| + | 21-MAY-2016 21:46 | Payment Processing Server | Windows Server 2008 System Files | Modified | High | C:\Windows\shell.exe | 
    | | Attribute | Expected Value | Actual Value | 
|---|
 | Attributes | Archive | Hidden, Archive |  | Permissions | DACL: D:AI(A;ID;FA;;;SY)(A;ID;FA;;;BA)(A;ID;0x1200a9;;;BU)
                    Account SID: S-1-5-18
                    Account Name: NT AUTHORITY\SYSTEM
                    Type: Allow
                    Inherited: Yes
                    Inheritance: None
                    Rights: FullControl
                    Account SID: S-1-5-32-544
                    Account Name: BUILTIN\Administrators
                    Type: Allow
                    Inherited: Yes
                    Inheritance: None
                    Rights: FullControl
                    Account SID: S-1-5-32-545
                    Account Name: BUILTIN\Users
                    Type: Allow
                    Inherited: Yes
                    Inheritance: None
                    Rights: ReadAndExecute, Synchronize | DACL: D:(A;;FA;;;WD)(A;ID;FA;;;SY)(A;ID;FA;;;BA)(A;ID;0x1200a9;;;BU)
                    Account SID: S-1-1-0
                    Account Name: Everyone
                    Type: Allow
                    Inherited: No
                    Inheritance: None
                    Rights: FullControl
                    Account SID: S-1-5-18
                    Account Name: NT AUTHORITY\SYSTEM
                    Type: Allow
                    Inherited: Yes
                    Inheritance: None
                    Rights: FullControl
                    Account SID: S-1-5-32-544
                    Account Name: BUILTIN\Administrators
                    Type: Allow
                    Inherited: Yes
                    Inheritance: None
                    Rights: FullControl
                    Account SID: S-1-5-32-545
                    Account Name: BUILTIN\Users
                    Type: Allow
                    Inherited: Yes
                    Inheritance: None
                    Rights: ReadAndExecute, Synchronize | 
 | 
| + | 21-MAY-2016 21:46 | Payment Processing Server | Windows Server 2008 System Files | Modified | High | C:\Windows\system32\comms.sys | 
| | Attribute | Expected Value | Actual Value | 
|---|
 | Modified Time | 2015-06-07T19:56:00.0000000Z | 2016-05-21T20:46:04.3302659Z |  | Size | 38 | 127 |  | CRC | FC0C263E | FE4CA530 |  | Hash | 9B845F457388D9C34BB4F1C36C14B143FCEBD65FF034EC6F3C6CD41F632D5471 | C5369BFEB9367586342796BDAEDC6CE4A6E76616BE10BAB9402BD891392FF42D | 
 | 
| + | 21-MAY-2016 21:46 | Payment Processing Server | Windows Server 2008 System Files | Modified | High | C:\Windows\system32\ip_stack.dll | 
| | Attribute | Expected Value | Actual Value | 
|---|
 | Modified Time | 2015-06-07T19:56:00.0000000Z | 2016-05-21T20:46:04.3302659Z |  | Size | 38 | 127 |  | CRC | FC0C263E | FE4CA530 |  | Hash | 9B845F457388D9C34BB4F1C36C14B143FCEBD65FF034EC6F3C6CD41F632D5471 | C5369BFEB9367586342796BDAEDC6CE4A6E76616BE10BAB9402BD891392FF42D | 
 | 
| + | 21-MAY-2016 21:46 | Payment Processing Server | Windows Server 2008 System Files | Added | High | C:\Windows\system32\keylogger.sys | 
    | | Attribute | Expected Value | Actual Value | 
|---|
 | Created Time |  | 2016-05-21T20:46:04.2834658Z |  | Modified Time |  | 2016-05-21T20:46:04.2834658Z |  | Size |  | 41 |  | CRC |  | FD4BCF7E |  | Hash |  | 15AD402CE3528BA48C2F10CC0E9AD8E7B7C6E0426B77CC4A15F86CD394A200D9 |  | Owner |  | Account SID: S-1-5-32-544
                    Account Name: BUILTIN\Administrators |  | Primary Group |  | Account SID: S-1-5-21-305035777-899029998-720635935-513
                    Account Name: KVAERNER-NO\Domain Users |  | Attributes |  | Archive |  | Permissions |  | DACL: D:AI(A;ID;FA;;;SY)(A;ID;FA;;;BA)(A;ID;0x1200a9;;;BU)
                    Account SID: S-1-5-18
                    Account Name: NT AUTHORITY\SYSTEM
                    Type: Allow
                    Inherited: Yes
                    Inheritance: None
                    Rights: FullControl
                    Account SID: S-1-5-32-544
                    Account Name: BUILTIN\Administrators
                    Type: Allow
                    Inherited: Yes
                    Inheritance: None
                    Rights: FullControl
                    Account SID: S-1-5-32-545
                    Account Name: BUILTIN\Users
                    Type: Allow
                    Inherited: Yes
                    Inheritance: None
                    Rights: ReadAndExecute, Synchronize |  | Audit Rules |  | SACL: | 
 | 
| + | 21-MAY-2016 21:46 | Payment Processing Server | Windows Server 2008 System Files | Modified | High | C:\Windows\system32\logon.exe | 
| | Attribute | Expected Value | Actual Value | 
|---|
 | Modified Time | 2015-06-07T19:56:00.0000000Z | 2016-05-21T20:46:04.3458659Z |  | Size | 38 | 127 |  | CRC | FC0C263E | FE4CA530 |  | Hash | 9B845F457388D9C34BB4F1C36C14B143FCEBD65FF034EC6F3C6CD41F632D5471 | C5369BFEB9367586342796BDAEDC6CE4A6E76616BE10BAB9402BD891392FF42D |  | Attributes | Archive | ReadOnly, Archive | 
