; ----------------------------------------------------------------------
; PARSING COMPUTER POLICY
; Source file:  .\ash-windows\scm\Windows_8_1\machine_registry.pol

Computer
Software\Microsoft\Windows\CurrentVersion\Policies\CredUI
EnumerateAdministrators
DWORD:0

Computer
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoDriveTypeAutoRun
DWORD:255

Computer
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoWebServices
DWORD:1

Computer
Software\Microsoft\Windows\CurrentVersion\Policies\System
MSAOptional
DWORD:1

Computer
Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableAutomaticRestartSignOn
DWORD:1

Computer
SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
LocalAccountTokenFilterPolicy
DWORD:0

Computer
Software\Policies\Microsoft\EMET\Defaults
Firefox
SZ:*\Mozilla Firefox\firefox.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
LyncCommunicator
SZ:*\Microsoft Lync\communicator.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
IE
SZ:*\Internet Explorer\iexplore.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
jre6_javaws
SZ:*\Java\jre6\bin\javaws.exe -HeapSpray

Computer
Software\Policies\Microsoft\EMET\Defaults
WinRARGUI
SZ:*\WinRAR\winrar.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
ThunderbirdPluginContainer
SZ:*\Mozilla Thunderbird\plugin-container.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
WindowsLiveMail
SZ:*\Windows Live\Mail\wlmail.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
Winzip
SZ:*\WinZip\winzip32.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
GoogleTalk
SZ:*\Google\Google Talk\googletalk.exe -DEP -SEHOP

Computer
Software\Policies\Microsoft\EMET\Defaults
Pidgin
SZ:*\Pidgin\pidgin.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
jre7_javaws
SZ:*\Java\jre7\bin\javaws.exe -HeapSpray

Computer
Software\Policies\Microsoft\EMET\Defaults
VisioViewer
SZ:*\OFFICE1*\VPREVIEW.EXE

Computer
Software\Policies\Microsoft\EMET\Defaults
Picture Manager
SZ:*\OFFICE1*\OIS.EXE

Computer
Software\Policies\Microsoft\EMET\Defaults
7zFM
SZ:*\7-Zip\7zFM.exe -EAF

Computer
Software\Policies\Microsoft\EMET\Defaults
Access
SZ:*\OFFICE1*\MSACCESS.EXE

Computer
Software\Policies\Microsoft\EMET\Defaults
Publisher
SZ:*\OFFICE1*\MSPUB.EXE

Computer
Software\Policies\Microsoft\EMET\Defaults
Word
SZ:*\OFFICE1*\WINWORD.EXE

Computer
Software\Policies\Microsoft\EMET\Defaults
AcrobatReader
SZ:*\Adobe\Reader*\Reader\AcroRd32.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
jre7_javaw
SZ:*\Java\jre7\bin\javaw.exe -HeapSpray

Computer
Software\Policies\Microsoft\EMET\Defaults
jre6_javaw
SZ:*\Java\jre6\bin\javaw.exe -HeapSpray

Computer
Software\Policies\Microsoft\EMET\Defaults
Outlook
SZ:*\OFFICE1*\OUTLOOK.EXE

Computer
Software\Policies\Microsoft\EMET\Defaults
jre7_java
SZ:*\Java\jre7\bin\java.exe -HeapSpray

Computer
Software\Policies\Microsoft\EMET\Defaults
7z
SZ:*\7-Zip\7z.exe -EAF

Computer
Software\Policies\Microsoft\EMET\Defaults
QuickTimePlayer
SZ:*\QuickTime\QuickTimePlayer.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
PhotoGallery
SZ:*\Windows Live\Photo Gallery\WLXPhotoGallery.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
VLC
SZ:*\VideoLAN\VLC\vlc.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
Thunderbird
SZ:*\Mozilla Thunderbird\thunderbird.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
Photoshop
SZ:*\Adobe\Adobe Photoshop CS*\Photoshop.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
mIRC
SZ:*\mIRC\mirc.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
Safari
SZ:*\Safari\Safari.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
Winzip64
SZ:*\WinZip\winzip64.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
UnRAR
SZ:*\WinRAR\unrar.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
Winamp
SZ:*\Winamp\winamp.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
FirefoxPluginContainer
SZ:*\Mozilla Firefox\plugin-container.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
WinRARConsole
SZ:*\WinRAR\rar.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
RealConverter
SZ:*\Real\RealPlayer\realconverter.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
Chrome
SZ:*\Google\Chrome\Application\chrome.exe -SEHOP

Computer
Software\Policies\Microsoft\EMET\Defaults
7zGUI
SZ:*\7-Zip\7zG.exe -EAF

Computer
Software\Policies\Microsoft\EMET\Defaults
SkyDrive
SZ:*\SkyDrive\SkyDrive.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
RealPlayer
SZ:*\Real\RealPlayer\realplay.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
Skype
SZ:*\Skype\Phone\Skype.exe -EAF

Computer
Software\Policies\Microsoft\EMET\Defaults
Opera
SZ:*\Opera\opera.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
FoxitReader
SZ:*\Foxit Reader\Foxit Reader.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
WindowsMediaPlayer
SZ:*\Windows Media Player\wmplayer.exe -SEHOP -EAF -MandatoryASLR

Computer
Software\Policies\Microsoft\EMET\Defaults
LiveWriter
SZ:*\Windows Live\Writer\WindowsLiveWriter.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
iTunes
SZ:*\iTunes\iTunes.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
PPTViewer
SZ:*\OFFICE1*\PPTVIEW.EXE

Computer
Software\Policies\Microsoft\EMET\Defaults
Wordpad
SZ:*\Windows NT\Accessories\wordpad.exe

Computer
Software\Policies\Microsoft\EMET\Defaults
Visio
SZ:*\OFFICE1*\VISIO.EXE

Computer
Software\Policies\Microsoft\EMET\Defaults
Lync
SZ:*\OFFICE1*\LYNC.EXE

Computer
Software\Policies\Microsoft\EMET\Defaults
PowerPoint
SZ:*\OFFICE1*\POWERPNT.EXE

Computer
Software\Policies\Microsoft\EMET\Defaults
jre6_java
SZ:*\Java\jre6\bin\java.exe -HeapSpray

Computer
Software\Policies\Microsoft\EMET\Defaults
InfoPath
SZ:*\OFFICE1*\INFOPATH.EXE

Computer
Software\Policies\Microsoft\EMET\Defaults
Excel
SZ:*\OFFICE1*\EXCEL.EXE

Computer
Software\Policies\Microsoft\EMET\Defaults
Acrobat
SZ:*\Adobe\Acrobat*\Acrobat\Acrobat.exe

Computer
Software\Policies\Microsoft\EMET\SysSettings
SEHOP
DWORD:2

Computer
Software\Policies\Microsoft\EMET\SysSettings
DEP
DWORD:2

Computer
Software\Policies\Microsoft\EMET\SysSettings
ASLR
DWORD:3

Computer
Software\Policies\Microsoft\Power\PowerSettings\0e796bdb-100d-47d6-a2d5-f7d2daa51f51
DCSettingIndex
DWORD:1

Computer
Software\Policies\Microsoft\Power\PowerSettings\0e796bdb-100d-47d6-a2d5-f7d2daa51f51
ACSettingIndex
DWORD:1

Computer
Software\Policies\Microsoft\Windows NT\Printers
DisableWebPnPDownload
DWORD:1

Computer
Software\Policies\Microsoft\Windows NT\Printers
DisableWebPnPDownload
DWORD:1

Computer
Software\Policies\Microsoft\Windows NT\Printers
DisableHTTPPrinting
DWORD:1

Computer
Software\Policies\Microsoft\Windows NT\Rpc
RestrictRemoteClients
DWORD:1

Computer
Software\Policies\Microsoft\Windows NT\Rpc
EnableAuthEpResolution
DWORD:0

Computer
Software\Policies\Microsoft\Windows NT\Rpc
RestrictRemoteClients
DWORD:1

Computer
Software\Policies\Microsoft\Windows NT\Rpc
EnableAuthEpResolution
DWORD:0

Computer
Software\policies\Microsoft\Windows NT\Terminal Services
fUseMailto
DELETE

Computer
Software\policies\Microsoft\Windows NT\Terminal Services
fAllowToGetHelp
DWORD:0

Computer
Software\policies\Microsoft\Windows NT\Terminal Services
fAllowUnsolicitedFullControl
DELETE

Computer
Software\policies\Microsoft\Windows NT\Terminal Services
fAllowUnsolicited
DWORD:0

Computer
Software\policies\Microsoft\Windows NT\Terminal Services
fAllowFullControl
DELETE

Computer
Software\policies\Microsoft\Windows NT\Terminal Services
MaxTicketExpiry
DELETE

Computer
Software\policies\Microsoft\Windows NT\Terminal Services
MaxTicketExpiryUnits
DELETE

Computer
SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services
MinEncryptionLevel
DWORD:3

Computer
SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services
fPromptForPassword
DWORD:1

Computer
SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services
fDisableCdm
DWORD:1

Computer
SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services
DisablePasswordSaving
DWORD:1

Computer
SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services
MinEncryptionLevel
DWORD:3

Computer
Software\policies\Microsoft\Windows NT\Terminal Services\RAUnsolicit
*
DELETEALLVALUES

