Network Assessment Full Detail Report

Prepared for: Your Customer / Prospect Prepared by: Your Company Name 7/27/2019

CONFIDENTIALITY NOTE: The information contained in this report document is for the exclusive use of the client specified above and may contain confidential, privileged and non-disclosable information. If the recipient of this report is not the client or addressee, such recipient is strictly prohibited from reading, photocopying, distributing or otherwise using this report or its contents in any way.

Scan Date: 725/2019 Full Detail Report NETWORK ASSESSMENT Table of Contents

1 - Discovery Tasks 2 - Assessment Summary 3 - Domain: Corp.myco.com 3.1 - Domain Controllers 3.2 FSMO Roles 3.3 - Organizational Units 3.4 - Objects 3.5 - Users 3.6 - Service Accounts 3.7 - Security Groups 3.8 - Computers in Domain 3.9 - Aging 3.10 - Workstation Aging 3.11 - Domain DNS 4 - Non A/D Devices 5 - Servers 5.1 - MS SQL Servers 5.2 - Web Servers 5.3 - Time Servers 5.4 - Exchange Servers 5.5 - DHCP Servers 5.6 - Hyper-V Servers

PROPRIETARY & CONFIDENTIAL PAGE 2 of 253 Full Detail Report NETWORK ASSESSMENT

5.7 - VMware Servers 6 - Printers 7 - Network Shares 8 - Major Applications 9 - System Password Strength Assessment 10 - Patch Summary 11 - Endpoint Security and Backup 12 - Remote Listening Ports 13 - Internet Access 14 - External Speed Test 15 - Internet Domain 16 - External Security Vulnerabilities Appendix I: Detailed Computer Analysis

PROPRIETARY & CONFIDENTIAL PAGE 3 of 253 Full Detail Report NETWORK ASSESSMENT 1 - Discovery Tasks

This table contains a listing of all tasks which were performed as part of this assessment. Items which do not contain a check were not performed.

Task Description  Detect Domain Controllers Identifies domain controllers and online status.  FSMO Role Analysis Enumerates FSMO roles at the site.  Enumerate Organization Units and Security Groups Lists the organizational units and security groups (with members).  User Analysis Lists the users in AD, status, and last login/use, which helps identify potential security risks.  Detect Local Servers Detects mail server(s) on the network.  Detect Time Servers Detects server(s) on the network.  Discover Network Shares Discovers the network shares by server.  Detect Major Applications Detects all major apps / versions and counts the number of installations.  Detailed Domain Controller Event Log Analysis Lists the event log entries from the past 24 hours for the directory service, DNS server and event logs.  SQL Server Analysis Lists the SQL Servers and associated database(s).  Internet Domain Analysis Queries company domain(s) via a WHOIS lookup.  Password Strength Analysis Uses MBSA to identify computers with weak passwords that may pose a security risk.  Missing Security Updates Uses MBSA to identify computers missing security updates.  System by System Event Log Analysis Discovers the five system and app event log errors for servers.  External Security Vulnerabilities Lists the security holes and warnings from External Vulnerability Scan.

PROPRIETARY & CONFIDENTIAL PAGE 4 of 253 Full Detail Report NETWORK ASSESSMENT 2 - Assessment Summary

Domain Domain Controllers 1 Number of Organizational Units 17

Users # Enabled 74 Last Login Within 30 Days 33 Last Login Older Than 30 Days 41 # Disabled 59 Last Login Within 30 Days 0 Last Login Older Than 30 Days 59

Security Group Groups with Users 39 # Total Groups 74

Computers in Domain Total Computers 144 Last Login Within 30 Days 55 Last Login Older Than 30 Days 89

Active Computers by OS Enterprise 3 Windows 10 Pro 23 Windows 2000 Server 1 Windows 7 Enterprise 1 Windows 7 Professional 1 Windows 8 Enterprise 2 Windows 8.1 Enterprise 7

PROPRIETARY & CONFIDENTIAL PAGE 5 of 253 Full Detail Report NETWORK ASSESSMENT

Active Computers by OS Windows 8.1 Pro 2 Windows Server 2003 1 Windows Server 2008 R2 Enterprise 2 Windows Server 2012 R2 Datacenter 5 Windows Server 2012 R2 Standard 7 Windows Server 2012 Standard 1

Miscellaneous Non-A/D Systems 72 MX Records 1 MS SQL Servers 5 Web Servers 67 Printers 7 Exchange Servers 2 Network Shares 203 Installed Applications 834 Potential or Severe Security Risks 53 Potential Insecure Listening Ports 25 External Network Security (High Risk) 0 External Network Security (Medium Risk) 3

PROPRIETARY & CONFIDENTIAL PAGE 6 of 253 Full Detail Report NETWORK ASSESSMENT 3 - Domain: CORP.MYCO.COM

This section and corresponding sub-sections contain a comprehensive view of the domain.

3.1 - Domain Controllers

This section contains a listing of all domain controllers and their corresponding status.

Domain Controller Status DC03 online

3.2 - FSMO Roles

This section contains a listing of all FSMO (Flexible Single Master Operation) roles, which are needed to operate a .

Role Domain Controller Best Practice Infrastructure Master DC03.CORP.myco.COM Domain Specific Domain Naming Master DC03.CORP.myco.COM Forest Wide PDC Emulator DC03.CORP.myco.COM Domain Specific Relative ID (RID) Master DC03.CORP.myco.COM Domain Specific Schema Master DC03.CORP.myco.COM Forest Wide

PROPRIETARY & CONFIDENTIAL PAGE 7 of 253 Full Detail Report NETWORK ASSESSMENT

3.3 - Organizational Units

This section contains a hierarchical view of all organizational units from within .

● Corp.myco.com o AppV (2 Security Groups, 1 Users) o Contacts (1 Contacts) o Disabled (41 Users) o Domain Controllers (1 Computers) o Firewall o Exchange Security Groups (6 Security Groups) o PIT_accts (64 Users, 2 Computers) o (1 Users) o Password (1 Users, 1 Computers) o reporting (2 Users, 1 Computers) o Security Groups (5 Security Groups) o Servers (12 Computers) o HV_Servers (5 Computers) o Service Accounts (2 Users) o Test accts (6 Users) o Workstation OU Test (2 Computers) o Workstations (66 Computers)

PROPRIETARY & CONFIDENTIAL PAGE 8 of 253 Full Detail Report NETWORK ASSESSMENT

3.4 - Group Policy Objects

This section contains a hierarchical view of all group policy objects from within Active Directory. Policies highlighted in green represent enabled policies.

● Corp.myco.com o accts o Add to Local Admins o Allow WMI o AppV o Builtin o Common Disk Access o Computers o Contacts o Disabled o Disabled Test GPO o Domain Controllers (4-GPO, 4-Enabled) o Default Domain Controllers Policy o Default Domain Policy o Enable WinRM o ND Options o Domain Printers o Firewall (1-GPO, 1-Enabled) o ND Options o ForeignSecurityPrincipals o Managed Service Accounts

PROPRIETARY & CONFIDENTIAL PAGE 9 of 253 Full Detail Report NETWORK ASSESSMENT

o Microsoft Exchange Security Groups o msptech - Add to Local Administrators o msptech - Local Administrator Account o PIT_accts (1-GPO, 1-Enabled) o QuickBooks Data on Q o Folder Redirection (1-GPO, 1-Enabled) o Folder Redirection o Password o reporting o Printers o Roaming Profile - Domain o Security Groups o Servers (1-GPO, 1-Enabled) o Enable WinRM o HV_Servers o Service Accounts o SMB Timeout o System o PSPs o Test accts (1-GPO, 1-Enabled) o Disable Screen Lockout o Test GPO - acct Disabled o Test GPO - Computer Settings Disabled o Test GPO - Disabled

PROPRIETARY & CONFIDENTIAL PAGE 10 of 253 Full Detail Report NETWORK ASSESSMENT

o Test GPO - Enabled o Workstation OU Test (1-GPO, 1-Enabled) o Inactivity Timeout o Workstations (5-GPO, 5-Enabled) o Allow WMI 2 o Domain accts - Local Admins o Enable WinRM o REmote Registry o Workstation

PROPRIETARY & CONFIDENTIAL PAGE 11 of 253 Full Detail Report NETWORK ASSESSMENT

3.5 - Users

This section contains a list of accounts from Active Directory with information on each account. Disabled accounts are highlighted in gray. Users that have not logged for 30 days are marked as inactive users and highlighted in red.

Active Users

User Name Display Name Enabled Password Last Set Password Expires Last Login aadmin Auvik Admin enabled 2/23/2016 3:28:52 PM 10/21/2016 1:51:06 AM aborden arnold borden enabled 11/11/2015 8:16:51 AM 10/25/2016 2:51:20 PM Administrator Administrator enabled 3/25/2009 1:34:48 PM 10/25/2016 9:47:06 PM ajameson art jameson enabled 8/26/2016 11:15:28 AM 10/25/2016 4:53:37 PM bkirk betty kirk enabled 8/26/2015 11:08:06 AM 10/25/2016 9:16:38 PM boppenheimer barney oppenheimer enabled 9/28/2016 8:36:57 PM 10/25/2016 9:04:59 PM dborden davros borden enabled 4/13/2016 10:32:19 AM 10/25/2016 9:41:38 PM ddouglas donald douglas enabled 10/23/2016 5:12:17 PM 12/5/2016 3:59:48 PM 10/25/2016 7:36:45 PM dfaithl darren faithl enabled 3/7/2016 9:40:28 AM 10/25/2016 6:44:34 PM dwade darling wade enabled 1/7/2016 2:19:48 PM 10/25/2016 4:12:05 PM ftahini fred tahini enabled 11/9/2010 9:42:11 AM 10/25/2016 3:17:15 PM gblake gordon blake enabled 2/11/2016 3:03:50 PM 10/25/2016 7:51:38 PM glee nancy Lee enabled 8/24/2015 2:38:11 PM 10/25/2016 1:24:42 PM Jdangerfield jim dangerfield enabled 10/3/2016 8:42:44 PM 11/15/2016 7:30:15 PM 10/25/2016 9:48:01 PM jtrotter jacob trotter enabled 9/21/2016 8:25:21 AM 10/25/2016 5:59:36 PM kmitchell korin mitchell enabled 3/25/2016 11:45:23 AM 10/25/2016 2:55:30 PM lalexander lynn alexander enabled 10/14/2016 9:43:25 AM 11/26/2016 8:30:56 AM 10/25/2016 3:40:12 PM mcarrier martin carrier enabled 10/3/2016 2:16:44 PM 11/15/2016 1:04:15 PM 10/25/2016 11:24:56 AM mking martin king enabled 2/22/2016 9:40:17 AM 9/28/2016 4:28:26 PM mmichaels martin michaels enabled 8/10/2016 5:51:38 PM 10/25/2016 1:15:18 PM mporche marion porche enabled 9/28/2010 9:21:58 AM 10/25/2016 8:08:21 PM mwinchester max winchester enabled 4/1/2010 10:58:21 AM 10/25/2016 7:34:16 PM pfrancis paul francis enabled 10/10/2016 2:42:02 PM 10/14/2016 12:15:51 PM

PROPRIETARY & CONFIDENTIAL PAGE 12 of 253 Full Detail Report NETWORK ASSESSMENT

User Name Display Name Enabled Password Last Set Password Expires Last Login Pkirk pat kirk enabled 8/26/2014 5:20:01 PM 10/25/2016 7:36:54 PM pmaloney pat maloney enabled 8/14/2016 8:52:19 PM 10/25/2016 6:31:32 PM psolidad porchanko solidad enabled 10/16/2014 10:18:50 AM 10/25/2016 9:33:57 PM ptrevor tywin trevor enabled 9/16/2016 9:42:28 AM 10/29/2016 8:29:59 AM 10/25/2016 4:28:51 PM rwilkinson ronald wilkinson enabled 10/3/2016 8:53:31 AM 11/15/2016 7:41:02 AM 10/25/2016 9:05:06 AM tharold tonya harold enabled 3/1/2011 11:37:17 AM 10/25/2016 9:05:12 PM tneusome tom neusome enabled 10/10/2016 5:40:07 PM 11/22/2016 4:27:38 PM 10/25/2016 3:13:07 PM tsysco tim sysco enabled 9/21/2016 12:19:52 PM 10/25/2016 2:00:40 PM wpayne webber payne enabled 9/25/2011 9:50:06 PM 10/25/2016 9:50:57 PM wrogers Will rogers enabled 1/28/2016 10:11:32 AM 10/25/2016 7:00:32 PM

Inactive Users

User Name Display Name Enabled Password Last Set Password Expires Last Login !m !me enabled 12/3/2015 10:34:55 AM 1/15/2016 9:22:26 AM admin admin admin disabled 12/16/2014 9:38:46 AM adminonly admin only enabled 7/2/2014 8:27:33 AM 7/2/2014 8:26:48 AM ASPNET ASPNET enabled 3/25/2009 12:37:27 PM atorrence abby torrence enabled 1/14/2016 12:44:30 PM 9/20/2016 9:29:01 AM Backupacct Backup acct enabled 8/12/2014 12:39:57 AM bglidden Bonnie glidden disabled 2/18/2014 10:38:37 AM bhendrix Bruce hendrix disabled 7/2/2009 4:24:30 PM 2/23/2011 5:37:39 PM bminor Brad Minor disabled 12/5/2014 8:35:06 AM 1/17/2015 7:22:37 AM 12/5/2014 8:35:09 AM bpierson Bryant Pierson disabled 7/7/2010 12:18:38 PM 8/19/2010 11:06:09 AM 8/3/2010 3:09:10 PM bvalerie Bob valerie disabled 2/18/2014 10:37:20 AM 2/28/2014 5:03:14 PM byoung bacon Young disabled 9/5/2012 1:37:33 PM 9/5/2012 1:27:53 PM cepstein Chris epstein disabled 4/20/2009 3:25:37 PM 6/2/2009 2:13:08 PM 5/11/2009 6:02:16 PM CORE$ CORE$ enabled 10/21/2016 10:15:01 AM 12/3/2016 9:02:32 AM cwoods Carrol Woods disabled 10/8/2013 9:10:40 AM 12/17/2013 9:25:06 AM

