Update doc assets (#33740)
After talking with eng team and @nonpunctual, the /assets folder is reserved for things inside the fleet app, so creating a new folder in `/docs/solutions` @AdamBaali - I updated your article paths and moved the assets to the new folder, do you mind taking a peek and making sure it looks good? Note: brock, we should also update handbook for new ritual to add articles with assets like this. --------- Co-authored-by: Brock Walters <153771548+nonpunctual@users.noreply.github.com>
This commit is contained in:
co-authored by
Brock Walters
parent
75104bfbcb
commit
9e3cab666e
@@ -0,0 +1,13 @@
|
||||
<Replace>
|
||||
<CmdID>25</CmdID>
|
||||
<Item>
|
||||
<Target>
|
||||
<LocURI>./Device/Vendor/MSFT/Policy/Config/Experience/AllowManualMDMUnenrollment</LocURI>
|
||||
</Target>
|
||||
<Meta>
|
||||
<Format xmlns="syncml:metinf">int</Format>
|
||||
<Type>text/plain</Type>
|
||||
</Meta>
|
||||
<Data>0</Data>
|
||||
</Item>
|
||||
</Replace>
|
||||
@@ -0,0 +1,79 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
|
||||
<plist version="1.0">
|
||||
<dict>
|
||||
<key>PayloadContent</key>
|
||||
<array>
|
||||
<dict>
|
||||
<key>PayloadDescription</key>
|
||||
<string>Configures Privacy Preferences Policy Control settings for CrowdStrike</string>
|
||||
<key>PayloadDisplayName</key>
|
||||
<string>Full Disk Access - Crowdstrike</string>
|
||||
<key>PayloadIdentifier</key>
|
||||
<string>com.fleet.privacy</string>
|
||||
<key>PayloadOrganization</key>
|
||||
<string>CrowdStrike Inc.</string>
|
||||
<key>PayloadType</key>
|
||||
<string>com.apple.TCC.configuration-profile-policy</string>
|
||||
<key>PayloadUUID</key>
|
||||
<string>C7B25543-8A46-4782-B5F1-FABF2CC07934</string>
|
||||
<key>PayloadVersion</key>
|
||||
<integer>1</integer>
|
||||
<key>Services</key>
|
||||
<dict>
|
||||
<key>SystemPolicyAllFiles</key>
|
||||
<array>
|
||||
<dict>
|
||||
<key>Allowed</key>
|
||||
<true/>
|
||||
<key>CodeRequirement</key>
|
||||
<string>identifier "com.crowdstrike.falcon.Agent" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = X9E956P446</string>
|
||||
<key>Comment</key>
|
||||
<string></string>
|
||||
<key>Identifier</key>
|
||||
<string>com.crowdstrike.falcon.Agent</string>
|
||||
<key>IdentifierType</key>
|
||||
<string>bundleID</string>
|
||||
<key>StaticCode</key>
|
||||
<false/>
|
||||
</dict>
|
||||
<dict>
|
||||
<key>Allowed</key>
|
||||
<true/>
|
||||
<key>CodeRequirement</key>
|
||||
<string>identifier "com.crowdstrike.falcon.App" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = X9E956P446</string>
|
||||
<key>Comment</key>
|
||||
<string></string>
|
||||
<key>Identifier</key>
|
||||
<string>com.crowdstrike.falcon.App</string>
|
||||
<key>IdentifierType</key>
|
||||
<string>bundleID</string>
|
||||
<key>StaticCode</key>
|
||||
<false/>
|
||||
</dict>
|
||||
</array>
|
||||
</dict>
|
||||
</dict>
|
||||
</array>
|
||||
<key>PayloadDescription</key>
|
||||
<string>CrowdStrike Falcon Full Disk Access</string>
|
||||
<key>PayloadDisplayName</key>
|
||||
<string>CrowdStrike - Privacy Preferences</string>
|
||||
<key>PayloadEnabled</key>
|
||||
<true/>
|
||||
<key>PayloadIdentifier</key>
|
||||
<string>com.fleet.privacy</string>
|
||||
<key>PayloadOrganization</key>
|
||||
<string>Fleet</string>
|
||||
<key>PayloadRemovalDisallowed</key>
|
||||
<false/>
|
||||
<key>PayloadScope</key>
|
||||
<string>System</string>
|
||||
<key>PayloadType</key>
|
||||
<string>Configuration</string>
|
||||
<key>PayloadUUID</key>
|
||||
<string>A4A2274E-370D-4641-A248-7A637ADFB169</string>
|
||||
<key>PayloadVersion</key>
|
||||
<integer>1</integer>
|
||||
</dict>
|
||||
</plist>
|
||||
@@ -0,0 +1,58 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
|
||||
<plist version="1.0">
|
||||
<dict>
|
||||
<key>PayloadContent</key>
|
||||
<array>
|
||||
<dict>
|
||||
<key>NotificationSettings</key>
|
||||
<array>
|
||||
<dict>
|
||||
<key>AlertType</key>
|
||||
<integer>1</integer>
|
||||
<key>BundleIdentifier</key>
|
||||
<string>com.crowdstrike.falcon.UserAgent</string>
|
||||
<key>CriticalAlertEnabled</key>
|
||||
<false/>
|
||||
<key>NotificationsEnabled</key>
|
||||
<true/>
|
||||
<key>ShowInLockScreen</key>
|
||||
<false/>
|
||||
<key>ShowInNotificationCenter</key>
|
||||
<true/>
|
||||
</dict>
|
||||
</array>
|
||||
<key>PayloadDisplayName</key>
|
||||
<string>Notifications</string>
|
||||
<key>PayloadIdentifier</key>
|
||||
<string>com.fleet.notifications</string>
|
||||
<key>PayloadType</key>
|
||||
<string>com.apple.notificationsettings</string>
|
||||
<key>PayloadUUID</key>
|
||||
<string>F5E94A3F-6E76-4A28-AF32-068455731244</string>
|
||||
<key>PayloadVersion</key>
|
||||
<integer>1</integer>
|
||||
</dict>
|
||||
</array>
|
||||
<key>PayloadDescription</key>
|
||||
<string>CrowdStrike Falcon Notification settings</string>
|
||||
<key>PayloadDisplayName</key>
|
||||
<string>CrowdStrike - Notifications</string>
|
||||
<key>PayloadEnabled</key>
|
||||
<true/>
|
||||
<key>PayloadIdentifier</key>
|
||||
<string>com.fleet.notifications</string>
|
||||
<key>PayloadOrganization</key>
|
||||
<string>Fleet</string>
|
||||
<key>PayloadRemovalDisallowed</key>
|
||||
<false/>
|
||||
<key>PayloadScope</key>
|
||||
<string>System</string>
|
||||
<key>PayloadType</key>
|
||||
<string>Configuration</string>
|
||||
<key>PayloadUUID</key>
|
||||
<string>F749D9AF-DE8B-45B0-98F5-CACA98C67FEC</string>
|
||||
<key>PayloadVersion</key>
|
||||
<integer>1</integer>
|
||||
</dict>
|
||||
</plist>
|
||||
@@ -0,0 +1,60 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
|
||||
<plist version="1.0">
|
||||
<dict>
|
||||
<key>PayloadContent</key>
|
||||
<array>
|
||||
<dict>
|
||||
<key>PayloadDescription</key>
|
||||
<string>Configures Service Management settings for CrowdStrike Falcon</string>
|
||||
<key>PayloadDisplayName</key>
|
||||
<string>Service Management</string>
|
||||
<key>PayloadIdentifier</key>
|
||||
<string>com.fleet.servicemanagement</string>
|
||||
<key>PayloadOrganization</key>
|
||||
<string>CrowdStrike Inc.</string>
|
||||
<key>PayloadType</key>
|
||||
<string>com.apple.servicemanagement</string>
|
||||
<key>PayloadUUID</key>
|
||||
<string>B2C3D4E5-F6G7-8901-2345-678901BCDEFG</string>
|
||||
<key>PayloadVersion</key>
|
||||
<integer>1</integer>
|
||||
<key>Rules</key>
|
||||
<array>
|
||||
<dict>
|
||||
<key>RuleType</key>
|
||||
<string>BundleIdentifier</string>
|
||||
<key>RuleValue</key>
|
||||
<string>com.crowdstrike.falcon.UserAgent</string>
|
||||
</dict>
|
||||
<dict>
|
||||
<key>RuleType</key>
|
||||
<string>TeamIdentifier</string>
|
||||
<key>RuleValue</key>
|
||||
<string>X9E956P446</string>
|
||||
</dict>
|
||||
</array>
|
||||
</dict>
|
||||
</array>
|
||||
<key>PayloadDescription</key>
|
||||
<string>CrowdStrike Falcon Service Management configuration</string>
|
||||
<key>PayloadDisplayName</key>
|
||||
<string>CrowdStrike - Service Management</string>
|
||||
