnershipPrivilege
10/14/2025 10:41:48 AM4674Audit Successpowerstrux-webinarSeTakeOwnershipPrivilege
10/14/2025 10:41:48 AM4674Audit Successpowerstrux-webinarSeTakeOwnershipPrivilege
10/14/2025 10:41:48 AM4674Audit Successpowerstrux-webinarSeTakeOwnershipPrivilege
10/14/2025 10:41:48 AM4674Audit Successpowerstrux-webinarSeTakeOwnershipPrivilege
10/14/2025 10:41:48 AM4674Audit Successpowerstrux-webinarSeTakeOwnershipPrivilege
10/14/2025 10:41:48 AM4674Audit Successpowerstrux-webinarSeTakeOwnershipPrivilege
10/14/2025 10:41:48 AM4674Audit Successpowerstrux-webinarSeTakeOwnershipPrivilege
TimeIDUserPrevious TimeNew Time
10/14/2025 9:37:48 AM4616LOCAL SERVICE10/14/2025 9:37:48 AM10/14/2025 9:37:48 AM
10/14/2025 9:15:51 AM4616LOCAL SERVICE10/14/2025 9:15:51 AM10/14/2025 9:15:51 AM
TimeIDDetailsAction
10/14/2025 9:37:48 AM1100The event logging service has shut down.Service shutdown
10/14/2025 9:17:17 AM1100The event logging service has shut down.Service shutdown
10/14/2025 9:15:51 AM1100The event logging service has shut down.Service shutdown
10/14/2025 8:37:30 AM1102The audit log was cleared. Subject: Security ID: S-1-5-21-1645087665-3375922359-1671035281-1001 Account Name: powerstrux-webinar Domain Name: DESKTOP-NM6VC29 Logon ID: 0x12F604AEService shutdown
Log NameMax Size (Bytes)Current Size (Bytes)Max Size (MB)Current Size (MB)Percent Full
Application33554432157982723215.0747.08
Security10485760001122672641000107.0710.71
System33554432231383043222.0768.96
SubcategorySetting
Security System ExtensionSuccess
System IntegritySuccess and Failure
IPsec DriverFailure
Other System EventsSuccess and Failure
Security State ChangeSuccess
LogonSuccess and Failure
LogoffSuccess
Account LockoutFailure
IPsec Main ModeNo Auditing
IPsec Quick ModeNo Auditing
IPsec Extended ModeNo Auditing
Special LogonSuccess
Other Logon/Logoff EventsSuccess and Failure
Network Policy ServerNo Auditing
User / Device ClaimsNo Auditing
Group MembershipSuccess
Access RightsNo Auditing
File SystemNo Auditing
RegistrySuccess
Kernel ObjectNo Auditing
SAMNo Auditing
Certification ServicesNo Auditing
Application GeneratedNo Auditing
Handle ManipulationNo Auditing
File ShareSuccess and Failure
Filtering Platform Packet DropNo Auditing
Filtering Platform ConnectionNo Auditing
Other Object Access EventsSuccess and Failure
Detailed File ShareFailure
Removable StorageSuccess and Failure
Central Policy StagingNo Auditing
Non Sensitive Privilege UseNo Auditing
Other Privilege Use EventsNo Auditing
Sensitive Privilege UseSuccess and Failure
Process CreationSuccess and Failure
Process TerminationNo Auditing
DPAPI ActivityNo Auditing
RPC EventsNo Auditing
Plug and Play EventsSuccess
Token Right Adjusted EventsNo Auditing
Audit Policy ChangeSuccess
Authentication Policy ChangeSuccess
Authorization Policy ChangeSuccess
MPSSVC Rule-Level Policy ChangeSuccess and Failure
Filtering Platform Policy ChangeNo Auditing
Other Policy Change EventsSuccess and Failure
Computer Account ManagementNo Auditing
Security Group ManagementSuccess
Distribution Group ManagementNo Auditing
Application Group ManagementNo Auditing
Other Account Management EventsNo Auditing
User Account ManagementSuccess and Failure
Directory Service AccessNo Auditing
Directory Service ChangesNo Auditing
Directory Service ReplicationNo Auditing
Detailed Directory Service ReplicationNo Auditing
Kerberos Service Ticket OperationsNo Auditing
Other Account Logon EventsNo Auditing
Kerberos Authentication ServiceNo Auditing
Credential ValidationSuccess and Failure
TimeIDSubject AccountTarget SubCategoryChangeTarget Account
10/14/2025 10:36:48 AM4719powerstrux-webinarRegistrySuccess added
10/14/2025 10:35:37 AM4719DESKTOP-NM6VC29$RegistrySuccess removed
10/14/2025 10:35:37 AM4719DESKTOP-NM6VC29$File SystemSuccess removed
10/14/2025 10:34:13 AM4719powerstrux-webinarRegistrySuccess added
10/14/2025 9:58:15 AM4719powerstrux-webinarFile SystemSuccess added
10/14/2025 9:14:00 AM4719DESKTOP-NM6VC29$RegistrySuccess removed
10/14/2025 8:38:59 AM4719powerstrux-webinarRegistrySuccess added

Report: 10-14-2025
NameVersionVendorInstall Date
Microsoft 365 - en-us16.0.19231.20156Microsoft Corporation
Microsoft OneDrive25.179.0914.0003Microsoft Corporation
Docker Desktop4.40.0Docker Inc.
Notepad++ (64-bit x64)8.8.1Notepad++ Team
Microsoft Update Health Tools5.72.0.0Microsoft Corporation01/07/2024
Windows Subsystem for Linux2.4.13.0Microsoft Corporation04/17/2025
Tenable Nessus (x64)10.8.4.20028Tenable, Inc.04/30/2025
Snagit 202525.1.1TechSmith Corporation04/30/2025
Snagit 202525.1.1.6503TechSmith Corporation04/30/2025
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.42.3443314.42.34433Microsoft Corporation05/01/2025
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.42.3443314.42.34433Microsoft Corporation05/01/2025
SCAP Compliance Checker 5.10.25.10.2NIWC Atlantic06/19/2025
VMware Workstation17.6.4VMware, Inc.08/22/2025
Office 16 Click-to-Run Licensing Component16.0.19029.20208Microsoft Corporation08/24/2025
PowerShell 7-x647.4.12.0Microsoft Corporation09/12/2025
Office 16 Click-to-Run Extensibility Component16.0.19231.20072Microsoft Corporation10/13/2025
NVIDIA Graphics Driver 512.72512.72NVIDIA Corporation11/14/2024
NVIDIA Install Application2.1002.370.0NVIDIA Corporation11/14/2024
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.36.3253214.36.32532.0Microsoft Corporation
Npcap OEM1.72Nmap Project
PowerShell 7.4.12.0-x647.4.12.0Microsoft Corporation
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.42.3443314.42.34433.0Microsoft Corporation
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.36.3253214.36.32532Microsoft Corporation03/19/2025
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.36.3253214.36.32532Microsoft Corporation03/19/2025
InstallRoot5.6DoD PKE07/31/2025
Sonos90.0.67300Sonos, Inc.09/14/2025
Google Chrome141.0.7390.67Google LLC10/13/2025
Microsoft Edge WebView2 Runtime141.0.3537.71Microsoft Corporation10/13/2025
Microsoft Edge141.0.3537.71Microsoft Corporation10/13/2025
TimeIDMachineNameAction
10/14/2025 9:38:17 AM4608DESKTOP-NM6VC29Security State Change: Windows Started
10/14/2025 9:17:41 AM4608DESKTOP-NM6VC29Security State Change: Windows Started
10/14/2025 9:16:19 AM4608DESKTOP-NM6VC29Security State Change: Windows Started
TimeIDTitleUserProcessShutdownType
10/14/2025 9:37:48 AM6006The Event Log service was stopped.Not RecordedNot RecordedNot Recorded
10/14/2025 9:37:43 AM1074The system has been shut down properly by a user or process.NT AUTHORITY\SYSTEMC:\WINDOWS\system32\winlogon.exe (DESKTOP-NM6VC29)restart
10/14/2025 9:17:16 AM1074The system has been shut down properly by a user or process.NT AUTHORITY\SYSTEMC:\WINDOWS\servicing\TrustedInstaller.exe (DESKTOP-NM6VC29)restart
10/14/2025 9:17:17 AM6006The Event Log service was stopped.Not RecordedNot RecordedNot Recorded
10/14/2025 9:15:51 AM6006The Event Log service was stopped.Not RecordedNot RecordedNot Recorded
NameServiceStatusStart Type
Agent Activation Runtime_104ec2AarSvc_104ec2StoppedManual
ADPSvcADPSvcStoppedManual
Application Layer Gateway ServiceALGStoppedManual
Application IdentityAppIDSvcStoppedManual
Application InformationAppinfoRunningManual
Application ManagementAppMgmtStoppedManual
App ReadinessAppReadinessStoppedManual
Microsoft App-V ClientAppVClientStoppedDisabled
AppX Deployment Service (AppXSVC)AppXSvcRunningManual
Windows Virtual Audio Device Proxy ServiceApxSvcStoppedManual
AssignedAccessManager ServiceAssignedAccessManagerSvcStoppedManual
AtherosSvcAtherosSvcRunningAutomatic
Windows Audio Endpoint BuilderAudioEndpointBuilderRunningAutomatic
Windows AudioAudiosrvRunningAutomatic
Cellular TimeautotimesvcStoppedManual
ActiveX Installer (AxInstSV)AxInstSVStoppedManual
GameDVR and Broadcast User Service_104ec2BcastDVRUserService_104ec2StoppedManual
BitLocker Drive Encryption ServiceBDESVCStoppedManual
Base Filtering EngineBFERunningAutomatic
Background Intelligent Transfer ServiceBITSStoppedManual
Bluetooth User Support Service_104ec2BluetoothUserService_104ec2RunningManual
Background Tasks Infrastructure ServiceBrokerInfrastructureRunningAutomatic
Bluetooth Audio Gateway ServiceBTAGServiceRunningManual
AVCTP serviceBthAvctpSvcRunningManual
Bluetooth Support ServicebthservRunningManual
Capability Access Manager ServicecamsvcRunningAutomatic
CaptureService_104ec2CaptureService_104ec2StoppedManual
Clipboard User Service_104ec2cbdhsvc_104ec2RunningAutomatic
Connected Devices Platform ServiceCDPSvcRunningAutomatic
Connected Devices Platform User Service_104ec2CDPUserSvc_104ec2RunningAutomatic
Certificate PropagationCertPropSvcRunningAutomatic
Microsoft Office Click-to-Run ServiceClickToRunSvcRunningAutomatic
Client License Service (ClipSVC)ClipSVCStoppedManual
Cloud Backup and Restore Service_104ec2CloudBackupRestoreSvc_104ec2StoppedManual
Microsoft Cloud Identity ServicecloudidsvcStoppedManual
Container Manager ServiceCmServiceRunningAutomatic