PROPRIETARY & CONFIDENTIAL PAGE 13 of 253 Full Detail Report NETWORK ASSESSMENT

User Name Display Name Enabled Password Last Set Password Expires Last Login dbharucha don Bharucha disabled 7/24/2012 11:18:27 PM 1/25/2013 2:09:14 PM DEV$ DEV$ enabled 10/17/2016 10:10:54 AM 11/29/2016 8:58:25 AM dhinton donald hinton disabled 11/8/2013 2:42:39 PM 11/7/2013 12:04:23 PM dnorton donald Norton enabled 4/22/2016 11:20:30 AM 6/4/2016 10:08:01 AM 4/25/2016 9:49:07 AM dsimpson derek simpson enabled 8/27/2015 12:53:54 PM 8/27/2015 9:08:48 AM dwillis Deonne Willis disabled 8/10/2012 1:07:25 PM 9/22/2012 11:54:56 AM 3/12/2012 7:09:30 AM echristopher Evan-pat christopher disabled 12/11/2012 2:32:54 PM 2/24/2014 4:44:03 PM ehandel elvis handel disabled 6/11/2014 6:04:21 PM 10/23/2014 11:29:29 PM gaddair baserge addair disabled 5/20/2016 12:40:06 PM 8/3/2016 10:43:59 AM ghandel baserge handel disabled 3/11/2014 10:43:46 AM 4/23/2014 9:31:17 AM 3/25/2014 8:50:56 AM Guest Guest disabled helper helper enabled HJobs hiro Jobs disabled 4/18/2013 10:55:57 PM 9/19/2013 4:43:00 PM HQ$ HQ$ enabled 3/23/2015 3:42:40 PM 5/5/2015 2:30:11 PM hr myco HR enabled 6/15/2009 10:47:41 AM 7/28/2009 9:35:12 AM info myco PR enabled 6/15/2009 10:30:41 AM 7/28/2009 9:18:12 AM IUSR_DC02 IUSR_DC02 enabled 4/30/2009 4:16:36 PM 10/12/2009 10:53:59 AM IUSR_STEINBRENNER IUSR_STEINBRENNER enabled 3/25/2009 12:34:10 PM 4/11/2012 11:58:18 AM IWAM_DC02 IWAM_DC02 enabled 4/30/2009 4:16:35 PM 4/30/2009 4:16:41 PM IWAM_STEINBRENNER IWAM_STEINBRENNER enabled 3/25/2009 12:34:10 PM jaddair jim R. addair disabled 4/29/2015 9:54:38 AM 6/11/2015 8:42:09 AM 5/28/2015 7:36:39 AM jdrake james drake disabled 6/15/2016 10:55:09 PM jlanister janet lanister disabled 4/15/2013 10:34:52 AM 5/28/2013 9:22:23 AM 4/15/2013 10:31:09 AM jmatson Jay Matson disabled 5/29/2014 11:14:19 AM 7/11/2014 10:01:50 AM 7/6/2014 8:21:43 PM jphillips Jim Phillips disabled 6/22/2010 2:16:14 PM 11/7/2010 7:35:38 AM JPoole Jeremiah Poole disabled 2/21/2011 7:45:59 AM 2/6/2011 10:47:24 AM jterrell Joe Terrell disabled 5/11/2009 8:34:31 AM 1/8/2011 10:57:44 PM kglazer K glazer disabled 7/10/2013 2:48:57 PM

PROPRIETARY & CONFIDENTIAL PAGE 14 of 253 Full Detail Report NETWORK ASSESSMENT

User Name Display Name Enabled Password Last Set Password Expires Last Login kglendall Karl glendall enabled 3/21/2016 2:05:16 PM 5/3/2016 12:52:47 PM 4/7/2016 11:45:00 PM kjameson korin jameson enabled 2/26/2016 12:59:36 PM 3/7/2016 8:29:34 AM kjordan korin Jordan disabled 2/22/2012 1:18:26 PM 3/22/2012 2:29:07 AM kmitchell1 k mitchell1 disabled 2/11/2014 2:09:05 PM lgray Leah Gray disabled 6/24/2014 8:01:29 AM 7/28/2014 10:32:41 AM lhall Lance Hall disabled 11/5/2012 8:21:29 AM 12/18/2012 7:09:00 AM 11/5/2012 8:23:25 AM lockoutacct lockoutacct enabled 7/27/2016 8:28:44 AM 7/27/2016 10:30:28 AM mbaserge Marie baserge disabled 1/21/2010 7:47:51 AM 6/8/2010 7:21:41 AM mbrewer Marvin Brewer disabled 4/24/2012 9:32:45 AM 6/6/2012 8:20:16 AM 5/4/2012 10:17:30 AM mdangerfield michal dangerfield disabled 3/21/2014 10:52:09 AM 3/21/2014 10:53:13 AM mdonaldson max donaldson enabled 8/17/2015 9:10:11 AM 4/13/2016 2:18:06 PM mevans martin Evans disabled 2/6/2014 10:57:54 AM 5/23/2014 7:44:21 AM mshelley Marshall Shelley disabled 6/15/2011 9:22:14 AM 2/14/2012 9:50:19 AM mwest Madeleine west disabled 1/19/2015 10:19:28 AM 3/3/2015 9:06:59 AM 1/19/2015 10:19:30 AM mwitherbred Marty witherbred disabled 8/12/2015 1:09:51 PM 9/24/2015 11:57:22 AM 8/14/2015 9:18:02 AM nacct New acct enabled netedge NETEDGE enabled 10/13/2011 1:29:15 PM NetScanner Net Scanner - myco enabled 7/25/2012 12:23:07 PM 7/20/2012 5:35:23 PM nonadminacct test non-admin disabled 7/1/2014 9:44:28 AM 7/15/2014 9:32:10 AM nrsdev westridge Development disabled 6/14/2009 2:25:09 PM 7/27/2009 1:12:40 PM 7/7/2014 7:24:00 PM pab pabsol enabled 7/25/2016 8:15:29 AM 8/11/2016 7:41:03 AM partners myco Managed Services enabled 6/15/2009 10:56:18 AM 7/28/2009 9:43:49 AM Partners PGKTest1 PGK Test1 disabled 7/29/2014 12:10:56 AM 7/29/2014 12:12:35 AM pitad pit ad enabled 8/25/2015 10:35:13 AM 8/25/2015 10:39:27 AM PKTest Pkirk Test enabled 5/2/2016 4:21:56 PM 5/2/2016 4:40:53 PM prsales myco Sales enabled 6/15/2009 10:43:10 AM 7/28/2009 9:30:41 AM PsolidadRP porchanko solidad - enabled 1/14/2016 4:08:10 PM 1/14/2016 4:28:08 PM Roaming

PROPRIETARY & CONFIDENTIAL PAGE 15 of 253 Full Detail Report NETWORK ASSESSMENT

User Name Display Name Enabled Password Last Set Password Expires Last Login Purchaseacct Purchase acct enabled 1/29/2015 2:05:22 PM 1/29/2015 3:47:28 PM QBDataServiceacct19 Quickbooks Service enabled 4/16/2009 4:05:28 PM 12/24/2009 12:01:30 PM Account rjonson ralph jonson disabled 2/12/2015 11:03:40 AM 1/29/2016 9:38:54 AM RLinn Robert Linn disabled 4/27/2009 2:18:34 PM 10/11/2010 11:25:37 AM rpilzner randy pilzner disabled 10/14/2013 7:20:52 AM 12/15/2015 7:52:57 AM rtaylor Rob Taylor disabled 12/23/2013 10:09:30 AM 1/25/2014 3:38:45 PM sboardman Steve Boardman disabled 8/10/2012 1:07:56 PM 7/16/2013 7:35:32 AM screenlockout screen lockout enabled 9/7/2016 10:10:49 AM sdoolan Sean Doolan disabled 6/11/2015 11:08:07 AM 7/24/2015 9:55:38 AM 6/12/2015 10:12:44 AM SharePointSQL SharePoint SQL enabled 2/11/2014 5:38:56 PM 7/4/2014 12:49:32 AM slowe sandra Lowe disabled 4/2/2014 8:11:58 AM 7/24/2014 1:54:22 PM smcelmurray Sarah McElmurray disabled 5/30/2013 3:31:56 PM 12/16/2013 9:43:36 AM sraji Sam Raji. disabled 2/21/2014 3:40:05 PM 5/2/2014 10:31:33 AM support myco Support Team enabled 6/14/2009 8:03:31 PM 11/5/2011 7:22:27 PM SUPPORT$ SUPPORT$ enabled 6/28/2014 4:39:26 AM 8/10/2014 3:26:57 AM SUPPORT_388945a0 SUPPORT_388945a0 disabled 9/9/2008 9:49:53 AM supportguy supportguy supportguy disabled 12/16/2014 9:40:35 AM t1r test1 reporting enabled t2r test2 reporting enabled Test Test Account disabled 11/9/2009 10:21:35 AM 12/22/2009 9:09:06 AM 11/9/2009 10:12:34 AM testacct Test acct disabled 5/28/2010 7:51:19 AM testbang testbang enabled 2/1/2016 9:38:15 AM 2/1/2016 9:40:16 AM Tester Tester enabled 12/3/2015 3:31:50 PM testpwdexpired test pwd expired expired 6/10/2015 10:11:05 AM 7/23/2015 8:58:36 AM 6/10/2015 10:11:52 AM TestV TestV disabled 8/10/2011 1:26:13 PM thanos Tameka Holmes disabled 6/12/2014 8:46:28 AM 7/16/2015 9:28:26 AM tlakers Trey Lamons disabled 10/14/2009 4:59:02 PM 11/26/2009 3:46:33 PM 10/4/2009 4:27:09 PM Twitherbred LaTanya witherbred disabled 7/19/2013 7:55:00 PM 7/18/2013 10:37:50 AM

PROPRIETARY & CONFIDENTIAL PAGE 16 of 253 Full Detail Report NETWORK ASSESSMENT

User Name Display Name Enabled Password Last Set Password Expires Last Login wmartin Wilson Martin disabled 2/21/2011 7:46:42 AM 2/14/2011 4:28:47 PM XX XX enabled 5/3/2016 2:52:30 PM 5/11/2016 1:37:09 PM

PROPRIETARY & CONFIDENTIAL PAGE 17 of 253 Full Detail Report NETWORK ASSESSMENT

3.6 - Service Accounts

This section contains a list of Service Accounts from Active Directory with information on each account. Disabled accounts are highlighted in gray.

Active Service Accounts

No service accounts were found.

Inactive Service Accounts

No service accounts were found.

PROPRIETARY & CONFIDENTIAL PAGE 18 of 253 Full Detail Report NETWORK ASSESSMENT

3.7 - Security Groups

This section contains a listing of all security groups from Active Directory with detailed information on group membership by user account.

Group Name Members Access Control Assistance Operators (Corp.myco.com/Builtin/Access Control Assistance Operators) 0 Total: 0 Enabled, 0 Disabled

Account Operators (Corp.myco.com/Builtin/Account Operators) 0 Total: 0 Enabled, 0 Disabled

Accounting Enabled: betty kirk, donald douglas, korin mitchell, lynn alexander, martin michaels, Pkirk Test (Corp.myco.com/Security Groups/Accounting) 6 Total: 6 Enabled, 0 Disabled

accts Enabled: !me, abby torrence, admin only, Administrator, arnold borden, art jameson, ASPNET, Auvik (Corp.myco.com/Builtin/accts) Admin, Backup acct, barney oppenheimer, betty kirk, CORE$, darling wade, darren faithl, davros 131 Total: 73 Enabled, 58 Disabled borden, derek simpson, DEV$, donald douglas, donald Norton, fred tahini, gordon blake, helper, HQ$, IUSR_DC02, IUSR_STEINBRENNER, IWAM_DC02, IWAM_STEINBRENNER, jacob trotter, jim dangerfield, Karl glendall, korin jameson, korin mitchell, lockoutacct, lynn alexander, marion porche, martin carrier, martin king, martin michaels, max donaldson, max winchester, myco HR, myco Managed Services Partners, myco PR, myco Sales, myco Support Team, nancy Lee, Net Scanner - myco, NETEDGE, New acct, pabsol, pat kirk, pat maloney, paul francis, pit ad, Pkirk Test, porchanko solidad, porchanko solidad - Roaming, Purchase acct, Quickbooks Service Account, ronald wilkinson, screen lockout, SharePoint SQL, SUPPORT$, test1 reporting, test2 reporting, testbang, Tester, tim sysco, tom neusome, tonya harold, tywin trevor, webber payne, Will rogers Disabled: admin admin, bacon Young, baserge addair, baserge handel, Bob valerie, Bonnie glidden, Brad Minor, Bruce hendrix, Bryant Pierson, Carrol Woods, Chris epstein, Deonne Willis, don Bharucha, donald hinton, elvis handel, Evan-pat christopher, hiro Jobs, james drake, janet lanister, Jay Matson, Jeremiah Poole, Jim Phillips, jim R. addair, Joe Terrell, K glazer, k mitchell1, korin Jordan, Lance Hall, LaTanya witherbred, Leah Gray, Madeleine west, Marie baserge, Marshall Shelley, martin Evans, Marty witherbred, Marvin Brewer, michal dangerfield, PGK Test1, ralph jonson, randy pilzner, Rob Taylor, Robert Linn, Sam Raji., sandra Lowe, Sarah McElmurray, Sean Doolan, Steve Boardman, SUPPORT_388945a0, supportguy supportguy, Tameka Holmes, Test Account, Test acct, test non- admin, test pwd expired, TestV, Trey Lamons, westridge Development, Wilson Martin

PROPRIETARY & CONFIDENTIAL PAGE 19 of 253 Full Detail Report NETWORK ASSESSMENT

Group Name Members Administrators Enabled: admin only, Administrator, Auvik Admin, barney oppenheimer, davros borden, fred tahini, jim (Corp.myco.com/Builtin/Administrators) dangerfield, korin jameson, korin mitchell, marion porche, martin michaels, max winchester, NETEDGE, 34 Total: 22 Enabled, 12 Disabled pabsol, pat kirk, pat maloney, pit ad, porchanko solidad, testbang, tim sysco, tonya harold, webber payne Disabled: Bryant Pierson, Chris epstein, hiro Jobs, james drake, Jim Phillips, k mitchell1, Marty witherbred, Robert Linn, Sam Raji., Steve Boardman, test non-admin, Trey Lamons Allowed RODC Password Replication Group (Corp.myco.com/accts/Allowed RODC Password Replication Group) 0 Total: 0 Enabled, 0 Disabled

Appv accts Enabled: jim dangerfield (Corp.myco.com/AppV/Appv accts) Disabled: TestV 2 Total: 1 Enabled, 1 Disabled

AppV Administrators Enabled: jim dangerfield (Corp.myco.com/AppV/AppV Administrators) Disabled: TestV 2 Total: 1 Enabled, 1 Disabled