<key>PayloadEnabled</key>
|
||||
<true/>
|
||||
<key>PayloadIdentifier</key>
|
||||
<string>com.fleet.servicemanagement</string>
|
||||
<key>PayloadOrganization</key>
|
||||
<string>Fleet</string>
|
||||
<key>PayloadRemovalDisallowed</key>
|
||||
<false/>
|
||||
<key>PayloadScope</key>
|
||||
<string>System</string>
|
||||
<key>PayloadType</key>
|
||||
<string>Configuration</string>
|
||||
<key>PayloadUUID</key>
|
||||
<string>5007F4E7-372B-4B90-8E64-BDC59E4C1D93</string>
|
||||
<key>PayloadVersion</key>
|
||||
<integer>1</integer>
|
||||
</dict>
|
||||
</plist>
|
||||
@@ -0,0 +1,61 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
|
||||
<plist version="1.0">
|
||||
<dict>
|
||||
<key>PayloadContent</key>
|
||||
<array>
|
||||
<dict>
|
||||
<key>AllowUserOverrides</key>
|
||||
<true/>
|
||||
<key>AllowedSystemExtensions</key>
|
||||
<dict>
|
||||
<key>X9E956P446</key>
|
||||
<array>
|
||||
<string>com.crowdstrike.falcon.Agent</string>
|
||||
</array>
|
||||
</dict>
|
||||
<key>NonRemovableFromUISystemExtensions</key>
|
||||
<dict>
|
||||
<key>X9E956P446</key>
|
||||
<array>
|
||||
<string>com.crowdstrike.falcon.Agent</string>
|
||||
</array>
|
||||
</dict>
|
||||
<key>PayloadDescription</key>
|
||||
<string>Configures System Extensions Policy settings for CrowdStrike Falcon</string>
|
||||
<key>PayloadDisplayName</key>
|
||||
<string>System Extensions - Crowdstrike</string>
|
||||
<key>PayloadIdentifier</key>
|
||||
<string>com.fleet.systemextensions</string>
|
||||
<key>PayloadOrganization</key>
|
||||
<string>CrowdStrike Inc.</string>
|
||||
<key>PayloadType</key>
|
||||
<string>com.apple.system-extension-policy</string>
|
||||
<key>PayloadUUID</key>
|
||||
<string>6527669C-0C1F-4B84-998F-33902DBFEB86</string>
|
||||
<key>PayloadVersion</key>
|
||||
<integer>1</integer>
|
||||
</dict>
|
||||
</array>
|
||||
<key>PayloadDescription</key>
|
||||
<string>CrowdStrike Falcon System Extensions configuration</string>
|
||||
<key>PayloadDisplayName</key>
|
||||
<string>CrowdStrike - System Extensions</string>
|
||||
<key>PayloadEnabled</key>
|
||||
<true/>
|
||||
<key>PayloadIdentifier</key>
|
||||
<string>com.fleet.systemextensions</string>
|
||||
<key>PayloadOrganization</key>
|
||||
<string>Fleet</string>
|
||||
<key>PayloadRemovalDisallowed</key>
|
||||
<false/>
|
||||
<key>PayloadScope</key>
|
||||
<string>System</string>
|
||||
<key>PayloadType</key>
|
||||
<string>Configuration</string>
|
||||
<key>PayloadUUID</key>
|
||||
<string>C84A8495-1B68-4C28-B29B-FDF3A40018D4</string>
|
||||
<key>PayloadVersion</key>
|
||||
<integer>1</integer>
|
||||
</dict>
|
||||
</plist>
|
||||
@@ -0,0 +1,57 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
|
||||
<plist version="1.0">
|
||||
<dict>
|
||||
<key>PayloadContent</key>
|
||||
<array>
|
||||
<dict>
|
||||
<key>FilterDataProviderBundleIdentifier</key>
|
||||
<string>com.crowdstrike.falcon.Agent</string>
|
||||
<key>FilterDataProviderDesignatedRequirement</key>
|
||||
<string>identifier "com.crowdstrike.falcon.Agent" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] and certificate leaf[field.1.2.840.113635.100.6.1.13] and certificate leaf[subject.OU] = "X9E956P446"</string>
|
||||
<key>FilterGrade</key>
|
||||
<string>inspector</string>
|
||||
<key>FilterPackets</key>
|
||||
<false/>
|
||||
<key>FilterSockets</key>
|
||||
<true/>
|
||||
<key>FilterType</key>
|
||||
<string>Plugin</string>
|
||||
<key>Organization</key>
|
||||
<string>CrowdStrike Inc.</string>
