Tripwire Report



Table of Contents

  1. Report Summary
  2. Rule Summary
  3. Object Summary
  4. Object Details
  5. Error Report


Report Summary

Generated By admin
Created On Mon, 01 May 2006 00:03:44 -0400
DB Updated Sun, 30 Apr 2006 22:37:52 -0400
Host Name ITL-00
IP Address 128.153.144.112
Host ID S-1-5-21-1935655697-1336601894-725345543
Policy File C:\Program Files\Tripwire\TFS\policy\tw.pol
Config File C:\Program Files\Tripwire\TFS\Bin\tw.cfg
DB File C:\Program Files\Tripwire\TFS\db\database.twd
Report File c:\Program Files\Tripwire\TFS\Report\after-alexa.twr
Command Line tripwire.exe --check --report-file c:\Program Files\Tripwire\TFS\Report\after-alexa.twr
Print Command twprint --print-report --report-file c:\Program Files\Tripwire\TFS\Report\after-alexa.twr -F html -o c:\Program Files\Tripwire\TFS\Report\after-alexa.html

Max Severity 1,000
Total Added 195
Total Removed 0
Total Modified 20
High Severity 21
Medium Severity 194
Low Severity 0



Rule Summary

Section: Windows File System

Rule NameSeverityAddedRemovedModifiedErrors
(*) Critical System Startup files [C:\] 1,000 1 0 0 0
OS Support Files [C:\WINDOWS] 35 0 0 0 0
System32 Folder [C:\WINDOWS\System32] 100 0 0 0 0
Network Configuration Files [C:\WINDOWS\System32\config\systemprofile] 100 0 0 0 0
Network Configuration Files [C:\WINDOWS\System32\dhcp] 100 0 0 0 0
Critical Drivers [C:\WINDOWS\System32\drivers] 35 0 0 0 0
Network Configuration Files [C:\WINDOWS\System32\drivers\etc\hosts] 100 0 0 0 0
Network Configuration Files [C:\WINDOWS\System32\drivers\etc\networks] 100 0 0 0 0
Network Configuration Files [C:\WINDOWS\System32\drivers\etc\protocol] 100 0 0 0 0
Network Configuration Files [C:\WINDOWS\System32\drivers\etc\services] 100 0 0 0 0
Network Configuration Files [C:\WINDOWS\System32\ras] 100 0 0 0 0
Network Configuration Files [C:\WINDOWS\System32\setup] 100 0 0 0 0
Network Configuration Files [C:\WINDOWS\System32\ShellExt] 100 0 0 0 0
Network Configuration Files [C:\WINDOWS\System32\wins] 100 0 0 0 0
OS Support Files [C:\WINDOWS\System32\dllcache] 35 0 0 0 0
OS Support Files [C:\WINDOWS\Config] 35 0 0 0 0
System Folder [C:\WINDOWS\System] 35 0 0 0 0
Network Configuration Files [C:\WINDOWS\security\templates] 100 0 0 0 0
Critical Drivers [C:\WINDOWS\Driver Cache] 35 0 0 0 0
OS Support Files [C:\WINDOWS\bootstat.dat] 35 0 0 0 0
OS Support Files [C:\WINDOWS\inf] 35 0 0 0 0
OS Support Files [C:\WINDOWS\repair] 35 0 0 0 0
Program Files Folder [C:\Program Files] 35 0 0 0 0
Tripwire for Servers Configuration Files [C:\PROGRAM FILES\TRIPWIRE\TFS\Policy] 1,000 0 0 0 0
Tripwire for Servers Executables [C:\PROGRAM FILES\TRIPWIRE\TFS\Bin] 1,000 0 0 0 0
Tripwire for Servers Executables [C:\PROGRAM FILES\TRIPWIRE\TFS\Bin\twagent.exe] 1,000 0 0 0 0
Tripwire for Servers Executables [C:\PROGRAM FILES\TRIPWIRE\TFS\Bin\tripwire.exe] 1,000 0 0 0 0
Tripwire for Servers Executables [C:\PROGRAM FILES\TRIPWIRE\TFS\Bin\twadmin.exe] 1,000 0 0 0 0
Tripwire for Servers Executables [C:\PROGRAM FILES\TRIPWIRE\TFS\Bin\twprint.exe] 1,000 0 0 0 0
Tripwire for Servers Executables [C:\PROGRAM FILES\TRIPWIRE\TFS\Bin\siggen.exe] 1,000 0 0 0 0
Tripwire for Servers Configuration Files [C:\PROGRAM FILES\TRIPWIRE\TFS\Bin\tw.cfg] 1,000 0 0 0 0
Tripwire for Servers Log and Support Files [C:\PROGRAM FILES\TRIPWIRE\TFS\Bin\twserver.cert] 1,000 0 0 0 0
Tripwire for Servers Configuration Files [C:\PROGRAM FILES\TRIPWIRE\TFS\DB] 1,000 0 0 0 0
Tripwire for Servers Configuration Files [C:\PROGRAM FILES\TRIPWIRE\TFS\Key] 1,000 0 0 0 0
Tripwire for Servers Log and Support Files [C:\PROGRAM FILES\TRIPWIRE\TFS\Docs] 1,000 0 0 0 0
System32 Folder [C:\WINDOWS\System32\CatRoot] 100 0 0 0 0
System32 Folder [C:\WINDOWS\System32\CatRoot2] 100 0 0 0 0
System32 Folder [C:\WINDOWS\System32\spool] 100 0 0 0 0
System32 Folder [C:\WINDOWS\System32\wbem\Logs] 100 0 0 0 0
System32 Folder [C:\WINDOWS\System32\wbem\Repository] 100 0 0 0 0
Network Configuration Files [C:\WINDOWS\System32\config] 100 0 0 0 0
Network Configuration Files [C:\WINDOWS\security] 100 0 0 0 0
Temporary Files Folder [C:\WINDOWS\temp] 15 0 0 0 0
Tripwire for Servers Log and Support Files [C:\PROGRAM FILES\TRIPWIRE\TFS\Report] 1,000 0 0 0 0