Computer
Software\Policies\Microsoft\Windows\EventLog\Application
MaxSize
DWORD:32768

Computer
Software\Policies\Microsoft\Windows\EventLog\Security
MaxSize
DWORD:196608

Computer
Software\Policies\Microsoft\Windows\EventLog\System
MaxSize
DWORD:32768

Computer
Software\Policies\Microsoft\Windows\Explorer
NoDataExecutionPrevention
DWORD:0

Computer
Software\Policies\Microsoft\Windows\Group Policy\{35378EAC-683F-11D2-A89A-00C04FBBCFA2}
NoGPOListChanges
DWORD:0

Computer
Software\Policies\Microsoft\Windows\Group Policy\{35378EAC-683F-11D2-A89A-00C04FBBCFA2}
NoBackgroundPolicy
DWORD:0

Computer
Software\Policies\Microsoft\Windows\Installer
AlwaysInstallElevated
DWORD:0

Computer
Software\Policies\Microsoft\Windows\Installer
AlwaysInstallElevated
DWORD:0

Computer
Software\Policies\Microsoft\Windows\Personalization
NoLockScreenCamera
DWORD:1

Computer
Software\Policies\Microsoft\Windows\Personalization
NoLockScreenSlideshow
DWORD:1

Computer
Software\Policies\Microsoft\Windows\System
DontEnumerateConnectedUsers
DWORD:1

Computer
Software\Policies\Microsoft\Windows\System
AllowDomainPINLogon
DWORD:0

Computer
Software\Policies\Microsoft\Windows\System
DontEnumerateConnectedUsers
DWORD:1

Computer
Software\Policies\Microsoft\Windows\System
EnumerateLocalUsers
DWORD:0

Computer
Software\Policies\Microsoft\Windows\System
DontDisplayNetworkSelectionUI
DWORD:1

Computer
Software\Policies\Microsoft\Windows\System
EnableSmartScreen
DWORD:2

Computer
Software\Policies\Microsoft\Windows\System
AllowDomainPINLogon
DWORD:0

Computer
SOFTWARE\Policies\Microsoft\Windows\Windows Search
AllowIndexingEncryptedStoresOrItems
DWORD:0

Computer
Software\Policies\Microsoft\Windows\WindowsUpdate\AU
RescheduleWaitTimeEnabled
DWORD:1

Computer
Software\Policies\Microsoft\Windows\WindowsUpdate\AU
AUOptions
DWORD:3

Computer
Software\Policies\Microsoft\Windows\WindowsUpdate\AU
NoAutoUpdate
DWORD:0

Computer
Software\Policies\Microsoft\Windows\WindowsUpdate\AU
RescheduleWaitTime
DWORD:1

Computer
Software\Policies\Microsoft\Windows\WindowsUpdate\AU
ScheduledInstallTime
DWORD:3

Computer
Software\Policies\Microsoft\Windows\WindowsUpdate\AU
NoAUAsDefaultShutdownOption
DWORD:0

Computer
Software\Policies\Microsoft\Windows\WindowsUpdate\AU
NoAUShutdownOption
DWORD:0

Computer
Software\Policies\Microsoft\Windows\WindowsUpdate\AU
NoAutoRebootWithLoggedOnUsers
DWORD:0

Computer
Software\Policies\Microsoft\Windows\WindowsUpdate\AU
ScheduledInstallDay
DWORD:0

Computer
Software\Policies\Microsoft\Windows\WinRM\Client
AllowDigest
DWORD:0

Computer
Software\Policies\Microsoft\Windows\WinRM\Client
AllowDigest
DWORD:0

Computer
Software\Policies\Microsoft\Windows\WinRM\Client
AllowUnencryptedTraffic
DWORD:0

Computer
Software\Policies\Microsoft\Windows\WinRM\Client
AllowBasic
DWORD:0

Computer
Software\Policies\Microsoft\Windows\WinRM\Client
AllowUnencryptedTraffic
DWORD:0

Computer
Software\Policies\Microsoft\Windows\WinRM\Client
AllowUnencryptedTraffic
DWORD:0

Computer
Software\Policies\Microsoft\Windows\WinRM\Service
AllowUnencryptedTraffic
DWORD:0

Computer
Software\Policies\Microsoft\Windows\WinRM\Service
AllowUnencryptedTraffic
DWORD:0

Computer
Software\Policies\Microsoft\Windows\WinRM\Service
AllowUnencryptedTraffic
DWORD:0

Computer
Software\Policies\Microsoft\Windows\WinRM\Service
DisableRunAs
DWORD:1

Computer
Software\Policies\Microsoft\Windows\WinRM\Service
DisableRunAs
DWORD:1

Computer
Software\Policies\Microsoft\Windows\WinRM\Service
AllowBasic
DWORD:0

Computer
Software\Policies\Microsoft\WindowsFirewall\DomainProfile
AllowLocalPolicyMerge
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\DomainProfile
DefaultOutboundAction
DWORD:0

