This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

UPDATED - Computer Update Status - WanaCrypt (MS17-010) - v2

Import under "Windows Server Update Services Analytics."

Based on the KBs and Security Bulletin listed in this article from Microsoft:

https://support.microsoft.com/en-us/help/4013389/title

Hoping this helps someone out there make sure their environment doesn't get hit by the latest in exciting ransomware.

A sample LEM rule for identifying suspicious activity from WanaCrypt can be found here: WanaCrypt v1 Detection Rule

UPDATE: I worked with one of the Support guys, and he pointed out I had a couple problems with the query that resulted in some environments getting many, many bytes in their TempDB.  This has now been fixed, so download version 2 and see if it works better!

Computer Update Status - WanaCrypt (MS17-010) v2.xdq
Parents
  • Much better!  For whatever reason, I have 8 computers that have an unknown installation state for 26 patches (many of which are server-based patches) and these are Windows 10 computers...  So this adds about 200 extra entries, but it gets me pretty close to what I need to see.  Thanks!

Reply
  • Much better!  For whatever reason, I have 8 computers that have an unknown installation state for 26 patches (many of which are server-based patches) and these are Windows 10 computers...  So this adds about 200 extra entries, but it gets me pretty close to what I need to see.  Thanks!

Children
No Data