Docker Desktop Servicecom.docker.serviceStoppedManual
COM+ System ApplicationCOMSysAppStoppedManual
ConsentUX User Service_104ec2ConsentUxUserSvc_104ec2StoppedManual
CoreMessagingCoreMessagingRegistrarRunningAutomatic
Intel(R) Content Protection HECI ServicecphsRunningManual
Intel(R) Content Protection HDCP ServicecplspconRunningAutomatic
CredentialEnrollmentManagerUserSvc_104ec2CredentialEnrollmentManagerUserSvc_104ec2StoppedManual
Cryptographic ServicesCryptSvcRunningAutomatic
Offline FilesCscServiceStoppedManual
DCOM Server Process LauncherDcomLaunchRunningAutomatic
Declared Configuration(DC) servicedcsvcStoppedManual
Optimize drivesdefragsvcStoppedManual
DeviceAssociationBroker_104ec2DeviceAssociationBrokerSvc_104ec2StoppedManual
Device Association ServiceDeviceAssociationServiceRunningAutomatic
Device Install ServiceDeviceInstallStoppedManual
DevicePicker_104ec2DevicePickerUserSvc_104ec2StoppedManual
DevicesFlow_104ec2DevicesFlowUserSvc_104ec2RunningManual
DevQuery Background Discovery BrokerDevQueryBrokerRunningManual
DHCP ClientDhcpRunningAutomatic
Diagnostic Execution ServicediagsvcStoppedManual
Connected User Experiences and TelemetryDiagTrackRunningAutomatic
DialogBlockingServiceDialogBlockingServiceStoppedDisabled
Display Policy ServiceDispBrokerDesktopSvcRunningAutomatic
Display Enhancement ServiceDisplayEnhancementServiceRunningManual
Device Management Enrollment ServiceDmEnrollmentSvcStoppedManual
Device Management Wireless Application Protocol (WAP) Push message Routing ServicedmwappushserviceStoppedManual
DNS ClientDnscacheRunningAutomatic
Delivery OptimizationDoSvcRunningAutomatic
Wired AutoConfigdot3svcStoppedManual
Diagnostic Policy ServiceDPSRunningAutomatic
Device Setup ManagerDsmSvcStoppedManual
Data Sharing ServiceDsSvcStoppedManual
Data UsageDusmSvcRunningAutomatic
Extensible Authentication ProtocolEapHostStoppedManual
Microsoft Edge Update Service (edgeupdate)edgeupdateStoppedAutomatic
Microsoft Edge Update Service (edgeupdatem)edgeupdatemStoppedManual
Encrypting File System (EFS)EFSStoppedManual
Embedded ModeembeddedmodeStoppedManual
Enterprise App Management ServiceEntAppSvcStoppedManual
Intel(R) Dynamic Platform and Thermal Framework serviceesifsvcRunningAutomatic
Windows Event LogEventLogRunningAutomatic
COM+ Event SystemEventSystemRunningAutomatic
FaxFaxStoppedManual
Function Discovery Provider HostfdPHostStoppedManual
Function Discovery Resource PublicationFDResPubStoppedManual
File History ServicefhsvcStoppedManual
FileSyncHelperFileSyncHelperRunningManual
Windows Font Cache ServiceFontCacheRunningAutomatic
Windows Camera Frame ServerFrameServerStoppedManual
Windows Camera Frame Server MonitorFrameServerMonitorStoppedManual
GameInput ServiceGameInputSvcStoppedManual
Hyper-V Guest Compute ServicegcsStoppedManual
Google Chrome Elevation Service (GoogleChromeElevationService)GoogleChromeElevationServiceStoppedManual
Google Updater Internal Service (GoogleUpdaterInternalService142.0.7416.0)GoogleUpdaterInternalService142.0.7416.0StoppedAutomatic
Google Updater Service (GoogleUpdaterService142.0.7416.0)GoogleUpdaterService142.0.7416.0StoppedAutomatic
Group Policy ClientgpsvcRunningAutomatic
GraphicsPerfSvcGraphicsPerfSvcStoppedManual
Intel(R) RST HFC Disable ServiceHfcDisableServiceStoppedDisabled
Human Interface Device ServicehidservRunningManual
Host Network ServicehnsRunningManual
Hotpatch Monitoring ServicehpatchmonStoppedManual
HV Host ServiceHvHostRunningManual
Intel(R) Optane(TM) Memory ServiceiaStorAfsServiceStoppedManual
Windows Mobile Hotspot ServiceicssvcStoppedManual
Intel(R) Graphics Command Center ServiceigccserviceRunningAutomatic
Intel(R) HD Graphics Control Panel ServiceigfxCUIService2.0.0.0RunningAutomatic
IKE and AuthIP IPsec Keying ModulesIKEEXTRunningAutomatic
Microsoft Store Install ServiceInstallServiceRunningManual
Intel(R) Capability Licensing Service TCP IP InterfaceIntel(R) Capability Licensing Service TCP IP InterfaceStoppedManual
Intel(R) TPM Provisioning ServiceIntel(R) TPM Provisioning ServiceStoppedAutomatic
Intel(R) Audio ServiceIntelAudioServiceRunningAutomatic
Inventory and Compatibility Appraisal serviceInventorySvcRunningAutomatic
IP HelperiphlpsvcRunningAutomatic
IP Translation Configuration ServiceIpxlatCfgSvcStoppedManual
Intel(R) Dynamic Application Loader Host Interface Servicejhi_serviceRunningAutomatic
CNG Key IsolationKeyIsoRunningManual
KtmRm for Distributed Transaction CoordinatorKtmRmStoppedManual
ServerLanmanServerRunningAutomatic
WorkstationLanmanWorkstationRunningAutomatic
Geolocation ServicelfsvcRunningManual
Windows License Manager ServiceLicenseManagerRunningManual
