Leaked source code of windows server 2003
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

1042 lines
63 KiB

  1. @*:This file defines default security settings.
  2. @*:Please do not edit. Instead, email kirksol with the requested change.
  3. @*:Thanks!
  4. ; Copyright (c) Microsoft Corporation. All rights reserved.
  5. ;
  6. ; Security Configuration Template for Security Configuration Editor
  7. ;
  8. ; Template Name: DefltSV.INF
  9. ; Template Version: 05.10.DS.0000
  10. ;
  11. ; Default Security For Windows NT 5.1 Server.
  12. [Profile Description]
  13. %SCEDefltSVProfileDescription%
  14. [version]
  15. signature="$CHICAGO$"
  16. revision=1
  17. [System Access]
  18. ;----------------------------------------------------------------
  19. ;Account Policies - Password Policy
  20. ;----------------------------------------------------------------
  21. MinimumPasswordAge = 0
  22. MaximumPasswordAge = 42
  23. MinimumPasswordLength = 0
  24. PasswordComplexity = 0
  25. PasswordHistorySize = 0
  26. RequireLogonToChangePassword = 0
  27. ClearTextPassword = 0
  28. ;----------------------------------------------------------------
  29. ;Account Policies - Lockout Policy
  30. ;----------------------------------------------------------------
  31. ;No Account Lockout
  32. LockoutBadCount = 0
  33. ;The following are not configured when No Account Lockout
  34. ;ResetLockoutCount = 30
  35. ;LockoutDuration = 30
  36. ;----------------------------------------------------------------
  37. ;Local Policies - Security Options
  38. ;----------------------------------------------------------------
  39. ;DC Only
  40. ;ForceLogoffWhenHourExpire = 0
  41. LSAAnonymousNameLookup = 0
  42. ;NewAdministatorName =
  43. ;NewGuestName =
  44. ;SecureSystemPartition
  45. ;----------------------------------------------------------------
  46. ;Event Log - Log Settings
  47. ;----------------------------------------------------------------
  48. ;Audit Log Retention Period:
  49. ;0 = Overwrite Events As Needed
  50. ;1 = Overwrite Events As Specified by Retention Days Entry
  51. ;2 = Never Overwrite Events (Clear Log Manually)
  52. [System Log]
  53. MaximumLogSize = 16384
  54. AuditLogRetentionPeriod = 0
  55. ;RetentionDays = 7
  56. RestrictGuestAccess = 1
  57. [Security Log]
  58. MaximumLogSize = 16384
  59. AuditLogRetentionPeriod = 0
  60. ;RetentionDays = 7
  61. RestrictGuestAccess = 1
  62. [Application Log]
  63. MaximumLogSize = 16384
  64. AuditLogRetentionPeriod = 0
  65. ;RetentionDays = 7
  66. RestrictGuestAccess = 1
  67. ;----------------------------------------------------------------
  68. ;Local Policies - Audit Policy
  69. ;----------------------------------------------------------------
  70. [Event Audit]
  71. AuditAccountLogon = 1
  72. AuditAccountManage = 0
  73. AuditSystemEvents = 0
  74. AuditLogonEvents = 1
  75. AuditObjectAccess = 0
  76. AuditPrivilegeUse = 0
  77. AuditPolicyChange = 0
  78. AuditProcessTracking = 0
  79. ;AuditDSAccess = 0
  80. CrashOnAuditFull = 0
  81. ;----------------------------------------------------------------
  82. ;Registry Values
  83. ;----------------------------------------------------------------
  84. [Registry Values]
  85. ; Registry value name in full path = Type, Value
  86. ; REG_SZ ( 1 )
  87. ; REG_EXPAND_SZ ( 2 ) // with environment variables to expand
  88. ; REG_BINARY ( 3 )
  89. ; REG_DWORD ( 4 )
  90. ; REG_MULTI_SZ ( 7 )
  91. MACHINE\System\CurrentControlSet\Control\Lsa\AuditBaseObjects=4,0
  92. MACHINE\System\CurrentControlSet\Control\Lsa\CrashOnAuditFail=4,0
  93. MACHINE\System\CurrentControlSet\Control\Lsa\DisableDomainCreds=4,0
  94. MACHINE\System\CurrentControlSet\Control\Lsa\EveryoneIncludesAnonymous=4,0
  95. MACHINE\System\CurrentControlSet\Control\Lsa\ForceGuest=4,0
  96. MACHINE\System\CurrentControlSet\Control\Lsa\FIPSAlgorithmPolicy=4,0
  97. MACHINE\System\CurrentControlSet\Control\Lsa\FullPrivilegeAuditing=3,0
  98. MACHINE\System\CurrentControlSet\Control\Lsa\LimitBlankPasswordUse=4,1
  99. MACHINE\System\CurrentControlSet\Control\Lsa\LmCompatibilityLevel=4,2
  100. MACHINE\System\CurrentControlSet\Control\Lsa\MSV1_0\NTLMMinClientSec=4,0
  101. MACHINE\System\CurrentControlSet\Control\Lsa\MSV1_0\NTLMMinServerSec=4,0
  102. MACHINE\System\CurrentControlSet\Control\Lsa\NoLMHash=4,0
  103. MACHINE\System\CurrentControlSet\Control\Lsa\NoDefaultAdminOwner=4,0
  104. MACHINE\System\CurrentControlSet\Control\Lsa\RestrictAnonymous=4,0
  105. MACHINE\System\CurrentControlSet\Control\Lsa\RestrictAnonymousSAM=4,1
  106. ;Domain Controllers Only
  107. ;MACHINE\System\CurrentControlSet\Control\Lsa\SubmitControl=4,0
  108. MACHINE\System\CurrentControlSet\Control\Print\Providers\LanMan Print Services\Servers\AddPrinterDrivers=4,1
  109. MACHINE\System\CurrentControlSet\Control\Session Manager\Kernel\ObCaseInsensitive=4,1
  110. MACHINE\System\CurrentControlSet\Control\Session Manager\Memory Management\ClearPageFileAtShutdown=4,0
  111. MACHINE\System\CurrentControlSet\Control\Session Manager\ProtectionMode=4,1
  112. MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\EnableSecuritySignature=4,0
  113. MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\RequireSecuritySignature=4,0
  114. MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\EnableForcedLogOff=4,1
  115. MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\AutoDisconnect=4,15
  116. MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\RestrictNullSessAccess=4,1
  117. MACHINE\System\CurrentControlSet\Services\LanmanWorkstation\Parameters\EnableSecuritySignature=4,1
  118. MACHINE\System\CurrentControlSet\Services\LanmanWorkstation\Parameters\RequireSecuritySignature=4,0
  119. MACHINE\System\CurrentControlSet\Services\LanmanWorkstation\Parameters\EnablePlainTextPassword=4,0
  120. MACHINE\System\CurrentControlSet\Services\LDAP\LDAPClientIntegrity=4,1
  121. MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters\DisablePasswordChange=4,0
  122. MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters\MaximumPasswordAge=4,30
  123. MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters\SignSecureChannel=4,1
  124. MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters\SealSecureChannel=4,1
  125. MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters\RequireSignOrSeal=4,1
  126. MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters\RequireStrongKey=4,0
  127. ;Potential to take on different values during and after setup
  128. ;MACHINE\Software\Microsoft\Driver Signing\Policy=3,1
  129. ;MACHINE\Software\Microsoft\Non-Driver Signing\Policy=3,0
  130. MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableCAD=4,0
  131. MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\DontDisplayLastUserName=4,0
  132. MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\LegalNoticeCaption=1,""
  133. MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\LegalNoticeText=7,""
  134. MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\ScForceOption=4,0
  135. MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\ShutdownWithoutLogon=4,0
  136. MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\UndockWithoutLogon=4,1
  137. MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Setup\RecoveryConsole\SecurityLevel=4,0
  138. MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Setup\RecoveryConsole\SetCommand=4,0
  139. MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\AllocateCDRoms=1,0
  140. MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\AllocateDASD=1,0
  141. MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\AllocateFloppies=1,0
  142. MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\CachedLogonsCount=1,10
  143. MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ForceUnlockLogon=4,0
  144. MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\PasswordExpiryWarning=4,14
  145. MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ScRemoveOption=1,0
  146. MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\AuthenticodeEnabled=4,0
  147. ;----------------------------------------------------------------------
  148. ; Privileges & Rights
  149. ;----------------------------------------------------------------------
  150. ;
  151. ;World S-1-1-0
  152. ;
  153. ;NT Authority S-1-5
  154. ;TERMINAL_SERVER 13
  155. ;LOCAL_SERVICE 19
  156. ;NETWORK_SERVICE 20
  157. ;
  158. ;Built-In Domain SubAuthority = S-1-5-32
  159. ;ADMINISTRATORS 544
  160. ;USERS 545
  161. ;GUESTS 546
  162. ;POWER_USERS 547
  163. ;ACCOUNT_OPS 548
  164. ;SYSTEM_OPS 549
  165. ;PRINT_OPS 550
  166. ;BACKUP_OPS 551
  167. ;REPLICATOR 552
  168. ;RAS_SERVERS 553
  169. ;PREW2KCOMPACCESS 554
  170. ;REMOTE_DESKTOP_USERS 555
  171. ;NETWORK_CONFIGURATION_OPS 556
  172. [Privilege Rights]
  173. SeAssignPrimaryTokenPrivilege = *S-1-5-19, *S-1-5-20
  174. SeAuditPrivilege = *S-1-5-19, *S-1-5-20
  175. SeBackupPrivilege = *S-1-5-32-544, *S-1-5-32-551
  176. SeBatchLogonRight =
  177. SeChangeNotifyPrivilege = *S-1-5-32-544, *S-1-5-32-551, *S-1-5-32-547, *S-1-5-32-545, *S-1-1-0
  178. SeCreateGlobalPrivilege = *S-1-5-6, *S-1-5-32-544
  179. SeCreatePagefilePrivilege = *S-1-5-32-544
  180. SeCreatePermanentPrivilege =
  181. SeCreateTokenPrivilege =
  182. SeDebugPrivilege = *S-1-5-32-544
  183. SeImpersonatePrivilege = *S-1-5-6, *S-1-5-32-544
  184. SeIncreaseBasePriorityPrivilege = *S-1-5-32-544
  185. SeIncreaseQuotaPrivilege = *S-1-5-32-544, *S-1-5-19, *S-1-5-20
  186. SeInteractiveLogonRight = *S-1-5-32-544, *S-1-5-32-551, *S-1-5-32-547, *S-1-5-32-545
  187. SeLoadDriverPrivilege = *S-1-5-32-544
  188. SeLockMemoryPrivilege =
  189. SeMachineAccountPrivilege =
  190. SeManageVolumePrivilege = *S-1-5-32-544
  191. SeNetworkLogonRight = *S-1-5-32-544, *S-1-5-32-551, *S-1-5-32-547, *S-1-5-32-545, *S-1-1-0
  192. SeProfileSingleProcessPrivilege = *S-1-5-32-544, *S-1-5-32-547
  193. SeRemoteInteractiveLogonRight = *S-1-5-32-544, *S-1-5-32-555
  194. SeRemoteShutdownPrivilege = *S-1-5-32-544
  195. SeRestorePrivilege = *S-1-5-32-544, *S-1-5-32-551
  196. SeSecurityPrivilege = *S-1-5-32-544
  197. SeServiceLogonRight =
  198. SeShutdownPrivilege = *S-1-5-32-544, *S-1-5-32-551, *S-1-5-32-547
  199. SeSystemEnvironmentPrivilege = *S-1-5-32-544
  200. SeSystemProfilePrivilege = *S-1-5-32-544
  201. SeSystemTimePrivilege = *S-1-5-32-544, *S-1-5-32-547
  202. SeTakeOwnershipPrivilege = *S-1-5-32-544
  203. SeTcbPrivilege =
  204. ;
  205. SeDenyInteractiveLogonRight =
  206. SeDenyBatchLogonRight =
  207. SeDenyServiceLogonRight =
  208. SeDenyNetworkLogonRight =
  209. SeDenyRemoteInteractiveLogonRight =
  210. ;
  211. SeUndockPrivilege = *S-1-5-32-544, *S-1-5-32-547
  212. SeSyncAgentPrivilege =
  213. SeEnableDelegationPrivilege =
  214. [Group Membership]
  215. %SceInfUsers%__Memberof =
  216. %SceInfUsers%__Members = %SceInfAuthUsers%,%SceInfInteractive%
  217. [Service General Setting]
  218. ;autostarted on workstations and servers, standalone or joined
  219. Browser,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  220. Dhcp,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRRC;;;NO)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  221. TrkWks,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  222. Dnscache,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRRC;;;NO)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  223. Eventlog,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  224. PolicyAgent,,"D:(A;;CCLCSWLORC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  225. dmserver,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  226. Messenger,4,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  227. PlugPlay,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  228. Spooler,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  229. ProtectedStorage,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  230. RpcSs,,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLORC;;;PU)(A;;CCLCSWRPLO;;;IU)(A;;CCLCSWRPLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  231. NtmsSvc,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  232. seclogon,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  233. SamSs,,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLORC;;;PU)(A;;CCLCSWRPLO;;;IU)(A;;CCLCSWRPLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  234. lanmanserver,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  235. SENS,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  236. Schedule,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  237. Sysmonlog,,"D:(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCRPLOCR;;;LU)S:AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  238. LmHosts,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  239. LanmanWorkstation,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  240. RemoteRegistry,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  241. ;Not autostarted, but non-default DACL - Remove PU ability to change template
  242. ClipSrv,4,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLORC;;;PU)(A;;CCLCSWRPLO;;;IU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  243. NetDDE,4,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLORC;;;PU)(A;;CCLCSWRPLO;;;IU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  244. NetDDEdsdm,4,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLORC;;;PU)(A;;CCLCSWRPLO;;;IU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  245. EventSystem,,"D:(A;;CCLCSWRPLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLORC;;;PU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  246. ;Not autostarted if machine is standalone
  247. Netlogon,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  248. W32Time,,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLORC;;;PU)(A;;CCLCSWRPLO;;;IU)(A;;CCLCSWRPLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  249. ;Not autostarted if Wksta
  250. Alerter,4,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  251. MSDTC,,"D:(A;;CCLCSWRPLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLORC;;;NS)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  252. ;Server Only Services
  253. Dfs,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  254. LicenseService,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  255. ;IIS Specific Services - Leave them alone
  256. ;IISADMIN,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  257. ;W3SVC,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  258. ;MSFTPSVC,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  259. ;SMTPSVC,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  260. ;
  261. ; set default startup for the following services - do not touch permissions
  262. ;
  263. @b:AudioSrv,4,""
  264. ;;FastUserSwitching service not installed in setup
  265. Mnmsrvc,4,""
  266. SharedAccess,4,""
  267. Themes,4,""
  268. TlntSvr,4,""
  269. TrkSvr,4,""
  270. ;;Tssdis service not installed in setup
  271. WmdmPmSp,3,""
  272. [Registry Keys]
  273. "MACHINE\Software",2,"D:P(A;CI;GR;;;BU)(A;CI;GRGWSD;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GRGWSD;;;S-1-5-13)"
  274. ;Not same as parent, and this is the target of a symlink - set explicitly.
  275. "MACHINE\SOFTWARE\Classes",2,"D:P(A;CI;GR;;;BU)(A;CI;GRGWSD;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  276. "MACHINE\SOFTWARE\Classes\helpfile",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  277. "MACHINE\SOFTWARE\Classes\.hlp",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  278. "MACHINE\SOFTWARE\Microsoft\ADs\Providers\LDAP\Extensions",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  279. @@:@i:"MACHINE\SOFTWARE\Microsoft\ADs\Providers\NDS",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  280. @@:@i:"MACHINE\SOFTWARE\Microsoft\ADs\Providers\NWCOMPAT",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  281. "MACHINE\SOFTWARE\Microsoft\ADs\Providers\WinNT",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  282. "MACHINE\SOFTWARE\Microsoft\Command Processor",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  283. "MACHINE\SOFTWARE\Microsoft\Cryptography",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  284. "MACHINE\SOFTWARE\Microsoft\Cryptography\Calais",2,"D:AR(A;CI;GRGWSD;;;LS)"
  285. "MACHINE\SOFTWARE\Microsoft\DeviceManager",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  286. "MACHINE\SOFTWARE\Microsoft\Driver Signing",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  287. "MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  288. "MACHINE\Software\Microsoft\EventSystem",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  289. "MACHINE\SOFTWARE\Microsoft\Non-Driver Signing",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  290. "MACHINE\SOFTWARE\Microsoft\NetDDE",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  291. "MACHINE\SOFTWARE\Microsoft\Ole",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  292. "MACHINE\SOFTWARE\Microsoft\Passport",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GR;;;NS)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  293. "MACHINE\SOFTWARE\Microsoft\Passport\KeyData",2,"D:P(A;CI;GR;;;NS)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  294. "MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider",1,"D:AR"
  295. "MACHINE\SOFTWARE\Microsoft\Rpc",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  296. "MACHINE\SOFTWARE\Microsoft\Secure",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  297. "MACHINE\Software\Microsoft\Speech",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  298. "MACHINE\SOFTWARE\Microsoft\SystemCertificates",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  299. "MACHINE\SOFTWARE\Microsoft\Tracing",2,"D:P(A;CI;GR;;;BU)(A;CI;GRGWSD;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GR;;;S-1-5-13)"
  300. "MACHINE\Software\Microsoft\Windows\CurrentVersion",2,"D:P(A;CI;GR;;;BU)(A;CI;GRGWSD;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  301. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  302. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Reliability",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  303. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  304. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  305. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  306. ;The following keys need to be writable by TERMINAL_SERVER_USER for App-Compat
  307. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths",2,"D:P(A;CI;GR;;;BU)(A;CI;GRGWSD;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GRGWSD;;;S-1-5-13)"
  308. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace",2,"D:P(A;CI;GR;;;BU)(A;CI;GRGWSD;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GRGWSD;;;S-1-5-13)"
  309. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks",2,"D:P(A;CI;GR;;;BU)(A;CI;GRGWSD;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GRGWSD;;;S-1-5-13)"
  310. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs",2,"D:P(A;CI;GR;;;BU)(A;CI;GRGWSD;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GRGWSD;;;S-1-5-13)"
  311. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall",2,"D:P(A;CI;GR;;;BU)(A;CI;GRGWSD;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GRGWSD;;;S-1-5-13)"
  312. ;The following keys do not exist when we run.
  313. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy",1,"D:AR"
  314. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer",1,"D:AR"
  315. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies",1,"D:AR"
  316. "MACHINE\SOFTWARE\Microsoft\MSDTC",1,"D:AR"
  317. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony",2,"D:P(A;CIOI;GR;;;BU)(A;CIOI;GRGWSD;;;PU)(A;CIOI;GA;;;NS)(A;CIOI;GA;;;LS)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  318. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  319. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AEDebug",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  320. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Asr\Commands",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  321. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Classes",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  322. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  323. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EFS",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  324. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Event Viewer",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  325. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Font Drivers",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  326. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontMapper",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  327. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  328. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  329. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GR;;;LS)(A;CI;GR;;;NS)(A;CI;GR;;;LU)(A;CI;GR;;;MU)"
  330. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\009",1,"D:AR"
  331. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  332. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports",2,"D:P(A;CI;GR;;;BU)(A;CI;GRGWSD;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  333. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  334. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SecEdit",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  335. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Setup\RecoveryConsole",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  336. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  337. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  338. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WbemPerf",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GR;;;LS)(A;CI;GR;;;NS)(A;CI;GR;;;LU)(A;CI;GR;;;MU)"
  339. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  340. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  341. "MACHINE\SOFTWARE\Microsoft\wbem",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GA;;;NS)(A;CI;GR;;;BU)"
  342. "MACHINE\SOFTWARE\Microsoft\wbem\CIMOM",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GR;;;BU)"
  343. "MACHINE\SOFTWARE\Microsoft\wbem\Transports",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GR;;;BU)"
  344. "MACHINE\SOFTWARE\Microsoft\wbem\ESS",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GR;;;BU)"
  345. "MACHINE\SOFTWARE\Microsoft\wbem\FWD",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GR;;;BU)"
  346. "MACHINE\SOFTWARE\Policies",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  347. "MACHINE\System",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  348. "MACHINE\SYSTEM\Clone",1,"D:AR"
  349. "MACHINE\SYSTEM\ControlSet001",1,"D:AR"
  350. "MACHINE\SYSTEM\ControlSet002",1,"D:AR"
  351. "MACHINE\SYSTEM\ControlSet003",1,"D:AR"
  352. "MACHINE\SYSTEM\ControlSet004",1,"D:AR"
  353. "MACHINE\SYSTEM\ControlSet005",1,"D:AR"
  354. "MACHINE\SYSTEM\ControlSet006",1,"D:AR"
  355. "MACHINE\SYSTEM\ControlSet007",1,"D:AR"
  356. "MACHINE\SYSTEM\ControlSet008",1,"D:AR"
  357. "MACHINE\SYSTEM\ControlSet009",1,"D:AR"
  358. "MACHINE\SYSTEM\ControlSet010",1,"D:AR"
  359. "MACHINE\SYSTEM\CurrentControlSet\Control\Class",0,"D:AR"
  360. "MACHINE\SYSTEM\CurrentControlSet\Control\Keyboard Layout",2,"D:(A;CI;GR;;;WD)"
  361. "MACHINE\SYSTEM\CurrentControlSet\Control\Keyboard Layouts",2,"D:(A;CI;GR;;;WD)"
  362. "MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Audit",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  363. "MACHINE\SYSTEM\CurrentControlSet\Control\LSA\JD",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  364. "MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Skew1",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  365. "MACHINE\SYSTEM\CurrentControlSet\Control\LSA\GBG",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  366. "MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Data",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  367. "MACHINE\SYSTEM\CurrentControlSet\Control\Network",2,"D:(A;CI;GRGWSD;;;NO)"
  368. "MACHINE\SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg",2,"D:P(A;CI;GA;;;BA)(A;;GR;;;BO)(A;CI;GR;;;LS)"
  369. "MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCache",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  370. "MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Executive",2,"D:(A;CI;GRGWSD;;;PU)"
  371. "MACHINE\SYSTEM\CurrentControlSet\Control\TimeZoneInformation",2,"D:(A;CI;GRGWSD;;;PU)"
  372. "MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Security",2,"D:P(A;CI;GR;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  373. "MACHINE\SYSTEM\CurrentControlSet\Services",0,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  374. ;Set security subkey permissions for those services created via default hives
  375. "MACHINE\SYSTEM\CurrentControlSet\Services\AppMgmt\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  376. "MACHINE\SYSTEM\CurrentControlSet\Services\ClipSrv\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  377. "MACHINE\SYSTEM\CurrentControlSet\Services\CryptSvc\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  378. "MACHINE\SYSTEM\CurrentControlSet\Services\ERSvc\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  379. @*:Fix for 477845 causes regression for 32625
  380. ;"MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  381. @*:We still can add a SACL to it though.
  382. "MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security",2,"S:AR(AU;OICISAFA;DCLCSDWDWO;;;WD)"
  383. @@:@6:"MACHINE\SYSTEM\CurrentControlSet\Services\IASJet\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  384. "MACHINE\SYSTEM\CurrentControlSet\Services\kdc\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  385. "MACHINE\SYSTEM\CurrentControlSet\Services\NetDDE\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  386. "MACHINE\SYSTEM\CurrentControlSet\Services\NetDDEdsdm\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  387. "MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  388. "MACHINE\SYSTEM\CurrentControlSet\Services\Samss\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  389. "MACHINE\SYSTEM\CurrentControlSet\Services\SCardSvr\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  390. "MACHINE\SYSTEM\CurrentControlSet\Services\TapiSrv\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  391. "MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  392. ;Set security subkey permissions for those services created in GUI-mode setup before SCE runs
  393. "MACHINE\SYSTEM\CurrentControlSet\Services\IREnum\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  394. "MACHINE\SYSTEM\CurrentControlSet\Services\STISvc\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  395. "MACHINE\SYSTEM\CurrentControlSet\Services\WMI\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  396. "MACHINE\SYSTEM\CurrentControlSet\Services\SysmonLog\Log Queries",2,"D:(A;CI;GA;;;NS)(A;CI;CCDCLCSWSDRC;;;LU)"
  397. "MACHINE\SYSTEM\CurrentControlSet\Enum",1,"D:AR"
  398. "MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles",1,"D:AR"
  399. "USERS\.DEFAULT",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  400. "USERS\.DEFAULT\Software\Microsoft\NetDDE",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  401. "USERS\.DEFAULT\SOFTWARE\Microsoft\Protected Storage System Provider",1,"D:AR"
  402. "USERS\.DEFAULT\SOFTWARE\Microsoft\SystemCertificates\Root\ProtectedRoots",1,"D:AR"
  403. [File Security]
  404. ;---------------------------------------------------------------------------------------
  405. ;x86 Boot Files
  406. ;---------------------------------------------------------------------------------------
  407. @@:@i:"%BootDrive%\boot.ini",2,"D:P(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  408. @@:@i:"%BootDrive%\ntdetect.com",2,"D:P(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  409. @@:@i:"%BootDrive%\ntldr",2,"D:P(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  410. @@:@i:"%BootDrive%\ntbootdd.sys",2,"D:P(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  411. @@:@i:"%BootDrive%\autoexec.bat",2,"D:P(A;;GRGX;;;BU)(A;;GRGWGXSD;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  412. @@:@i:"%BootDrive%\config.sys",2,"D:P(A;;GRGX;;;BU)(A;;GRGWGXSD;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  413. ;---------------------------------------------------------------------------------------
  414. ;amd64 Boot Files
  415. ;---------------------------------------------------------------------------------------
  416. @@:@a:"%BootDrive%\boot.ini",2,"D:P(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  417. @@:@a:"%BootDrive%\ntdetect.com",2,"D:P(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  418. @@:@a:"%BootDrive%\ntldr",2,"D:P(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  419. ;---------------------------------------------------------------------------------------
  420. ;System Drive
  421. ;---------------------------------------------------------------------------------------
  422. ;SetupSecurity will contain the new root acl. Ignore docs and settings if it's reapplied (e.g. on conversion from FAT)
  423. "%SystemDrive%\Documents and Settings",1,"D:AR"
  424. ; Directories that might not exist when security is applied; but are listed here
  425. ; so that they get secured correctly on converting the file system to NTFS
  426. "%SystemDrive%\perflogs",2,"D:P(A;CIOI;GRGX;;;MU)(A;CIOI;GRGWGXSDRC;;;NS)(A;CIOI;GRGWGXSDRC;;;LU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  427. "%SystemDrive%\System Volume Information",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  428. "%SystemDrive%\wmpub",2,"D:P(A;CIOI;GRGWGXSD;;;BU)(A;CIOI;GRGWGXSD;;;NS)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  429. ;---------------------------------------------------------------------------------------------
  430. ;ProgramFiles
  431. ;---------------------------------------------------------------------------------------------
  432. "%SceInfProgramFiles%",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)(A;CIOI;GRGWGXSD;;;S-1-5-13)"
  433. "%SceInfProgramFiles%\Microsoft SQL Server\MSSQL$UDDI",2,"D:P(A;CIOI;GA;;;BA)"
  434. "%SceInfProgramFiles%\WindowsUpdate",2,"D:P(A;CIOI;GRGWGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  435. "%SceInfCommonProgramFiles%\Microsoft Shared\Speech",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  436. "%SceInfCommonProgramFiles%\SpeechEngines\Microsoft\TTS",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  437. ;---------------------------------------------------------------------------------------------
  438. ;ia64 ProgramFiles Directory
  439. ;---------------------------------------------------------------------------------------------
  440. @@:@m:"%SceInfProgramFilesx86%",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)(A;CIOI;GRGWGXSD;;;S-1-5-13)"
  441. ;---------------------------------------------------------------------------------------------
  442. ;System Root (Typically \WINDOWS)
  443. ;---------------------------------------------------------------------------------------------
  444. "%SystemRoot%",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  445. ;Directories that existed and inherited on NT4 out of the box.
  446. ;The text-mode files within these directories are individually secured below.
  447. ;Config, Cursors, Help, Media, Repair, System, Fonts, INF
  448. ;Directories that existed but did not inherit on NT4.
  449. "%SystemRoot%\repair",2,"D:P(A;CI;GRGX;;;BU)(A;CIOI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  450. ;Directories with a legacy history that now ship in the box.
  451. ;Allow Power User Modify on the directory, but Read Only to the files installed during setup.
  452. "%SystemRoot%\addins",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  453. "%SystemRoot%\Connection Wizard",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  454. "%SystemRoot%\java",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  455. "%SystemRoot%\msagent",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  456. "%SystemRoot%\security",2,"D:P(A;CI;GX;;;BU)(A;CI;GX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  457. "%SystemRoot%\security\templates",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  458. "%SystemRoot%\speech",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  459. "%SystemRoot%\TAPI",2,"D:P(A;CIOI;GR;;;BU)(A;CIOI;GRGWSD;;;PU)(A;CIOI;GA;;;NS)(A;CIOI;GA;;;LS)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  460. "%SystemRoot%\twain_32",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  461. "%SystemRoot%\Web",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  462. ;Directories with a legacy history that no longer ship in the box
  463. "%SystemRoot%\speech",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  464. ;Directories with a legacy history being changed for security reasons
  465. "%SystemRoot%\Debug",2,"D:P(A;;GX;;;BU)(A;;GX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  466. "%SystemRoot%\Debug\UserMode",2,"D:PAR(A;;0x00100023;;;BU)(A;OIIO;0x00100006;;;BU)(A;CIOI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  467. "%SystemRoot%\help",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)(A;CIOI;GRGWGX;;;S-1-5-13)"
  468. "%SystemRoot%\Temp",2,"D:P(A;CI;0x100026;;;BU)(A;CIOI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  469. ;Directories with no legacy to preserve. Power Users the same as Users
  470. "%SystemRoot%\AppPatch",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  471. "%SystemRoot%\Driver Cache",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  472. "%SystemRoot%\mui",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  473. "%SystemRoot%\Resources",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  474. "%SystemRoot%\Web\printers\prtcabs",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)(A;CIOI;GRGWGXSD;;;NS)"
  475. "%SystemRoot%\WinSxS",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  476. ;Directories that do not exist when security applied during clean-install - Creator specifies directory security.
  477. ;We explicitly ignore so as not to whack the component-specified DIRECTORY security on upgrade or reapplication of defaults.
  478. "%SystemRoot%\CSC",1,"D:AR"
  479. ;Profiles folder (typically %SystemRoot%\Profiles)
  480. "%Profiles%",1,"D:AR"
  481. ; Directories that might not exist when security is applied; but are listed here
  482. ; so that they get secured correctly on converting the file system to NTFS
  483. "%SystemRoot%\Installer",2,"D:P(A;CIOI;GRGX;;;WD)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  484. "%SystemRoot%\PCHEALTH\HELPCTR",2,"D:P(A;CIOI;GRGX;;;WD)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  485. "%SystemRoot%\PCHEALTH\HELPCTR\Config",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  486. "%SystemRoot%\PCHEALTH\HELPCTR\DataColl",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  487. "%SystemRoot%\PCHEALTH\HELPCTR\PackageStore",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  488. "%SystemRoot%\prefetch",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  489. "%SystemRoot%\Registration",2,"D:P(A;OI;GRGX;;;WD)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  490. "%SystemRoot%\Registration\CRMLog",0,"D:P(A;;0x1200ab;;;BU)(A;OIIO;GRGWSD;;;BU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  491. "%SystemRoot%\Tasks",2,"D:P(A;;0x1200ab;;;BO)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  492. ;Directories that do not exist when security applied during setup - Creator does not specify directory security.
  493. ;Creator should specify FILE security in optional component INF that gets applied on clean-install AND upgrade.
  494. ;Omit (rather than ignore) to allow component-specified file security to be set on reapplication of defaults.
  495. ;Use MARTA (rather than omit) for any components that set protected run-time security.
  496. ;"%SystemRoot%\Downloaded Program Files",0,"D:AR"
  497. ;"%SystemRoot%\Offline Web Pages",0,"D:AR"
  498. ;"%SystemRoot%\IME",0,"D:AR"
  499. ;"%SystemRoot%\mww32",0,"D:AR"
  500. ;"%SystemRoot%\PCHEALTH",0,"D:AR"
  501. ;"%SystemRoot%\SchCache",0,"D:AR"
  502. ;"%SystemRoot%\srchasst",0,"D:AR"
  503. ;---------------------------------------------------------------------------------------------
  504. ;System Directory (Typically \Windows\System32)
  505. ;---------------------------------------------------------------------------------------------
  506. "%SystemDirectory%",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  507. ;Directories that existed and inherited on NT4 out of the box.
  508. ;The text-mode files within these directories are individually secured below.
  509. ;OS2, RAS, Spool, Viewers, WINS, Certsrv
  510. ;Directories that existed but did not inherit on NT4.
  511. "%SystemDirectory%\config",2,"D:P(A;CI;GRGX;;;BU)(A;CI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  512. ;Profile for system account - moved from Docs and Settings in Whistler. Creator specifies security.
  513. "%SystemDirectory%\config\systemprofile",1,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  514. "%SystemDirectory%\dhcp",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  515. "%SystemDirectory%\dllcache",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  516. "%SystemDirectory%\drivers",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  517. ;Directories with a legacy history that now ship in the box.
  518. ;Allow Power User Modify on the directory, but Read Only to the files installed during setup.
  519. "%SystemDirectory%\ShellExt",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  520. "%SystemDirectory%\spool\drivers",2,"D:(A;CIOI;GRGX;;;WD)"
  521. "%SystemDirectory%\wbem",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  522. ;Directories with a legacy history that no longer ship in the box
  523. ;
  524. ;Directories with a legacy history being changed for security reasons
  525. "%SystemDirectory%\catroot",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  526. "%SystemDirectory%\catroot2",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  527. "%SystemDirectory%\ias",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  528. ;Directories with no legacy to preserve. Power Users the same as Users
  529. "%SystemDirectory%\3com_dmi",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  530. "%SystemDirectory%\administration",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  531. "%SystemDirectory%\Export",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  532. "%SystemDirectory%\icsxml",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  533. "%SystemDirectory%\LogFiles",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  534. "%SystemDirectory%\mui",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  535. @@:@i:"%SystemDirectory%\oobe",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  536. ;Directories with no legacy to preserve. Different from parent.
