Last active
July 16, 2020 06:00
-
-
Save darkpixel/f638b1827b41b4e530a86854223f70fa to your computer and use it in GitHub Desktop.
PDQ Deploy Registry Remediation Package
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
<?xml version="1.0" encoding="utf-8"?> | |
<AdminArsenal.Export Code="PDQDeploy" Name="PDQ Deploy" Version="19.0.40.0" MinimumVersion="15.0"> | |
<Package> | |
<CurrentLibraryPackageVersionId value="null" /> | |
<PackageDefinition name="Definition"> | |
<Conditions type="list"> | |
<PackageStepCondition> | |
<Architecture>Both</Architecture> | |
<Version>AllServers</Version> | |
<TypeName>OperatingSystem</TypeName> | |
</PackageStepCondition> | |
<PackageStepCondition> | |
<IsUserLoggedOn>AlwaysRun</IsUserLoggedOn> | |
<TypeName>LoggedOnUser</TypeName> | |
</PackageStepCondition> | |
<PackageStepCondition> | |
<ConditionMode>None</ConditionMode> | |
<InventoryCollectionId value="null" /> | |
<InventoryCollectionName></InventoryCollectionName> | |
<TypeName>Collection</TypeName> | |
</PackageStepCondition> | |
</Conditions> | |
<CopyMode>Default</CopyMode> | |
<DelayedApprovalTimeSpan>7.00:00:00</DelayedApprovalTimeSpan> | |
<DownloadApprovalMode>Manual</DownloadApprovalMode> | |
<InventoryScanProfileId value="null" /> | |
<IsDownloadApprovalModeInherited value="true" /> | |
<ScanAfterDeployment value="null" /> | |
<Steps type="list"> | |
<CommandStep> | |
<Command>reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNS\Parameters" /v "TcpReceivePacketSize" /t REG_DWORD /d 0xFF00 /f</Command> | |
<Files></Files> | |
<SuccessCodes>0</SuccessCodes> | |
<RunAs value="null" /> | |
<Conditions type="list"> | |
<PackageStepCondition> | |
<Architecture>Both</Architecture> | |
<Version>All</Version> | |
<TypeName>OperatingSystem</TypeName> | |
</PackageStepCondition> | |
<PackageStepCondition> | |
<IsUserLoggedOn>AlwaysRun</IsUserLoggedOn> | |
<TypeName>LoggedOnUser</TypeName> | |
</PackageStepCondition> | |
<PackageStepCondition> | |
<ConditionMode>None</ConditionMode> | |
<InventoryCollectionId value="null" /> | |
<InventoryCollectionName></InventoryCollectionName> | |
<TypeName>Collection</TypeName> | |
</PackageStepCondition> | |
</Conditions> | |
<ErrorMode>StopDeploymentFail</ErrorMode> | |
<Title>Create Registry Key</Title> | |
<TypeName>Command</TypeName> | |
<IsEnabled value="true" /> | |
<IsPostStep value="false" /> | |
<IsPreStep value="false" /> | |
</CommandStep> | |
<CommandStep> | |
<Command>sc stop dns</Command> | |
<Files></Files> | |
<SuccessCodes>0</SuccessCodes> | |
<RunAs value="null" /> | |
<Conditions type="list"> | |
<PackageStepCondition> | |
<Architecture>Both</Architecture> | |
<Version>All</Version> | |
<TypeName>OperatingSystem</TypeName> | |
</PackageStepCondition> | |
<PackageStepCondition> | |
<IsUserLoggedOn>AlwaysRun</IsUserLoggedOn> | |
<TypeName>LoggedOnUser</TypeName> | |
</PackageStepCondition> | |
<PackageStepCondition> | |
<ConditionMode>None</ConditionMode> | |
<InventoryCollectionId value="null" /> | |
<InventoryCollectionName></InventoryCollectionName> | |
<TypeName>Collection</TypeName> | |
</PackageStepCondition> | |
</Conditions> | |
<ErrorMode>StopDeploymentFail</ErrorMode> | |
<Title>Stop DNS Service</Title> | |
<TypeName>Command</TypeName> | |
<IsEnabled value="true" /> | |
<IsPostStep value="false" /> | |
<IsPreStep value="false" /> | |
</CommandStep> | |
<SleepStep> | |
<Seconds value="10" /> | |
<Conditions type="list"> | |
<PackageStepCondition> | |
<Architecture>Both</Architecture> | |
<Version>All</Version> | |
<TypeName>OperatingSystem</TypeName> | |
</PackageStepCondition> | |
<PackageStepCondition> | |
<IsUserLoggedOn>AlwaysRun</IsUserLoggedOn> | |
<TypeName>LoggedOnUser</TypeName> | |
</PackageStepCondition> | |
<PackageStepCondition> | |
<ConditionMode>None</ConditionMode> | |
<InventoryCollectionId value="null" /> | |
<InventoryCollectionName></InventoryCollectionName> | |
<TypeName>Collection</TypeName> | |
</PackageStepCondition> | |
</Conditions> | |
<ErrorMode>StopDeploymentFail</ErrorMode> | |
<Title>Sleep</Title> | |
<TypeName>Sleep</TypeName> | |
<IsEnabled value="true" /> | |
<IsPostStep value="false" /> | |
<IsPreStep value="false" /> | |
</SleepStep> | |
<CommandStep> | |
<Command>sc start dns</Command> | |
<Files></Files> | |
<SuccessCodes>0</SuccessCodes> | |
<RunAs value="null" /> | |
<Conditions type="list"> | |
<PackageStepCondition> | |
<Architecture>Both</Architecture> | |
<Version>All</Version> | |
<TypeName>OperatingSystem</TypeName> | |
</PackageStepCondition> | |
<PackageStepCondition> | |
<IsUserLoggedOn>AlwaysRun</IsUserLoggedOn> | |
<TypeName>LoggedOnUser</TypeName> | |
</PackageStepCondition> | |
<PackageStepCondition> | |
<ConditionMode>None</ConditionMode> | |
<InventoryCollectionId value="null" /> | |
<InventoryCollectionName></InventoryCollectionName> | |
<TypeName>Collection</TypeName> | |
</PackageStepCondition> | |
</Conditions> | |
<ErrorMode>StopDeploymentFail</ErrorMode> | |
<Title>Start DNS Service</Title> | |
<TypeName>Command</TypeName> | |
<IsEnabled value="true" /> | |
<IsPostStep value="false" /> | |
<IsPreStep value="false" /> | |
</CommandStep> | |
</Steps> | |
<Timeout value="60" /> | |
<UseCustomTimeout value="false" /> | |
<RunAs value="null" /> | |
</PackageDefinition> | |
<Description></Description> | |
<NewLibraryPackageVersionId value="null" /> | |
<OriginalId value="null" /> | |
<Version></Version> | |
<IsAutoDownload value="false" /> | |
<FolderId value="3" /> | |
<LibraryPackageVersionId value="null" /> | |
<Name>CVE-2020-1350 Registry Remediation</Name> | |
<Path>Packages\CVE-2020-1350 Registry Remediation</Path> | |
<PackageDisplaySettings name="DisplaySettings"> | |
<DisplayType>Normal</DisplayType> | |
<IconKey>Icon-Package</IconKey> | |
<SortOrder value="7" /> | |
</PackageDisplaySettings> | |
</Package> | |
</AdminArsenal.Export> |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment