Jump to content

GeneMoody-Action1

Members
  • Posts

    37
  • Joined

  • Last visited

Everything posted by GeneMoody-Action1

  1. We do have a readiness report that will show W11 compatibility, not sure if there were any major changes in system requirements between versions or builds though.
  2. Ok, so what I have found out is it had to do with how the upgrade assistant interacts specifically with education versions. But that does not mean it is dead in the water. Our support manager is firing up in his lab and getting a more solid answer and or workarounds if possible, I will keep you posted. We need a better answer than "wont" either way, it should be "will" or "Will not for these verifiable reasons documented here." I'll stick with it till one of those is found. I appreciate your patience! Is the reddit thread on the same topic you as well?
  3. Ok, I just talked to support manager, who said that this belief was incorrect as far as he knew as well. Can you DM me a case number, he said he will look into it and find out what is going on. If you do not have a case number still, the email you use to sign in with will work as well.
  4. This is news to me, let me see what I can find out.
  5. Apologies, I do not have automatic monitoring on this form, so late getting to this, did you get this resolved?
  6. It is not out of the question, of course if tampering, it *may* not be malicious. It is not uncommon for vendors to insert special management classes into the WMI, it could be a common driver or application doing this, I would personally experiment as such, deploy vanilla, test, install normal drivers, test, apps, test, and see if you can find a step that induces the behavior. Typically that kind of diagnostics time I reserve just for situations like this, where I have a distributed problem, no good answer, and need one before something critical happens. It is tedious and time consuming, but it beats something going catastrophically wrong in the future and stating the clock then.
  7. A little late to this party, but if these machines do not share a common image, then I would question a very specific type of corruption in WMI on several systems. *Could* be indicative of tampering.
  8. What issues are you having with it specifically, apologies I am not familiar with the client?
  9. Network cables are extremely complex signals at high frequency (Stick a toner next to a data cable at its termination where noisiest) Sound like induction to me, it is specifically engineered around and or shielded in most systems, but things inside get rearranged and moved, and HW also degrades sometimes to produce extraneous out of spec signaling. With even a home built inductive pickup coil, you can listen to a network cable and easily hear if it is passing over a ballast transformer or ran parallel to power. 60Hz vs 250Mhz in Cat6, VERY distinctly different sound. I would also be interested to see if the same system did it live booted into linux, as it is unlikely, but technically possible this could be a byproduct of signal interference in the software at a driver level as well. Since it did no do it in ten but doe sin eleven, its worth the test.
  10. To everyone frustrated with the LinkedIn-based validation process: That was a temporary measure, put in place urgently. We had credible reports from authorities that multiple instances of our free platform was being misused as command-and-control infrastructure for malicious campaigns, with single threat actors leveraging multiple free accounts created under our older, more relaxed sign-up process. We had no real choice. If we had not acted, endpoint security tools (AV, EDR, XDR, etc.) could have begun flagging our agent as malicious. That would have meant locking millions of legitimate, paying customers out of the systems they rely on. So while the change wasn’t ideal, it was the most effective and immediate way to root out abusers. It was also non-negotiable, we had to stop it, root out the offenders, and hold them back until the situation could be remedied. A few important clarifications: Action1 never requested anyone's personal ID beyond a validated LinkedIn profile. If your experience was different please contact me. LinkedIn was selected solely because it leverages CLEAR, an identity verification provider trusted by TSA and others. Action1 does not receive your personal information from CLEAR or LinkedIn, only a verification token, much like a certificate chain of trust. We consider you validated because we trust the person that validated you. We did/do not store your LinkedIn data. It was simply a method to validate authenticity of a person. We could have taken the easy route, offering the platform freely with no verification. But free users receive the exact same platform as paid customers: same agent, features, codebase, and capabilities. If a free user acts maliciously, it can jeopardize the reputation of the platform for everyone. And with tens of millions of managed endpoints, including those that provide the only remote access to critical infrastructure, we cannot risk paid customer operations for the sake of anonymity in the free tier. That is mildly inconvenient for free users, but we simply cannot. The only cost of the free tier is that it cannot be anonymous. That is a small price to pay to maintain the security and continuity our customers demand. Ask any IT admin who has had an agent flagged because of someone else’s misuse, you’ll find they agree: “We’re paying you; our systems should work regardless of what free users do.” That’s a reasonable expectation, that the only real alternative if no more free. We have NO intention of going that route, in fact as our free offer just doubled again 100Ep->200Ep as of Feb. 4 '25, we expect it to grow, not go away. So What’s next? We knew LinkedIn would not be our long-term solution. It was a stopgap, one that gave us time to build something better. That’s why we’re currently transitioning to OnFido for identity verification (pending final testing). Like CLEAR, OnFido verifies identity independently, and Action1 never sees or stores the information you provide to them. If LinkedIn isn’t your preferred method, for example, if you keep LinkedIn for personal use, do not or refuse to have one, or any other reason, we’re happy to work with you. All current signs point to OnFido becoming our primary method, LinkedIn will serve as a fallback, and beyond that, our team is ready to help you find another reasonable path if those two are not acceptable, but they will have to verify identity by a real tangible and accurate method. Some users were mistakenly told that LinkedIn was the only way. That was incorrect, and we’ve addressed it internally as well as everywhere we could find it was misrepresented online. Our only goal is to verify that you’re a real person, with real intent to use the platform responsibly. Strong identity verification significantly reduces abuse. And if someone still manages to get through that will malicious intent, we can confidently explain that we upheld rigorous standards. We're a business. We give away a powerful platform for free, and we employ real people to support it, and those peoples jobs/paychecks depend on our company's success.. There have to be limits and guardrails. Identity verification is that guardrail. If you have any questions or concerns, I’m always happy to talk. Just reach out. Here or direct, PM me, send me contact, I will even take a call if you need it. you can locate me on LinkedIn and Reddit as well, we can direct chat it out there and get you helped in a manner we both agree to find acceptable. And let me know, anyone, if that leaves ANYTHING unclear.
  11. Though it often seems cliche to quote Orwell: “Nearly all children nowadays were horrible. What was worst of all was that by means of such organizations as the Spies, they were systematically turned into ungovernable little savages, and yet this produced in them no tendency whatever to rebel against the discipline of the Party. On the contrary, they adored the Party and everything connected with it.” — Part 1, Chapter 2 And while I agree that there have always been kids doing bad things, and to a certain degree developing self identity and discipline is a bumpy road for all of us. But the constantly streaming, camera connected to the internet, digitally addicted youth, have certainly raised the bar. Example: When I went to highschool, there was a length limit on pocket knives, and our school handbook stated "All firearms on school property have to be in a locked vehicle", was not uncommon at all to see someone who was coming from before school or headed to after school, hunting. I learned to dis/re assemble and clean a 12g pump shotgun in AG class! No one was ever shot, stabbed, and even in a fight if it got out of control others stepped in. We even had a coach that had boxing gloves / sparing gear, and would take to people that just felt they had to lay into one another, to the gym, and offer them the gloves to "just get it out so we can all get back to learning". Seldom to never did they even put the gloves on. Now days the kids intervening in the fight would just be cheering them on with 30 cell phones pointed at them, and the coach would be fired, most likely sued as well. So there is a generational difference, while not new, it is exponentially worse. And I am not sure who thought giving children unrestricted access to all the debauchery, corrupt ideology, and in general wrapping their entire existence up in the affairs of strangers, would end any different. Cell phones help overthrow governments, they will topple schools and homes like stacked playing cards. Once, when a child had questions, their circle of influence was small, keeping track of who supported them with their best interest in mind, was easier for educators, parents, and people that cared about them to manage. Now they are a search away from people telling them that whatever issue you are gong through, here are a thousand other people who feel the same, and are here to "help". IF that is "I want to kill all the people that are mean to me" to "I want to kill myself". That just could not happen pre internet/smartphone. And while laws may vary from country to country, district to district, one I feel is fairly universal is the types of content it is illegal to give children, such as pornographic, extreme violence, cult/extremist group recruitment, et alia... But it is completely acceptable to give them a device with access to all of it + a million things you never even dreamed possible. This guy, he knows whats up. And any humor you may find in this is directly proportional to the sadly true nature of it all. But... What they are being exposed to has an absolutely opposite effect of what biology intended, they are NOT learning things that benefit their species, they are participating in mindless exploitation than weakens their ability to carry their species into the future. We are starting to pay for this already, expect the next 35-50 years of electing leaders from this pool to be challenging. The people making it know they have the inability to control those impulses, so they turn the meter to max, and let it rip in the name of profit and attracting more of them. If you have nextflix go watch the social dilemma where they use a mock family to demonstrate what the actual minds (Google, facebook, etc engineers) behind a lot of the social phenomenon's development. And they tell you HOW these things were designed to do what they are doing to our youth (And a lot of adults)... It's criminal, it is lord of the flies with a billion kids stranded on an island in the internet. After watching see if you can get your school to approve a mass watching, invite the parents... That one line "Everyone is entitled to their own facts", SMDH
  12. It's a bleak outlook for sure. And I know the average parent is like "Yeah, he just dropped that, and it broke into 5 pieces, I'm not paying for it." I don't get it, even my kids did not get it while in school, it is one thing to fight for social acceptance, it is another entirely to lower your standards of decency to fit in. My youngest again when asked why he never brings friends to the house as we lived right next to the school. "Because everyone in my class only wants to smoke weed, do stupid stuff for likes, and if you are not friends on socials, you are not friends in real life." My heart goes out to all of you who have to deal with this day in day out, I honestly do not know how you maintain your sanity in all of it. I only contracted for schools, and I thought that was bad. Made my business support days and even the worst office user, seem like a cake walk.
  13. Yeah, as if schools are not hot-labs already! I get the school's frustration, but there have to be better ways than promoting the unsanitary and removing privacy. Hire bathroom monitors if you have to.
  14. So I saw this reading the news, and since schools are the place where kids are apparently doing this, I figured I would share in case others had not seen. Things like this tend to blow out of proportion fast, so... I am not sure why we tolerate the youth of today brazenly doing what they will, for the sake of a moment of social media recognition. In my youngest son's school the last year he was there, there was one of these where the goal was just "destroy school property" and i had to go have a couple rounds with a principal, because my son could not use bathroom facilities at school due to stalls not having doors, 2 of 5 toilets that worked, and missing sinks because they had literally been ripped off the wall so you could not even wash your hands. They told the kids "we are not putting them back until someone tells us who did it", which was a bit extreme for the kids that had nothing to do with it. Told them fixed by the end of the week or my next call was the local news. It was unsafe, undignified, and just plain gross. While it is NOT new that kids can be mischievous and destructive, the latter was a relative rarity pre-social media and streaming platforms. School tech also always gets more than its fair share of abuse, but wanton destruction is another matter. I cannot imagine people could not be seriously injured by device fires in a classroom, so if someone reports their chromebook went up in smoke, I would not take it as a chance occurrence without some investigation! https://www.tomshardware.com/laptops/chromebooks/a-new-tiktok-challenge-has-kids-attempting-to-short-circuit-school-issued-chromebooks
  15. Well that seems a heck of a lot easier, lol.
  16. Does rename of bootim.exe not just repair on an SFC? That would be my first concern, if not I would not rename it I would simply remove ALL permissions, and make admin the owner. bootim and WinRE are not the same thing, but they do look almost exactly the same. WinRE is a WIM boot image, reagentc /disable deactivates WinRE, the recovery environment WIM and XML files can be located by reagentc /info (If enabled) you can delete them too, but if you ever change your mind, you will need to pull them form install media to get it back. You can also remove the recovery partition and just absorb it into the drives other partitions if at the end. But you can nuke it none the less. IIRC bootim actually initiates as the computer is powering off, it is not "booting" to it, it only looks that way because or the similarities between it and WinRE. I *believe* it is launching it in lieu of an actual shutdown. So just keep in mind you are not tampering with one thing, you are actually tampering with two. tinkering at that level can cause future update issues, so in reality the best way to handle this is with policy. Let an unauthorized tinkering individual explain to HR why they are corrupting company systems unauthorized. Make it a potential resume generating event, the message will get around, and make examples of the people that do it. If that is simply not an option, I would go for a slightly different approach, disable WinRE (perfectly fine, not in any way essential to OS). And then a simple app/script/service to check every 100ms and kill any instance of bootim.exe found in active processes. In theory you could try applocker on it as well, or install sysmon from windows sysinternals, log process creation, tie a task to the event or a powershell||WMI event log monitor to the event. Just to prove it works fast, I would try sysmon first. Install, then configure sysmon with the following XML <Sysmon schemaversion="4.50"> <EventFiltering> <ProcessCreate onmatch="include"> <Image condition="end with">bootim.exe</Image> </ProcessCreate> </EventFiltering> </Sysmon> Subsequent event ID 1 in Microsoft-Windows-Sysmon/Operational should correspond to an instance of that binary being loaded. Right click that event and choose "Attach task to this event" have that task pop off "tskill bootim" Albeit none of this is tested it is off the top of my head, but it should work. You don't prevent them starting it, you immediately kill it when they do! The sysmon install/configure and the task exported as XML, can easily be scripted across a large endpoint count. Setup of the whole thing (including downloading sysmon) could be a single powershell script. I do not own a windows system on HW, only in virtual labs. But I would be curious to know if it worked. P.S. if I needed to do this non-hackish, a kernel driver would be best, because it could be intercepted pre-execution like an AV would, but I expect the "non-techie" implies not coding drivers any time soon. Good luck!