  537. "%SystemDirectory%\LogFiles\ShutDown",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  538. "%SystemDirectory%\setup",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  539. "%SystemDirectory%\wbem\mof",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  540. "%SystemDirectory%\wbem\repository",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  541. "%SystemDirectory%\wbem\logs",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)(A;CIOI;GRGXGW;;;NS)(A;CIOI;GRGXGW;;;LS)"
  542. "%SystemDirectory%\wbem\AutoRecover",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  543. ;Directories that do not exist when security applied during clean-install - Creator specifies directory security.
  544. ;We explicitly ignore so as not to whack the component-specified DIRECTORY security on upgrade or reapplication of defaults.
  545. "%SystemDirectory%\appmgmt",1,"D:AR"
  546. "%SystemDirectory%\DTCLog",1,"D:AR"
  547. "%SystemDirectory%\ReinstallBackups",1,"D:AR"
  548. "%SystemDirectory%\repl",1,"D:AR"
  549. ; Directories that might not exist when security is applied; but are listed here
  550. ; so that they get secured correctly on converting the file system to NTFS
  551. "%SystemDirectory%\com\dmp",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  552. "%SystemDirectory%\CPL.CFG",2,"D:(A;CIOI;GA;;;NS)"
  553. "%SystemDirectory%\CertLog",2,"D:P(A;CIOI;GA;;;BO)(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICIIO;FA;;;CO)"
  554. "%SystemDirectory%\FxsTmp",2,"D:P(A;;0x100003;;;BU)(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICIIO;FA;;;CO)"
  555. "%SystemDirectory%\GroupPolicy",2,"D:P(A;CIOI;GRGX;;;AU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  556. "%SystemDirectory%\LLS",2,"D:(A;CIOI;GA;;;NS)"
  557. "%SystemDirectory%\LLS\CPL.CFG",2,"D:P(A;CIOI;GA;;;NS)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  558. "%SystemDirectory%\LLS\LlsCert.LLS",2,"D:P(A;CIOI;GA;;;NS)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  559. "%SystemDirectory%\LLS\LlsMap.LLS",2,"D:P(A;CIOI;GA;;;NS)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  560. "%SystemDirectory%\LLS\LlsUser.LLS",2,"D:P(A;CIOI;GA;;;NS)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  561. "%SystemDirectory%\LogFiles\Fax\Incoming",2,"D:P(A;CIOI;GA;;;NS)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  562. "%SystemDirectory%\LogFiles\Fax\Outgoing",2,"D:P(A;CIOI;GA;;;NS)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  563. "%SystemDirectory%\LogFiles\UDDI",2,"D:(A;CIOI;GRGWGXSD;;;NS)"
  564. "%SystemDirectory%\LogFiles\wms",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GRGWGXSD;;;NS)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  565. "%SystemDirectory%\LServer",2,"D:P(A;OICI;GRGWGXDTSDCCLC;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  566. "%SystemDirectory%\msdtc",2,"D:P(A;OICI;GRGWGX;;;NS)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  567. "%SystemDirectory%\msmq",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  568. "%SystemDirectory%\NTMSData",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  569. "%SystemDirectory%\RemoteStorage",2,"D:P(A;CIOI;GRGX;;;BO)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  570. "%SystemDirectory%\spool\printers",2,"D:P(A;CI;0x1000ae;;;BU)(A;CI;0x1000ae;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  571. "%SystemDirectory%\tssesdir",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  572. "%SystemDirectory%\Windows media",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGWGXSD;;;NS)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  573. ;Directories that do not exist when security applied during setup - Creator does not specify directory security.
  574. ;Creator should specify FILE security in optional component INF that gets applied on clean-install AND upgrade.
  575. ;Omit (rather than ignore) to allow component-specified file security to be set on reapplication of defaults.
  576. ;Use MARTA (rather than omit) for any components that set protected run-time security.
  577. ;"%SystemDirectory%\Cache",0,"D:AR"
  578. ;"%SystemDirectory%\clients",0,"D:AR"
  579. ;"%SystemDirectory%\Com",0,"D:AR"
  580. ;"%SystemDirectory%\inetsrv",0,"D:AR"
  581. ;"%SystemDirectory%\Microsoft",0,"D:AR"
  582. ;"%SystemDirectory%\netmon",0,"D:AR"
  583. ;"%SystemDirectory%\npp",0,"D:AR"
  584. ;"%SystemDirectory%\oobe",0,"D:AR"
  585. ;"%SystemDirectory%\restore",0,"D:AR"
  586. ;"%SystemDirectory%\reminst",0,"D:AR"
  587. ;"%SystemDirectory%\rocket",0,"D:AR"
  588. ;"%SystemDirectory%\usmt",0,"D:AR"
  589. ;-----------------------------------------------------------------------------------------
  590. ; SysWOW64 directories
  591. ;-----------------------------------------------------------------------------------------
  592. @@:@6:"%Systemroot%\SysWOW64",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  593. @@:@6:"%Systemroot%\SysWOW64\wbem",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  594. @@:@6:"%Systemroot%\SysWOW64\Export",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  595. @@:@6:"%Systemroot%\SysWOW64\ias",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  596. ;-----------------------------------------------------------------------------------------
  597. ;Individual File Settings.
  598. ;So that Power User Modify is not inherited from parent.