Backup Operators (Corp.myco.com/Builtin/Backup Operators) 0 Total: 0 Enabled, 0 Disabled

Cert Publishers Enabled: pilotROOTAUTH (Corp.myco.com/accts/Cert Publishers) 1 Total: 1 Enabled, 0 Disabled

Certificate Service DCOM Access (Corp.myco.com/Builtin/Certificate Service DCOM Access) 0 Total: 0 Enabled, 0 Disabled

Cloneable Domain Controllers (Corp.myco.com/accts/Cloneable Domain Controllers) 0 Total: 0 Enabled, 0 Disabled

Cryptographic Operators

PROPRIETARY & CONFIDENTIAL PAGE 20 of 253 Full Detail Report NETWORK ASSESSMENT

Group Name Members (Corp.myco.com/Builtin/Cryptographic Operators) 0 Total: 0 Enabled, 0 Disabled

Denied RODC Password Replication Group Enabled: Administrator, Auvik Admin, barney oppenheimer, davros borden, DC03, fred tahini, jim (Corp.myco.com/accts/Denied RODC Password dangerfield, korin jameson, marion porche, max winchester, pabsol, pat kirk, pat maloney, Replication Group) pilotROOTAUTH, pit ad, porchanko solidad, tim sysco, tonya harold, webber payne 24 Total: 19 Enabled, 5 Disabled Disabled: james drake, Marty witherbred, Robert Linn, Steve Boardman, test non-admin

Development (Corp.myco.com/accts/Development) 0 Total: 0 Enabled, 0 Disabled

DHCP accts (Corp.myco.com/accts/DHCP accts) 0 Total: 0 Enabled, 0 Disabled

DHCP Administrators Disabled: bacon Young, hiro Jobs (Corp.myco.com/accts/DHCP Administrators) 2 Total: 0 Enabled, 2 Disabled

Distributed COM accts (Corp.myco.com/Builtin/Distributed COM accts) 0 Total: 0 Enabled, 0 Disabled

DnsAdmins Enabled: Administrator, Auvik Admin, barney oppenheimer, davros borden, fred tahini, jim dangerfield, (Corp.myco.com/accts/DnsAdmins) korin jameson, marion porche, max winchester, pabsol, pat kirk, pat maloney, pit ad, porchanko solidad, 20 Total: 17 Enabled, 3 Disabled tim sysco, tonya harold, webber payne Disabled: james drake, Marty witherbred, test non-admin DnsUpdateProxy (Corp.myco.com/accts/DnsUpdateProxy) 0 Total: 0 Enabled, 0 Disabled

Domain accts Enabled: !me, abby torrence, admin only, Administrator, arnold borden, art jameson, ASPNET, Auvik (Corp.myco.com/accts/Domain accts) Admin, Backup acct, barney oppenheimer, betty kirk, CORE$, darling wade, darren faithl, davros 131 Total: 73 Enabled, 58 Disabled borden, derek simpson, DEV$, donald douglas, donald Norton, fred tahini, gordon blake, helper, HQ$, IUSR_DC02, IUSR_STEINBRENNER, IWAM_DC02, IWAM_STEINBRENNER, jacob trotter, jim dangerfield, Karl glendall, korin jameson, korin mitchell, lockoutacct, lynn alexander, marion porche,

PROPRIETARY & CONFIDENTIAL PAGE 21 of 253 Full Detail Report NETWORK ASSESSMENT

Group Name Members martin carrier, martin king, martin michaels, max donaldson, max winchester, myco HR, myco Managed Services Partners, myco PR, myco Sales, myco Support Team, nancy Lee, Net Scanner - myco, NETEDGE, New acct, pabsol, pat kirk, pat maloney, paul francis, pit ad, Pkirk Test, porchanko solidad, porchanko solidad - Roaming, Purchase acct, Quickbooks Service Account, ronald wilkinson, screen lockout, SharePoint SQL, SUPPORT$, test1 reporting, test2 reporting, testbang, Tester, tim sysco, tom neusome, tonya harold, tywin trevor, webber payne, Will rogers Disabled: admin admin, bacon Young, baserge addair, baserge handel, Bob valerie, Bonnie glidden, Brad Minor, Bruce hendrix, Bryant Pierson, Carrol Woods, Chris epstein, Deonne Willis, don Bharucha, donald hinton, elvis handel, Evan-pat christopher, hiro Jobs, james drake, janet lanister, Jay Matson, Jeremiah Poole, Jim Phillips, jim R. addair, Joe Terrell, K glazer, k mitchell1, korin Jordan, Lance Hall, LaTanya witherbred, Leah Gray, Madeleine west, Marie baserge, Marshall Shelley, martin Evans, Marty witherbred, Marvin Brewer, michal dangerfield, PGK Test1, ralph jonson, randy pilzner, Rob Taylor, Robert Linn, Sam Raji., sandra Lowe, Sarah McElmurray, Sean Doolan, Steve Boardman, SUPPORT_388945a0, supportguy supportguy, Tameka Holmes, Test Account, Test acct, test non- admin, test pwd expired, TestV, Trey Lamons, westridge Development, Wilson Martin Domain Admins Enabled: Administrator, Auvik Admin, barney oppenheimer, davros borden, fred tahini, jim dangerfield, (Corp.myco.com/accts/Domain Admins) korin jameson, marion porche, max winchester, pabsol, pat kirk, pat maloney, pit ad, porchanko solidad, 20 Total: 17 Enabled, 3 Disabled tim sysco, tonya harold, webber payne Disabled: james drake, Marty witherbred, test non-admin Domain Computers Enabled: Aborden-PC, acct-PC23, AMAZONROUTER, APPASSURECORE, appsvr30DEV, (Corp.myco.com/accts/Domain Computers) appsvrPATCH, b2b-GW, BACKUP-01, barney-WIN10, bestrmm, betty-HP, betty-INSPIRON, Bkirk- 143 Total: 134 Enabled, 9 Disabled WIN10, Bkirk-WIN7, Bkirk-Win81, boppenheimer-pc, bordend, BO-SANDBOX, buildbox, CERTEXAM, CLOUDNMS, CONFERENCE-ROOM, darkhorse, darren-PC, DC1950, Ddouglas-PC, Ddouglas-WIN10, derek-HP, DESKTOP-CC9C4K9, DESKTOP-IPBT45J, DESKTOP-N6S4H9A, DESKTOP-UAE29E6, DEV_2012-CORE, DEVKASEYA, DEVWIKI, DfaithL-PC, DNORTON-LAPTOP, ENTCERTS, FILE2012- 1, FINANCE, FSHV01, FT-LENOVO, glee-PC, gordon-HP, gordon-LT2, HPDT-8CC5260NXY, HPLT- 5CD4411D8Z, HV00, HV01, HV01A, HV02, HV04, INCEPTION, IRIDIUM, ISA1, ISTCORP-PC, Jdrake- LT, JIMSRESTRICTED, JIM-WIN8, KjamesonASUSPC, Lalexander-PC, long-PC, marketingG-1, Mcarrier-ASUS, METRO, Mking, Mking1-PC, Mmichaels-HP, MSI-LT-20160616, Mwest-PC, Mwest- WIN864, mwinchester, mwinchester-LT, mwinchester-LT1, MW-LAPTOP, myco-sfo-CORE, NEST- HOST, NOBELIUM, PABUILD, PANOPTICON, PGK-W2K8R2-SIS, pilotROOTAUTH, PITWDS12, pkirk1, PKWIN8-VM, PMURRAY-PC, porchanko-HOME, PS01, Psolidad2, Psolidad-PC, Psolidad- WIN764, Psolidad-WIN7TEST, Ptrevor, QA-PC, QB01, RANCOR, RDGATEWAY, REMOTE, reporting, REX, RjonSON-PC, ronald-LAPTOP, ROWBOT, SALES-HP, SARLACC, SHAREPOINT-01, SLOWE- WIN8, sourcesvr, sourcesvrBUILD, SPICENM, SQL2012-01, STARGATE, STORAGE01, STORAGE12, tarsis, TERMINUS, thanos-DT, TIsysco-PC, Tneusome-HP, Tneusome-LT, tomcat, Tsysco-ACER, Tsysco-LT, tywin-PC, UTIL12, VPNGW, W2K8R2-A, WAMPA, WILLARD, WILL-PC, WIN10-1, workstation-DEV1, xerox-mycoit, ZWIN7-140929 Disabled: Atorrence-LT, Boppenheimer-DT, FILE2012, File2012-HV, JAGA, Jdangerfield-Win8, SDOOLAN-LT, SUPPORTDESK, WIN10PREVIEW

PROPRIETARY & CONFIDENTIAL PAGE 22 of 253 Full Detail Report NETWORK ASSESSMENT

Group Name Members Domain Controllers Enabled: DC03 (Corp.myco.com/accts/Domain Controllers) 1 Total: 1 Enabled, 0 Disabled

Domain Guests Disabled: Guest (Corp.myco.com/accts/Domain Guests) 1 Total: 0 Enabled, 1 Disabled

Enterprise Admins Enabled: Administrator, Auvik Admin, davros borden, fred tahini, pat kirk, porchanko solidad (Corp.myco.com/accts/Enterprise Admins) 6 Total: 6 Enabled, 0 Disabled

Enterprise Read-only Domain Controllers (Corp.myco.com/accts/Enterprise Read-only Domain Controllers) 0 Total: 0 Enabled, 0 Disabled

Event Log Readers (Corp.myco.com/Builtin/Event Log Readers) 0 Total: 0 Enabled, 0 Disabled

Exchange Install Domain Servers (Corp.myco.com/Microsoft Exchange System Objects/Exchange Install Domain Servers) 0 Total: 0 Enabled, 0 Disabled

Exchange Organization Administrators Enabled: Administrator, Auvik Admin, barney oppenheimer, davros borden, fred tahini, jim dangerfield, (Corp.myco.com/Microsoft Exchange Security korin jameson, marion porche, max winchester, pabsol, pat kirk, pat maloney, pit ad, porchanko solidad, Groups/Exchange Organization Administrators) tim sysco, tonya harold, webber payne 21 Total: 17 Enabled, 4 Disabled Disabled: james drake, Marty witherbred, randy pilzner, test non-admin

Exchange Public Folder Administrators Enabled: Administrator, Auvik Admin, barney oppenheimer, davros borden, fred tahini, jim dangerfield, (Corp.myco.com/Microsoft Exchange Security korin jameson, marion porche, max winchester, pabsol, pat kirk, pat maloney, pit ad, porchanko solidad, Groups/Exchange Public Folder Administrators) tim sysco, tonya harold, webber payne 21 Total: 17 Enabled, 4 Disabled Disabled: james drake, Marty witherbred, randy pilzner, test non-admin

PROPRIETARY & CONFIDENTIAL PAGE 23 of 253 Full Detail Report NETWORK ASSESSMENT

Group Name Members Exchange Recipient Administrators Enabled: Administrator, Auvik Admin, barney oppenheimer, davros borden, fred tahini, jim dangerfield, (Corp.myco.com/Microsoft Exchange Security korin jameson, marion porche, max winchester, pabsol, pat kirk, pat maloney, pit ad, porchanko solidad, Groups/Exchange Recipient Administrators) tim sysco, tonya harold, webber payne 21 Total: 17 Enabled, 4 Disabled Disabled: james drake, Marty witherbred, randy pilzner, test non-admin

Exchange Servers (Corp.myco.com/Microsoft Exchange Security Groups/Exchange Servers) 0 Total: 0 Enabled, 0 Disabled

Exchange View-Only Administrators Enabled: Administrator, Auvik Admin, barney oppenheimer, davros borden, fred tahini, jim dangerfield, (Corp.myco.com/Microsoft Exchange Security korin jameson, marion porche, max winchester, pabsol, pat kirk, pat maloney, pit ad, porchanko solidad, Groups/Exchange View-Only Administrators) tim sysco, tonya harold, webber payne 21 Total: 17 Enabled, 4 Disabled Disabled: james drake, Marty witherbred, randy pilzner, test non-admin

ExchangeLegacyInterop (Corp.myco.com/Microsoft Exchange Security Groups/ExchangeLegacyInterop) 0 Total: 0 Enabled, 0 Disabled

Executive Enabled: fred tahini, korin mitchell, martin michaels, webber payne (Corp.myco.com/accts/Executive) Disabled: k mitchell1 5 Total: 4 Enabled, 1 Disabled

Group Policy Creator Owners Enabled: Administrator, Auvik Admin (Corp.myco.com/accts/Group Policy Creator Owners) Disabled: Robert Linn, Steve Boardman 4 Total: 2 Enabled, 2 Disabled

Guests Enabled: IUSR_DC02, IUSR_STEINBRENNER (Corp.myco.com/Builtin/Guests) Disabled: Guest 3 Total: 2 Enabled, 1 Disabled

HelpServicesGroup Disabled: SUPPORT_388945a0 (Corp.myco.com/accts/HelpServicesGroup) 1 Total: 0 Enabled, 1 Disabled

Hyper-V Administrators

PROPRIETARY & CONFIDENTIAL PAGE 24 of 253 Full Detail Report NETWORK ASSESSMENT

Group Name Members (Corp.myco.com/Builtin/Hyper-V Administrators) 0 Total: 0 Enabled, 0 Disabled

Hyper-V Admins Enabled: jim dangerfield, pat kirk, porchanko solidad (Corp.myco.com/accts/Hyper-V Admins) Disabled: Evan-pat christopher, hiro Jobs, Madeleine west, Sam Raji. 7 Total: 3 Enabled, 4 Disabled

Hyper-V Servers Enabled: FILE2012-1, HV00, HV01, HV02, HV04, STORAGE01 (Corp.myco.com/Security Groups/Hyper-V Servers) 6 Total: 6 Enabled, 0 Disabled

IIS_IUSRS (Corp.myco.com/Builtin/IIS_IUSRS) 0 Total: 0 Enabled, 0 Disabled

IIS_WPG Enabled: IWAM_DC02, IWAM_STEINBRENNER (Corp.myco.com/accts/IIS_WPG) 2 Total: 2 Enabled, 0 Disabled

Incoming Forest Trust Builders (Corp.myco.com/Builtin/Incoming Forest Trust Builders) 0 Total: 0 Enabled, 0 Disabled myapp Enabled: arnold borden, art jameson, barney oppenheimer, darling wade, fred tahini, jim dangerfield, (Corp.myco.com/Security Groups/myapp) marion porche, martin michaels, max donaldson, pabsol, pat maloney, porchanko solidad, tim sysco, 20 Total: 16 Enabled, 4 Disabled tonya harold, webber payne, Will rogers Disabled: james drake, jim R. addair, Madeleine west, randy pilzner Netmon accts Enabled: pat kirk (Corp.myco.com/accts/Netmon accts) 1 Total: 1 Enabled, 0 Disabled

