Jump to content

captainu99

Members
  • Content Count

    37
  • Joined

  • Last visited

  • Days Won

    4

captainu99 last won the day on July 24 2019

captainu99 had the most liked content!

Community Reputation

4 Neutral

My Information

  • Agent Count
    1500 - 2000 Agents

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

  1. Thank You. I uploaded the wrong version 🙂
  2. $RegKeyPath = "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\PersonalizationCSP" $LockScreenPath = "LockScreenImagePath" $LockScreenStatus = "LockScreenImageStatus" $LockScreenUrl = "LockScreenImageUrl" $StatusValue = "1" $customclientbackground = "C:\Program Files\BGInfo\DG_Custombackground.jpg" $url = "CHANGETHIS TO SOME URL THAT YOU WANT TO DOWNLOAD THE IMAGE FROM" $LockScreenImageValue = "C:\DTC\DTC-LockScreen.jpg" $directory = "C:\DTC\" if ((Test-Path -Path $directory) -eq $FALSE) { New-Item -Path $directory -ItemType directory } if ((Test-Path -Path $customclientbackground) -eq $FALSE) { $wc = New-Object System.Net.WebClient $wc.DownloadFile($url, $LockScreenImageValue) } else{ Copy-Item -Path $customclientbackground -Destination $LockScreenImageValue } if (!(Test-Path $RegKeyPath)) { Write-Host "Creating registry path $($RegKeyPath)." New-Item -Path $RegKeyPath -Force | Out-Null } New-ItemProperty -Path $RegKeyPath -Name $LockScreenStatus -Value $StatusValue -PropertyType DWORD -Force | Out-Null New-ItemProperty -Path $RegKeyPath -Name $LockScreenPath -Value $LockScreenImageValue -PropertyType STRING -Force | Out-Null New-ItemProperty -Path $RegKeyPath -Name $LockScreenUrl -Value $LockScreenImageValue -PropertyType STRING -Force | Out-Null RUNDLL32.EXE USER32.DLL, UpdatePerUserSystemParameters 1, TRUE
  3. LOL I have a very similar script running. Great find 🙂
  4. See attached .xml that we used (I think it was @DarrenWhite99 that I copied a good portion from) I have this set to run against a group at least once a day. I record the current password into an edf so I know if a computer doesn't get the new password I still have its current password recorded. Copy of DTC Local Admin Account Maintenance.xml
  5. I have never done it. but profwizpro is what comes to mind as a starting point.
  6. The thought occurred to me after I had a rouge DHCP Server took down my network. I setup Darrens RougeDHCPDetection but enabled it. Thoughts. I would love to put this monitor on all computers/agents and if more then 1 computer goes into a fail state instead of each computer creating its own monitoring ticket. Create a 1x master ticket. In this scenario, any computer in the same subnet will be part of my master ticket. No idea where to start with this yet.
  7. Is there a way for me to force a computer to fast talk at the beginning of a script and keep fast talk on (Even through reboots) until the script finishes? I am finding that after the computer reboots it goes back to every 5 minutes.
  8. Thanks I finally got this working properly. For future reference: In the searches its located under Labtech -> Roles - > Bitlocker Enabled.
  9. I changed it a little so that the results will display why the alert triggered off and also display all events found within 24 hours with a clean output so that the techs can diagnose without having to manually weed through the event logs %windir%\System32\WindowsPowerShell\v1.0\powershell.exe "$allevents = Get-EventLog -LogName 'Security' -InstanceId 4625 -After ([DateTime]::Now.AddDays(-1)) -ErrorAction SilentlyContinue | Select-Object TimeGenerated, @{Name='TargetUserName' ; Expression={$_.ReplacementStrings[5]} }, @{Name='WorkstationName' ; Expression={$_.ReplacementStrings[1] -replace '\$$'} }, @{Name='LogonType' ; Expression={$_.ReplacementStrings[10]}}, @{Name='IpAddress' ; Expression={$_.ReplacementStrings[-2]}}, @{Name='IpPort' ; Expression={$_.ReplacementStrings[-5]}} | Where-Object {$_.TargetUserName -ne $env:computername + '$' -and $_.TargetUserName -ne $env:computername -and $_.TargetUserName -ne '-' -and $_.TargetUserName -ne '@'} ; $allevents | Group-Object LogonType, TargetUserName | Where-Object {$_.Count -ge 8} | Sort-Object Count -Descending | FT Count, Name -autosize ; $allevents "
  10. Where is this located? I cannot seem to find the correct field to add that in.
  11. Is there any way to have remote command prompt from the webinterface *.hostedrmm.com or /Automate version? Thanks
×
×
  • Create New...