  599. ;-----------------------------------------------------------------------------------------
  600. "%Systemroot%\*",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  601. Exception="win.ini"
  602. "%Systemroot%\System\*",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  603. "%Systemroot%\Inf\*",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  604. Exception="msmail.inf"
  605. "%Systemroot%\Help\*",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  606. "%Systemroot%\Help\mail\smtpsnap.cnt",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  607. "%Systemroot%\Help\mail\smtpsnap.hlp",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  608. "%Systemroot%\Help\news\nntpsnap.cnt",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  609. "%Systemroot%\Help\news\nntpsnap.hlp",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  610. "%Systemroot%\Fonts\*",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  611. "%Systemroot%\Config\*",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  612. "%Systemroot%\Media\*",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  613. "%Systemroot%\Cursors\*",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  614. "%Systemroot%\repair\default",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  615. "%Systemroot%\repair\ntuser.dat",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  616. "%Systemroot%\repair\sam",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  617. "%Systemroot%\repair\security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  618. "%Systemroot%\repair\software",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  619. "%Systemroot%\repair\system",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  620. "%SystemRoot%\TAPI\tsec.ini",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  621. "%Systemdirectory%\hal.dll",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  622. "%Systemdirectory%\inetsrv\aqadmin.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  623. "%Systemdirectory%\inetsrv\aqueue.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  624. "%Systemdirectory%\inetsrv\ddrop.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  625. "%Systemdirectory%\inetsrv\isrpc.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  626. "%Systemdirectory%\inetsrv\mailmsg.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  627. "%Systemdirectory%\inetsrv\nntpadm.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  628. "%Systemdirectory%\inetsrv\nntpfs.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  629. "%Systemdirectory%\inetsrv\nntpsnap.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  630. "%Systemdirectory%\inetsrv\nntpsvc.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  631. "%Systemdirectory%\inetsrv\ntfsdrv.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  632. "%Systemdirectory%\inetsrv\rcancel.vbs",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  633. "%Systemdirectory%\inetsrv\regfilt.vbs",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  634. "%Systemdirectory%\inetsrv\rexpire.vbs",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  635. "%Systemdirectory%\inetsrv\rfeed.vbs",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  636. "%Systemdirectory%\inetsrv\rgroup.vbs",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  637. "%Systemdirectory%\inetsrv\rsess.vbs",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  638. "%Systemdirectory%\inetsrv\SCRIPTO.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  639. "%Systemdirectory%\inetsrv\seo.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  640. "%Systemdirectory%\inetsrv\seos.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  641. "%Systemdirectory%\inetsrv\smtpadm.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  642. "%Systemdirectory%\inetsrv\smtpsnap.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  643. "%Systemdirectory%\inetsrv\smtpsvc.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  644. "%Systemdirectory%\netmon\bhsupp.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  645. "%Systemdirectory%\netmon\hexedit.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  646. "%Systemdirectory%\netmon\netmon.exe",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  647. "%Systemdirectory%\netmon\netmon.ini",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  648. "%Systemdirectory%\netmon\nmapi.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  649. "%Systemdirectory%\netmon\parser.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  650. "%Systemdirectory%\netmon\parser.ini",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  651. "%Systemdirectory%\netmon\slbs.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  652. "%Systemdirectory%\netmon\default.adr",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  653. "%Systemdirectory%\netmon\captures\default.cf",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  654. "%Systemdirectory%\netmon\captures\default.df",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  655. "%Systemdirectory%\netmon\parsers\atalk.ini",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  656. "%Systemdirectory%\netmon\parsers\atalk.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  657. "%Systemdirectory%\netmon\parsers\BONE.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  658. "%Systemdirectory%\netmon\parsers\BROWSER.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  659. "%Systemdirectory%\netmon\parsers\FRAME.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  660. "%Systemdirectory%\netmon\parsers\IPX.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  661. "%Systemdirectory%\netmon\parsers\IPX.INI",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  662. "%Systemdirectory%\netmon\parsers\LLC.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  663. "%Systemdirectory%\netmon\parsers\LLC.INI",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  664. "%Systemdirectory%\netmon\parsers\MAC.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  665. "%Systemdirectory%\netmon\parsers\MAC.INI",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  666. "%Systemdirectory%\netmon\parsers\MSRPC.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  667. "%Systemdirectory%\netmon\parsers\MSRPC.INI",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  668. "%Systemdirectory%\netmon\parsers\NCP.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  669. "%Systemdirectory%\netmon\parsers\NETBIOS.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  670. "%Systemdirectory%\netmon\parsers\NETLOGON.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  671. "%Systemdirectory%\netmon\parsers\PPP.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  672. "%Systemdirectory%\netmon\parsers\PPP.INI",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  673. "%Systemdirectory%\netmon\parsers\PPPOE.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  674. "%Systemdirectory%\netmon\parsers\SMB.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  675. "%Systemdirectory%\netmon\parsers\SNMP.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  676. "%Systemdirectory%\netmon\parsers\TCPIP.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  677. "%Systemdirectory%\netmon\parsers\TCPIP.INI",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  678. "%Systemdirectory%\netmon\parsers\TRAIL.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  679. "%Systemdirectory%\netmon\parsers\TRAIL.INI",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  680. "%Systemdirectory%\netmon\parsers\VINES.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  681. "%Systemdirectory%\netmon\parsers\VINES.INI",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  682. "%Systemdirectory%\netmon\parsers\XNS.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  683. "%Systemdirectory%\netmon\parsers\XNS.INI",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  684. "%Systemdirectory%\netmon\parsers\LOGON.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  685. "%Systemdirectory%\netmon\parsers\LSARPC.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  686. "%Systemdirectory%\netmon\parsers\WINSPL.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  687. "%Systemdirectory%\netmon\parsers\RSVP.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  688. "%Systemdirectory%\netmon\parsers\LANE.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  689. "%Systemdirectory%\netmon\parsers\ATMARP.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  690. "%Systemdirectory%\netmon\parsers\ATMARP.INI",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  691. "%Systemdirectory%\netmon\parsers\LDAP.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  692. "%Systemdirectory%\netmon\parsers\mcast.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  693. "%Systemdirectory%\netmon\parsers\kerbprsr.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  694. "%Systemdirectory%\netmon\parsers\upnpparser.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  695. "%Systemdirectory%\netmon\parsers\upnpparser.ini",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  696. "%Systemdirectory%\spoolss.dll",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  697. "%Systemdirectory%\*",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  698. Exception="autoexec.nt"