|
||||
<key>PayloadDisplayName</key>
|
||||
<string>Web Content Filter</string>
|
||||
<key>PayloadIdentifier</key>
|
||||
<string>com.fleet.webfilter</string>
|
||||
<key>PayloadType</key>
|
||||
<string>com.apple.webcontent-filter</string>
|
||||
<key>PayloadUUID</key>
|
||||
<string>E63C7607-408B-485F-BF2F-0900AAE6797F</string>
|
||||
<key>PayloadVersion</key>
|
||||
<integer>1</integer>
|
||||
<key>PluginBundleID</key>
|
||||
<string>com.crowdstrike.falcon.App</string>
|
||||
</dict>
|
||||
</array>
|
||||
<key>PayloadDescription</key>
|
||||
<string>CrowdStrike Falcon Web Content Filter configuration</string>
|
||||
<key>PayloadDisplayName</key>
|
||||
<string>CrowdStrike - Web Filter</string>
|
||||
<key>PayloadEnabled</key>
|
||||
<true/>
|
||||
<key>PayloadIdentifier</key>
|
||||
<string>com.fleet.webfilter</string>
|
||||
<key>PayloadOrganization</key>
|
||||
<string>Fleet</string>
|
||||
<key>PayloadRemovalDisallowed</key>
|
||||
<false/>
|
||||
<key>PayloadScope</key>
|
||||
<string>System</string>
|
||||
<key>PayloadType</key>
|
||||
<string>Configuration</string>
|
||||
<key>PayloadUUID</key>
|
||||
<string>141ECE18-BC29-4A0E-9743-055A4E649512</string>
|
||||
<key>PayloadVersion</key>
|
||||
<integer>1</integer>
|
||||
</dict>
|
||||
</plist>
|
||||
@@ -0,0 +1,5 @@
|
||||
- name: Windows - Hide uninstall and modify options for Fleet osquery
|
||||
platform: windows
|
||||
description: "This policy checks if the uninstall and modify options are hidden for Fleet osquery by ensuring both the NoRemove and NoModify registry values are set to 1."
|
||||
resolution: "As an IT admin, set the NoRemove and NoModify registry values to 1 under the Fleet osquery uninstall key to prevent users from uninstalling or modifying the agent."
|
||||
query: SELECT CASE WHEN COUNT(*) = 1 THEN 1 ELSE 0 END AS compliant FROM registry nr JOIN registry d ON d.path = REPLACE(nr.path, '\NoRemove', '\DisplayName') JOIN registry nm ON nm.path = REPLACE(nr.path, '\NoRemove', '\NoModify') WHERE nr.path LIKE 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\%\NoRemove' AND d.data = 'Fleet osquery' AND nr.data = '1' AND nm.data = '1';
|
||||
@@ -0,0 +1,27 @@
|
||||
# Prevents uninstall/change of Fleet osquery via Windows UI.
|
||||
# Sets NoRemove and NoModify = 1 under Fleet osquery uninstall entry.
|
||||
# Hides uninstall/change options across Control Panel and Settings > Apps.
|
||||
# Works on all Windows editions.
|
||||
|
||||
$UninstallPaths = @(
|
||||
"HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*",
|
||||
"HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*"
|
||||
)
|
||||
|
||||
$FleetEntry = Get-ItemProperty -Path $UninstallPaths -ErrorAction SilentlyContinue |
|
||||
Where-Object { $_.DisplayName -like "Fleet osquery*" }
|
||||
|
||||
if ($FleetEntry) {
|
||||
Write-Output "[INFO] Fleet osquery found: $($FleetEntry.DisplayName)"
|
||||
$RegKeyPath = $FleetEntry.PSPath
|
||||
|
||||
New-ItemProperty -Path $RegKeyPath -Name "NoRemove" -Value 1 -PropertyType DWord -Force | Out-Null
|
||||
Write-Output "[SET] NoRemove = 1"
|
||||
|
||||
New-ItemProperty -Path $RegKeyPath -Name "NoModify" -Value 1 -PropertyType DWord -Force | Out-Null
|
||||
Write-Output "[SET] NoModify = 1"
|
||||
|
||||
Write-Output "[DONE] Fleet osquery uninstall options hardened."
|
||||
} else {
|
||||
Write-Output "[WARN] Fleet osquery not found. Nothing changed."
|
||||
}
|
||||
Reference in New Issue
Block a user