Link-Layer Topology Discovery MapperlltdsvcStoppedManual
TCP/IP NetBIOS HelperlmhostsRunningManual
Intel(R) Management and Security Application Local Management ServiceLMSRunningAutomatic
Kerberos Local Key Distribution CenterLocalKdcStoppedManual
Local Session ManagerLSMRunningAutomatic
Language Experience ServiceLxpSvcStoppedManual
Downloaded Maps ManagerMapsBrokerStoppedAutomatic
Mobile Connectivity Management ServiceMcmSvcStoppedManual
McpManagementServiceMcpManagementServiceStoppedManual
Microsoft Defender Core ServiceMDCoreSvcRunningAutomatic
MessagingService_104ec2MessagingService_104ec2StoppedManual
Microsoft Edge Elevation Service (MicrosoftEdgeElevationService)MicrosoftEdgeElevationServiceStoppedManual
Windows MIDI ServicemidisrvStoppedManual
Windows Defender FirewallmpssvcRunningAutomatic
Distributed Transaction CoordinatorMSDTCStoppedManual
Microsoft iSCSI Initiator ServiceMSiSCSIStoppedManual
Windows InstallermsiserverStoppedManual
Microsoft Keyboard FilterMsKeyboardFilterStoppedDisabled
Nahimic serviceNahimicServiceRunningAutomatic
Natural AuthenticationNaturalAuthenticationStoppedManual
Network Connectivity AssistantNcaSvcStoppedManual
Network Connection BrokerNcbServiceRunningManual
Network Connected Devices Auto-SetupNcdAutoSetupStoppedManual
NetlogonNetlogonStoppedManual
Network ConnectionsNetmanStoppedManual
Network List ServicenetprofmRunningManual
Network Setup ServiceNetSetupSvcStoppedManual
Net.Tcp Port Sharing ServiceNetTcpPortSharingStoppedDisabled
Microsoft Passport ContainerNgcCtnrSvcRunningManual
Microsoft PassportNgcSvcRunningManual
Network Location AwarenessNlaSvcStoppedManual
Now Playing Session Manager Service_104ec2NPSMSvc_104ec2StoppedManual
Network Store Interface ServicensiRunningAutomatic
Network Virtualization ServicenvagentRunningManual
NVIDIA Display Container LSNVDisplay.ContainerLocalSystemRunningAutomatic
OneDrive Updater ServiceOneDrive Updater ServiceStoppedManual
Sync Host_104ec2OneSyncSvc_104ec2RunningAutomatic
P9RdrService_104ec2P9RdrService_104ec2StoppedManual
Program Compatibility Assistant ServicePcaSvcRunningAutomatic
BranchCachePeerDistSvcStoppedManual
PenService_104ec2PenService_104ec2StoppedManual
Windows Perception Simulation ServiceperceptionsimulationStoppedManual
Performance Counter DLL HostPerfHostStoppedManual
Phone ServicePhoneSvcRunningManual
Contact Data_104ec2PimIndexMaintenanceSvc_104ec2StoppedManual
Performance Logs & AlertsplaStoppedManual
Plug and PlayPlugPlayRunningManual
IPsec Policy AgentPolicyAgentRunningManual
PowerPowerRunningAutomatic
Print Device Configuration ServicePrintDeviceConfigurationServiceStoppedManual
Printer Extensions and NotificationsPrintNotifyStoppedManual
PrintScanBrokerServicePrintScanBrokerServiceStoppedManual
PrintWorkflow_104ec2PrintWorkflowUserSvc_104ec2StoppedManual
User Profile ServiceProfSvcRunningAutomatic
Windows PushToInstall ServicePushToInstallStoppedManual
Qualcomm Atheros WLAN Driver ServiceQcomWlanSrvRunningAutomatic
Quality Windows Audio Video ExperienceQWAVEStoppedManual
Remote Access Auto Connection ManagerRasAutoStoppedManual
Remote Access Connection ManagerRasManRunningManual
ReFS Dedup ServicerefsdedupsvcStoppedManual
Routing and Remote AccessRemoteAccessStoppedDisabled
Remote RegistryRemoteRegistryStoppedManual
Retail Demo ServiceRetailDemoStoppedManual
Radio Management ServiceRmSvcRunningManual
RPC Endpoint MapperRpcEptMapperRunningAutomatic
Remote Procedure Call (RPC) LocatorRpcLocatorStoppedManual
Remote Procedure Call (RPC)RpcSsRunningAutomatic
Intel(R) Storage Middleware ServiceRstMwServiceRunningAutomatic
Realtek Audio Universal ServiceRtkAudioUniversalServiceRunningAutomatic
Security Accounts ManagerSamSsRunningAutomatic
Smart CardSCardSvrStoppedAutomatic
Smart Card Device Enumeration ServiceScDeviceEnumStoppedManual
Task SchedulerScheduleRunningAutomatic
Smart Card Removal PolicySCPolicySvcStoppedManual
Windows BackupSDRSVCStoppedManual
Secondary LogonseclogonRunningManual
Windows Security ServiceSecurityHealthServiceRunningManual
Payments and NFC/SE ManagerSEMgrSvcStoppedManual
System Event Notification ServiceSENSRunningAutomatic
Windows Defender Advanced Threat Protection ServiceSenseStoppedManual
Sensor Data ServiceSensorDataServiceStoppedManual
Sensor ServiceSensorServiceStoppedManual
Sensor Monitoring ServiceSensrSvcStoppedManual
Remote Desktop ConfigurationSessionEnvRunningManual
Internet Connection Sharing (ICS)SharedAccessRunningManual
Shell Hardware DetectionShellHWDetectionRunningAutomatic
Shared PC Account ManagershpamsvcStoppedDisabled
Microsoft Storage Spaces SMPsmphostRunningManual
Microsoft Windows SMS Router Service.SmsRouterStoppedManual
SNMP TrapSNMPTrapStoppedManual
SonosLibraryServiceSonosLibraryServiceStoppedAutomatic
Print SpoolerSpoolerRunningAutomatic
Software ProtectionsppsvcStoppedAutomatic
SSDP DiscoverySSDPSRVRunningManual
OpenSSH Authentication Agentssh-agentStoppedDisabled
Secure Socket Tunneling Protocol ServiceSstpSvcRunningManual
State Repository ServiceStateRepositoryRunningAutomatic
Windows Image Acquisition (WIA)StiSvcRunningManual
Storage ServiceStorSvcRunningAutomatic
Spot VerifiersvsvcStoppedManual
Microsoft Software Shadow Copy ProviderswprvStoppedManual
SysMainSysMainRunningAutomatic
SysmonSysmonRunningAutomatic
System Events BrokerSystemEventsBrokerRunningAutomatic
TelephonyTapiSrvStoppedManual
Tenable NessusTenable NessusRunningAutomatic
Remote Desktop ServicesTermServiceRunningManual
Text Input Management ServiceTextInputManagementServiceRunningAutomatic
ThemesThemesRunningAutomatic
Storage Tiers ManagementTieringEngineServiceStoppedManual
Time BrokerTimeBrokerSvcRunningManual
Web Account ManagerTokenBrokerRunningManual
Distributed Link Tracking ClientTrkWksRunningAutomatic
Recommended Troubleshooting ServiceTroubleshootingSvcStoppedManual
Windows Modules InstallerTrustedInstallerStoppedManual
Auto Time Zone UpdatertzautoupdateStoppedManual
Udk User Service_104ec2UdkUserSvc_104ec2RunningManual
User Experience Virtualization ServiceUevAgentServiceStoppedDisabled
Remote Desktop Services UserMode Port RedirectorUmRdpServiceRunningManual
User Data Storage_104ec2UnistoreSvc_104ec2StoppedManual
UPnP Device HostupnphostStoppedManual
User Data Access_104ec2UserDataSvc_104ec2StoppedManual
User ManagerUserManagerRunningAutomatic
Update Orchestrator ServiceUsoSvcRunningAutomatic
Credential ManagerVaultSvcRunningManual
Virtual DiskvdsStoppedManual
VMware Authorization ServiceVMAuthdServiceRunningAutomatic
Hyper-V Host Compute ServicevmcomputeRunningManual
Hyper-V Guest Service InterfacevmicguestinterfaceStoppedManual
Hyper-V Heartbeat ServicevmicheartbeatStoppedManual
Hyper-V Data Exchange ServicevmickvpexchangeStoppedManual
Hyper-V Remote Desktop Virtualization ServicevmicrdvStoppedManual
Hyper-V Guest Shutdown ServicevmicshutdownStoppedManual
Hyper-V Time Synchronization ServicevmictimesyncStoppedManual
Hyper-V PowerShell Direct ServicevmicvmsessionStoppedManual
Hyper-V Volume Shadow Copy RequestorvmicvssStoppedManual
VMware DHCP ServiceVMnetDHCPRunningAutomatic
VMware USB Arbitration ServiceVMUSBArbServiceRunningAutomatic
VMware NAT ServiceVMware NAT ServiceRunningAutomatic
VMware Autostart ServiceVmwareAutostartServiceStoppedManual
Volume Shadow CopyVSSStoppedManual
Windows TimeW32TimeRunningAutomatic
WaaSMedicSvcWaaSMedicSvcStoppedManual
WalletServiceWalletServiceStoppedManual
Warp JIT ServiceWarpJITSvcStoppedManual
Block Level Backup Engine ServicewbengineStoppedManual
Windows Biometric ServiceWbioSrvcStoppedManual
Windows Connection ManagerWcmsvcRunningAutomatic
Windows Connect Now - Config RegistrarwcncsvcStoppedManual
Diagnostic Service HostWdiServiceHostStoppedManual
Diagnostic System HostWdiSystemHostRunningManual
Microsoft Defender Antivirus Network Inspection ServiceWdNisSvcRunningManual
WebClientWebClientStoppedManual
Web Threat Defense ServicewebthreatdefsvcRunningManual
Web Threat Defense User Service_104ec2webthreatdefusersvc_104ec2RunningAutomatic
Windows Event CollectorWecsvcStoppedManual
Windows Encryption Provider Host ServiceWEPHOSTSVCStoppedManual
Problem Reports Control Panel SupportwercplsupportStoppedManual
Windows Error Reporting ServiceWerSvcStoppedManual
Wi-Fi Direct Services Connection Manager ServiceWFDSConMgrSvcStoppedManual
Windows Health and Optimized ExperienceswhesvcRunningAutomatic
Still Image Acquisition EventsWiaRpcStoppedManual
Microsoft Defender Antivirus ServiceWinDefendRunningAutomatic
WinHTTP Web Proxy Auto-Discovery ServiceWinHttpAutoProxySvcRunningManual
Windows Management InstrumentationWinmgmtRunningAutomatic
Windows Remote Management (WS-Management)WinRMRunningAutomatic
Windows Insider ServicewisvcStoppedManual
WLAN AutoConfigWlanSvcRunningAutomatic
Microsoft Account Sign-in AssistantwlidsvcRunningManual
Local Profile Assistant ServicewlpasvcStoppedManual
Windows Management ServiceWManSvcStoppedManual
WMI Performance AdapterwmiApSrvStoppedManual
Intel(R) Management Engine WMI Provider RegistrationWMIRegistrationServiceRunningAutomatic
Windows Media Player Network Sharing ServiceWMPNetworkSvcStoppedManual
Work FoldersworkfolderssvcStoppedManual
Parental ControlsWpcMonSvcRunningManual
Portable Device Enumerator ServiceWPDBusEnumStoppedManual
Windows Push Notifications System ServiceWpnServiceRunningAutomatic
