| GR-PO-ADM-C-SeriouSAM HiveNightmare vulnerability | |
| Data collected on: 2-9-2025 10:00:39 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\tentolouris.5-adm |
| Created | 13-8-2021 15:34:34 |
| Modified | 9-2-2023 15:06:22 |
| User Revisions | 0 (AD), 0 (SYSVOL) |
| Computer Revisions | 8 (AD), 8 (SYSVOL) |
| Unique ID | {0c38f899-a90f-4e4d-8f46-eb4e59aa9f1b} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Clients | No | Enabled | emea.tpg.ads/GR/Systems/Clients |
| Name |
|---|
| EMEA\GR-L-SEC-Vuln SeriousSam Hive |
| NT AUTHORITY\Authenticated Users |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\Domain Computers | Read | No |
| EMEA\GR-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\GR-L-SEC-Vuln SeriousSam Hive | Read (from Security Filtering) | No |
| EMEA\tentolouris.5-adm | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read (from Security Filtering) | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Action | Update |
| Name | SeriouSAM HiveNightmare vulnerability | |||
| Author | EMEA\tentolouris.5-adm | |||
| Description | ||||
| Run only when user is logged on | ||||
| GroupId | NT AUTHORITY\SYSTEM | |||
| Run with highest privileges | LeastPrivilege | |||
| Hidden | No | |||
| Configure for | 1.2 | |||
| Enabled | Yes |
| 1. At startup | ||||
| Enabled | Yes | |||
| 1. Start a program | ||||
| Program/script | C:\Windows\System32\cmd.exe | |||
| Arguments | /c IF NOT EXIST C:\TPSTUFF\MARK-SeriousSAMHiveNightmareRemediation.txt icacls %windir%\system32\config\*.* /inheritance:e>>"C:\TPSTUFF\MARK-SeriousSAMHiveNightmareRemediation.txt" |
| Stop if the computer ceases to be idle | No | |||
| Restart if the idle state resumes | No | |||
| Start the task only if the computer is on AC power | No | |||
| Stop if the computer switches to battery power | No | |||
| Allow task to be run on demand | No | |||
| Stop task if it runs longer than | Immediately | |||
| If the running task does not end when requested, force it to stop | No | |||
| If the task is already running, then the following rule applies | IgnoreNew |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |