Skip to main content

SMBv1 Enable Detection Ticketing - Per Client

Summary​

This client script creates a ticket for each client with the computer count where remediation is required.

Sample Run​

Sample Run

Dependencies​

Variables​

NameDescription
@VulnerableagentCount@This stores the count of computers where remediation is required, marked by the script @Script: SMBv1 Enabled Detection & Remediation [DV,Param].
TicIDThis stores the ticket ID if any existing open ticket is detected, allowing comments to be made on the same ticket.

Output​

  • Ticket

Ticketing​

  1. Ticketing:

    Subject:
    SMB1 Enable audit data detected on the client: @sqlname@
    Here, @sqlname@ is the client's name.

    Body:
    The SMBv1 Enable status audit was detected on the @VulnerableagentCount@ computer(s) of client "@sqlname@".
    Please review the dataview for the computer list.

    OR

    The SMBv1 Enable status audit was detected on @VulnerableagentCount@ computer(s) of client "@sqlname@".
    Please review the dataview for the computer list.

Changelog​

2025-04-10​

  • Initial version of the document