| Rule Name | Severity | Added | Removed | Modified | Errors |
| (*)
|
Critical System Startup files [C:\] |
1,000 |
1 |
0 |
0 |
0 |
|
OS Support Files [C:\WINDOWS] |
35 |
0 |
0 |
0 |
0 |
|
System32 Folder [C:\WINDOWS\System32] |
100 |
0 |
0 |
0 |
0 |
|
Network Configuration Files [C:\WINDOWS\System32\config\systemprofile] |
100 |
0 |
0 |
0 |
0 |
|
Network Configuration Files [C:\WINDOWS\System32\dhcp] |
100 |
0 |
0 |
0 |
0 |
|
Critical Drivers [C:\WINDOWS\System32\drivers] |
35 |
0 |
0 |
0 |
0 |
|
Network Configuration Files [C:\WINDOWS\System32\drivers\etc\hosts] |
100 |
0 |
0 |
0 |
0 |
|
Network Configuration Files [C:\WINDOWS\System32\drivers\etc\networks] |
100 |
0 |
0 |
0 |
0 |
|
Network Configuration Files [C:\WINDOWS\System32\drivers\etc\protocol] |
100 |
0 |
0 |
0 |
0 |
|
Network Configuration Files [C:\WINDOWS\System32\drivers\etc\services] |
100 |
0 |
0 |
0 |
0 |
|
Network Configuration Files [C:\WINDOWS\System32\ras] |
100 |
0 |
0 |
0 |
0 |
|
Network Configuration Files [C:\WINDOWS\System32\setup] |
100 |
0 |
0 |
0 |
0 |
|
Network Configuration Files [C:\WINDOWS\System32\ShellExt] |
100 |
0 |
0 |
0 |
0 |
|
Network Configuration Files [C:\WINDOWS\System32\wins] |
100 |
0 |
0 |
0 |
0 |
|
OS Support Files [C:\WINDOWS\System32\dllcache] |
35 |
0 |
0 |
0 |
0 |
|
OS Support Files [C:\WINDOWS\Config] |
35 |
0 |
0 |
0 |
0 |
|
System Folder [C:\WINDOWS\System] |
35 |
0 |
0 |
0 |
0 |
|
Network Configuration Files [C:\WINDOWS\security\templates] |
100 |
0 |
0 |
0 |
0 |
|
Critical Drivers [C:\WINDOWS\Driver Cache] |
35 |
0 |
0 |
0 |
0 |
|
OS Support Files [C:\WINDOWS\bootstat.dat] |
35 |
0 |
0 |
0 |
0 |
|
OS Support Files [C:\WINDOWS\inf] |
35 |
0 |
0 |
0 |
0 |
|
OS Support Files [C:\WINDOWS\repair] |
35 |
0 |
0 |
0 |
0 |
|
Program Files Folder [C:\Program Files] |
35 |
0 |
0 |
0 |
0 |
|
Tripwire for Servers Configuration Files [C:\PROGRAM FILES\TRIPWIRE\TFS\Policy] |
1,000 |
0 |
0 |
0 |
0 |
|
Tripwire for Servers Executables [C:\PROGRAM FILES\TRIPWIRE\TFS\Bin] |
1,000 |
0 |
0 |
0 |
0 |
|
Tripwire for Servers Executables [C:\PROGRAM FILES\TRIPWIRE\TFS\Bin\twagent.exe] |
1,000 |
0 |
0 |
0 |
0 |
|
Tripwire for Servers Executables [C:\PROGRAM FILES\TRIPWIRE\TFS\Bin\tripwire.exe] |
1,000 |
0 |
0 |
0 |
0 |
|
Tripwire for Servers Executables [C:\PROGRAM FILES\TRIPWIRE\TFS\Bin\twadmin.exe] |
1,000 |
0 |
0 |
0 |
0 |
|
Tripwire for Servers Executables [C:\PROGRAM FILES\TRIPWIRE\TFS\Bin\twprint.exe] |
1,000 |
0 |
0 |
0 |
0 |
|
Tripwire for Servers Executables [C:\PROGRAM FILES\TRIPWIRE\TFS\Bin\siggen.exe] |
1,000 |
0 |
0 |
0 |
0 |
|
Tripwire for Servers Configuration Files [C:\PROGRAM FILES\TRIPWIRE\TFS\Bin\tw.cfg] |
1,000 |
0 |
0 |
0 |
0 |
|
Tripwire for Servers Log and Support Files [C:\PROGRAM FILES\TRIPWIRE\TFS\Bin\twserver.cert] |
1,000 |
0 |
0 |
0 |
0 |
|
Tripwire for Servers Configuration Files [C:\PROGRAM FILES\TRIPWIRE\TFS\DB] |
1,000 |
0 |
0 |
0 |
0 |
|
Tripwire for Servers Configuration Files [C:\PROGRAM FILES\TRIPWIRE\TFS\Key] |
1,000 |
0 |
0 |
0 |
0 |
|
Tripwire for Servers Log and Support Files [C:\PROGRAM FILES\TRIPWIRE\TFS\Docs] |
1,000 |
0 |
0 |
0 |
0 |
|
System32 Folder [C:\WINDOWS\System32\CatRoot] |
100 |
0 |
0 |
0 |
0 |
|
System32 Folder [C:\WINDOWS\System32\CatRoot2] |
100 |
0 |
0 |
0 |
0 |
|
System32 Folder [C:\WINDOWS\System32\spool] |
100 |
0 |
0 |
0 |
0 |
|
System32 Folder [C:\WINDOWS\System32\wbem\Logs] |
100 |
0 |
0 |
0 |
0 |
|
System32 Folder [C:\WINDOWS\System32\wbem\Repository] |
100 |
0 |
0 |
0 |
0 |
|
Network Configuration Files [C:\WINDOWS\System32\config] |
100 |
0 |
0 |
0 |
0 |
|
Network Configuration Files [C:\WINDOWS\security] |
100 |
0 |
0 |
0 |
0 |
|
Temporary Files Folder [C:\WINDOWS\temp] |
15 |
0 |
0 |
0 |
0 |
|
Tripwire for Servers Log and Support Files [C:\PROGRAM FILES\TRIPWIRE\TFS\Report] |
1,000 |
0 |
0 |
0 |
0 |
| Rule Name | Severity | Added | Removed | Modified | Errors |
|
Hardware keys [HKEY_LOCAL_MACHINE\SYSTEM\Setup] |
35 |
0 |
0 |
0 |
0 |
| (*)
|
Service Registry Keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services] |
100 |
0 |
0 |
9 |
0 |
|
Service Registry Keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysmonLog\Log Queries] |
100 |
0 |
0 |
0 |
0 |
| (*)
|
Critical Tripwire Registry keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\TripwireAdminUtility_sys] |
1,000 |
0 |
0 |
2 |
0 |
| (*)
|
Critical Tripwire Registry keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\TripwireAdminUtility_sec] |