 | 
| + | 21-MAY-2016 21:46 | Payment Processing Server | Windows Server 2008 Network Files | Modified | Medium | C:\Windows\system32\drivers\etc\hosts | 
    | | Attribute | Expected Value | Actual Value | 
|---|
 | Modified Time | 2015-06-07T19:56:00.0000000Z | 2016-05-21T20:46:04.2834658Z |  | Size | 26 | 28 |  | CRC | FE16DFAE | FF18C403 |  | Hash | F0EF3092BE99D84879D21FF98A32EFCBD9BC27A901AB01E719B9386E005FFD18 | 4EE7C8230D51DFDF604045FCA3F3F17C87067C008314EA8CB2DF42ED1E0E1C87 |  | Permissions | DACL: D:AI(A;ID;FA;;;SY)(A;ID;FA;;;BA)(A;ID;0x1200a9;;;BU)
                    Account SID: S-1-5-18
                    Account Name: NT AUTHORITY\SYSTEM
                    Type: Allow
                    Inherited: Yes
                    Inheritance: None
                    Rights: FullControl
                    Account SID: S-1-5-32-544
                    Account Name: BUILTIN\Administrators
                    Type: Allow
                    Inherited: Yes
                    Inheritance: None
                    Rights: FullControl
                    Account SID: S-1-5-32-545
                    Account Name: BUILTIN\Users
                    Type: Allow
                    Inherited: Yes
                    Inheritance: None
                    Rights: ReadAndExecute, Synchronize | DACL: D:(A;;FA;;;WD)(A;ID;FA;;;SY)(A;ID;FA;;;BA)(A;ID;0x1200a9;;;BU)
                    Account SID: S-1-1-0
                    Account Name: Everyone
                    Type: Allow
                    Inherited: No
                    Inheritance: None
                    Rights: FullControl
                    Account SID: S-1-5-18
                    Account Name: NT AUTHORITY\SYSTEM
                    Type: Allow
                    Inherited: Yes
                    Inheritance: None
                    Rights: FullControl
                    Account SID: S-1-5-32-544
                    Account Name: BUILTIN\Administrators
                    Type: Allow
                    Inherited: Yes
                    Inheritance: None
                    Rights: FullControl
                    Account SID: S-1-5-32-545
                    Account Name: BUILTIN\Users
                    Type: Allow
                    Inherited: Yes
                    Inheritance: None
                    Rights: ReadAndExecute, Synchronize | 
 | 
| + | 21-MAY-2016 21:46 | File Server | Windows Server 2012 System Files | Modified | High | C:\Windows\system32\ip_stack.dll | 
| | Attribute | Expected Value | Actual Value | 
|---|
 | Modified Time | 2015-06-07T19:56:00.0000000Z | 2016-05-21T20:46:04.4238661Z |  | Size | 38 | 127 |  | CRC | FC0C263E | FE4CA530 |  | Hash | 9B845F457388D9C34BB4F1C36C14B143FCEBD65FF034EC6F3C6CD41F632D5471 | C5369BFEB9367586342796BDAEDC6CE4A6E76616BE10BAB9402BD891392FF42D |  | Attributes | Archive | Hidden, Archive | 
 | 
| + | 21-MAY-2016 21:46 | File Server | Windows Server 2012 Network Files | Modified | Medium | C:\Windows\system32\drivers\etc\hosts | 
    | | Attribute | Expected Value | Actual Value | 
|---|
 | Permissions | DACL: D:AI(A;ID;FA;;;SY)(A;ID;FA;;;BA)(A;ID;0x1200a9;;;BU)
                    Account SID: S-1-5-18
                    Account Name: NT AUTHORITY\SYSTEM
                    Type: Allow
                    Inherited: Yes
                    Inheritance: None
                    Rights: FullControl
                    Account SID: S-1-5-32-544
                    Account Name: BUILTIN\Administrators
                    Type: Allow
                    Inherited: Yes
                    Inheritance: None
                    Rights: FullControl
                    Account SID: S-1-5-32-545
                    Account Name: BUILTIN\Users
                    Type: Allow
                    Inherited: Yes
                    Inheritance: None
                    Rights: ReadAndExecute, Synchronize | DACL: D:(A;;FA;;;WD)(A;ID;FA;;;SY)(A;ID;FA;;;BA)(A;ID;0x1200a9;;;BU)
                    Account SID: S-1-1-0
                    Account Name: Everyone
                    Type: Allow
                    Inherited: No
                    Inheritance: None
                    Rights: FullControl
                    Account SID: S-1-5-18
                    Account Name: NT AUTHORITY\SYSTEM
                    Type: Allow
                    Inherited: Yes
                    Inheritance: None
                    Rights: FullControl
                    Account SID: S-1-5-32-544
                    Account Name: BUILTIN\Administrators
                    Type: Allow
                    Inherited: Yes
                    Inheritance: None
                    Rights: FullControl
                    Account SID: S-1-5-32-545
                    Account Name: BUILTIN\Users
                    Type: Allow
                    Inherited: Yes
                    Inheritance: None
                    Rights: ReadAndExecute, Synchronize | 
 |