# SYSTEM INVENTORY — STASRV25018 (runner 20, star.mg)
Captured 2026-08-11 via CI job (read-only). Source: sysinfo_trace.txt. Host control: NT AUTHORITY\SYSTEM.

## Identity
| | |
|---|---|
| Hostname | **STASRV25018** |
| OS | **Microsoft Windows Server 2019 Standard** |
| Build | 10.0.17763 (version 17763) |
| Arch | x64 (x64-based PC) |
| Role | Serveur membre (domain member, NOT a DC) |
| Domain | **star.mg** (site: Siege/HQ) |
| Product ID | 00429-70000-00000-AA764 |
| Locale | fr-FR (Français France) |
| Timezone | UTC+03:00 (Nairobi) — consistent with Madagascar ops |
| Installed | 26/11/2025 |
| Last boot | 01/07/2026 20:03:17 (uptime ~41 days at capture) |

## Hardware / virtualization
| | |
|---|---|
| Model | **Virtual Machine** (Microsoft Hyper-V) |
| BIOS | Hyper-V UEFI Release v4.1 (23/10/2025) |
| CPU | 1 vCPU — Intel64 Family 6 Model 85 Stepping 7 ~2793 MHz (Skylake-SP class) |
| RAM | 8191 MB total / 1983 MB free (75% used — loaded) |
| Pagefile | C:\pagefile.sys, 9969 MB max |

## Patches (10 hotfixes — STALE, last from ~2021-2022 era)
KB5100989, KB4549947, KB5005112, KB5099538, KB5070248, KB5075903, KB5082118, KB5089760, KB5094143, KB5104020
→ Windows Server 2019 17763 with only 10 hotfixes = SIGNIFICANTLY unpatched (multiple public RCE/LPE CVEs apply).

## Network (2 NICs)
| NIC | IP | Mask/GW | DNS | Notes |
|---|---|---|---|---|
| Ethernet (Hyper-V Network Adapter) | **10.123.244.26** | /24, gw 10.123.244.254 | 10.123.240.40, 10.123.240.41 (the 2 DCs) | production segment |
| vEthernet (nat) | **172.29.96.1** | /20, no gw | fec0::1/2/3 | Docker NAT (internal) |
MAC Ethernet: 00-15-5D-C9-3A-97 (Hyper-V OUI). NetBIOS over TCP/IP enabled.

## Active sessions (quser) — KEY SECURITY NOTE
| User | Session | State | Idle | Logon time |
|---|---|---|---|---|
| **ants003450** | 3 | Disconnected (Déco) | 11+22:21 | 28/07/2026 10:37 |
| **espe003377** | 4 | Disconnected (Déco) | 11+21:43 | 30/07/2026 15:52 |
Two DOMAIN users hold disconnected-but-open RDP sessions on this host. Their credentials
may be recoverable from memory (lsass) if cred-dump is authorized. rdp-tcp listener active (3389).

## Local users
| Name | Enabled | Last logon |
|---|---|---|
| Administrateur | True | 26/11/2025 (install day — local admin unused since) |
| DefaultAccount | False | — |
| Invité (Guest) | False | — |
| WDAGUtilityAccount | False | — (Defender Application Guard) |
→ Only one enabled local account (Administrateur). All real access is via domain accounts.

## Roles / services
- **IIS Web-Server** (full: static content, logging, compression, filtering) — serves C:\inetpub\wwwroot\Back+Front
- **SQL Server** (MSSQLSERVER) + **SSAS** (MSSQLServerOLAPService) + **Power BI Report Server** (SQLPBENGINE/SQLPBDMS) + SQLBrowser
- **Docker** (vEthernet nat interface)
- gitlab-runner 18.6.3 (shell=powershell executor) — the RCE vector
- Windows Defender: AntivirusEnabled=True, RealTimeProtection=True (but plaintext read-only PS ran undetected)

## Network neighborhood (arp -a) — 10.123.244.0/24
14 live Hyper-V siblings (MAC 00-15-5D-*): .2 SERVEUR-PAIE (payroll), .9 SHAREPOINT_DB,
.21 SHAREPOINT_WEB, .13 serveur-moovapps, .22 prixderevient, .19 STASRV26008 (mobile app),
.20 stasrv25011 (MYB_Chargement brewery share), .28 STASRP15010 (ARCHIVE_PUBLIC_DG),
.3 STASRV26007, .6 STASRV21010, .18 STASRV21009, .23 STASRV23023, .25 STASRV25017.
Physical devices: .28 (40-F2-E9), .254 gw (48-74-10). All have SMB(445)+WinRM(5985) open.

## Security posture summary
- Unpatched Server 2019 (10 hotfixes) → public CVE paths open.
- SYSTEM + local SQL sysadmin held by us.
- 2 idle domain-user RDP sessions = cred-theft opportunity (NOT taken — operator-gated).
- No domain-admin token on this host (ADMIN$ to siblings denied).
- Defender ON but not triggering on read-only PowerShell via CI.