Computer
Software\Policies\Microsoft\WindowsFirewall\DomainProfile
DisableNotifications
DWORD:0

Computer
Software\Policies\Microsoft\WindowsFirewall\DomainProfile
EnableFirewall
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\DomainProfile
AllowLocalIPsecPolicyMerge
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\DomainProfile
DisableUnicastResponsesToMulticastBroadcast
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\DomainProfile
DefaultInboundAction
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\DomainProfile\Logging
LogDroppedPackets
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\DomainProfile\Logging
LogFilePath
SZ:%SYSTEMROOT%\System32\logfiles\firewall\domainfw.log

Computer
Software\Policies\Microsoft\WindowsFirewall\DomainProfile\Logging
LogFilePath
SZ:%SYSTEMROOT%\System32\logfiles\firewall\domainfw.log

Computer
Software\Policies\Microsoft\WindowsFirewall\DomainProfile\Logging
LogFileSize
DWORD:16384

Computer
Software\Policies\Microsoft\WindowsFirewall\DomainProfile\Logging
LogSuccessfulConnections
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\DomainProfile\Logging
LogFileSize
DWORD:16384

Computer
Software\Policies\Microsoft\WindowsFirewall\DomainProfile\Logging
LogSuccessfulConnections
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\DomainProfile\Logging
LogDroppedPackets
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\PrivateProfile
EnableFirewall
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\PrivateProfile
AllowLocalIPsecPolicyMerge
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\PrivateProfile
AllowLocalPolicyMerge
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\PrivateProfile
DisableNotifications
DWORD:0

Computer
Software\Policies\Microsoft\WindowsFirewall\PrivateProfile
DefaultInboundAction
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\PrivateProfile
DisableUnicastResponsesToMulticastBroadcast
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\PrivateProfile
DefaultOutboundAction
DWORD:0

Computer
Software\Policies\Microsoft\WindowsFirewall\PrivateProfile\Logging
LogSuccessfulConnections
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\PrivateProfile\Logging
LogDroppedPackets
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\PrivateProfile\Logging
LogDroppedPackets
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\PrivateProfile\Logging
LogFilePath
SZ:%SYSTEMROOT%\System32\logfiles\firewall\privatefw.log

Computer
Software\Policies\Microsoft\WindowsFirewall\PrivateProfile\Logging
LogFileSize
DWORD:16384

Computer
Software\Policies\Microsoft\WindowsFirewall\PrivateProfile\Logging
LogFileSize
DWORD:16384

Computer
Software\Policies\Microsoft\WindowsFirewall\PrivateProfile\Logging
LogFilePath
SZ:%SYSTEMROOT%\System32\logfiles\firewall\privatefw.log

Computer
Software\Policies\Microsoft\WindowsFirewall\PrivateProfile\Logging
LogSuccessfulConnections
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\PublicProfile
DefaultOutboundAction
DWORD:0

Computer
Software\Policies\Microsoft\WindowsFirewall\PublicProfile
EnableFirewall
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\PublicProfile
DisableNotifications
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\PublicProfile
DisableUnicastResponsesToMulticastBroadcast
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\PublicProfile
AllowLocalIPsecPolicyMerge
DWORD:0

Computer
Software\Policies\Microsoft\WindowsFirewall\PublicProfile
AllowLocalPolicyMerge
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\PublicProfile
DefaultInboundAction
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\PublicProfile\Logging
LogFileSize
DWORD:16384

Computer
Software\Policies\Microsoft\WindowsFirewall\PublicProfile\Logging
LogDroppedPackets
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\PublicProfile\Logging
LogDroppedPackets
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\PublicProfile\Logging
LogFilePath
SZ:%SYSTEMROOT%\System32\logfiles\firewall\publicfw.log

Computer
Software\Policies\Microsoft\WindowsFirewall\PublicProfile\Logging
LogFileSize
DWORD:16384

Computer
Software\Policies\Microsoft\WindowsFirewall\PublicProfile\Logging
LogSuccessfulConnections
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\PublicProfile\Logging
LogSuccessfulConnections
DWORD:1

Computer
Software\Policies\Microsoft\WindowsFirewall\PublicProfile\Logging
LogFilePath
SZ:%SYSTEMROOT%\System32\logfiles\firewall\publicfw.log

Computer
SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest
UseLogonCredential
DWORD:0

Computer
System\CurrentControlSet\Policies\EarlyLaunch
DriverLoadPolicy
DWORD:3

; PARSING COMPLETED.
; ----------------------------------------------------------------------