1,000 |
0 |
0 |
2 |
0 |
|
Critical Tripwire Registry keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Tripwire_sec] |
1,000 |
0 |
0 |
0 |
0 |
| (*)
|
Critical Tripwire Registry keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\TripwirePrintUtility_sec] |
1,000 |
0 |
0 |
2 |
0 |
|
Critical Tripwire Registry keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Tripwire] |
1,000 |
0 |
0 |
0 |
0 |
| (*)
|
Critical Tripwire Registry keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\TripwireAdminUtility] |
1,000 |
0 |
0 |
2 |
0 |
|
Security Information keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Windows] |
100 |
0 |
0 |
0 |
0 |
| (*)
|
Critical Security Account Keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA] |
1,000 |
0 |
0 |
2 |
0 |
| (*)
|
Critical Tripwire Registry keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Audit\Sources\TripwireAdminUtility_sec] |
1,000 |
0 |
0 |
1 |
0 |
|
Security Information keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FileSystem] |
100 |
0 |
0 |
0 |
0 |
|
Security Information keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetworkProvider] |
100 |
0 |
0 |
0 |
0 |
|
Security Information keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Providers\Lanman Print Services] |
100 |
0 |
0 |
0 |
0 |
|
Security Information keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurePipeServers] |
100 |
0 |
0 |
0 |
0 |
|
Security Information keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment] |
100 |
0 |
0 |
0 |
0 |
|
Security Information keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Executive] |
100 |
0 |
0 |
0 |
0 |
|
Security Information keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs] |
100 |
0 |
0 |
0 |
0 |
|
Security Information keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\+ClearPageFileAtShutdown] |
100 |
0 |
0 |
0 |
0 |
|
Security Information keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems] |
100 |
0 |
0 |
0 |
0 |
|
Hardware keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles] |
35 |
0 |
0 |
0 |
0 |
|
Critical Security Account Keys [HKEY_LOCAL_MACHINE\SECURITY\SAM\Domains\Account] |
1,000 |
0 |
0 |
0 |
0 |
|
Critical Security Account Keys [HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account] |
1,000 |
0 |
0 |
0 |
0 |
|
Local Admin Activity [HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Users\000001F4] |
1,000 |
0 |
0 |
0 |
0 |
|
Local Admin Login [HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Users\000001F4\+F] |
1,000 |
0 |
0 |
0 |
0 |
|
Local Admin Password Change [HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Users\000001F4\+V] |
1,000 |
0 |
0 |
0 |
0 |
|
Guest Account Activity [HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Users\000001F5] |
1,000 |
0 |
0 |
0 |
0 |
|
System Startup Executables [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] |
1,000 |
0 |
0 |
0 |
0 |
|
System Startup Executables [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx] |
1,000 |
0 |
0 |
0 |
0 |
|
Critical System Registry Keys [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Drivers] |
100 |
0 |
0 |
0 |
0 |
|
Critical System Registry Keys [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] |
100 |
0 |
0 |
0 |
0 |
|
Critical System Registry Keys [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Drivers32] |
100 |
0 |
0 |
0 |
0 |
|
Critical System Registry Keys [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Network] |
100 |
0 |
0 |
0 |
0 |
|
Critical System Registry Keys [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\WOW] |
100 |
0 |
0 |
0 |
0 |
|
Critical System Registry Keys [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AeDebug] |
100 |
0 |
0 |
0 |
0 |
|
Critical System Registry Keys [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Embedding] |
100 |
0 |
0 |
0 |
0 |
|
Critical System Registry Keys [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Userinstallable.drivers] |
100 |
0 |
0 |
0 |
0 |
|
System Startup Executables [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\IniFileMapping] |
1,000 |
0 |
0 |
0 |
0 |
|
Security Information keys [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options] |
100 |
0 |
0 |
0 |
0 |
|
Security Information keys [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Hotfix] |
100 |
0 |
0 |
0 |
0 |
|
Software keys [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc] |
35 |
0 |
0 |
