Report date: 11/27/2025 12:38:20
📊 Dashboard
🔍 Details
Domain
INFO.LAB
Scanned Files
221
Suspicious Files
59
Elapsed Time
00:00:23

Indicator Risk : 100

Top 5 Files
NameCount
Zones_DNS2.docx5
useradd.bat3
adduser.vbs3
Zones_DNS1.docx3
Zones_DNS1.docx3
Top 5 Reason
NameCount
password12
pass10
Suspicious Image9
requires_check8
Commande Net User6
  • Harden-Sysvol Version : 2.2.0
  • Release : 11/2025
  • Author : Dakhama Mehdi

    Credit : HardenAD Community HardenAD
    Credit : It-connect Community It-Connect
    Thanks : Przemyslaw Klys Evotec for Module PSWriteHTML/PswriteOffice
Types of Extensions found
NameCount
docx5
bat3
vbs1
txt1
xlsx1
exe4
doc8
msi4
bmp4
csv1
7z1
zip2
odp2
jpg9
pptx1
png1
reg1
pdf1
ico1
ods1
odt1
pfx2
xls4
FilePathReasonValueCreated
\\INFO.LAB\sysvol\info.lab\Policies\{56D66B52-9F35-497C-B7D3-BF1B785E1CAA}\Machine\microsoft\windows nt\Audit\audit.csvcredential,System,Audit Credential Validation,{0cce923f-69ae-11d9-bed3-505054503030},Success and Failure,,32022-01-03
\\INFO.LAB\sysvol\info.lab\scripts\Applis\7z1900-x64.msiNotSignedFile is Not Signed2020-10-28
\\INFO.LAB\sysvol\info.lab\scripts\certificat\bill03.pfxProtected Certificate"The specified network password is not correct.2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\certificat\pfx_pass.pfxProtected Certificate"The specified network password is not correct.2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\images\ctfexample (1).jpgSuspicious ImageZIP detected in pictures. Containing: got2.jpg2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\images\ctfexample.jpgSuspicious ImageZIP detected in pictures. Containing: got2.jpg2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\images\dog.jpgSuspicious ImageZIP detected in pictures. Containing: hidden_text.txt2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\Applis\vlc-3.0.8-win64.msiLarge sizeSize is so much, file ignored: (size: 53.35 MB)2020-10-28
\\INFO.LAB\sysvol\info.lab\scripts\images\solitaire.jpgcheck requiredBinary does not match2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\openoffice\file_example_ODS_100.odspasswordat least 2 characters found2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\images\hiden.jpgSuspicious ImageZIP detected in pictures. Containing: trid.exe, readme.txt2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\images\hiden2.jpgSuspicious ImageEXE file found in image with unexpected binary ending2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\images\imageexe.bmpSuspicious ImageEXE file with '0000004000' string detected2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\openoffice\sample2.odtpasswordat least 3 characters found2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\images\imagemsi.bmpSuspicious ImageFile MSI detected in the image2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\temp\excel\file_example_XLSX_50.xlsxpass@{Value=password}2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\temp\excel\file_example_XLSX_50.xlsxpassword@{Value=password}2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\temp\excel\file_example_XLS_50.xlserrorYou cannot call a method on a null-valued expression.2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\temp\excel\Sample-Spreadsheet-100-rows.xlserrorYou cannot call a method on a null-valued expression.2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\temp\excel\Sample-Spreadsheet-10000-rows.xlserrorYou cannot call a method on a null-valued expression.2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\temp\word\Downloading Documents.docrequires_checkWord is not installed2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\temp\word\file-sample_100kB.docrequires_checkWord is not installed2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\temp\word\file-sample_1MB.docrequires_checkWord is not installed2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\temp\word\Sample-doc-file-1000kb.docrequires_checkWord is not installed2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\temp\word\Sample-doc-file-100kb.docrequires_checkWord is not installed2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\temp\word\Sample-doc-file-2000kb (1).docrequires_checkWord is not installed2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\temp\word\test.docrequires_checkWord is not installed2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\temp\file_example_XLS_1000.xlserrorYou cannot call a method on a null-valued expression.2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\images\example (1).jpgSuspicious ImageZIP detected in pictures. Containing: secret.txt2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\images\example.jpgSuspicious ImageZIP detected in pictures. Containing: secret.txt2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\temp\shavi-v1.msiNotSignedFile is Not Signed2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\temp\Zones_DNS.docxpassLa taille des zones DNS pour les grandes entreprises ne dépasse généralement pas quelques KO, voire 4 ou 5 MO, ce qui nous permet d'avoir plusieurs sauvegardes sans risque d'occuper trop d'espace.2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\temp\Zones_DNS.docxpassCochez également la case "Exécuter même si l'utilisateur n'est pas connecté". Cela nécessitera la saisie du mot de passe. Il est recommandé d'utiliser un compte de service de type GMSA ou tout autre compte dédié aux tâches/scripts d'automatisation sur les contrôleurs de domaine 2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\temp\Zones_DNS1.docxpassLa sauvegarde des contrôleurs de domaine avec différents outils (Veeam, Commvault, Windows Backup) ne permet de sauvegarder que le fichier en cours. passwords2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\temp\Zones_DNS1.docxpassLa taille des zones DNS pour les grandes entreprises ne dépasse généralement pas quelques KO, voire 4 ou 5 MO, ce qui nous permet d'avoir plusieurs sauvegardes sans risque d'occuper trop d'espace.2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\temp\Zones_DNS1.docxpasswordat least 2 characters found2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\temp\Zones_DNS2.docxauthAuthentification = coucou2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\temp\Zones_DNS2.docxauthAuthent2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\temp\Zones_DNS2.docxmdpat least 2 characters found2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\temp\Zones_DNS2.docxpassat least 2 characters found2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\temp\Zones_DNS2.docxpasswordat least 2 characters found2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\Zip\Documents.7zZip protectedFile protected by password2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\Zip\au2mator 5.0.194.zipLarge sizeSize is so much, file ignored: (size: 458.41 MB)2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\Zip\Documents.zipZip protectedFile protected by password2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\3.bmpcheck requiredBinary does not match2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\7IsD.execheck requiredBinary does not match2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\temp\BIMcollab Zoom 8.1 build 7.msiLarge sizeSize is so much, file ignored: (size: 250.69 MB)2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\7z2301-x64 .doccheck requiredBinary does not match2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\7z2301-x64.exeNotSignedFile is Not Signed2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\7zip.regpassword"Password"="C:\\Program Files\\7-Zip\\"2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\a8a0maxk9.pngLarge sizeFile ignored: (size: 4.14 MB)2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\Active Directory Security Self Assessment v1.4.pdf\blogin\bat least 1 characters found2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\ADcheck.icocheck requiredBinary does not match2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\adduser.vbspasswordDim strUserAccount, strFullName, strLastName, strFirstName, strMail, strPassword2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\adduser.vbspasswordstrPassword = "P@ssw0rd"2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\adduser.vbspasswordobjNewUser.SetPassword str2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\Admin.batCommande Net Usernet user user info /domain2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\file_example_ODP.odppasswordat least 2 characters found2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\laurent.txtIPv4ipadress = 192.168.10.102024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\laurent.txtSHA-1sha1=6153A6FA0E4880D9B8D0BE4720F78E895265D0A92024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\morskie-oko-tatry.jpgLarge sizeSize is so much, file ignored: (size: 20.3 MB)2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\ppt.pptxrequires_checkOffice is not installed2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\Registry.bmpcheck requiredBinary does not match2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\Sans nom 1.odppasswordat least 2 characters found2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\NetTools.exeNotSignedFile is Not Signed2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\testbat.batCommande Net Usernet user user info /domain2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\testbat.batCommande Net Usernet use * \\s-dc\netlogon /Persistent:yes /user:username Pa$$W0rd2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\useradd.batCommande Net Usernet user user info /domain2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\useradd.batCommande Net Usernet user user2 info /add2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\useradd.batCommande Net Usernet user /add user3 info12024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\Vhd2disk.exeNotSignedFile is Not Signed2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\Zones_DNS.docxpassLa taille des zones DNS pour les grandes entreprises ne dépasse généralement pas quelques KO, voire 4 ou 5 MO, ce qui nous permet d'avoir plusieurs sauvegardes sans risque d'occuper trop d'espace.2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\Zones_DNS.docxpassCochez également la case "Exécuter même si l'utilisateur n'est pas connecté". Cela nécessitera la saisie du mot de passe. Il est recommandé d'utiliser un compte de service de type GMSA ou tout autre compte dédié aux tâches/scripts d'automatisation sur les contrôleurs de domaine 2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\Zones_DNS1.docxpassLa sauvegarde des contrôleurs de domaine avec différents outils (Veeam, Commvault, Windows Backup) ne permet de sauvegarder que le fichier en cours. passwords2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\Zones_DNS1.docxpassLa taille des zones DNS pour les grandes entreprises ne dépasse généralement pas quelques KO, voire 4 ou 5 MO, ce qui nous permet d'avoir plusieurs sauvegardes sans risque d'occuper trop d'espace.2024-10-25
\\INFO.LAB\sysvol\info.lab\scripts\Zones_DNS1.docxpasswordat least 2 characters found2024-10-25
Suspicious Shares
DCShareTypeACLReasonComment
DC-1.info.labCertEnrollDiskClean-Partage de services de certificats Active Directory
DC-1.info.labDossier-de-travailDiskWrongACLAUTORITE NT\SERVICE LOCAL has '268435456, FullControl'
DC-1.info.labDossier-de-travailDiskWrongACLINFO\Utilisateurs du domaine has 'WriteAttributes'
DC-1.info.labDossier-de-travailDiskWrongACLINFO\mehdi has 'WriteAttributes'
DC-1.info.labREMINSTDiskWrongACLS-1-5-80-1688844526-3235337491-1375791646-891369040-3692469510 has 'FullControl'Partage des services de déploiement Windows
DC-1.info.labShareDiskClean-
DC-1.info.labshare2DiskClean-
DC-1.info.labsourcesDiskWrongACLTout le monde has 'FullControl'
DC-1.info.labsourcesDiskWrongACLAUTORITE NT\Utilisateurs authentifiés has 'FullControl'
DC-1.info.labsourcesDiskWrongACLINFO\mehdi has 'FullControl'
DC-1.info.labTestDiskWrongACLBUILTIN\Utilisateurs has 'Modify'
DC-1.info.labTestDiskWrongACLINFO\user1 has 'Modify'
Errors logs
Error
Unexpected folder found in SYSVOL: \\INFO.LAB\sysvol\APkCVFNwrq
Unexpected folder found in SYSVOL: \\INFO.LAB\sysvol\bervWlVhwf
Unexpected folder found in SYSVOL: \\INFO.LAB\sysvol\hXMYimRjat
Unexpected folder found in SYSVOL: \\INFO.LAB\sysvol\info.lab
Unexpected folder found in SYSVOL: \\INFO.LAB\sysvol\KQrZMgDwhp