Skip to content

Commit ad3df2e

Browse files
committed
Clean-up Inventory and add rest of analyses
1 parent 4c09395 commit ad3df2e

File tree

59 files changed

+1118
-581
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

59 files changed

+1118
-581
lines changed

Analyses/Applications - Audit Usage - Windows.bes

Lines changed: 0 additions & 33 deletions
This file was deleted.

Analyses/Applications - Gather Usage - Windows.bes

Lines changed: 0 additions & 36 deletions
This file was deleted.
Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
<?xml version="1.0" encoding="UTF-8"?>
2+
<BES xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="BES.xsd">
3+
<Analysis>
4+
<Title>Applications - Java - Windows</Title>
5+
<Description>Information about Java </Description>
6+
<Relevance>true</Relevance>
7+
<Source>Internal</Source>
8+
<SourceReleaseDate>2016-04-12</SourceReleaseDate>
9+
<MIMEField>
10+
<Name>x-fixlet-modification-time</Name>
11+
<Value>Mon, 25 Apr 2016 01:43:51 +0000</Value>
12+
</MIMEField>
13+
<Domain>BESC</Domain>
14+
<Property Name="Java - Installed - Windows (x86)" ID="1">values "DisplayName" of (keys whose (value "DisplayName" of it as string starts with "Java") of keys "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall" of ( x32 registry)) as string</Property>
15+
<Property Name="Java - Installed - Windows (x64)" ID="2">if (x64 of operating system) then (values "DisplayName" of (keys whose (value "DisplayName" of it as string starts with "Java") of keys "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall" of ( x64 registry)) as string) else ("N/A (not 64-bit)")</Property>
16+
<Property Name="Java - Config - exceptions.sites - Windows" ID="3">unique values of (it as string) of lines of files "exception.sites" of folders "AppData\LocalLow\Sun\Java\Deployment\security" of folders whose(exists folders "AppData\LocalLow\Sun\Java\Deployment\security" of it) of folder "C:\Users"</Property>
17+
</Analysis>
18+
</BES>
19+
Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
<?xml version="1.0" encoding="UTF-8"?>
2+
<BES xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="BES.xsd">
3+
<Analysis>
4+
<Title>Applications - Universal</Title>
5+
<Description>Application Inventory</Description>
6+
<Relevance>true</Relevance>
7+
<Source>Internal</Source>
8+
<SourceReleaseDate>2016-03-30</SourceReleaseDate>
9+
<MIMEField>
10+
<Name>x-fixlet-modification-time</Name>
11+
<Value>Mon, 25 Apr 2016 02:26:28 +0000</Value>
12+
</MIMEField>
13+
<Domain>BESC</Domain>
14+
<Property Name="Applications - Currently Running - Universal" ID="1">running applications</Property>
15+
<Property Name="Applications - Registered Applications - Universal" ID="2" EvaluationPeriod="PT1H">regapps</Property>
16+
<Property Name="Applications - Installed - Windows" ID="4" EvaluationPeriod="P1D">unique values of (it as string) of (value "DisplayName" of it as string as trimmed string, (value "DisplayVersion" of it as string | "None")) of keys whose (exists value "DisplayName" of it) of keys "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall" of (if x64 of operating system then (x64 registry;x32 registry) else x32 registry)</Property>
17+
<Property Name="Applications - Uninstall Strings - Windows" ID="5" EvaluationPeriod="P2D">(value "DisplayName" of it as string | "N\A", value "UninstallString" of it as string | "N\A") of (keys of keys "HKLM\software\microsoft\windows\currentversion\uninstall" of ( x32 registry; (if exists x64 registry then x64 registry else nothing) )) whose ((exists (it) and it as string does not contain "Oarpmany.exe") of value "UninstallString" of it)</Property>
18+
<Property Name="Applications - Silent Uninstall Strings - Windows" ID="6" EvaluationPeriod="P2D">(value "DisplayName" of it as string | "N\A", value "QuietUninstallString" of it as string | "N\A") of (keys of keys "HKLM\software\microsoft\windows\currentversion\uninstall" of ( x32 registry; (if exists x64 registry then x64 registry else nothing) )) whose ((exists (it) and it as string does not contain "Oarpmany.exe") of value "QuietUninstallString" of it)</Property>
19+
</Analysis>
20+
</BES>
21+

Analyses/Audit - Process Creation - Windows.bes

Lines changed: 0 additions & 32 deletions
This file was deleted.

Analyses/DNS - Hosts File - WinMac.bes

Lines changed: 0 additions & 19 deletions
This file was deleted.

Analyses/Drivers - Printers - Windows.bes

Lines changed: 0 additions & 18 deletions
This file was deleted.

Analyses/Drivers - Windows.bes

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
<?xml version="1.0" encoding="UTF-8"?>
2+
<BES xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="BES.xsd">
3+
<Analysis>
4+
<Title>Drivers - Windows</Title>
5+
<Description>This analysis covers the action that Windows takes when loading drivers with invalid or missing digital signatures as well as the install printer drivers on the system.</Description>
6+
<Relevance><![CDATA[windows of operating system and version of operating system >= "5.1"]]></Relevance>
7+
<Relevance>not in proxy agent context</Relevance>
8+
<Source>Internal</Source>
9+
<SourceReleaseDate>2016-04-23</SourceReleaseDate>
10+
<MIMEField>
11+
<Name>x-fixlet-modification-time</Name>
12+
<Value>Sun, 24 Apr 2016 20:13:38 +0000</Value>
13+
</MIMEField>
14+
<Domain>BESC</Domain>
15+
<Property Name="Drivers - Behavior on Signature Failure - Windows" ID="1">(if (it = "00") then ("Ignore") else (if (it = "01") then "Warn" else "Block")) of (value "Policy" of key "HKEY_LOCAL_MACHINE\Software\Microsoft\Non-Driver Signing" of native registry as string)</Property>
16+
<Property Name="Drivers - Printers - Windows" ID="3">unique values of names of keys of keys of keys "Drivers" of keys of key "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Environments" of native registry</Property>
17+
<Property Name="Drivers - Printers with Versions - Windows" ID="4">(names of it, value "DriverVersion" of it as string) of keys of keys of keys "Drivers" of keys of key "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Environments" of native registry</Property>
18+
</Analysis>
19+
</BES>
20+

Analyses/Event Log - Max Size - Windows.bes

Lines changed: 0 additions & 35 deletions
This file was deleted.

Analyses/Event Log - Windows.bes

Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
<?xml version="1.0" encoding="UTF-8"?>
2+
<BES xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="BES.xsd">
3+
<Analysis>
4+
<Title>Event Log - Windows</Title>
5+
<Description><![CDATA[Learn more about this analysis online: <A href="http://bigfix.me/cdb/analysis/2995921">http://bigfix.me/cdb/analysis/2995921</A><BR><BR>Pulls the maximum size of various event logs from the Windows Registry and formats them as megabytes ]]></Description>
6+
<Relevance><![CDATA[windows of operating system and version of operating system >= "6.0"]]></Relevance>
7+
<MIMEField>
8+
<Name>bigfixme-added-time</Name>
9+
<Value>Wed, 13 Apr 2016 22:23:53 GMT</Value>
10+
</MIMEField>
11+
<MIMEField>
12+
<Name>bigfixme-modification-time</Name>
13+
<Value>Wed, 13 Apr 2016 22:23:53 GMT</Value>
14+
</MIMEField>
15+
<MIMEField>
16+
<Name>bigfixme-keywords</Name>
17+
<Value>Poor Man's Inventory</Value>
18+
</MIMEField>
19+
<MIMEField>
20+
<Name>bigfixme-ID</Name>
21+
<Value>2995921</Value>
22+
</MIMEField>
23+
<MIMEField>
24+
<Name>x-fixlet-modification-time</Name>
25+
<Value>Sun, 24 Apr 2016 20:14:52 +0000</Value>
26+
</MIMEField>
27+
<Domain>BESC</Domain>
28+
<Property Name="Event Log - Security Max Size (MB) - Windows" ID="1">(value "MaxSize" of key "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\EventLog\Security" of registry) as string as integer / 1024 / 1024</Property>
29+
<Property Name="Event Log - Hardware Events Max Size (MB) - Windows" ID="2">(value "MaxSize" of key "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\EventLog\HardwareEvents" of registry) as string as integer / 1024 / 1024</Property>
30+
<Property Name="Event Log - Key Management Service Max Size (MB) - Windows" ID="4">(value "MaxSize" of key "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\EventLog\Key Management Service" of registry) as string as integer / 1024 / 1024</Property>
31+
<Property Name="Event Log - System Max Size (MB) - Windows" ID="5">(value "MaxSize" of key "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\EventLog\System" of registry) as string as integer / 1024 / 1024</Property>
32+
<Property Name="Event Log - Powershell - Max Size (MB) - Windows" ID="6">(value "MaxSize" of key "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\EventLog\Windows PowerShell" of registry) as string as integer / 1024 / 1024</Property>
33+
</Analysis>
34+
</BES>
35+

0 commit comments

Comments
 (0)