0 |
0 |
|
Software keys [HKEY_LOCAL_MACHINE\SOFTWARE\Clients] |
35 |
0 |
0 |
0 |
0 |
|
Hardware keys [HKEY_LOCAL_MACHINE\hardware] |
35 |
0 |
0 |
0 |
0 |
|
Critical System Registry Keys [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies] |
100 |
0 |
0 |
0 |
0 |
|
System Startup Executables [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] |
1,000 |
0 |
0 |
0 |
0 |
|
Security Information keys [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions] |
100 |
0 |
0 |
0 |
0 |
|
Current User Registry keys [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\WinTrust] |
15 |
0 |
0 |
0 |
0 |
|
Current User Registry keys [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] |
15 |
0 |
0 |
0 |
0 |
|
Current User Registry keys [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Network\Persistent Connections] |
15 |
0 |
0 |
0 |
0 |
|
Current User Registry keys [HKEY_CURRENT_USER\Software\Microsoft\RegEdt32] |
15 |
0 |
0 |
0 |
0 |
|
Current User Registry keys [HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates] |
15 |
0 |
0 |
0 |
0 |
|
System Startup Executables [HKEY_CURRENT_USER\Control Panel\Desktop\+ScreenSaveActive] |
1,000 |
0 |
0 |
0 |
0 |
|
System Startup Executables [HKEY_CURRENT_USER\Control Panel\Desktop\+ScreenSaverIsSecure] |
1,000 |
0 |
0 |
0 |
0 |
|
System Startup Executables [HKEY_CURRENT_USER\Control Panel\Desktop\+ScreenSaveTimeOut] |
1,000 |
0 |
0 |
0 |
0 |
|
Current User Registry keys [HKEY_CURRENT_USER\Environment] |
15 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\Network] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\AllFilesystemObjects] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\AppID] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\batfile] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\cmdfile] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\comfile] |
35 |
0 |
0 |
0 |
0 |
| (*)
|
Class keys [HKEY_CLASSES_ROOT\Component Categories] |
35 |
5 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\Directory] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\Drive] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\exefile] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\file] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\FILETYPE] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\Filter] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\Folder] |
35 |
0 |
0 |
0 |
0 |
| (*)
|
Class keys [HKEY_CLASSES_ROOT\Interface] |
35 |
189 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\ldap] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\LDAPNamespace] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\lnkfile] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\Media Type] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\MIME] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\NDS] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\NDSNamespace] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\Pathname] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\PROTOCOLS] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\SecurityDescriptor] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\Shell.Application] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\Shell.Explorer] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\txtfile] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\Unknown] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\WinNT] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\WinNTNamespace] |
35 |
0 |
0 |
0 |
0 |
|
Service Registry Keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters] |
100 |
0 |
0 |
0 |
0 |
|
Service Registry Keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters] |
100 |
0 |
0 |
0 |
0 |
|
Service Registry Keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DNSRegisteredAdapters] |
100 |
0 |
0 |
0 |
0 |
|
Service Registry Keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces] |
100 |
0 |
0 |
0 |
0 |
|
Service Registry Keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TrkWks\Parameters] |
100 |
0 |
0 |
0 |
0 |
|
Critical System Registry Keys [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions] |
100 |
0 |
0 |
0 |
0 |
|
Critical System Registry Keys [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList] |
100 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\CLSID] |
35 |
0 |
0 |
0 |
0 |
|
Class keys [HKEY_CLASSES_ROOT\Typelib] |
35 |
0 |
0 |
0 |
0 |