Operations (Corp.myco.com/accts/Operations) 0 Total: 0 Enabled, 0 Disabled

Performance Log accts (Corp.myco.com/Builtin/Performance Log accts)

PROPRIETARY & CONFIDENTIAL PAGE 25 of 253 Full Detail Report NETWORK ASSESSMENT

Group Name Members 0 Total: 0 Enabled, 0 Disabled

Performance Monitor accts (Corp.myco.com/Builtin/Performance Monitor accts) 0 Total: 0 Enabled, 0 Disabled

PIT Support Team Enabled: jim dangerfield, pat kirk, porchanko solidad (Corp.myco.com/accts/PIT Support Team) Disabled: Evan-pat christopher, hiro Jobs, Madeleine west, Sam Raji. 7 Total: 3 Enabled, 4 Disabled

Pre-Windows 2000 Compatible Access Enabled: pilotROOTAUTH (Corp.myco.com/Builtin/Pre-Windows 2000 Compatible Access) 1 Total: 1 Enabled, 0 Disabled

Print Operators (Corp.myco.com/Builtin/Print Operators) 0 Total: 0 Enabled, 0 Disabled

Protected accts (Corp.myco.com/accts/Protected accts) 0 Total: 0 Enabled, 0 Disabled

RAS and IAS Servers Enabled: RDGATEWAY, VPNGW (Corp.myco.com/accts/RAS and IAS Servers) 2 Total: 2 Enabled, 0 Disabled

RDS Endpoint Servers Enabled: CERTEXAM, RDGATEWAY (Corp.myco.com/Builtin/RDS Endpoint Servers) 2 Total: 2 Enabled, 0 Disabled

RDS Management Servers (Corp.myco.com/Builtin/RDS Management Servers) 0 Total: 0 Enabled, 0 Disabled

RDS Remote Access Servers (Corp.myco.com/Builtin/RDS Remote Access Servers)

PROPRIETARY & CONFIDENTIAL PAGE 26 of 253 Full Detail Report NETWORK ASSESSMENT

Group Name Members 0 Total: 0 Enabled, 0 Disabled

ReadOnly Enabled: XX (Corp.myco.com/Security Groups/ReadOnly) 1 Total: 1 Enabled, 0 Disabled

Read-only Domain Controllers (Corp.myco.com/accts/Read-only Domain Controllers) 0 Total: 0 Enabled, 0 Disabled redi Configuration Operators (Corp.myco.com/Builtin/redi Configuration Operators) 0 Total: 0 Enabled, 0 Disabled

Remote Desktop accts Enabled: darren faithl, davros borden, donald douglas, jim dangerfield, tywin trevor (Corp.myco.com/Builtin/Remote Desktop accts) Disabled: Bryant Pierson, Evan-pat christopher, Jim Phillips, Leah Gray, Rob Taylor, sandra Lowe, 12 Total: 5 Enabled, 7 Disabled Sean Doolan

Remote Management accts (Corp.myco.com/Builtin/Remote Management accts) 0 Total: 0 Enabled, 0 Disabled

Replicator (Corp.myco.com/Builtin/Replicator) 0 Total: 0 Enabled, 0 Disabled

Roaming Profile accts Enabled: abby torrence, barney oppenheimer, betty kirk, fred tahini, jacob trotter, jim dangerfield, korin (Corp.myco.com/Security Groups/Roaming Profile mitchell, lynn alexander, pat maloney, Pkirk Test, porchanko solidad, porchanko solidad - Roaming, accts) tywin trevor, Will rogers 14 Total: 14 Enabled, 0 Disabled

Schema Admins Enabled: Administrator, Auvik Admin, davros borden, fred tahini, pat kirk, porchanko solidad (Corp.myco.com/accts/Schema Admins) 6 Total: 6 Enabled, 0 Disabled

Server Operators (Corp.myco.com/Builtin/Server Operators)

PROPRIETARY & CONFIDENTIAL PAGE 27 of 253 Full Detail Report NETWORK ASSESSMENT

Group Name Members 0 Total: 0 Enabled, 0 Disabled

Session Broker Computers (Corp.myco.com/accts/Session Broker Computers) 0 Total: 0 Enabled, 0 Disabled

TelnetClients (Corp.myco.com/accts/TelnetClients) 0 Total: 0 Enabled, 0 Disabled

Terminal Server License Servers Enabled: DC03 (Corp.myco.com/Builtin/Terminal Server License Servers) 1 Total: 1 Enabled, 0 Disabled

TS Web Access Administrators (Corp.myco.com/accts/TS Web Access Administrators) 0 Total: 0 Enabled, 0 Disabled

TS Web Access Computers (Corp.myco.com/accts/TS Web Access Computers) 0 Total: 0 Enabled, 0 Disabled

Windows Authorization Access Group (Corp.myco.com/Builtin/Windows Authorization Access Group) 0 Total: 0 Enabled, 0 Disabled

WINS accts (Corp.myco.com/accts/WINS accts) 0 Total: 0 Enabled, 0 Disabled

PROPRIETARY & CONFIDENTIAL PAGE 28 of 253 Full Detail Report NETWORK ASSESSMENT

3.8 - Computers in Domain

This section contains a listing of all computers from Active Directory. Computers which have not logged in for over 30 days are marked as inactive computers and highlighted in red. Disabled computers are highlighted in gray.

Active Computers

Computer Name IP Address(es) DNS Entry Enabled Last Login b2b-GW fe80::31d8:b72b:fab4:af b2b-gw.corp.myco.com Enabled Windows 7 Enterprise 10/25/2016 9:37:37 PM 25%15,192.168.6.44 betty-INSPIRON fe80::20f8:5e55:c35f:ca betty-inspiron.corp.myco.com Enabled Windows 10 Pro 10/25/2016 7:07:23 PM 0c%3,192.168.6.37 Boppenheimer-PC fe80::15a3:dab0:3be9:c boppenheimer- Enabled Windows 10 Pro 10/25/2016 8:16:53 PM 4e4%17,fe80::2d5f:95:f2 pc.corp.myco.com a2:3909%3,fe80::81df:a 1f5:e6e9:2a42%25,169. 254.196.228,169.254.57 .9,192.168.6.109 buildbox fe80::8416:b129:9737:7 buildbox.corp.myco.com Enabled Windows 10 Pro 10/25/2016 9:43:46 PM 0d%5,fe80::8966:eb6:55 a8:ac9f%6,169.254.7.13 ,192.168.6.63 CERTEXAM fe80::1509:e668:f2a6:e2 certexam.corp.myco.com Enabled Windows Server 2012 R2 10/25/2016 9:50:27 PM ea%12,192.168.6.5 Standard CONFERENCE-ROOM fe80::ad41:cacc:ac6e:e0 conference- Enabled Windows 10 Pro 10/25/2016 9:15:15 PM 41%4,192.168.6.56 room.corp.myco.com darkhorse fe80::59f3:9394:d4fe:18 darkhorse.corp.myco.com Enabled Windows 10 Pro 10/25/2016 9:06:54 PM 96%7,fe80::a8a8:6c1c:2 b2c:3aec%17,fe80::c42: 9dab:83a1:ea7f%5,169. 254.24.150,169.254.58. 236,192.168.6.80 darren-PC fe80::2508:aae8:1619:2 darren-pc.corp.myco.com Enabled Windows 10 Pro 10/25/2016 9:26:18 PM 2e1%4,192.168.6.134 DC03 fe80::b59a:c6dc:c17b:15 dc03.corp.myco.com, Enabled Windows Server 2012 R2 10/25/2016 3:04:50 PM b9%14,169.254.52.150, corp.myco.com Datacenter

PROPRIETARY & CONFIDENTIAL PAGE 29 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Name IP Address(es) DNS Entry Enabled Operating System Last Login 192.168.1.23,192.168.1. 4,192.168.1.3 Ddouglas-PC Enabled Windows 8.1 Enterprise 10/23/2016 9:27:02 AM Ddouglas-WIN10 192.168.7.17 ddouglas- Enabled Windows 10 Pro 10/25/2016 8:41:05 PM win10.corp.myco.com DESKTOP-N6S4H9A fe80::8cb3:404b:e5b6:5 desktop- Enabled Windows 10 Pro 10/25/2016 9:18:39 PM d3d%2,fe80::2939:588a: n6s4h9a.corp.myco.com 4461:8b92%18,169.254. 93.61,192.168.6.85 DESKTOP-UAE29E6 fe80::a1de:172c:ae6f:b8 desktop- Enabled Windows 10 Pro 10/25/2016 9:48:46 PM 10%3,192.168.6.45 uae29e6.corp.myco.com FILE2012-1 192.168.1.41 file2012-1.corp.myco.com, Enabled Windows Server 2012 R2 10/25/2016 8:56:50 PM store2012-1.corp.myco.com Standard FT-LENOVO Enabled Windows 8.1 Enterprise 10/25/2016 4:43:23 PM gordon-LT2 fe80::899b:6b81:d2ea:3 gordon-lt2.corp.myco.com Enabled Windows 7 Professional 10/25/2016 7:33:23 PM 128%15,192.168.6.136 HPDT-8CC5260NXY fe80::3976:6b9e:2f9b:bf hpdt- Enabled Windows 10 Pro 10/25/2016 9:36:40 PM 97%4,192.168.6.9 8cc5260nxy.corp.myco.com HPLT-5CD4411D8Z fe80::46c:aed6:f88f:7c1 hplt- Enabled Windows 10 Pro 10/25/2016 9:23:22 PM d%3,192.168.6.26 5cd4411d8z.corp.myco.com HV00 192.168.1.100 hv00.corp.myco.com Enabled Windows Server 2012 R2 10/25/2016 3:47:00 PM Datacenter HV02 192.168.1.123,192.168. hv02.corp.myco.com Enabled Windows Server 2012 R2 10/25/2016 3:30:52 PM 1.121,192.168.1.122 Standard HV04 fe80::b154:892c:8aff:ea hv04.corp.myco.com Enabled Windows Server 2012 R2 10/25/2016 8:09:37 PM ed%34,fe80::3dea:a06f: Datacenter b703:63a1%31,fe80::31 c1:2aac:ddc0:2f34%29,f e80::c816:f63e:3756:f45 c%27,fe80::edf7:37ef:5b d0:1ef2%25,fe80::509:8 7e7:645f:b91e%24,fe80: :5:63b:4d3f:8%22,169.2 54.234.237,169.254.99. 161,169.254.185.30,192 .168.6.108,192.168.6.10

PROPRIETARY & CONFIDENTIAL PAGE 30 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Name IP Address(es) DNS Entry Enabled Operating System Last Login 5,192.168.6.100,192.16 8.1.104 IRIDIUM fe80::a51c:74ae:208b:d iridium.corp.myco.com Enabled Windows 10 Pro 10/25/2016 9:29:49 PM 920%2,192.168.6.165 ISA1 192.168.1.6 isa1.corp.myco.com Enabled Windows Server 2003 10/25/2016 9:47:53 PM ISTCORP-PC 192.168.7.123 istcorp-pc.corp.myco.com Enabled Windows 8.1 Pro 10/25/2016 8:59:21 PM JIM-WIN8 192.168.7.44 jim-win8.corp.myco.com Enabled Windows 8.1 Enterprise 10/25/2016 8:40:06 PM Lalexander-PC fe80::7194:3d73:8692:1 lalexander-pc.corp.myco.com Enabled Windows 10 Pro 10/25/2016 9:06:34 PM 09a%3,192.168.6.81 Mcarrier-ASUS Enabled Windows 10 Pro 10/25/2016 3:26:04 PM Mmichaels-HP 192.168.7.95 mmichaels- Enabled Windows 8.1 Enterprise 10/25/2016 5:31:22 PM hp.corp.myco.com Mwest-WIN864 fe80::7977:c113:9a24:4 mwest- Enabled Windows 8 Enterprise 10/25/2016 9:02:39 PM 0a1%17,192.168.6.30 win864.corp.myco.com mwinchester Enabled Windows 10 Pro 10/25/2016 7:05:13 PM NOBELIUM Enabled Windows 8 Enterprise 10/6/2016 1:21:30 PM PANOPTICON fe80::a4a0:5c06:b6d4:d panopticon.corp.myco.com Enabled Windows 10 Pro 10/25/2016 9:46:57 PM 020%26,192.168.6.133 PITWDS12 192.168.1.63,192.168.1. pitwds12.corp.myco.com Enabled Windows Server 2012 R2 10/25/2016 9:46:18 PM 64 Datacenter PKWIN8-VM fe80::5d0f:a0de:55fa:48 pkwin8-vm.corp.myco.com Enabled Windows 8.1 Pro 10/25/2016 9:41:38 PM c4%4,fe80::25ca:4556:3 551:9e23%3,192.168.19 9.34,192.168.6.120 porchanko-HOME Enabled Windows 8.1 Enterprise 10/24/2016 7:28:36 AM Psolidad-PC fe80::4016:d634:6959:c psolidad-pc.corp.myco.com Enabled Windows 10 Pro 10/25/2016 8:34:33 PM 570%11,fe80::9c83:ca9 d:1a7d:7f24%4,169.254. 197.112,192.168.6.12 Psolidad-WIN764 fe80::20dd:cdd2:c1bf:95 psolidad- Enabled Windows 8.1 Enterprise 10/25/2016 6:01:59 PM dc%3,192.168.6.14 win764.corp.myco.com, dfaithl-pc.corp.myco.com