Windows Push Notifications User Service_104ec2WpnUserService_104ec2RunningAutomatic
WSAIFabricSvcWSAIFabricSvcRunningAutomatic
Security CenterwscsvcRunningAutomatic
Windows SearchWSearchRunningAutomatic
WSL ServiceWSLServiceRunningAutomatic
Windows UpdatewuauservRunningManual
Microsoft Usage and Quality InsightswuqisvcStoppedManual
WWAN AutoConfigWwanSvcStoppedManual
Xbox Live Auth ManagerXblAuthManagerStoppedManual
Xbox Live Game SaveXblGameSaveStoppedManual
Xbox Accessory Management ServiceXboxGipSvcStoppedManual
Xbox Live Networking ServiceXboxNetApiSvcStoppedManual
ZTDNS Helper serviceZTHELPERStoppedManual
ProtocolLocal AddressForeign AddressConnection State
TCP0.0.0.0:1350.0.0.0:0LISTENING
TCP0.0.0.0:4450.0.0.0:0LISTENING
TCP0.0.0.0:9030.0.0.0:0LISTENING
TCP0.0.0.0:9130.0.0.0:0LISTENING
TCP0.0.0.0:33890.0.0.0:0LISTENING
TCP0.0.0.0:50400.0.0.0:0LISTENING
TCP0.0.0.0:59850.0.0.0:0LISTENING
TCP0.0.0.0:76800.0.0.0:0LISTENING
TCP0.0.0.0:88340.0.0.0:0LISTENING
TCP0.0.0.0:470010.0.0.0:0LISTENING
TCP0.0.0.0:496640.0.0.0:0LISTENING
TCP0.0.0.0:496650.0.0.0:0LISTENING
TCP0.0.0.0:496660.0.0.0:0LISTENING
TCP0.0.0.0:496670.0.0.0:0LISTENING
TCP0.0.0.0:496680.0.0.0:0LISTENING
TCP0.0.0.0:496690.0.0.0:0LISTENING
TCP0.0.0.0:496970.0.0.0:0LISTENING
TCP127.0.0.1:49695127.0.0.1:49696ESTABLISHED
TCP127.0.0.1:49696127.0.0.1:49695ESTABLISHED
TCP127.0.0.1:49700127.0.0.1:49701ESTABLISHED
TCP127.0.0.1:49701127.0.0.1:49700ESTABLISHED
TCP192.168.4.61:1390.0.0.0:0LISTENING
TCP192.168.4.61:4940820.59.87.227:443ESTABLISHED
TCP192.168.4.61:4967452.96.79.114:443ESTABLISHED
TCP192.168.4.61:4967652.96.79.114:443ESTABLISHED
TCP192.168.4.61:4974034.98.64.218:443ESTABLISHED
TCP192.168.4.61:52736192.168.0.1:53TIME_WAIT
TCP192.168.4.61:52915130.211.23.194:443ESTABLISHED
TCP192.168.4.61:54673151.101.193.229:443ESTABLISHED
TCP192.168.4.61:5557035.208.249.213:443ESTABLISHED
TCP192.168.4.61:5607135.244.154.8:443ESTABLISHED
TCP192.168.4.61:56275135.234.174.40:443ESTABLISHED
TCP192.168.4.61:57035172.202.211.174:443ESTABLISHED
TCP192.168.4.61:5790735.208.249.213:443ESTABLISHED
TCP192.168.4.61:5898034.149.50.64:443ESTABLISHED
TCP192.168.4.61:5962052.104.31.25:443TIME_WAIT
TCP192.168.4.61:5962323.211.206.47:443ESTABLISHED
TCP192.168.4.61:5962635.211.7.4:443ESTABLISHED
TCP192.168.4.61:6004634.160.72.119:443ESTABLISHED
TCP192.168.4.61:60060192.168.0.1:53TIME_WAIT
TCP192.168.4.61:6006120.190.157.12:443ESTABLISHED
TCP192.168.4.61:6006220.190.135.47:443ESTABLISHED
TCP192.168.4.61:6006320.189.173.28:443ESTABLISHED
TCP192.168.4.61:6095535.186.193.173:443ESTABLISHED
TCP192.168.4.61:61604192.168.0.1:53TIME_WAIT
TCP192.168.4.61:6381035.227.252.103:443ESTABLISHED
TCP192.168.4.61:63973192.168.0.1:53TIME_WAIT
TCP192.168.4.61:64722172.183.7.194:443ESTABLISHED
TCP192.168.13.1:1390.0.0.0:0LISTENING
TCP192.168.195.1:1390.0.0.0:0LISTENING
TCP[::]:135[::]:0LISTENING
TCP[::]:445[::]:0LISTENING
TCP[::]:3389[::]:0LISTENING
TCP[::]:5985[::]:0LISTENING
TCP[::]:7680[::]:0LISTENING
TCP[::]:8834[::]:0LISTENING
TCP[::]:47001[::]:0LISTENING
TCP[::]:49664[::]:0LISTENING
TCP[::]:49665[::]:0LISTENING
TCP[::]:49666[::]:0LISTENING
TCP[::]:49667[::]:0LISTENING
TCP[::]:49668[::]:0LISTENING
TCP[::]:49669[::]:0LISTENING
TCP[::]:49697[::]:0LISTENING
TCP[::1]:49672[::]:0LISTENING
UDP0.0.0.0:123*:*13032
UDP0.0.0.0:500*:*6060
UDP0.0.0.0:3389*:*1836
UDP0.0.0.0:3544*:*5808
UDP0.0.0.0:3702*:*3656
UDP0.0.0.0:3702*:*3656
UDP0.0.0.0:4500*:*6060
UDP0.0.0.0:5050*:*10432
UDP0.0.0.0:5353*:*15764
UDP0.0.0.0:5353*:*15764
UDP0.0.0.0:5353*:*2476
UDP0.0.0.0:5353*:*15764
UDP0.0.0.0:5353*:*15764
UDP0.0.0.0:5355*:*2476
UDP0.0.0.0:50949*:*2476
UDP0.0.0.0:57515*:*2476
UDP0.0.0.0:59139*:*2476
UDP0.0.0.0:59928*:*3656
UDP127.0.0.1:1900*:*5476
UDP127.0.0.1:49670127.0.0.1:496705808
UDP127.0.0.1:65524*:*5476
UDP192.168.4.61:137*:*4
UDP192.168.4.61:138*:*4
UDP192.168.4.61:1900*:*5476
UDP192.168.4.61:50228*:*5808
UDP192.168.4.61:65523*:*5476
UDP192.168.13.1:137*:*4
UDP192.168.13.1:138*:*4
UDP192.168.13.1:1900*:*5476
UDP192.168.13.1:65521*:*5476
UDP192.168.195.1:137*:*4
UDP192.168.195.1:138*:*4
UDP192.168.195.1:1900*:*5476
UDP192.168.195.1:65522*:*5476
UDP[::]:123*:*13032
UDP[::]:500*:*6060
UDP[::]:3389*:*1836
UDP[::]:3702*:*3656
UDP[::]:3702*:*3656
UDP[::]:4500*:*6060
UDP[::]:5353*:*15764
UDP[::]:5353*:*2476
UDP[::]:50949*:*2476
UDP[::]:57515*:*2476
UDP[::]:59139*:*2476
UDP[::]:59929*:*3656
UDP[::1]:1900*:*5476
UDP[::1]:65520*:*5476
TimeIDActionUserTask
10/14/2025 10:34:19 AM4699A scheduled task was deletedDESKTOP-NM6VC29$\NahimicTask64
10/14/2025 10:34:19 AM4699A scheduled task was deletedDESKTOP-NM6VC29$\NahimicTask32
10/14/2025 10:34:19 AM4698A scheduled task was createdDESKTOP-NM6VC29$\NahimicTask64
10/14/2025 10:34:19 AM4698A scheduled task was createdDESKTOP-NM6VC29$\NahimicTask32
10/14/2025 10:34:19 AM4699A scheduled task was deletedDESKTOP-NM6VC29$\NahimicTask64
10/14/2025 10:34:19 AM4699A scheduled task was deletedDESKTOP-NM6VC29$\NahimicTask32
10/14/2025 10:34:19 AM4698A scheduled task was createdDESKTOP-NM6VC29$\NahimicTask64
10/14/2025 10:34:19 AM4698A scheduled task was createdDESKTOP-NM6VC29$\NahimicTask32
10/14/2025 10:34:19 AM4699A scheduled task was deletedDESKTOP-NM6VC29$\NahimicTask64
10/14/2025 10:34:19 AM4699A scheduled task was deletedDESKTOP-NM6VC29$\NahimicTask32
TimeIDUserService NameService File Name
10/14/2025 9:38:28 AM4697DESKTOP-NM6VC29$WpnUserService_104ec2C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
10/14/2025 9:38:28 AM4697DESKTOP-NM6VC29$webthreatdefusersvc_104ec2C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p
10/14/2025 9:38:28 AM4697DESKTOP-NM6VC29$UserDataSvc_104ec2C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
10/14/2025 9:38:28 AM4697DESKTOP-NM6VC29$UnistoreSvc_104ec2C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup
10/14/2025 9:38:28 AM4697DESKTOP-NM6VC29$UdkUserSvc_104ec2C:\WINDOWS\system32\svchost.exe -k UdkSvcGroup
10/14/2025 9:38:28 AM4697DESKTOP-NM6VC29$PrintWorkflowUserSvc_104ec2C:\WINDOWS\system32\svchost.exe -k PrintWorkflow
10/14/2025 9:38:28 AM4697DESKTOP-NM6VC29$PimIndexMaintenanceSvc_104ec2C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
10/14/2025 9:38:28 AM4697DESKTOP-NM6VC29$PenService_104ec2C:\WINDOWS\system32\svchost.exe -k PenService
10/14/2025 9:38:28 AM4697DESKTOP-NM6VC29$P9RdrService_104ec2C:\WINDOWS\system32\svchost.exe -k P9RdrService -p
10/14/2025 9:38:28 AM4697DESKTOP-NM6VC29$OneSyncSvc_104ec2C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup

Report: 10-15-2025
BenchmarkCAT I OpenCAT I TotalCAT II OpenCAT II TotalCAT III OpenCAT III TotalScore
Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual Questions3420370043.9
SubTotal3420370043.9
Vuln IDBenchmarkRule TitleSeverityStatusCCI
V-213426Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to block the Potentially Unwanted Application (PUA) feature.CAT IOpenCCI-001243
V-213452Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV spyware definition age must not exceed 7 days.CAT IOpenCCI-001240
V-213453Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV virus definition age must not exceed 7 days.CAT IOpenCCI-001240
Vuln IDBenchmarkRule TitleSeverityStatusCCI
V-213431Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to enable the Automatic Exclusions feature.CAT IIOpenCCI-001242
V-213433Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to check in real time with MAPS before content is run or accessed.CAT IIOpenCCI-001242
V-213434Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to join Microsoft MAPS.CAT IIOpenCCI-001170
V-213435Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to only send safe samples for MAPS telemetry.CAT IIOpenCCI-001170
V-213449Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to scan removable drives.CAT IIOpenCCI-000870
V-213450Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to perform a weekly scheduled scan.CAT IIOpenCCI-001241
V-213451Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to turn on e-mail scanning.CAT IIOpenCCI-001170
V-213454Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to check for definition updates daily.CAT IIOpenCCI-001308
V-213455Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured for automatic remediation action to be taken for threat alert level Severe.CAT IIOpenCCI-001662
V-213456Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to block executable content from email client and webmail.CAT IIOpenCCI-001170
V-213457Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured block Office applications from creating child processes.CAT IIOpenCCI-001170
V-213458Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured block Office applications from creating executable content.CAT IIOpenCCI-001170
V-213459Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to block Office applications from injecting into other processes.CAT IIOpenCCI-001170
V-213460Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to impede JavaScript and VBScript to launch executables.CAT IIOpenCCI-001170
V-213461Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to block execution of potentially obfuscated scripts.CAT IIOpenCCI-001170
V-213462Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to block Win32 imports from macro code in Office.CAT IIOpenCCI-001170
V-213463Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to prevent user and apps from accessing dangerous websites.CAT IIOpenCCI-001170
