Driver Audit - Windows
Log In or Register to download the BES file, and more.

0 Votes

Description

<enter a description of the analysis here>

Property Details

ID2994712
StatusAlpha - Code that was just developed
TitleDriver Audit - Windows
DomainBESC
Added by on 9/3/2014 11:51:34 AM
Last Modified by on 9/3/2014 11:51:34 AM
Counters 2999 Views / 20 Downloads
User Rating 1 star 2 star 3 star 4 star 5 star * Average over 0 ratings. ** Log In or Register to add your rating.

Properties

Number of EPSON trusted publisher certs
Period 1 day
 
  * Results in a true/false
Show indented relevance
number of (it) whose(it contains "5345494b4f204550534f4e") of (values "Blob" of keys of key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates" of native registry as string)
(#, Description) of supported models of installed logitech drivers
Period 1 day
 
  * Results in a "string"/number
Show indented relevance
(multiplicity of it, it) of unique values of ("Logitech " & (it as string)) of (if (it starts with "Logitech ") then (following text of first "Logitech " of it) else it) of (if (it contains "Logitech QuickCam Pro ") then (following text of first "Logitech QuickCam " of it) else it) of (if (it contains "Webcam ") then (following text of first "Webcam " of it) else it) of (if (it contains ")") then (preceding text of last ")" of it) else it) of (if (it contains "(") then (following text of first "(" of it) else it) of (preceding text of last "%22" of following text of first "%22" of following text of first "=" of it) of items 3 of (item 0 of it, item 1 of it, minimum of line numbers of item 2 of it, lines of item 0 of it) whose(((item 1 of it) < line number of item 3 of it) AND ((item 2 of it) > (line number of item 3 of it)) AND (item 3 of it contains "PID_")) of (item 0 of it, item 1 of it, lines whose(it starts with "[" AND it ends with "]") of item 0 of it) whose(item 1 of it < line number of item 2 of it) of (it, line number of line whose(it starts with "[Strings]") of it) of items 0 whose(content of it contains "Logitech") of (files of item 0 of it, item 1 of it) whose(name of item 0 of it as lowercase = item 1 of it) of (it, (it & ".inf") of preceding text of first ".inf" of (name of it as lowercase)) of folders whose( ((name of it as lowercase starts with "lv") OR (name of it as lowercase starts with "lpro")) AND (name of it as lowercase contains ".inf") ) of folders "DriverStore\FileRepository" of system x64 folder
Names of Scanners of Epson Drivers currently installed in system
Period 12 hours
 
  * Results in a "string"/number
Show indented relevance
keys "DSName" of sections "Strings" of items 0 of (files of item 0 of it, item 1 of it) whose(name of item 0 of it as lowercase = item 1 of it) of (it, (it & ".inf") of preceding text of first ".inf" of (name of it as lowercase)) of folders whose((name of it as lowercase starts with "es") AND (name of it as lowercase contains ".inf")) of folders "DriverStore\FileRepository" of system x64 folder
NVIDIA
Period 2 days
 
  * Results in a true/false
Show indented relevance
unique values of (it as trimmed string) of (preceding text of last "%22" of following text of first "%22" of it) of lines whose(it starts with "NVIDIA_DEV") of files whose(name of it as lowercase ends with ".inf") of folders whose(name of it as lowercase starts with "nvlewu") of folders "DriverStore\FileRepository" of system folder
Intel
Period 2 days
 
  * Results in a true/false
Show indented relevance
unique values of (it as trimmed string) of (preceding text of last "%22" of following text of first "%22" of it) of (concatenation of characters whose (it != "%00") of it) of lines whose(exists (concatenation of characters whose (it != "%00") of it) whose(it starts with "i" AND it contains "Intel(R) ")) of files whose(name of it as lowercase ends with ".inf") of folders whose(name of it as lowercase starts with "igdlh") of folders "DriverStore\FileRepository" of system folder

Relevance

isWindows (Relevance 1172)
Used in 1155 fixlets and 538 analyses   * Results in a true/false
Show indented relevance
windows of operating system

Sharing

Social Media:
Share this page on Yammer

Comments

Log In or Register to leave comments!