Repository navigation
Expand file tree
/
Copy pathSecurityCheck.ps1
More file actions
185 lines (171 loc) · 6.18 KB
/
Copy pathSecurityCheck.ps1
File metadata and controls
185 lines (171 loc) · 6.18 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
# Author: Greg Lawler (greg@outsideopen.com)
# Date: 2024-12-05
#
# This script performs a comprehensive security check of the system. It generates a report with details on:
# - Installed remote access tools
# - Active network connections
# - DNS cache entries
# - Auto-start programs in Run and RunOnce registry keys
# - Scheduled tasks
# - Local user accounts
# - ScreenConnect processes
# - Running processes
# - Running services
#
# Instructions:
# 1. Save this script as `SecurityCheck.ps1` in your desired location.
# 2. Configure the `$outputDirectory` variable to set the location of the log file.
# Define the output file directory and file name
$outputDirectory = "C:\kworking"
$timestamp = Get-Date -Format "yyyyMMdd-HHmmss"
$outputFile = Join-Path -Path $outputDirectory -ChildPath "SecurityReport-$timestamp.txt"
# Ensure the output directory exists
if (-not (Test-Path -Path $outputDirectory)) {
New-Item -ItemType Directory -Path $outputDirectory -Force
}
# Helper function to append text to the report
function Append-Report {
param (
[string]$Text
)
$Text | Out-File -FilePath $outputFile -Append
}
# Start the report
"Security Check Report" | Out-File -FilePath $outputFile
"Paste this output into ChatGPT or any AI for security analysis of possible threats and remote access tools." | Out-File -FilePath $outputFile -Append
"Generated on: $(Get-Date)" | Out-File -FilePath $outputFile -Append
"==========================================" | Out-File -FilePath $outputFile -Append
# Check installed remote access tools
Append-Report "`nChecking for installed remote access tools..."
$remoteTools = @(
"*TeamViewer*",
"*AnyDesk*",
"*UltraVNC*",
"*LogMeIn*",
"*GoToMyPC*",
"*Chrome Remote Desktop*",
"*Splashtop*",
"*Radmin*",
"*ConnectWise Control*",
"*Kaseya*",
"*ScreenConnect*"
)
foreach ($tool in $remoteTools) {
$installed = @(
Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\* 2>$null |
Where-Object { $_.DisplayName -like $tool }
Get-ItemProperty HKLM:\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\* 2>$null |
Where-Object { $_.DisplayName -like $tool }
)
if ($installed) {
foreach ($item in $installed) {
Append-Report " Found: $($item.DisplayName)"
}
} else {
Append-Report " $tool not found."
}
}
# Check for ScreenConnect processes
Append-Report "`nChecking for ScreenConnect processes..."
try {
$screenConnectProcesses = Get-Process | Where-Object { $_.Name -like "*ScreenConnect*" }
if ($screenConnectProcesses) {
foreach ($proc in $screenConnectProcesses) {
Append-Report " ScreenConnect Process Found: Name: $($proc.Name), ID: $($proc.Id), Path: $($proc.Path)"
}
} else {
Append-Report " No ScreenConnect processes found."
}
} catch {
Append-Report " Failed to check for ScreenConnect processes: $($_.Exception.Message)"
}
# Check active network connections
Append-Report "`nChecking active network connections..."
try {
$netstat = netstat -ano | Select-String "TCP" | Select-String "ESTABLISHED"
if ($netstat) {
Append-Report " Active connections:"
$netstat | ForEach-Object { Append-Report " $_" }
} else {
Append-Report " No active connections found."
}
} catch {
Append-Report " Failed to check network connections: $($_.Exception.Message)"
}
# Check DNS cache
Append-Report "`nChecking DNS cache..."
try {
$dnsCache = ipconfig /displaydns
if ($dnsCache) {
Append-Report " DNS cache entries:"
$dnsCache | ForEach-Object { Append-Report " $_" }
} else {
Append-Report " No DNS cache found."
}
} catch {
Append-Report " Failed to check DNS cache: $($_.Exception.Message)"
}
# Check Run and RunOnce registry keys
Append-Report "`nChecking Run and RunOnce registry keys..."
$regKeys = @(
"HKCU:\Software\Microsoft\Windows\CurrentVersion\Run",
"HKCU:\Software\Microsoft\Windows\CurrentVersion\RunOnce",
"HKLM:\Software\Microsoft\Windows\CurrentVersion\Run",
"HKLM:\Software\Microsoft\Windows\CurrentVersion\RunOnce"
)
foreach ($key in $regKeys) {
Append-Report "`nChecking $key..."
try {
$values = Get-ItemProperty -Path $key -ErrorAction Stop
if ($values.PSObject.Properties.Name -ne "PSPath") {
$values.PSObject.Properties | ForEach-Object {
Append-Report " $($_.Name): $($_.Value)"
}
} else {
Append-Report " No entries found in $key."
}
} catch {
Append-Report " Failed to access ${key}: $($_.Exception.Message)"
}
}
# Check for suspicious scheduled tasks
Append-Report "`nChecking scheduled tasks..."
try {
$tasks = Get-ScheduledTask | Where-Object { $_.TaskPath -notlike "\Microsoft\*" }
if ($tasks) {
Append-Report " Suspicious scheduled tasks:"
$tasks | ForEach-Object {
Append-Report " Task Name: $($_.TaskName)"
Append-Report " Task Path: $($_.TaskPath)"
}
} else {
Append-Report " No suspicious tasks found."
}
} catch {
Append-Report " Failed to check scheduled tasks: $($_.Exception.Message)"
}
# Check for all running processes
Append-Report "`nChecking all running processes..."
try {
$processes = Get-Process
foreach ($proc in $processes) {
Append-Report " Process: $($proc.Name), ID: $($proc.Id), Path: $($proc.Path)"
}
} catch {
Append-Report " Failed to check running processes: $($_.Exception.Message)"
}
# Check for all running services
Append-Report "`nChecking all running services..."
try {
$services = Get-Service
foreach ($svc in $services) {
Append-Report " Service: $($svc.Name), Status: $($svc.Status), StartType: $($svc.StartType)"
}
} catch {
Append-Report " Failed to check services: $($_.Exception.Message)"
}
# End the report
Append-Report "`nSecurity check completed."
Append-Report "=========================================="
Write-Host "Security check completed. Report saved to $outputFile"
Write-Host "Upload this report to ChatGPT 4 or newer and ask for a summary vulnerability analysis" -ForegroundColor Yellow