V-213464Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured for automatic remediation action to be taken for threat alert level High.CAT IIOpenCCI-001662
V-213465Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured for automatic remediation action to be taken for threat alert level Medium.CAT IIOpenCCI-001662
V-213466Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured for automatic remediation action to be taken for threat alert level Low.CAT IIOpenCCI-001662
Vuln IDBenchmarkRule TitleSeverityStatusCCI
NoneNoneNoneNoneNoneNone
Vuln IDBenchmarkRule TitleSeverityStatusCCI
V-213427Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to automatically take action on all detected tasks.CAT IINot a FindingCCI-001243
V-213428Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to run and scan for malware and other potentially unwanted software.CAT INot a FindingCCI-001242
V-213429Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to not exclude files for scanning.CAT IINot a FindingCCI-001242
V-213430Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to not exclude files opened by specified processes.CAT IINot a FindingCCI-001242
V-213432Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to disable local setting override for reporting to Microsoft MAPS.CAT IINot a FindingCCI-001170
V-213436Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured for protocol recognition for network protection.CAT IINot a FindingCCI-001242
V-213437Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to not allow local override of monitoring for file and program activity.CAT IINot a FindingCCI-001695
V-213438Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to not allow override of monitoring for incoming and outgoing file activity.CAT IINot a FindingCCI-001695
V-213439Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to not allow override of scanning for downloaded files and attachments.CAT IINot a FindingCCI-001169
V-213440Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to not allow override of behavior monitoring.CAT IINot a FindingCCI-001170
V-213441Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV Group Policy settings must take priority over the local preference settings.CAT IINot a FindingCCI-001242
V-213442Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must monitor for incoming and outgoing files.CAT IINot a FindingCCI-001242
V-213443Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to monitor for file and program activity.CAT IINot a FindingCCI-001242
V-213444Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to scan all downloaded files and attachments.CAT IINot a FindingCCI-001169
V-213445Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to always enable real-time protection.CAT IINot a FindingCCI-001242
V-213446Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to enable behavior monitoring.CAT IINot a FindingCCI-001170
V-213447Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to process scanning when real-time protection is enabled.CAT IINot a FindingCCI-001242
V-213448Microsoft Defender Antivirus STIG SCAP Benchmark - NIWC Enhanced with Manual QuestionsMicrosoft Defender AV must be configured to scan archive files.CAT IINot a FindingCCI-001242

Report: 10-14-2025
KeyValue
ReportLocation C:\Temp
ReportName $(Get-Date -Format yyyyMMdd)-$($env:COMPUTERNAME)-POWERSTRUXWA-REPORT
DaysToAudit 1
AuditDataTransfers 1
FilteredSids S-1-5-18,S-1-5-19,S-1-5-90-0-1,S-1-5-20,S-1-5-96-0-1,S-1-5-96-0-0,S-1-5-90-0-2,S-1-5-96-0-2,S-1-5-90-0-4,S-1-5-96-0-4,S-1-5-90-0-3,S-1-5-96-0-3
ShowDisabledUsers 0
PathLogSecurity C:\Windows\System32\winevt\Logs\Security.evtx
PathLogApplication C:\Windows\System32\winevt\Logs\Application.evtx
PathLogSystem C:\Windows\System32\winevt\Logs\System.evtx
PathLogPrint C:\Windows\System32\winevt\Logs\Microsoft-Windows-PrintService%4Operational.evtx
ClearLogSecurity 0
ClearLogBackupPathSecurity C:\Windows\System32\winevt\Logs
ClearLogBackupFileNameSecurity $(Get-Date -Format yyyyMMdd)-$env:COMPUTERNAME-Security.evtx
ClearLogApplication 0
ClearLogBackupPathApplication C:\Windows\System32\winevt\Logs
ClearLogBackupFileNameApplication $(Get-Date -Format yyyyMMdd)-$env:COMPUTERNAME-Application.evtx
ClearLogSystem 0
ClearLogBackupPathSystem C:\Windows\System32\winevt\Logs
ClearLogBackupFileNameSystem $(Get-Date -Format yyyyMMdd)-$env:COMPUTERNAME-System.evtx
ClearLogPrint 0
ClearLogBackupPathPrint C:\Windows\System32\winevt\Logs
ClearLogBackupFileNamePrint $(Get-Date -Format yyyyMMdd)-$env:COMPUTERNAME-Print.evtx
EnableSccScan 1
SccRootDirectory C:\Security
ShowDefender 1