PROPRIETARY & CONFIDENTIAL PAGE 31 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Name IP Address(es) DNS Entry Enabled Operating System Last Login QB01 fe80::c96c:9b21:9265:d qb01.corp.myco.com Enabled Windows Server 2008 R2 10/25/2016 9:43:33 PM 258%13,192.168.6.142 Enterprise REMOTE Enabled Windows 2000 Server 10/25/2016 4:35:09 PM REX 192.168.6.112 rex.corp.myco.com Enabled Windows 8.1 Enterprise 10/25/2016 7:17:17 PM ronald-LAPTOP Enabled Windows 10 Pro 10/25/2016 11:30:17 AM ROWBOT fe80::454:2408:32d3:29 rowbot.corp.myco.com Enabled Windows 10 Enterprise 10/25/2016 8:03:13 PM 68%6,192.168.6.161 SARLACC fe80::8193:586d:e05d:7 sarlacc.corp.myco.com Enabled Windows 10 Enterprise 10/25/2016 9:47:18 PM 355%4,192.168.6.132 sourcesvr 192.168.1.16 sourcesvr.corp.myco.com, Enabled Windows Server 2012 10/25/2016 9:34:23 PM qbserver.corp.myco.com Standard sourcesvrBUILD fe80::55d4:f030:5179:36 sourcesvrbuild.corp.myco.co Enabled Windows Server 2012 R2 10/25/2016 9:37:50 PM 78%13,192.168.6.67 m Standard STORAGE01 192.168.1.69 storage01.corp.myco.com Enabled Windows Server 2008 R2 10/25/2016 9:38:22 PM Enterprise STORAGE12 192.168.1.65,192.168.1. storage12.corp.myco.com Enabled Windows Server 2012 R2 10/25/2016 9:40:18 PM 67,192.168.1.66 Datacenter tarsis fe80::6cc2:c951:fb29:80 tarsis.corp.myco.com Enabled Windows 10 Pro 10/25/2016 8:18:14 PM e3%8,192.168.6.195 Tneusome-HP Enabled Windows 10 Pro 10/24/2016 11:50:36 AM Tneusome-LT Enabled Windows 10 Pro 10/25/2016 3:08:31 PM tywin-PC 192.168.7.49 tywin-pc.corp.myco.com, Enabled Windows 10 Pro 10/25/2016 9:30:06 PM myco- inspiron1.corp.myco.com, win- hnq8g0o1rai.corp.myco.com, winxp64.corp.myco.com UTIL12 192.168.1.15 util12.corp.myco.com Enabled Windows Server 2012 R2 10/25/2016 9:47:11 PM Standard VPNGW fe80::5106:35a5:8930:9 vpngw.corp.myco.com, Enabled Windows Server 2012 R2 10/25/2016 9:34:17 PM e7e%12,192.168.1.5,19 corp.myco.com Standard 2.168.6.159 WAMPA fe80::a568:a9c:b4a6:14 wampa.corp.myco.com Enabled Windows 10 Pro 10/25/2016 8:27:58 PM c3%9,192.168.6.125

PROPRIETARY & CONFIDENTIAL PAGE 32 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Name IP Address(es) DNS Entry Enabled Operating System Last Login WILLARD fe80::c015:b490:31f4:12 willard.corp.myco.com Enabled Windows 10 Enterprise 10/25/2016 8:32:27 PM be%16,192.168.6.52

Inactive Computers

Computer Name IP Address(es) DNS Entry Enabled Operating System Last Login Aborden-PC Enabled Windows 8.1 Pro 8/16/2016 4:40:05 PM acct-PC23 Enabled Windows 7 Enterprise 6/16/2016 3:21:39 PM AMAZONROUTER Enabled Windows Server 2008 R2 10/1/2014 2:43:32 PM Datacenter APPASSURECORE Enabled Windows Server 2012 R2 10/29/2014 1:22:50 AM Standard appsvr30DEV Enabled Windows 2000 Server 6/17/2016 5:52:31 PM appsvrPATCH Enabled Windows 2000 Server 12/3/2014 7:54:39 AM Atorrence-LT disabled Windows 8.1 Pro 9/20/2016 11:59:17 AM BACKUP-01 Enabled Windows Server 2012 R2 2/11/2015 6:49:29 PM Standard barney-WIN10 Enabled Windows 10 Pro Insider 10/14/2015 9:57:20 PM Preview bestrmm Enabled Windows Server 2012 R2 2/28/2016 11:57:05 PM Standard betty-HP Enabled Windows 10 Pro 5/13/2016 3:20:24 AM Bkirk-WIN10 Enabled Windows 10 Pro 4/6/2016 10:06:33 AM Bkirk-WIN7 Enabled Windows 7 Enterprise 7/24/2014 12:11:58 PM Bkirk-Win81 Enabled Windows 8.1 Pro 9/23/2015 2:26:14 AM Boppenheimer-DT disabled Windows 8.1 Enterprise 1/15/2016 2:15:48 PM bordend Enabled Windows 8.1 Enterprise 6/11/2016 3:29:02 PM BO-SANDBOX Enabled Windows 7 Enterprise 8/11/2016 10:06:37 AM CLOUDNMS Enabled Windows Server 2012 R2 4/20/2016 11:50:26 AM Standard

PROPRIETARY & CONFIDENTIAL PAGE 33 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Name IP Address(es) DNS Entry Enabled Operating System Last Login DC1950 Enabled Windows Server 2012 R2 12/14/2014 10:04:10 PM Standard derek-HP Enabled Windows 7 Professional 8/27/2015 10:51:54 AM DESKTOP-CC9C4K9 Enabled Windows 10 Pro 4/12/2016 1:32:01 PM DESKTOP-IPBT45J Enabled Windows 10 Pro 6/15/2016 3:46:40 PM DEV_2012-CORE Enabled Hyper-V Server 2012 12/3/2014 7:50:54 AM DEVKASEYA Enabled Windows Server 2008 R2 12/3/2014 7:55:11 AM Standard DEVWIKI Enabled Windows Server 2003 4/24/2015 3:56:31 AM DfaithL-PC Enabled Windows 10 Pro 3/7/2016 1:19:54 PM DNORTON-LAPTOP Enabled Windows 10 Pro 4/26/2016 7:04:55 AM ENTCERTS Enabled Windows Server 2012 R2 12/29/2015 2:38:15 PM Datacenter FILE2012 disabled Windows Server 2012 R2 6/19/2014 12:11:35 AM Standard File2012-HV disabled 6/19/2014 12:11:35 AM FINANCE Enabled Windows Server 2008 R2 9/16/2014 6:28:28 PM Standard FSHV01 Enabled Windows Server 2012 R2 2/19/2016 10:16:39 PM Standard glee-PC Enabled Windows 8 Enterprise 9/20/2016 6:31:16 PM gordon-HP Enabled Windows 7 Professional 3/1/2016 1:34:20 PM HV01 Enabled Windows Server 2012 R2 10/5/2015 3:51:05 PM Standard HV01A Enabled Windows Server 2016 2/29/2016 7:38:52 PM Technical Preview 3 INCEPTION Enabled Windows 8 Enterprise 8/6/2015 7:23:51 AM JAGA disabled Windows Server 2003 12/3/2014 7:57:05 AM Jdangerfield-Win8 disabled Windows 8.1 Pro 9/25/2016 9:10:27 PM Jdrake-LT Enabled Windows 10 Pro 3/31/2016 3:23:52 PM

PROPRIETARY & CONFIDENTIAL PAGE 34 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Name IP Address(es) DNS Entry Enabled Operating System Last Login JIMSRESTRICTED Enabled Windows 7 Enterprise 9/25/2016 9:03:42 PM KjamesonASUSPC Enabled Windows 8.1 Pro 5/4/2016 12:11:09 PM long-PC Enabled Windows 10 Pro 9/1/2016 4:18:29 PM marketingG-1 Enabled Windows 7 Enterprise 2/11/2015 5:37:13 PM METRO Enabled Windows 8 Enterprise 4/10/2015 1:12:55 AM Mking Enabled Windows 8.1 Pro 9/3/2015 10:54:00 AM Mking1-PC Enabled Windows 8.1 Pro 7/9/2015 12:21:12 PM MSI-LT-20160616 Enabled Windows 10 Pro 6/16/2016 3:59:05 PM Mwest-PC Enabled Windows 8 Enterprise 6/24/2015 8:14:12 AM mwinchester-LT Enabled Windows 7 Enterprise 2/29/2016 2:49:21 PM mwinchester-LT1 Enabled Windows 8.1 Pro 5/25/2016 5:28:58 PM MW-LAPTOP Enabled Windows 8.1 Pro with Media 10/8/2014 8:54:11 AM Center myco-sfo-CORE Enabled Windows Server 2003 12/3/2014 7:55:47 AM NEST-HOST Enabled Windows Server 2016 10/13/2015 4:42:34 PM Technical Preview 3 Standard PABUILD Enabled Windows Server 2003 3/2/2015 3:16:35 PM PGK-W2K8R2-SIS Enabled Windows Server 2008 R2 6/28/2016 10:48:23 AM Datacenter pilotROOTAUTH Enabled Windows Server 2012 R2 9/22/2015 2:15:09 PM Datacenter pkirk1 Enabled Windows 10 Pro 6/27/2016 2:11:09 PM PMURRAY-PC Enabled Windows 10 Pro 8/22/2016 3:19:18 PM PS01 192.168.7.99 ps01.corp.myco.com Enabled Windows Server 2012 R2 9/12/2016 7:33:37 PM Standard Psolidad2 Enabled Windows 7 Enterprise 10/29/2015 7:05:11 PM Psolidad-WIN7TEST Enabled Windows 7 Professional 7/12/2016 9:23:25 PM Ptrevor Enabled Windows 8.1 Enterprise 9/3/2015 11:02:02 AM

PROPRIETARY & CONFIDENTIAL PAGE 35 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Name IP Address(es) DNS Entry Enabled Operating System Last Login QA-PC Enabled Windows 7 Professional 5/28/2015 10:26:11 AM RANCOR Enabled Windows 8 Enterprise 8/4/2016 2:46:27 PM RDGATEWAY Enabled Windows Server 2012 R2 5/31/2015 3:44:39 PM Datacenter reporting Enabled RjonSON-PC Enabled Windows 8.1 Enterprise 10/28/2015 5:08:09 PM SALES-HP Enabled Windows 7 Professional 8/21/2015 2:00:42 PM SDOOLAN-LT disabled Windows 8 Enterprise 6/15/2015 11:01:09 AM SHAREPOINT-01 Enabled Windows Server 2012 7/3/2014 10:24:39 PM Datacenter SLOWE-WIN8 Enabled Windows 8 Enterprise 12/5/2014 2:48:23 PM SPICENM Enabled Windows Server 2012 R2 2/24/2016 4:03:26 PM Standard SQL2012-01 Enabled Windows Server 2012 R2 12/3/2014 7:46:23 AM Datacenter STARGATE Enabled Windows 8 Enterprise 8/5/2015 2:31:12 PM SUPPORTDESK disabled Windows 8 Enterprise 5/19/2015 5:07:13 PM TERMINUS Enabled Windows 8 Enterprise 10/16/2014 8:22:06 AM thanos-DT Enabled Windows 7 Professional 10/28/2015 4:06:39 PM TIsysco-PC Enabled Windows 8.1 Enterprise 3/4/2016 4:28:06 PM tomcat Enabled Windows 8 Enterprise 8/22/2016 1:25:20 PM Tsysco-ACER Enabled Windows 10 Pro 8/31/2016 2:37:16 PM Tsysco-LT Enabled Windows 10 Enterprise 6/19/2016 1:53:48 PM W2K8R2-A Enabled Windows Server 2008 R2 10/20/2015 11:46:46 AM Datacenter WILL-PC Enabled Windows 8.1 Enterprise 8/3/2016 2:08:32 PM WIN10-1 Enabled Windows Technical Preview 4/24/2015 4:03:15 AM for Enterprise WIN10PREVIEW disabled Windows 10 Pro Insider 10/21/2015 9:58:43 AM Preview

PROPRIETARY & CONFIDENTIAL PAGE 36 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Name IP Address(es) DNS Entry Enabled Operating System Last Login workstation-DEV1 Enabled Windows 8 Pro 9/16/2014 9:44:20 AM xerox-mycoit Enabled Windows 8 Pro 4/20/2015 3:19:58 PM ZWIN7-140929 Enabled Windows 7 Enterprise 3/24/2015 11:15:48 AM

PROPRIETARY & CONFIDENTIAL PAGE 37 of 253 Full Detail Report NETWORK ASSESSMENT

3.9 - Server Aging

This section is in indicator of the age of the active servers based on the date their operating system was installed. The actual age of the server may vary if the operating system was re-installed for any reason. Older systems are highlighted in red and much older systems are bolded.

Computer Operating System OS Install Date Age (months) STORAGE01 Windows Server 2008 R2 Enterprise 1/28/2011 4:42:28 PM 69 sourcesvr Windows Server 2012 Standard 11/21/2013 10:29:42 AM 35 HV02 Windows Server 2012 R2 Standard 12/5/2013 3:55:52 PM 34 DC03 Windows Server 2012 R2 Datacenter 1/30/2014 12:16:06 AM 33 UTIL12 Windows Server 2012 R2 Standard 3/4/2014 9:23:32 PM 31 FILE2012-1 Windows Server 2012 R2 Standard 3/28/2014 4:46:39 PM 31 PS01 Windows Server 2012 R2 Standard 6/24/2014 11:49:15 AM 28 HV00 Windows Server 2012 R2 Datacenter 7/10/2014 4:39:32 AM 27 HV04 Windows Server 2012 R2 Datacenter 7/10/2014 4:39:32 AM 27 CERTEXAM Windows Server 2012 R2 Standard 7/28/2014 8:38:10 PM 27 VPNGW Windows Server 2012 R2 Standard 9/19/2014 4:10:34 AM 25 sourcesvrBUILD Windows Server 2012 R2 Standard 11/19/2014 7:20:16 AM 23 QB01 Windows Server 2008 R2 Enterprise 9/22/2015 2:28:21 PM 13 STORAGE12 Windows Server 2012 R2 Datacenter 6/25/2016 2:46:16 AM 4 PITWDS12 Windows Server 2012 R2 Datacenter 6/27/2016 1:17:57 PM 4

PROPRIETARY & CONFIDENTIAL PAGE 38 of 253 Full Detail Report NETWORK ASSESSMENT

3.10 - Workstation Aging

This section is in indicator of the age of the active workstations based on the date their operating system was installed. The actual age of the workstation may vary if the operating system was re-installed for any reason. Older systems are highlighted in red and much older systems are bolded.