Total Objects: 7,105
Total Violations: 1

Section: Windows Registry

Rule NameSeverityAddedRemovedModifiedErrors
Hardware keys [HKEY_LOCAL_MACHINE\SYSTEM\Setup] 35 0 0 0 0
(*) Service Registry Keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services] 100 0 0 9 0
Service Registry Keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysmonLog\Log Queries] 100 0 0 0 0
(*) Critical Tripwire Registry keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\TripwireAdminUtility_sys] 1,000 0 0 2 0
(*) Critical Tripwire Registry keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\TripwireAdminUtility_sec] 1,000 0 0 2 0
Critical Tripwire Registry keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Tripwire_sec] 1,000 0 0 0 0
(*) Critical Tripwire Registry keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\TripwirePrintUtility_sec] 1,000 0 0 2 0
Critical Tripwire Registry keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Tripwire] 1,000 0 0 0 0
(*) Critical Tripwire Registry keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\TripwireAdminUtility] 1,000 0 0 2 0
Security Information keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Windows] 100 0 0 0 0
(*) Critical Security Account Keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA] 1,000 0 0 2 0
(*) Critical Tripwire Registry keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Audit\Sources\TripwireAdminUtility_sec] 1,000 0 0 1 0
Security Information keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FileSystem] 100 0 0 0 0
Security Information keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetworkProvider] 100 0 0 0 0
Security Information keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Providers\Lanman Print Services] 100 0 0 0 0
Security Information keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurePipeServers] 100 0 0 0 0
Security Information keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment] 100 0 0 0 0
Security Information keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Executive] 100 0 0 0 0
Security Information keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs] 100 0 0 0 0
Security Information keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\+ClearPageFileAtShutdown] 100 0 0 0 0
Security Information keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems] 100 0 0 0 0
Hardware keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles] 35 0 0 0 0
Critical Security Account Keys [HKEY_LOCAL_MACHINE\SECURITY\SAM\Domains\Account] 1,000 0 0 0 0
Critical Security Account Keys [HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account] 1,000 0 0 0 0
Local Admin Activity [HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Users\000001F4] 1,000 0 0 0 0
Local Admin Login [HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Users\000001F4\+F] 1,000 0 0 0 0
Local Admin Password Change [HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Users\000001F4\+V] 1,000 0 0 0 0
Guest Account Activity [HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Users\000001F5] 1,000 0 0 0 0
System Startup Executables [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] 1,000 0 0 0 0
System Startup Executables [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx] 1,000 0 0 0 0
Critical System Registry Keys [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Drivers] 100 0 0 0 0
Critical System Registry Keys [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 100 0 0 0 0
Critical System Registry Keys [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Drivers32] 100 0 0 0 0
Critical System Registry Keys [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Network] 100 0 0 0 0
Critical System Registry Keys [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\WOW] 100 0 0 0 0
Critical System Registry Keys [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AeDebug] 100 0 0 0 0
Critical System Registry Keys [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Embedding] 100 0 0 0 0
Critical System Registry Keys [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Userinstallable.drivers] 100 0 0 0 0
System Startup Executables [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\IniFileMapping] 1,000 0 0 0 0
Security Information keys [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options] 100 0 0 0 0
Security Information keys [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Hotfix] 100 0 0 0 0
Software keys [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc] 35 0 0 0 0
Software keys [HKEY_LOCAL_MACHINE\SOFTWARE\Clients] 35 0 0 0 0
Hardware keys [HKEY_LOCAL_MACHINE\hardware] 35 0 0 0 0
Critical System Registry Keys [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies] 100 0 0 0 0
System Startup Executables [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] 1,000 0 0 0 0
Security Information keys [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions] 100 0 0 0 0
Current User Registry keys [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\WinTrust] 15 0 0 0 0
Current User Registry keys [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 15 0 0 0 0
Current User Registry keys [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Network\Persistent Connections] 15 0 0 0 0
Current User Registry keys [HKEY_CURRENT_USER\Software\Microsoft\RegEdt32] 15 0 0 0 0
Current User Registry keys [HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates] 15 0 0 0 0
System Startup Executables [HKEY_CURRENT_USER\Control Panel\Desktop\+ScreenSaveActive] 1,000 0 0 0 0
System Startup Executables [HKEY_CURRENT_USER\Control Panel\Desktop\+ScreenSaverIsSecure] 1,000 0 0 0 0
System Startup Executables [HKEY_CURRENT_USER\Control Panel\Desktop\+ScreenSaveTimeOut] 1,000 0 0 0 0
Current User Registry keys [HKEY_CURRENT_USER\Environment] 15 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\Network] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\AllFilesystemObjects] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\AppID] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\batfile] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\cmdfile] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\comfile] 35 0 0 0 0
(*) Class keys [HKEY_CLASSES_ROOT\Component Categories] 35 5 0 0 0
Class keys [HKEY_CLASSES_ROOT\Directory] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\Drive] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\exefile] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\file] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\FILETYPE] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\Filter] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\Folder] 35 0 0 0 0
(*) Class keys [HKEY_CLASSES_ROOT\Interface] 35 189 0 0 0
Class keys [HKEY_CLASSES_ROOT\ldap] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\LDAPNamespace] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\lnkfile] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\Media Type] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\MIME] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\NDS] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\NDSNamespace] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\Pathname] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\PROTOCOLS] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\SecurityDescriptor] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\Shell.Application] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\Shell.Explorer] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\txtfile] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\Unknown] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\WinNT] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\WinNTNamespace] 35 0 0 0 0
Service Registry Keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters] 100 0 0 0 0
Service Registry Keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters] 100 0 0 0 0
Service Registry Keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DNSRegisteredAdapters] 100 0 0 0 0
Service Registry Keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces] 100 0 0 0 0
Service Registry Keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TrkWks\Parameters] 100 0 0 0 0
Critical System Registry Keys [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions] 100 0 0 0 0
Critical System Registry Keys [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList] 100 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\CLSID] 35 0 0 0 0
Class keys [HKEY_CLASSES_ROOT\Typelib] 35 0 0 0 0

Total Objects: 34,421
Total Violations: 214


Object Summary

Section: Windows File System

Rule: Critical System Startup files [C:\]

Section: Windows Registry

Rule: Service Registry Keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

Rule: Critical Tripwire Registry keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\TripwireAdminUtility_sys]

Rule: Critical Tripwire Registry keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\TripwireAdminUtility_sec]

Rule: Critical Tripwire Registry keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\TripwirePrintUtility_sec]

Rule: Critical Tripwire Registry keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\TripwireAdminUtility]

Rule: Critical Security Account Keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA]

Rule: Critical Tripwire Registry keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Audit\Sources\TripwireAdminUtility_sec]

Rule: Class keys [HKEY_CLASSES_ROOT\Component Categories]

Rule: Class keys [HKEY_CLASSES_ROOT\Interface]



Object Details

Section: Windows File System

Rule: Critical System Startup files [C:\]

Start Point C:\
Severity 1,000
Added Objects 1
Removed Objects 0
Modified Objects 0
Errors 0

Section: Windows Registry

Rule: Service Registry Keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

Start Point HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
Severity 100
Added Objects 0
Removed Objects 0
Modified Objects 9
Errors 0

Modified Object: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\TripwirePrintUtility\+EventMessageFile

PropertyExpectedObserved
(*) Data Length 92 82
(*) CRC32 d9d32cf4 b5c8d607
(*) MD5 9b90f0a0ceb4deba35b12b5101c22d32 21397d836e6a301326842a16587dc8e8


Modified Object: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\TripwirePrintUtility\+ParameterMessageFile

PropertyExpectedObserved
(*) Data Length 92 82
(*) CRC32 d9d32cf4 b5c8d607
(*) MD5 9b90f0a0ceb4deba35b12b5101c22d32 21397d836e6a301326842a16587dc8e8


Modified Object: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\TripwirePrintUtility_sys\+EventMessageFile

PropertyExpectedObserved
(*) Data Length 92 82
(*) CRC32 d9d32cf4 b5c8d607
(*) MD5 9b90f0a0ceb4deba35b12b5101c22d32 21397d836e6a301326842a16587dc8e8


Modified Object: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\TripwirePrintUtility_sys\+ParameterMessageFile

PropertyExpectedObserved
(*) Data Length 92 82
(*) CRC32 d9d32cf4 b5c8d607
(*) MD5 9b90f0a0ceb4deba35b12b5101c22d32 21397d836e6a301326842a16587dc8e8


Modified Object: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\+Epoch

PropertyExpectedObserved
(*) CRC32 17c7c6f1 47e600e1
(*) MD5 3e2f6479346ef30ed48eb842b9bfad52 4c6ca9599ae456bbe0964c0bc09e6814


Modified Object: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{A88C54CD-8430-42F4-BDDC-3340D7F8FE62}\Parameters\Tcpip\+LeaseObtainedTime

PropertyExpectedObserved
(*) CRC32 3d730bd9 261535c0
(*) MD5 eadb4a351e477e13c755595eea78325f 126ab47bf7dd7c353426e56c927a710a


Modified Object: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{A88C54CD-8430-42F4-BDDC-3340D7F8FE62}\Parameters\Tcpip\+LeaseTerminatesTime

PropertyExpectedObserved
(*) CRC32 a8824871 c411db20
(*) MD5 5f42a6b17294292c200994864b01a1f3 aaa17e5f4c18bf65a4a4e0874853af7d


Modified Object: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{A88C54CD-8430-42F4-BDDC-3340D7F8FE62}\Parameters\Tcpip\+T1

PropertyExpectedObserved
(*) CRC32 fdea8b74 8c847377
(*) MD5 be89eefc4588a65b998c9601cebf4764 5e4cd4111059bdd1d34649fe0ac937cb


Modified Object: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{A88C54CD-8430-42F4-BDDC-3340D7F8FE62}\Parameters\Tcpip\+T2

PropertyExpectedObserved
(*) CRC32 aaa93aa2 9eceaf63
(*) MD5 c1556c94b34a4122d57972313f35c88d e32186bf5f754bc10e32da1829d75e88


Rule: Critical Tripwire Registry keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\TripwireAdminUtility_sys]

Start Point HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\TripwireAdminUtility_sys
Severity 1,000
Added Objects 0
Removed Objects 0
Modified Objects 2
Errors 0

Modified Object: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\TripwireAdminUtility_sys\+EventMessageFile

PropertyExpectedObserved
(*) Data Length 92 82
(*) CRC32 92ddd3d4 fec62927
(*) MD5 23f68a249fbc61a577cdf0bf8bde8aaf 610b65cddf861a4e38815f566b9a5257


Modified Object: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\TripwireAdminUtility_sys\+ParameterMessageFile

PropertyExpectedObserved
(*) Data Length 92 82
(*) CRC32 92ddd3d4 fec62927
(*) MD5 23f68a249fbc61a577cdf0bf8bde8aaf 610b65cddf861a4e38815f566b9a5257


Rule: Critical Tripwire Registry keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\TripwireAdminUtility_sec]

Start Point HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\TripwireAdminUtility_sec
Severity 1,000
Added Objects 0
Removed Objects 0
Modified Objects 2
Errors 0

Modified Object: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\TripwireAdminUtility_sec\+EventMessageFile