  699. Exception="cmos.ram"
  700. Exception="config.nt"
  701. Exception="hpmon.dll"
  702. Exception="hpmon.hlp"
  703. Exception="localmon.dll"
  704. Exception="midimap.cfg"
  705. Exception="append.exe"
  706. Exception="arp.exe"
  707. Exception="at.exe"
  708. Exception="atmadm.exe"
  709. Exception="attrib.exe"
  710. Exception="bootcfg.exe"
  711. Exception="cacls.exe"
  712. Exception="certreq.exe"
  713. Exception="certutil.exe"
  714. Exception="change.exe"
  715. Exception="chcp.com"
  716. Exception="chglogon.exe"
  717. Exception="chgport.exe"
  718. Exception="chgusr.exe"
  719. Exception="chkdsk.exe"
  720. Exception="chkntfs.exe"
  721. Exception="choice.exe"
  722. Exception="cidaemon.exe"
  723. Exception="cipher.exe"
  724. Exception="clip.exe"
  725. Exception="cluster.exe"
  726. Exception="cmd.exe"
  727. Exception="cmdkey.exe"
  728. Exception="comclust.exe"
  729. Exception="command.com"
  730. Exception="comp.exe"
  731. Exception="compact.exe"
  732. Exception="convert.exe"
  733. Exception="convlog.exe"
  734. Exception="cprofile.exe"
  735. Exception="cscript.exe"
  736. Exception="csvde.exe"
  737. Exception="dcgpofix.exe"
  738. Exception="dcphelp.exe"
  739. Exception="debug.exe"
  740. Exception="defrag.exe"
  741. Exception="dfscmd.exe"
  742. Exception="diantz.exe"
  743. Exception="diskcomp.com"
  744. Exception="diskcopy.com"
  745. Exception="diskpart.exe"
  746. Exception="diskperf.exe"
  747. Exception="dns.exe"
  748. Exception="doskey.exe"
  749. Exception="dosx.exe"
  750. Exception="driverquery.exe"
  751. Exception="dsadd.exe"
  752. Exception="dsget.exe"
  753. Exception="dsmod.exe"
  754. Exception="dsmove.exe"
  755. Exception="dsquery.exe"
  756. Exception="dsrm.exe"
  757. Exception="edit.com"
  758. Exception="edlin.exe"
  759. Exception="esentutl.exe"
  760. Exception="eventcreate.exe"
  761. Exception="eventtriggers.exe"
  762. Exception="evntcmd.exe"
  763. Exception="exe2bin.exe"
  764. Exception="expand.exe"
  765. Exception="fastopen.exe"
  766. Exception="fc.exe"
  767. Exception="find.exe"
  768. Exception="findstr.exe"
  769. Exception="finger.exe"
  770. Exception="flattemp.exe"
  771. Exception="forcedos.exe"
  772. Exception="forfiles.exe"
  773. Exception="format.com"
  774. Exception="freedisk.exe"
  775. Exception="fsutil.exe"
  776. Exception="ftp.exe"
  777. Exception="fxssvc.exe"
  778. Exception="getmac.exe"
  779. Exception="gettype.exe"
  780. Exception="gpresult.exe"
  781. Exception="gpupdate.exe"
  782. Exception="graftabl.com"
  783. Exception="graphics.com"
  784. Exception="grovel.exe"
  785. Exception="help.exe"
  786. Exception="hostname.exe"
  787. Exception="iisreset.exe"
  788. Exception="inuse.exe"
  789. Exception="ipconfig.exe"
  790. Exception="ipsec6.exe"
  791. Exception="ipxroute.exe"
  792. Exception="ismserv.exe"
  793. Exception="jetconv.exe"
  794. Exception="jetpack.exe"
  795. Exception="kb16.com"
  796. Exception="label.exe"
  797. Exception="ldifde.exe"
  798. Exception="loadfix.com"
  799. Exception="locator.exe"
  800. Exception="lodctr.exe"
  801. Exception="logman.exe"
  802. Exception="logoff.exe"
  803. Exception="lpq.exe"
  804. Exception="lpr.exe"
  805. Exception="lserver.exe"
  806. Exception="macfile.exe"
  807. Exception="makecab.exe"
  808. Exception="mem.exe"
  809. Exception="mode.com"
  810. Exception="more.com"
  811. Exception="mountvol.exe"
  812. Exception="mqbkup.exe"
  813. Exception="mqdssvc.exe"
  814. Exception="mqsvc.exe"
  815. Exception="mqtgsvc.exe"
  816. Exception="mrinfo.exe"
  817. Exception="mscdexnt.exe"
  818. Exception="msg.exe"
  819. Exception="msiexec.exe"
  820. Exception="nbtstat.exe"
  821. Exception="net.exe"
  822. Exception="net1.exe"
  823. Exception="netsh.exe"
  824. Exception="netstat.exe"
  825. Exception="nlb.exe"
  826. Exception="nlsfunc.exe"
  827. Exception="nslookup.exe"
  828. Exception="ntbackup.exe"
  829. Exception="ntdsutil.exe"
  830. Exception="ntfrs.exe"
  831. Exception="ntsd.exe"
  832. Exception="ntvdm.exe"
  833. Exception="nw16.exe"
  834. Exception="nwscript.exe"
  835. Exception="odbcconf.exe"
  836. Exception="openfiles.exe"
  837. Exception="pathping.exe"
  838. Exception="pentnt.exe"
  839. Exception="ping.exe"
  840. Exception="ping6.exe"
  841. Exception="powercfg.exe"
  842. Exception="print.exe"
  843. Exception="proxycfg.exe"
  844. Exception="qappsrv.exe"
  845. Exception="qprocess.exe"
  846. Exception="query.exe"
  847. Exception="quser.exe"
  848. Exception="qwinsta.exe"
  849. Exception="rasautou.exe"
  850. Exception="rasdial.exe"
  851. Exception="rcp.exe"
  852. Exception="recover.exe"
  853. Exception="redir.exe"
  854. Exception="reg.exe"
  855. Exception="regini.exe"
  856. Exception="register.exe"
  857. Exception="regsvr32.exe"
  858. Exception="relog.exe"
  859. Exception="replace.exe"
  860. Exception="reset.exe"
  861. Exception="rexec.exe"
  862. Exception="route.exe"
  863. Exception="routemon.exe"
  864. Exception="rsh.exe"
  865. Exception="RsLnk.exe"
  866. Exception="rsm.exe"
  867. Exception="Rss.exe"
  868. Exception="RsServ.exe"
  869. Exception="RsTore.exe"
  870. Exception="runas.exe"
  871. Exception="rwinsta.exe"
  872. Exception="sacsess.exe"
  873. Exception="sc.exe"
  874. Exception="scardsvr.exe"
  875. Exception="schtasks.exe"
  876. Exception="schupgr.exe"
  877. Exception="secedit.exe"
  878. Exception="setver.exe"
  879. Exception="setx.exe"
  880. Exception="sfc.exe"
  881. Exception="sfmprint.exe"
  882. Exception="sfmpsexe.exe"
  883. Exception="sfmsvc.exe"
  884. Exception="shadow.exe"
  885. Exception="share.exe"
  886. Exception="shutdown.exe"
  887. Exception="snmp.exe"
  888. Exception="snmptrap.exe"
  889. Exception="sort.exe"
  890. Exception="subst.exe"
  891. Exception="systeminfo.exe"
  892. Exception="takeown.exe"
  893. Exception="tapicfg.exe"
  894. Exception="taskkill.exe"
  895. Exception="tasklist.exe"
  896. Exception="tcpsvcs.exe"
  897. Exception="telnet.exe"
  898. Exception="tftp.exe"
  899. Exception="tftpd.exe"
  900. Exception="timeout.exe"
  901. Exception="tlntadmn.exe"
  902. Exception="tlntsess.exe"
  903. Exception="tracerpt.exe"
  904. Exception="tracert.exe"
  905. Exception="tracert6.exe"
  906. Exception="tree.com"
  907. Exception="tscon.exe"
  908. Exception="tsdiscon.exe"
  909. Exception="tsecimp.exe"
  910. Exception="tskill.exe"
  911. Exception="tsprof.exe"
  912. Exception="tssdis.exe"
  913. Exception="tsshutdn.exe"
  914. Exception="typeperf.exe"
  915. Exception="unlodctr.exe"
  916. Exception="upg351db.exe"
  917. Exception="ups.exe"
  918. Exception="verifier.exe"
  919. Exception="vssadmin.exe"
  920. Exception="vwipxspx.exe"
  921. Exception="w32tm.exe"
  922. Exception="waitfor.exe"
  923. Exception="where.exe"
  924. Exception="whoami.exe"
  925. Exception="win.com"
  926. Exception="wins.exe"
  927. Exception="wlbs.exe"
  928. Exception="xcopy.exe"
  929. Exception="wpa.bak"
  930. Exception="wpa.dbl"
  931. "%Systemdirectory%\cmd.exe",2,"D:P(A;;GRGX;;;IU)(A;;GRGX;;;SU)(A;;GA;;;BA)(A;;GA;;;SY)(A;;GA;;;CO)"
  932. "%Systemdirectory%\wpa.bak",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  933. "%Systemdirectory%\wpa.dbl",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  934. "%Systemdirectory%\OS2\*",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  935. "%Systemdirectory%\OS2\DLL\*",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  936. "%Systemdirectory%\RAS\*",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  937. "%Systemdirectory%\Viewers\*",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"