  17. Here if you need me, ask me anything. I am the same one that mans reddit, and a bunch of other outlets.
  18. Thanks all to those mentioning Action1, I patrol around online forums, helping where I can with Action1 and with things not Action1. I am not sales, I am the Field CTO, so I do not entertain pricing related discussions, but I can say we do have educational pricing models. And of course as mentioned, our first 200 endpoints are free, zero monetization, zero data scraping free patch management , so you really can just be up and using it in 5 minutes deciding for yourself if it is what you need. If there is anything I can assist with, reach out to me any time.
  19. You asked "So the question is, on which subnet should the actual DHCP server... sit" and the answer is that it is completely arbitrary as long as it is properly configured for each subnet / vlan / nic or you are condensing into a single supernet. Remember DHCP is not IP aware, it is subnet aware, Id est, broadcast domain aware. If they are in the same broadcast domain, they will have no problem racing to serve IPs to anyone asking; and that can get very messy. And a rogue DHCP server on your network will learn you fast NEVER do that again. Do you have a diagram?
  20. Does Get-WindowsUpdateLog provide further clues? I always factor in reloads to a fleet when doing version upgrades, some will just have strangeness not worth investigating.
  21. Curious if that was it or if it got resolved?
  22. Have you contacted sales to discuss Educational pricing, contact sales form a school address to get that started, or just ask a rep if you already have one? As well we have increased our free model now to 200 free endpoints and those stay free, so they will come of a purchase quantity if you need to scale past 200. So if you like Action1 but are favoring another comparable solution due to price, please let someone assist you with that If I can be of any assistance there just let me know.
  23. do a rsop (On the client), check user > Administrative Templates / Windows Components / File Explorer Check : Remove File Explorer’s default context menu
  24. Thank you for the mention there, and yes we are free for the first 100 endpoints. We are a patch management solution but we do have other features such as scripting & automation, reporting & alerting, etc. It is the latter you would want here, since it is highly extensible, you can create custom data sources out of anything you can script. If I were going at this, I would create a custom data source where I check the last modified time on the ntuser.dat file (User registry hive) for each profile on the system. This would be worlds faster than gathering windows events. Using logic like if this date is greater than the last date make the reference date this date, etc. Ending basically at the *newest* last time any user logged in. You could either store that date/time, or for more utility equate it to True/False by doing a comparison like is it > than x amount of days before current date. And put that into a custom attribute. Then create a report that displays computer name, and that attribute. You could then set an alert on that report based on the value being true/false. End result, any computer not logged into in X will generate an alert. Pretty simple to do and if you want to give it a go, just let me know, I would be happy to assist.
  25. Thanks there, yes we are completely free for the first 100, no feature or time limit. As for accessing the manager, I ssh to mine, I would never dream of putting it on a public IP, but with ngrok and an internal SSH server, I can port forward to anything I need to in a pinch. I use Yubikey to MFA (PW + Cert + Key) but the Google authenticator PAM module works great as well to get (PW + Cert + OTP) I experimented with a power automate workflow to send an email to up ngrok on command from an email, but in the end never really needed it, properly set up and patched SSH servers are pretty solid.
×
×
  • Create New...