PropertyExpectedObserved
(*) Data Length 92 82
(*) CRC32 92ddd3d4 fec62927
(*) MD5 23f68a249fbc61a577cdf0bf8bde8aaf 610b65cddf861a4e38815f566b9a5257


Modified Object: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\TripwireAdminUtility_sec\+ParameterMessageFile

PropertyExpectedObserved
(*) Data Length 92 82
(*) CRC32 92ddd3d4 fec62927
(*) MD5 23f68a249fbc61a577cdf0bf8bde8aaf 610b65cddf861a4e38815f566b9a5257


Rule: Critical Tripwire Registry keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\TripwirePrintUtility_sec]

Start Point HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\TripwirePrintUtility_sec
Severity 1,000
Added Objects 0
Removed Objects 0
Modified Objects 2
Errors 0

Modified Object: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\TripwirePrintUtility_sec\+EventMessageFile

PropertyExpectedObserved
(*) Data Length 92 82
(*) CRC32 d9d32cf4 b5c8d607
(*) MD5 9b90f0a0ceb4deba35b12b5101c22d32 21397d836e6a301326842a16587dc8e8


Modified Object: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\TripwirePrintUtility_sec\+ParameterMessageFile

PropertyExpectedObserved
(*) Data Length 92 82
(*) CRC32 d9d32cf4 b5c8d607
(*) MD5 9b90f0a0ceb4deba35b12b5101c22d32 21397d836e6a301326842a16587dc8e8


Rule: Critical Tripwire Registry keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\TripwireAdminUtility]

Start Point HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\TripwireAdminUtility
Severity 1,000
Added Objects 0
Removed Objects 0
Modified Objects 2
Errors 0

Modified Object: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\TripwireAdminUtility\+EventMessageFile

PropertyExpectedObserved
(*) Data Length 92 82
(*) CRC32 92ddd3d4 fec62927
(*) MD5 23f68a249fbc61a577cdf0bf8bde8aaf 610b65cddf861a4e38815f566b9a5257


Modified Object: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\TripwireAdminUtility\+ParameterMessageFile

PropertyExpectedObserved
(*) Data Length 92 82
(*) CRC32 92ddd3d4 fec62927
(*) MD5 23f68a249fbc61a577cdf0bf8bde8aaf 610b65cddf861a4e38815f566b9a5257


Rule: Critical Security Account Keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA]

Start Point HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA
Severity 1,000
Added Objects 0
Removed Objects 0
Modified Objects 2
Errors 0

Modified Object: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\+LsaPid

PropertyExpectedObserved
(*) CRC32 8c8c3b4d fd362b66
(*) MD5 63b51f5f7d582c462f5ab3da40416d29 1dc27d477d2dd6e0e2d8f2d29f810a77


Modified Object: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Audit\Sources\TripwirePrintUtility_sec\+ExecutableImagePath

PropertyExpectedObserved
(*) Data Length 92 82
(*) CRC32 d9d32cf4 b5c8d607
(*) MD5 9b90f0a0ceb4deba35b12b5101c22d32 21397d836e6a301326842a16587dc8e8


Rule: Critical Tripwire Registry keys [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Audit\Sources\TripwireAdminUtility_sec]

Start Point HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Audit\Sources\TripwireAdminUtility_sec
Severity 1,000
Added Objects 0
Removed Objects 0
Modified Objects 1
Errors 0

Modified Object: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Audit\Sources\TripwireAdminUtility_sec\+ExecutableImagePath

PropertyExpectedObserved
(*) Data Length 92 82
(*) CRC32 92ddd3d4 fec62927
(*) MD5 23f68a249fbc61a577cdf0bf8bde8aaf 610b65cddf861a4e38815f566b9a5257


Rule: Class keys [HKEY_CLASSES_ROOT\Component Categories]

Start Point HKEY_CLASSES_ROOT\Component Categories
Severity 35
Added Objects 5
Removed Objects 0
Modified Objects 0
Errors 0

Rule: Class keys [HKEY_CLASSES_ROOT\Interface]

Start Point HKEY_CLASSES_ROOT\Interface
Severity 35
Added Objects 189
Removed Objects 0
Modified Objects 0
Errors 0



Error Report

No Errors




Report generated by Tripwire(R) for Servers version 4.6.0.188 for Windows(R) Operating Systems

Tripwire is a registered trademark of Tripwire, Inc. All rights reserved.