Ask the Community
Groups
Identifying and Reporting on Machines That Do Not Have Patches Related To WannaCry SMB Vulnerability - Connect IT Community | Kaseya
<main> <article class="userContent"> <p><span style="color: #000000;"><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;"><strong>Background: </strong></span></span></span><span style="color: #000000;"><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;"><strong><br></strong></span></span></span><span style="color: #000000;"><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;">Due to recent events surrounding the recent outbreak of the “WannaCry” ransomware, the </span></span></span><span style="color: #000000;"><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;">WannaCry/Crypt has made international headlines due to the rate of spread for a ransomware attack. The technical community is still assessing the full impact and it is important to understand the vulnerability for the attack was a known vulnerability in Windows. Those with patched OS's should not be affected.</span></span></span></p> <p><span style="color: #000000;"><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;">This Knowledgebase (KB) article is provided to assist customers during their investigation to quickly and easily create a report that identifies machines that may be at risk if they do not have the security monthly rollup or the MS17-010 patches. We have provided two options in which to generate a report, Option 1 being a report based on using log data and Option 2 based on using a custom field.</span></span></span></p> <p><span style="color: #000000;"><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;">Special Note:</span></span></span><span style="color: #000000;"><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;"> </span></span></span><span style="color: #000000;"><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;">If you have Windows XP/2003/embedded/vista machines, specific patches were released for those, and you can easily manage this through Patch Management without any further intervention. </span></span></span><span style="color: #ff0000;"><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;"><strong>This KB is not to be</strong></span></span></span><span style="color: #ff0000;"><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;"> used as substitute for thorough investigation and patch strategy.</span></span></span></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;"><span style="color: #000000;"><strong>Follow the below step-by-step instructions to generate a report based on whichever option you elect:</strong></span></span></span></p> <p><span style="font-family: Calibri, serif;"><span style="font-size: medium;"><u><strong>OPTION 1 – This generates a report using log data </strong></u></span></span></p> <p><span style="font-family: Calibri, serif;"><span style="font-size: small;"><strong>Step 1: </strong></span></span></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;">Decompress the zip file and find 3 attached files (which can be found in a zip file at the end of this article):</span> </span></p> <p><img src="https://us.v-cdn.net/6032361/uploads/migrated/IIX2GZBEYLCA/ms17.png" alt="ms17.png" class="embedImage-img importedEmbed-img"></img></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;"><strong>Step 2: </strong></span></span></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;">Upload MS17-010_Installed.ps1 in the managed files in the Agent Procedure module:</span></span></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;">The file needs to be directly in the Shared folder.</span></span></p> <p><img src="https://us.v-cdn.net/6032361/uploads/migrated/UE9YG0AOGPU5/ms17-1.jpg" alt="ms17-1.jpg" class="embedImage-img importedEmbed-img"></img></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;">Import both XML files in the System Module under Import Center:</span></span></p> <p><img src="https://us.v-cdn.net/6032361/uploads/migrated/AX19AYYCMEHY/ms17-2.jpg" alt="ms17-2.jpg" class="embedImage-img importedEmbed-img"></img></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;"><strong>Step 3: </strong></span></span></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;">Schedule the Agent Procedure to run on all the required endpoints. (We advise no more than 50 agents at a time for a big environment, otherwise it will overload the SQL server.)</span></span></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;">The procedure may have been imported in a different folder. The search function might be required to locate it.</span></span></p> <p><img src="https://us.v-cdn.net/6032361/uploads/migrated/AX19AYYCMEHY/ms17-2.jpg" alt="ms17-2.jpg" class="embedImage-img importedEmbed-img"></img></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;"><strong>Step 4:</strong></span></span></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;">Once the procedure has successfully ran on all agents, schedule the report in the Info Center module, under Reporting/Reports.</span></span></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;">The Report can either be Ran Now or Scheduled at any time you need</span><span style="font-size: small;">.</span></span></p> <p><img src="https://us.v-cdn.net/6032361/uploads/migrated/QWLPXFQHTBS0/ms17-5.jpg" alt="ms17-5.jpg" class="embedImage-img importedEmbed-img"></img><img src="https://us.v-cdn.net/6032361/uploads/migrated/9JFCBRA266ES/ms17-8.jpg" alt="ms17-8.jpg" class="embedImage-img importedEmbed-img"></img><img src="https://us.v-cdn.net/6032361/uploads/migrated/R9VALECRLPW9/ms17-7.jpg" alt="ms17-7.jpg" class="embedImage-img importedEmbed-img"></img><img src="https://us.v-cdn.net/6032361/uploads/migrated/JKBRRURZY7T6/ms17-6.jpg" alt="ms17-6.jpg" class="embedImage-img importedEmbed-img"></img><img src="https://us.v-cdn.net/6032361/uploads/migrated/Z6DWZKD29WN8/ms17-10.jpg" alt="ms17-10.jpg" class="embedImage-img importedEmbed-img"></img><img src="https://us.v-cdn.net/6032361/uploads/migrated/VHZ9KYS1LCQB/ms17-9.jpg" alt="ms17-9.jpg" class="embedImage-img importedEmbed-img"></img><img src="https://us.v-cdn.net/6032361/uploads/migrated/TLLJ02Y5SMXZ/ms17-11.jpg" alt="ms17-11.jpg" class="embedImage-img importedEmbed-img"></img><img src="https://us.v-cdn.net/6032361/uploads/migrated/JBV97VP60JCL/ms17-12jpg.jpg" alt="ms17-12jpg.jpg" class="embedImage-img importedEmbed-img"></img><img src="https://us.v-cdn.net/6032361/uploads/migrated/8UUZU5AS6PC5/ms17-13.jpg" alt="ms17-13.jpg" class="embedImage-img importedEmbed-img"></img><img src="https://us.v-cdn.net/6032361/uploads/migrated/5Z81S9VUW19L/ms17-4.jpg" alt="ms17-4.jpg" class="embedImage-img importedEmbed-img"></img></p> <p><span style="font-family: Calibri, serif;"> </span></p> <p><span style="font-family: Calibri, serif;"><span style="font-size: medium;"><u><strong>OPTION 2 – This generates a report using a custom field </strong></u></span></span></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;"><strong>Step 1: </strong></span></span></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;">Decompress the zip file and find 3 attached files (which can be found in a zip file at the end of this article): </span></span></p> <p><img src="https://us.v-cdn.net/6032361/uploads/migrated/QWLPXFQHTBS0/ms17-5.jpg" alt="ms17-5.jpg" class="embedImage-img importedEmbed-img"></img></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;"><strong>Step 2: </strong></span></span></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;">Upload MS17-010_Installed.ps1 in the managed files in the Agent Procedure module:</span></span></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;">The file needs to be directly in the Shared folder.</span></span></p> <p><img src="https://us.v-cdn.net/6032361/uploads/migrated/JKBRRURZY7T6/ms17-6.jpg" alt="ms17-6.jpg" class="embedImage-img importedEmbed-img"></img></p> <p> </p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;">Import both XML files in the System Module under Import Center:</span> </span></p> <p><img src="https://us.v-cdn.net/6032361/uploads/migrated/R9VALECRLPW9/ms17-7.jpg" alt="ms17-7.jpg" class="embedImage-img importedEmbed-img"></img></p> <p> </p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;"><strong>Step 3: </strong></span></span></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;">Schedule the Agent Procedure to run on all the required endpoints. (We advise no more than 50 agents at a time for a big environment, it will overload the SQL server otherwise)</span></span></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;">The procedure may have been imported in a different folder. The search function might be required to locate it.</span></span></p> <p><img src="https://us.v-cdn.net/6032361/uploads/migrated/9JFCBRA266ES/ms17-8.jpg" alt="ms17-8.jpg" class="embedImage-img importedEmbed-img"></img></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;"><strong>Step 4: </strong></span></span></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;">Create the Custom Field in the Audit module under View Individual Data/Machine Summary. <br>The Custom Field needs to be named “Wanna Crypt” for the procedure to store the data correctly.</span></span></p> <p><img src="https://us.v-cdn.net/6032361/uploads/migrated/VHZ9KYS1LCQB/ms17-9.jpg" alt="ms17-9.jpg" class="embedImage-img importedEmbed-img"></img></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;"><strong>Step 5:</strong></span></span></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;">Once the procedure has been successfully ran on all agents, the report needs to be edited to display data from the correct Custom Field. In the Report module, edit the “Wanna Crypt Report (Custom Field)” to reflect the correct Custom Field. For instance, on the previous screenshot, “Wanna Crypt” is the second Custom Field being used, which in the report will show as Custom Field 01 (the first custom field starting at 00)</span></span></p> <p><img src="https://us.v-cdn.net/6032361/uploads/migrated/Z6DWZKD29WN8/ms17-10.jpg" alt="ms17-10.jpg" class="embedImage-img importedEmbed-img"></img></p> <p><img src="https://us.v-cdn.net/6032361/uploads/migrated/TLLJ02Y5SMXZ/ms17-11.jpg" alt="ms17-11.jpg" class="embedImage-img importedEmbed-img"></img></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;">schedule the report in the Info Center module, under Reporting/Reports.</span></span></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;">The Report can either be Ran Now or Scheduled at any time you need in the Info Center module, under Reporting/Reports </span></span></p> <p><img src="https://us.v-cdn.net/6032361/uploads/migrated/JBV97VP60JCL/ms17-12jpg.jpg" alt="ms17-12jpg.jpg" class="embedImage-img importedEmbed-img"></img></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;"><strong>Step 6:</strong></span></span></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;">In addition to running the report, you may create a View to include all the Vulnerable machine. In any module using view, create a new View, Check the “Advanced agent data filter [Define Filter …]” Checkbox and edit the line of [Define Filter] corresponding to the Wanna Cry custom field:</span></span></p> <p><img src="https://us.v-cdn.net/6032361/uploads/migrated/8UUZU5AS6PC5/ms17-13.jpg" alt="ms17-13.jpg" class="embedImage-img importedEmbed-img"></img></p> <p><span style="font-family: Times New Roman, serif;"><span style="font-size: medium;">The Agent Procedure would need to be ran a second time after patching the machines in order to update the data in the custom field and update the View and Report to reflect an up to date environment.</span></span></p> <p><span style="font-family: Calibri, serif;"><span style="font-size: medium;"><strong>NOTE: </strong></span></span><span style="color: #000000;"><span style="font-family: Calibri, serif;"><span style="font-size: medium;">If you encounter any issues or need assistance with these steps, please contact our Kaseya Support team by submitting a support ticket via our helpdesk portal at </span></span></span><a rel="nofollow" href="/home/leaving?allowTrusted=1&target=https%3A%2F%2Fhelpdesk.kaseysa.com"><span style="font-family: Calibri, serif;"><span style="font-size: medium;"><a href="/home/leaving?allowTrusted=1&target=https%3A%2F%2Fhelpdesk.kaseysa.com">https://helpdesk.kaseysa.com</a></span></span></a></p> </article> </main>