Computer Operating System OS Install Date Age (months) Mwest-WIN864 Windows 8 Enterprise 11/28/2012 8:17:17 AM 47 b2b-GW Windows 7 Enterprise 8/12/2013 8:57:44 AM 38 JIM-WIN8 Windows 8.1 Enterprise 11/21/2013 10:07:40 AM 35 Psolidad-WIN764 Windows 8.1 Enterprise 11/21/2013 1:32:55 PM 35 ISTCORP-PC Windows 8.1 Pro 11/22/2013 3:12:45 PM 35 PKWIN8-VM Windows 8.1 Pro 3/3/2014 1:09:54 PM 31 Mmichaels-HP Windows 8.1 Enterprise 3/26/2014 4:46:56 PM 31 REX Windows 8.1 Enterprise 11/17/2015 10:42:10 AM 11 SARLACC Windows 10 Enterprise 12/23/2015 5:10:11 PM 10 gordon-LT2 Windows 7 Professional 2/11/2016 2:47:18 PM 8 WILLARD Windows 10 Enterprise 8/3/2016 2:53:18 PM 2 darkhorse Windows 10 Pro 8/4/2016 6:33:57 AM 2 ROWBOT Windows 10 Enterprise 8/16/2016 5:05:26 PM 2 DESKTOP-UAE29E6 Windows 10 Pro 8/21/2016 8:55:55 PM 2 Psolidad-PC Windows 10 Pro 9/2/2016 6:24:05 AM 1 DESKTOP-N6S4H9A Windows 10 Pro 9/2/2016 9:23:35 AM 1 buildbox Windows 10 Pro 9/19/2016 4:50:35 AM 1 betty-INSPIRON Windows 10 Pro 9/20/2016 5:52:31 AM 1 HPDT-8CC5260NXY Windows 10 Pro 9/20/2016 8:27:01 PM 1 CONFERENCE-ROOM Windows 10 Pro 9/20/2016 8:47:44 PM 1 Lalexander-PC Windows 10 Pro 9/22/2016 4:27:06 AM 1 tarsis Windows 10 Pro 9/25/2016 8:08:00 PM 1 PANOPTICON Windows 10 Pro 9/26/2016 4:40:16 AM 1 HPLT-5CD4411D8Z Windows 10 Pro 9/27/2016 4:24:57 AM 1

PROPRIETARY & CONFIDENTIAL PAGE 39 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System OS Install Date Age (months) tywin-PC Windows 10 Pro 9/27/2016 2:41:54 PM 1 Boppenheimer-PC Windows 10 Pro 9/29/2016 10:38:10 AM 1 WAMPA Windows 10 Pro 10/5/2016 4:09:43 AM 0 IRIDIUM Windows 10 Pro 10/8/2016 4:20:16 AM 0 darren-PC Windows 10 Pro 10/10/2016 11:37:34 AM 0 Ddouglas-WIN10 Windows 10 Pro 10/23/2016 1:33:07 PM 0

PROPRIETARY & CONFIDENTIAL PAGE 40 of 253 Full Detail Report NETWORK ASSESSMENT

3.11 - Domain DNS

This section contains a listing of all IP addresses and hostnames from DNS, with conflicting entries highlighted in red.

IP Address Hostname 10.200.2.3 bo-sandbox.Corp.myco.com 172.20.0.4 Corp.myco.com 172.20.0.5 Corp.myco.com 192.168.0.24 bestrmm.Corp.myco.com 192.168.0.31 FSHV01.Corp.myco.com 192.168.0.32 FSHV01.Corp.myco.com 192.168.0.33 FSHV01.Corp.myco.com 192.168.0.34 FSHV01.Corp.myco.com 192.168.1.3 Corp.myco.com 192.168.1.3 dc03.Corp.myco.com 192.168.1.4 Corp.myco.com 192.168.1.4 dc03.Corp.myco.com 192.168.1.5 Corp.myco.com 192.168.1.5 VPNGW.Corp.myco.com 192.168.1.6 ISA1.Corp.myco.com 192.168.1.11 DC1950.Corp.myco.com 192.168.1.11 shredder.Corp.myco.com 192.168.1.15 Util12.Corp.myco.com 192.168.1.16 QBServer.Corp.myco.com 192.168.1.16 sourcesvr.Corp.myco.com 192.168.1.17 myco-sfo-core.Corp.myco.com 192.168.1.21 RDGateway.Corp.myco.com 192.168.1.23 Corp.myco.com 192.168.1.23 dc03.Corp.myco.com 192.168.1.27 AppAssureCore.Corp.myco.com

PROPRIETARY & CONFIDENTIAL PAGE 41 of 253 Full Detail Report NETWORK ASSESSMENT

IP Address Hostname 192.168.1.33 thrash2.Corp.myco.com 192.168.1.41 File2012-1.Corp.myco.com 192.168.1.41 Store2012-1.Corp.myco.com 192.168.1.43 EntCerts.Corp.myco.com 192.168.1.44 pilotRootAuth.Corp.myco.com 192.168.1.50 engineers.Corp.myco.com 192.168.1.60 HPV00.Corp.myco.com 192.168.1.61 SQL2012-01.Corp.myco.com 192.168.1.63 PITWDS12.Corp.myco.com 192.168.1.64 PITWDS12.Corp.myco.com 192.168.1.65 Storage12.Corp.myco.com 192.168.1.66 Storage12.Corp.myco.com 192.168.1.67 Storage12.Corp.myco.com 192.168.1.69 Storage01.Corp.myco.com 192.168.1.71 SharePoint-01.Corp.myco.com 192.168.1.90 HYPERV-02.Corp.myco.com 192.168.1.90 HYPERV-03.Corp.myco.com 192.168.1.90 MigTest.Corp.myco.com 192.168.1.100 HV00.Corp.myco.com 192.168.1.104 HV04.Corp.myco.com 192.168.1.109 FTDellLaptop.Corp.myco.com 192.168.1.111 HV01.Corp.myco.com 192.168.1.111 HV01a.Corp.myco.com 192.168.1.121 HV02.Corp.myco.com 192.168.1.122 HV02.Corp.myco.com 192.168.1.123 HV02.Corp.myco.com 192.168.1.215 hjobs-vm-win764.Corp.myco.com 192.168.1.242 honker.Corp.myco.com

PROPRIETARY & CONFIDENTIAL PAGE 42 of 253 Full Detail Report NETWORK ASSESSMENT

IP Address Hostname 192.168.1.243 SEC30CDA792322C.Corp.myco.com 192.168.3.2 AmazonRouter.Corp.myco.com 192.168.3.11 SALES01.Corp.myco.com 192.168.3.24 WinXP32.Corp.myco.com 192.168.6.0 tneusome-LT.Corp.myco.com 192.168.6.1 CMHX5D1.Corp.myco.com 192.168.6.2 tywins-iMac.Corp.myco.com 192.168.6.3 FTWork-PC.Corp.myco.com 192.168.6.4 TERMINUS.Corp.myco.com 192.168.6.5 CertExam.Corp.myco.com 192.168.6.6 android-2ea726647b1bba34.Corp.myco.com 192.168.6.8 svr1-99ZO-U.Corp.myco.com 192.168.6.9 HPDT-8CC5260NXY.Corp.myco.com 192.168.6.10 newbuild.Corp.myco.com 192.168.6.11 svr1-99ZF.Corp.myco.com 192.168.6.12 psolidad-pc.Corp.myco.com 192.168.6.13 martinKking.Corp.myco.com 192.168.6.14 DfaithL-PC.Corp.myco.com 192.168.6.14 psolidad-win764.Corp.myco.com 192.168.6.16 svr1-65LI.Corp.myco.com 192.168.6.19 android-872e9a5fd9b127d8.Corp.myco.com 192.168.6.20 The-Titanic.Corp.myco.com 192.168.6.21 svr1-99ZO.Corp.myco.com 192.168.6.24 CloudNMS.Corp.myco.com 192.168.6.24 svr1-91OD-U.Corp.myco.com 192.168.6.26 HPLT-5CD4411D8Z.Corp.myco.com 192.168.6.27 android-35eb169d716d3a4f.Corp.myco.com 192.168.6.28 android-9d778efbf30c431e.Corp.myco.com

PROPRIETARY & CONFIDENTIAL PAGE 43 of 253 Full Detail Report NETWORK ASSESSMENT

IP Address Hostname 192.168.6.28 sandra-win8.Corp.myco.com 192.168.6.29 KCmitchellsiPhone.Corp.myco.com 192.168.6.30 mwest-win864.Corp.myco.com 192.168.6.33 svr1-14TA-U.Corp.myco.com 192.168.6.34 squid.Corp.myco.com 192.168.6.35 android-7201cfb0c4604141.Corp.myco.com 192.168.6.37 betty-Inspiron.Corp.myco.com 192.168.6.39 android-d8c70586ea812847.Corp.myco.com 192.168.6.41 RakealbordensAir.Corp.myco.com 192.168.6.43 android-b239e67ca278be59.Corp.myco.com 192.168.6.44 b2b-GW.Corp.myco.com 192.168.6.45 DESKTOP-UAE29E6.Corp.myco.com 192.168.6.46 svr1-99ZG-U.Corp.myco.com 192.168.6.47 svr1-99ZG.Corp.myco.com 192.168.6.48 svr1-99ZP.Corp.myco.com 192.168.6.50 freds-Mini.Corp.myco.com 192.168.6.51 devwiki.Corp.myco.com 192.168.6.52 WILLARD.Corp.myco.com 192.168.6.53 android-a7006fb96d99c1f1.Corp.myco.com 192.168.6.55 DESKTOP-1AVTJC6.Corp.myco.com 192.168.6.56 Conference-Room.Corp.myco.com 192.168.6.57 testvm2-2dev.Corp.myco.com 192.168.6.58 iPhone.Corp.myco.com 192.168.6.62 workstation-DEV2.Corp.myco.com 192.168.6.63 buildbox.Corp.myco.com 192.168.6.64 android-5e3c2f65752abdb4.Corp.myco.com 192.168.6.66 android-4eb64fa2d25b5841.Corp.myco.com 192.168.6.67 sourcesvrBuild.Corp.myco.com

PROPRIETARY & CONFIDENTIAL PAGE 44 of 253 Full Detail Report NETWORK ASSESSMENT

IP Address Hostname 192.168.6.70 mwinchester.Corp.myco.com 192.168.6.71 workstation-DEV2-U.Corp.myco.com 192.168.6.73 workstation-49SW-U.Corp.myco.com 192.168.6.74 fereydopleWatch.Corp.myco.com 192.168.6.76 MW-Laptop.Corp.myco.com 192.168.6.77 tywinsiPhone.Corp.myco.com 192.168.6.79 Mcarrier-ASUS.Corp.myco.com 192.168.6.80 darkhorse.Corp.myco.com 192.168.6.81 Lalexander-PC.Corp.myco.com 192.168.6.82 mintlinux.Corp.myco.com 192.168.6.83 svr1-99ZF-U.Corp.myco.com 192.168.6.84 android-6f792f916f672843.Corp.myco.com 192.168.6.85 DESKTOP-N6S4H9A.Corp.myco.com 192.168.6.86 svr1-00JY.Corp.myco.com 192.168.6.87 svr1-91OD.Corp.myco.com 192.168.6.91 svr1-14TA.Corp.myco.com 192.168.6.92 svr1-16CA.Corp.myco.com 192.168.6.93 HP25833F.Corp.myco.com 192.168.6.95 DESKTOP-U5NHKVQ.Corp.myco.com 192.168.6.96 workstation-POLY2.Corp.myco.com 192.168.6.97 svr1-16CA-U.Corp.myco.com 192.168.6.100 HV04.Corp.myco.com 192.168.6.103 PGK-W520.Corp.myco.com 192.168.6.104 workstation-POLY2-U.Corp.myco.com 192.168.6.105 HV04.Corp.myco.com 192.168.6.107 svr1-99ZB.Corp.myco.com 192.168.6.108 HV04.Corp.myco.com 192.168.6.109 boppenheimer-pc.Corp.myco.com

PROPRIETARY & CONFIDENTIAL PAGE 45 of 253 Full Detail Report NETWORK ASSESSMENT

IP Address Hostname 192.168.6.112 rex.Corp.myco.com 192.168.6.113 amatoMBP.Corp.myco.com 192.168.6.114 testvm5-2dev.Corp.myco.com 192.168.6.115 ronald-Laptop.Corp.myco.com 192.168.6.116 android-72205b74046a198b.Corp.myco.com 192.168.6.119 svr1-99ZR.Corp.myco.com 192.168.6.120 PKWin8-VM.Corp.myco.com 192.168.6.121 android-f156a47b8f29525c.Corp.myco.com 192.168.6.125 WAMPA.Corp.myco.com 192.168.6.126 Tneusome-HP.Corp.myco.com 192.168.6.127 android-1d9d2de68a81d75f.Corp.myco.com 192.168.6.128 EX6200.Corp.myco.com 192.168.6.132 SARLACC.Corp.myco.com 192.168.6.133 PANOPTICON.Corp.myco.com 192.168.6.134 darren-PC.Corp.myco.com 192.168.6.136 gordon-LT2.Corp.myco.com 192.168.6.142 QB01.Corp.myco.com 192.168.6.143 svr1-99ZB-U.Corp.myco.com 192.168.6.144 android-511e304503559577.Corp.myco.com 192.168.6.150 workstation-TEST1.Corp.myco.com 192.168.6.152 workstation-1337-U.Corp.myco.com 192.168.6.153 ILOMX280201WZ.Corp.myco.com 192.168.6.157 WIN-8U9TQSL0T69.Corp.myco.com 192.168.6.160 workstation-marion-U.Corp.myco.com 192.168.6.161 RowBot.Corp.myco.com 192.168.6.162 fereydosiPhone2.Corp.myco.com 192.168.6.165 Iridium.Corp.myco.com 192.168.6.192 FT-LENOVO.Corp.myco.com

PROPRIETARY & CONFIDENTIAL PAGE 46 of 253 Full Detail Report NETWORK ASSESSMENT

IP Address Hostname 192.168.6.195 tarsis.Corp.myco.com 192.168.6.204 android-ca01b8b758415e1.Corp.myco.com 192.168.6.211 MWDWIN8TESTBOX.Corp.myco.com 192.168.7.10 dangerfield-xp.Corp.myco.com 192.168.7.13 Dev-Win8.Corp.myco.com 192.168.7.14 CONFERENCE_ROOM.Corp.myco.com 192.168.7.16 DevSymantec.Corp.myco.com 192.168.7.17 ddouglas-win10.Corp.myco.com 192.168.7.22 slowe-win8.Corp.myco.com 192.168.7.24 Corp.myco.com 192.168.7.24 Costen-SG.Corp.myco.com 192.168.7.27 Corp.myco.com 192.168.7.44 jim-win8.Corp.myco.com 192.168.7.49 myco-inspiron1.Corp.myco.com 192.168.7.49 tywin-PC.Corp.myco.com 192.168.7.49 WIN-HNQ8G0O1RAI.Corp.myco.com 192.168.7.49 winxp64.Corp.myco.com 192.168.7.52 Vm-jdangerfield-win7.Corp.myco.com 192.168.7.53 DEV_2012-CORE.Corp.myco.com 192.168.7.53 EXCHANGE2013.Corp.myco.com 192.168.7.53 janet-PC.Corp.myco.com 192.168.7.55 appsvrpatch.Corp.myco.com 192.168.7.58 Corp.myco.com 192.168.7.59 windesktop.Corp.myco.com 192.168.7.60 PKWin7Ent.Corp.myco.com 192.168.7.61 appsvrdemo.Corp.myco.com 192.168.7.66 HJOBS-WIN764.Corp.myco.com 192.168.7.67 appsvrdemo.Corp.myco.com

PROPRIETARY & CONFIDENTIAL PAGE 47 of 253 Full Detail Report NETWORK ASSESSMENT

IP Address Hostname 192.168.7.67 jaga.Corp.myco.com 192.168.7.68 remote.Corp.myco.com 192.168.7.68 VM-WIN7.Corp.myco.com 192.168.7.76 DevBestCrypt.Corp.myco.com 192.168.7.78 Dell120720.Corp.myco.com 192.168.7.79 Ptrevor.Corp.myco.com 192.168.7.83 WIN-7C9O0471SH6.Corp.myco.com 192.168.7.86 rob.Corp.myco.com 192.168.7.93 workstation-22MP.Corp.myco.com 192.168.7.94 workstation-22MP-U.Corp.myco.com 192.168.7.95 mmichaels-hp.Corp.myco.com 192.168.7.97 Dev-Win7.Corp.myco.com 192.168.7.98 WIN-QM7JGQHEPEK.Corp.myco.com 192.168.7.99 PS01.Corp.myco.com 192.168.7.100 pabuild.Corp.myco.com 192.168.7.112 DEVKASEYA.Corp.myco.com 192.168.7.123 Istcorp-PC.Corp.myco.com 192.168.199.20 303.Corp.myco.com 192.168.199.22 305.Corp.myco.com 192.168.199.23 381.Corp.myco.com 192.168.199.24 313.Corp.myco.com 192.168.199.25 314.Corp.myco.com 192.168.199.26 308.Corp.myco.com 192.168.199.27 316.Corp.myco.com 192.168.199.28 306.Corp.myco.com 192.168.199.29 312.Corp.myco.com 192.168.199.30 311.Corp.myco.com 192.168.199.31 317.Corp.myco.com

PROPRIETARY & CONFIDENTIAL PAGE 48 of 253 Full Detail Report NETWORK ASSESSMENT

IP Address Hostname 192.168.199.32 9020.Corp.myco.com 192.168.199.33 396.Corp.myco.com 192.168.199.36 307.Corp.myco.com

PROPRIETARY & CONFIDENTIAL PAGE 49 of 253 Full Detail Report NETWORK ASSESSMENT 4 - Non A/D Devices

This section contains a listing of all devices which were not joined to a domain or workgroup.

IP Address Computer Name Listening Port(s) Device Type 192.168.0.1 Telnet (23/TCP), HTTP (80/TCP) Web Server 192.168.0.2 SSH (22/TCP), Telnet (23/TCP), HTTP ProCurve J4904A Switch 2848, revision I.10.105, ROM (80/TCP) I.08.07 (/sw/code/build/mako) 192.168.0.3 SSH (22/TCP), Telnet (23/TCP), HTTP Web Server (80/TCP) 192.168.0.11 SSH (22/TCP), HTTP (80/TCP), Ruckus Wireless Inc (C) 2006 HTTPS (443/TCP) 192.168.0.241 HTTPS (443/TCP) lighttpd/1.4.31 192.168.0.242 HTTPS (443/TCP) lighttpd/1.4.31 192.168.1.1 SSH (22/TCP), Telnet (23/TCP), HTTP (80/TCP), HTTPS (443/TCP) 192.168.1.24 FTP (21/TCP), SSH (22/TCP) Linux pitauvik 3.16.0-30-generic #40~14.04.1-Ubuntu SMP Thu Jan 15 17:43:14 UTC 2015 x86_64 192.168.1.31 HVFS RDP (3389/TCP) 192.168.1.32 HVFS RDP (3389/TCP) 192.168.1.33 HVFS RDP (3389/TCP) 192.168.1.34 HVFS RDP (3389/TCP) 192.168.1.50 myco-bdr FTP (21/TCP), HTTP (80/TCP), VNC Cherokee (5900/TCP) 192.168.1.51 FTP (21/TCP), Telnet (23/TCP), HTTP APC Web/SNMP Management Card (MB:v4.0.1 (80/TCP) PF:v6.1.1 PN:apc_hw05_aos_611.bin AF1:v6.1.1 AN1:apc_hw05_sumx_611.bin MN:AP9630 HR:05 SN: ZA1423019779 MD:07/05/2014) (Embedded PowerNet SNMP Agent SW v2.2 compatible) 192.168.1.52 FTP (21/TCP), Telnet (23/TCP), HTTP APC Web/SNMP Management Card (MB:v4.0.1 (80/TCP) PF:v6.1.1 PN:apc_hw05_aos_611.bin AF1:v6.1.1 AN1:apc_hw05_sumx_611.bin MN:AP9630 HR:05 SN: ZA1423019820 MD:07/06/2014) (Embedded PowerNet SNMP Agent SW v2.2 compatible)

PROPRIETARY & CONFIDENTIAL PAGE 50 of 253 Full Detail Report NETWORK ASSESSMENT

IP Address Computer Name Listening Port(s) Device Type 192.168.1.81 FINANCE HTTP (80/TCP), HTTPS (443/TCP), Microsoft-IIS/7.5 RDP (3389/TCP) 192.168.1.201 SSH (22/TCP), HTTP (80/TCP), Mbedthis-Appweb/2.4.2 HTTPS (443/TCP), VNC (5900/TCP) 192.168.1.202 SSH (22/TCP), HTTP (80/TCP), Mbedthis-Appweb/2.4.2 HTTPS (443/TCP), VNC (5900/TCP) 192.168.1.203 SSH (22/TCP), HTTP (80/TCP), httpd HTTPS (443/TCP), VNC (5900/TCP) 192.168.1.204 SSH (22/TCP), HTTP (80/TCP), httpd HTTPS (443/TCP), VNC (5900/TCP) 192.168.1.205 SSH (22/TCP), HTTP (80/TCP), Mbedthis-Appweb/2.4.2 HTTPS (443/TCP), VNC (5900/TCP) 192.168.1.240 SSH (22/TCP), HTTP (80/TCP), lighttpd/1.4.28 HTTPS (443/TCP) 192.168.1.243 SEC30CDA792322C.CORP.myco.CO HTTP (80/TCP) Samsung Samsung M283x Series; V3.00.01.04 JUN-19- M 2014;Engine V1.00.10 06-10-2014;NIC V6.01.01;S/N 075WB8GFCF0027R 192.168.1.244 BRN30055C36B0DA FTP (21/TCP), Telnet (23/TCP), HTTP Brother NC-8300h, Firmware Ver.1.12 (13.11.13),MID (80/TCP), HTTPS (443/TCP) 84U-D17 192.168.1.245 FTP (21/TCP), Telnet (23/TCP), SMTP Brother NC-6700h, Firmware Ver.0.30 (09.06.25),MID (25/TCP), HTTP (80/TCP) 8CE-217,FID 2 192.168.1.254 monitor-GW 192.168.3.5 MYCO-DC01 DNS (53/TCP), 192.168.3.6 MYCO-DC02 DNS (53/TCP), 192.168.5.1 SSH (22/TCP), Telnet (23/TCP), HTTP (80/TCP), HTTPS (443/TCP) 192.168.6.3 FTWORK-PC.CORP.myco.COM HTTP (80/TCP), RDP (3389/TCP) 192.168.6.7 HTTP (80/TCP), HTTPS (443/TCP) 192.168.6.8 svr1-99ZO-U.CORP.myco.COM 192.168.6.10 NEWBUILD.CORP.myco.COM HTTP (80/TCP) Microsoft-IIS/8.0 192.168.6.11 svr1-99ZF.CORP.myco.COM HTTPS (443/TCP), RDP (3389/TCP) 192.168.6.16 svr1-65LI.CORP.myco.COM HTTPS (443/TCP), RDP (3389/TCP)

PROPRIETARY & CONFIDENTIAL PAGE 51 of 253 Full Detail Report NETWORK ASSESSMENT

IP Address Computer Name Listening Port(s) Device Type 192.168.6.21 svr1-99ZO.CORP.myco.COM HTTPS (443/TCP), RDP (3389/TCP) 192.168.6.33 svr1-14TA-U.CORP.myco.COM 192.168.6.34 SQUID.CORP.myco.COM HTTP (80/TCP) Apache/2.4.18 (Ubuntu) 192.168.6.46 svr1-99ZG-U.CORP.myco.COM 192.168.6.47 svr1-99ZG.CORP.myco.COM HTTPS (443/TCP), RDP (3389/TCP) 192.168.6.48 svr1-99ZP.CORP.myco.COM HTTPS (443/TCP), RDP (3389/TCP) 192.168.6.49 SSH (22/TCP), HTTP (80/TCP), HTTPS (443/TCP), VNC (5900/TCP) 192.168.6.50 fredS-MINI.CORP.myco.COM 192.168.6.59 192.168.6.62 workstation-DEV2.CORP.myco.COM HTTP (80/TCP), HTTPS (443/TCP), Microsoft-IIS/8.0 RDP (3389/TCP) 192.168.6.68 FRONTDOOR.HQ.myco.COM 192.168.6.71 workstation-DEV2- U.CORP.myco.COM 192.168.6.82 MINTLINUX.CORP.myco.COM SSH (22/TCP) 192.168.6.83 svr1-99ZF-U.CORP.myco.COM 192.168.6.86 svr1-00JY.CORP.myco.COM HTTPS (443/TCP), RDP (3389/TCP) 192.168.6.87 svr1-91OD.CORP.myco.COM HTTPS (443/TCP), RDP (3389/TCP) 192.168.6.91 svr1-14TA.CORP.myco.COM HTTPS (443/TCP), RDP (3389/TCP) 192.168.6.92 svr1-16CA.CORP.myco.COM HTTPS (443/TCP), RDP (3389/TCP) 192.168.6.93 HP25833F.CORP.myco.COM HTTP (80/TCP), HTTP (8080/TCP) HP ETHERNET MULTI-ENVIRONMENT 192.168.6.96 workstation-POLY2.CORP.myco.COM HTTPS (443/TCP), RDP (3389/TCP) 192.168.6.97 svr1-16CA-U.CORP.myco.COM 192.168.6.98 HV2016-PK.CORE.myco.COM RDP (3389/TCP) 192.168.6.104 workstation-POLY2- U.CORP.myco.COM 192.168.6.106 workstation-marion HTTPS (443/TCP), RDP (3389/TCP)

PROPRIETARY & CONFIDENTIAL PAGE 52 of 253 Full Detail Report NETWORK ASSESSMENT

IP Address Computer Name Listening Port(s) Device Type 192.168.6.107 svr1-99ZB.CORP.myco.COM HTTPS (443/TCP), RDP (3389/TCP) 192.168.6.119 svr1-99ZR.CORP.myco.COM HTTPS (443/TCP), RDP (3389/TCP) 192.168.6.123 HV01.CORE.myco.COM HTTP (80/TCP), RDP (3389/TCP) 192.168.6.124 HV01.CORE.myco.COM HTTP (80/TCP), RDP (3389/TCP) 192.168.6.128 EX6200.CORP.myco.COM Telnet (23/TCP), HTTP (80/TCP) 192.168.6.143 svr1-99ZB-U.CORP.myco.COM 192.168.6.150 workstation-TEST1.CORP.myco.COM HTTPS (443/TCP), RDP (3389/TCP) 192.168.6.151 HV01.CORE.myco.COM HTTP (80/TCP), RDP (3389/TCP) 192.168.6.152 workstation-1337-U.CORP.myco.COM 192.168.6.153 ILOMX280201WZ.CORP.myco.COM SSH (22/TCP), HTTP (80/TCP), HTTPS (443/TCP) 192.168.6.154 HTTP (80/TCP), HTTPS (443/TCP) 192.168.6.160 workstation-marion- U.CORP.myco.COM 192.168.6.163 HV05.CORE.myco.COM RDP (3389/TCP)

PROPRIETARY & CONFIDENTIAL PAGE 53 of 253 Full Detail Report NETWORK ASSESSMENT 5 - Servers

This section and corresponding sub-sections contain a comprehensive listing of servers by type, which are then categorized by domain or workgroup membership.

5.1 - MS SQL Servers

CORP.MYCO.COM

MS SQL Server Name Instance Version # of Databases Active SQL Agent Jobs? DDOUGLAS-WIN10 UPSWS2012SERVER 11.0.5058.0 MWEST-WIN864 SQLEXPRESS 192.168.2531.0 REMOTE 8.00.194 STORAGE01 SUNBELT 9.00.5000.00 WILLARD SQLEXPRESS 12.0.2000.8

5.2 - Web Servers

CORP.MYCO.COM

IP Address Web Server Name Listening Port(s) Server Type 192.168.1.5 VPNGW 80/TCP, 443/TCP Microsoft-IIS/8.5 192.168.1.6 ISA1 80/TCP, 8080/TCP 192.168.1.15 UTIL12 80/TCP, 443/TCP Microsoft-IIS/8.5 192.168.1.16 SOURCESVR 80/TCP, 8080/TCP 192.168.1.41 FILE2012-1 80/TCP, 443/TCP 192.168.1.69 STORAGE01 80/TCP, 443/TCP Microsoft-IIS/7.5 192.168.1.81 FINANCE 80/TCP, 443/TCP Microsoft-IIS/7.5 192.168.1.121 HV02 80/TCP 192.168.1.122 HV02 80/TCP

PROPRIETARY & CONFIDENTIAL PAGE 54 of 253 Full Detail Report NETWORK ASSESSMENT

IP Address Web Server Name Listening Port(s) Server Type 192.168.1.123 HV02 80/TCP 192.168.6.5 CERTEXAM 80/TCP, 443/TCP Microsoft-IIS/8.5 192.168.6.109 BOPPENHEIMER-PC 80/TCP Microsoft-IIS/10.0 192.168.6.112 REX 80/TCP Microsoft-IIS/8.5 192.168.6.117 ISA1 80/TCP 192.168.6.142 QB01 80/TCP, 443/TCP Microsoft-IIS/7.5 192.168.6.159 VPNGW 80/TCP, 443/TCP Microsoft-IIS/8.5 192.168.6.165 IRIDIUM 80/TCP, 443/TCP 192.168.7.99 PS01 80/TCP

No Domain

IP Address Web Server Name Listening Port(s) Server Type 192.168.0.1 80/TCP Web Server 192.168.0.2 80/TCP eHTTP v2.0 192.168.0.3 80/TCP Web Server 192.168.0.11 80/TCP, 443/TCP GoAhead-Webs 192.168.0.241 443/TCP lighttpd/1.4.31 192.168.0.242 443/TCP lighttpd/1.4.31 192.168.1.1 80/TCP, 443/TCP 192.168.1.21 RDGATEWAY 80/TCP, 443/TCP Microsoft-IIS/7.5 192.168.1.50 MYCO-BDR 80/TCP Cherokee 192.168.1.51 80/TCP 192.168.1.52 80/TCP 192.168.1.201 80/TCP, 443/TCP Mbedthis-Appweb/2.4.2 192.168.1.202 80/TCP, 443/TCP Mbedthis-Appweb/2.4.2 192.168.1.203 80/TCP, 443/TCP httpd 192.168.1.204 80/TCP, 443/TCP httpd

PROPRIETARY & CONFIDENTIAL PAGE 55 of 253 Full Detail Report NETWORK ASSESSMENT

IP Address Web Server Name Listening Port(s) Server Type 192.168.1.205 80/TCP, 443/TCP Mbedthis-Appweb/2.4.2 192.168.1.240 80/TCP, 443/TCP lighttpd/1.4.28 192.168.1.243 SEC30CDA792322C 80/TCP 192.168.1.244 BRN30055C36B0DA 80/TCP, 443/TCP debut/1.20 192.168.1.245 80/TCP debut/1.08 192.168.3.2 AMAZONROUTER 80/TCP, 443/TCP 192.168.5.1 80/TCP, 443/TCP 192.168.6.3 FTWORK-PC 80/TCP 192.168.6.7 80/TCP, 443/TCP 192.168.6.10 NEWBUILD 80/TCP Microsoft-IIS/8.0 192.168.6.11 SVR1-99ZF 443/TCP 192.168.6.16 SVR1-65LI 443/TCP 192.168.6.21 SVR1-99ZO 443/TCP 192.168.6.34 SQUID 80/TCP Apache/2.4.18 (Ubuntu) 192.168.6.47 SVR1-99ZG 443/TCP 192.168.6.48 SVR1-99ZP 443/TCP 192.168.6.49 80/TCP, 443/TCP 192.168.6.62 WORKSTATION-DEV2 80/TCP, 443/TCP Microsoft-IIS/8.0 192.168.6.86 SVR1-00JY 443/TCP 192.168.6.87 SVR1-91OD 443/TCP 192.168.6.91 SVR1-14TA 443/TCP 192.168.6.92 SVR1-16CA 443/TCP 192.168.6.93 HP25833F 80/TCP, 8080/TCP HP HTTP Server; HP HP Officejet Pro 8610 - A7F64A; Serial Number: CN5B4FX01D; Built:Fri Jan 09, 2015 04:48:51PM {FDP1CN1502AR} 192.168.6.96 WORKSTATION-POLY2 443/TCP 192.168.6.106 WORKSTATION-MARION 443/TCP 192.168.6.107 SVR1-99ZB 443/TCP

PROPRIETARY & CONFIDENTIAL PAGE 56 of 253 Full Detail Report NETWORK ASSESSMENT

IP Address Web Server Name Listening Port(s) Server Type 192.168.6.119 SVR1-99ZR 443/TCP 192.168.6.123 HV01 80/TCP 192.168.6.124 HV01 80/TCP 192.168.6.128 EX6200 80/TCP 192.168.6.150 WORKSTATION-TEST1 443/TCP 192.168.6.151 HV01 80/TCP 192.168.6.153 ILOMX280201WZ 80/TCP, 443/TCP 192.168.6.154 80/TCP, 443/TCP

5.3 - Time Servers

CORP.MYCO.COM

Time Server Name IP Address DC03 192.168.1.23

5.4 - Exchange Servers

CORP.MYCO.COM

Exchange Server Name Type MYCO-SFO-EXCHTKT Exchange 2007 MYCO-SFO-EXTEST Exchange 2007

5.5 - DHCP Servers

CORP.MYCO.COM

IP Address(es) Server Name Errors (last 24 hours) dc01.corp.myco.com

PROPRIETARY & CONFIDENTIAL PAGE 57 of 253 Full Detail Report NETWORK ASSESSMENT

IP Address(es) Server Name Errors (last 24 hours) hv2012-1.corp.myco.com 192.168.1.69 storage01.pit.com 192.168.1.3 DC03.Corp.myco.com

5.6 - Hyper-V Servers

CORP.MYCO.COM

Hyper-V Guest Information Host Name State Operating System Notes Boppenheimer-PC svr1-99ZR Running Windows 8.1 Pro (Windows 10 Pro) DESKTOP-N6S4H9A svr1-14TA Running Windows 8.1 Pro (Windows 10 Pro) svr1-14TA-U Running HV00 Finance Running Windows Server 2008 R2 Standard (Windows Server 2012 R2 ISA1 Running Server 2003 R2 Datacenter) PKWin8-VM Running Windows 8.1 Pro PS01 Running Windows Server 2012 R2 Standard QB01 Running Windows Server 2008 R2 Enterprise qualysvm Running RDGateway Running Windows Server 2008 R2 Standard Remote Running sourcesvr Running Windows Server 2012 Standard Storage01 Running Windows Server 2008 R2 Enterprise svr1-65LI Running Windows 8.1 Pro svr1-99ZB Running Windows 8.1 Pro svr1-99ZB-U Running svr1-99ZO Running Windows 8.1 Pro svr1-99ZO-U Running svr1-99ZP Running Windows 8.1 Pro TS12-01 Running Windows Server 2012 R2 Datacenter VPNGW Running Windows Server 2012 R2 Standard W2k8R2-B Running Windows Server 2008 R2 Datacenter Auvik Appliance (poss Off HV01) CloudView Off

PROPRIETARY & CONFIDENTIAL PAGE 58 of 253 Full Detail Report NETWORK ASSESSMENT

Hyper-V Guest Information Host Name State Operating System Notes Dev2012-Core Off Dev-Symantec Off Dev-Wiki Off Dev-Win2008 Off Omega Off psolidad-win7-sandbox Off RDGateway (old) Off TESTDC01 Off TSCW Off W2k8R2-A Off Active-Active FS for shared disk W2008R2? WDS.Dev Off WDS.HQ Off HV02 b2b-GW Running Windows 7 Enterprise (Windows Server 2012 R2 barney Sandbox Running Windows 7 Enterprise Standard) borden_PC Running Windows 10 Pro buildbox Running Windows 10 Pro DC02.Core Running Windows Server 2012 R2 Datacenter mint Running MWDWIN8TESTBOX Running Windows 8.1 sourcesvrBuild Running Windows Server 2012 R2 Standard svr1-91OD Running Windows 8.1 Pro svr1-91OD-U Running tonya-win10 Running Windows 10 Enterprise Win10Insider Running appliance-linux Off appliance-windows Off Dev-JAGA Off Dev-Kaseya Off Dev-McAfee Off EntCerts Off hv01-xp-1 Off inception Off Jdangerfield-Win8 Off Created by Pkirk for JD to try and eliminate physical box in closet KRANG Off mwitherbred-win8 Off sourcesvr - NOT! Off

PROPRIETARY & CONFIDENTIAL PAGE 59 of 253 Full Detail Report NETWORK ASSESSMENT

Hyper-V Guest Information Host Name State Operating System Notes SPICENM Off SQL2012-01 Off HV04 Finance Running Windows Server 2008 R2 Standard (Windows Server 2012 R2 ISA1 Running Microsoft Windows Server 2003 R2 Datacenter) PKWin8-VM Running Windows 8.1 Pro PS01 Running Windows Server 2012 R2 Standard QB01 Running Windows Server 2008 R2 Enterprise qualysvm Running RDGateway Running Windows Server 2008 R2 Standard Remote Running sourcesvr Running Windows Server 2012 Standard Storage01 Running Windows Server 2008 R2 Enterprise svr1-65LI Running Windows 8.1 Pro svr1-99ZB Running Windows 8.1 Pro svr1-99ZB-U Running svr1-99ZO Running Windows 8.1 Pro svr1-99ZO-U Running svr1-99ZP Running Windows 8.1 Pro TS12-01 Running Windows Server 2012 R2 Datacenter VPNGW Running Windows Server 2012 R2 Standard W2k8R2-B Running Windows Server 2008 R2 Datacenter Auvik Appliance (poss Off HV01) CloudView Off Dev2012-Core Off Dev-Symantec Off Dev-Wiki Off Dev-Win2008 Off Omega Off psolidad-win7-sandbox Off RDGateway (old) Off TESTDC01 Off TSCW Off W2k8R2-A Off Active-Active FS for shared disk W2008R2? WDS.Dev Off WDS.HQ Off

PROPRIETARY & CONFIDENTIAL PAGE 60 of 253 Full Detail Report NETWORK ASSESSMENT

Hyper-V Guest Information Host Name State Operating System Notes PANOPTICON VS Emulator 5.2-inch Off Emulator 192.168.10586.0 (Windows 10 Pro) Marshmallow (6.0.0) SDDisk|C:\accts\dwade.myco\AppData\Local XXHDPI Phone.dwade \Microsoft\VisualStudioEmulator\Android\Co ntainers\Local\Devices\vhd\5.2_Marshmallo w_(6.0.0)_XXHDPI_Phone\image.sdcard.vh d VS Emulator 5-inch KitKat Off Emulator 192.168.10586.0 (4.4) XXHDPI SDDisk|C:\accts\dwade.myco\AppData\Local Phone.dwade \Microsoft\VisualStudioEmulator\Android\Co ntainers\Local\Devices\vhd\5_KitKat_(4.4)_X XHDPI_Phone\image.sdcard.vhd Psolidad-PC svr1-00JY Running Windows 8.1 Pro (Windows 10 Pro) svr1-76CH Off svr1-76CH-U Off TestMemoryVm Off WILLARD svr1-99ZW Off (Windows 10 Enterprise) svr1-99ZW-U Off Windows 7 x64 Off

5.7 - VMware Servers

LOCALDOMAIN

Hyper-V Guest Information Host Name State Operating System Notes 10.0.0.9 Windows-Test Off Microsoft Windows 8 (64-bit) (VMware ESXi 6.0.0 build-3620759) Linux-UB On Other (32-bit) Linux-RH Off Other (32-bit) INTERNAL-5DF2 Off Microsoft Windows 8 (64-bit) SPOCK-VM On Other (32-bit) OVA with VMWare tools ND23-60XS On Microsoft Windows 8 (64-bit)

PROPRIETARY & CONFIDENTIAL PAGE 61 of 253 Full Detail Report NETWORK ASSESSMENT 6 - Printers

This section contains a listing of all printers categorized by a combination of domain or workgroup membership and method of access. Alerts for SNMP-enabled printers are also displayed in red.

CORP.MYCO.COM (from WMI)

IP Address Printer Name Accessed From Location Comment 169.254.196.228, Brother HL-6180DW series Boppenheimer-PC 169.254.57.9, 192.168.6.109 Printer 169.254.24.150, SEC30CDA792322C darkhorse Administrator 169.254.58.236, 192.168.6.80 192.168.6.134 Brother HL-6180DW series darren-PC Printer 192.168.6.134 Brother MFC-9320CW Printer darren-PC 192.168.7.17 HP Officejet Pro 8610 Ddouglas-WIN10 169.254.93.61, 192.168.6.85 Brother HL-6180DW series DESKTOP-N6S4H9A Printer 169.254.93.61, 192.168.6.85 Brother MFC-9320CW Printer DESKTOP-N6S4H9A 192.168.6.9 Brother HL-6180DW series HPDT-8CC5260NXY Printer 192.168.6.26 Brother HL-6180DW series HPLT-5CD4411D8Z Printer 192.168.7.123 Brother HL-6180DW series ISTCORP-PC 192.168.7.123 Brother MFC-9320CW Printer ISTCORP-PC 192.168.7.44 Brother MFC-9320CW Printer JIM-WIN8 192.168.6.81 Brother HL-6180DW series Lalexander-PC Printer 192.168.6.81 Brother MFC-9320CW Printer Lalexander-PC 192.168.7.95 hp LaserJet 1320 PCL 5 Mmichaels-HP 192.168.6.30 Brother MFC-9320CW Printer Mwest-WIN864

PROPRIETARY & CONFIDENTIAL PAGE 62 of 253 Full Detail Report NETWORK ASSESSMENT

IP Address Printer Name Accessed From Location Comment 192.168.6.30 Dev office printer Mwest-WIN864 Administrator 192.168.7.99 Brother HL-6180DW PS01 192.168.7.99 Brother MFC-9320CW Printer PS01 169.254.197.112, Brother HL-6180DW series Psolidad-PC 192.168.6.12 Printer 192.168.6.14 Brother HL-6180DW series Psolidad-WIN764 Printer 192.168.6.195 SEC30CDA792322C tarsis Administrator 192.168.7.49 HP Officejet Pro 8600 tywin-PC 192.168.6.52 SEC30CDA792322C WILLARD Administrator

Networked (from SNMP)

IP Address Printer Name Hostname Description Alerts 192.168.1.243 SEC30CDA792322C SEC30CDA792322C.CORP.m Samsung Samsung M283x yco.COM Series; V3.00.01.04 JUN-19- 2014;Engine V1.00.10 06-10- 2014;NIC V6.01.01;S/N 075WB8GFCF0027R 192.168.1.244 BRN30055C36B0DA Brother NC-8300h, Firmware Sleep Ver.1.12 (13.11.13),MID 84U- D17 192.168.1.245 Brother NC-6700h, Firmware Toner Low Black(K) Ver.0.30 (09.06.25),MID 8CE- 217,FID 2 192.168.6.93 HP25833F HP25833F.CORP.myco.COM HP ETHERNET MULTI- 65561 65561 65561 65561 ENVIRONMENT

CORP.MYCO.COM (from Shares)

PROPRIETARY & CONFIDENTIAL PAGE 63 of 253 Full Detail Report NETWORK ASSESSMENT

Share Permissions Shared Printer User/Group Full Control Change Read \\ISTCORP-PC\Brother MFC-9320CW Printer Istcorp-PC\Istcorp    (Brother MFC-9320CW Printer,LocalsplOnly) Everyone    APPLICATION PACKAGE AUTHORITY\ALL    APPLICATION PACKAGES BUILTIN\Administrators    \\PS01\Brother HL-6180DW Everyone    (Brother HL-6180DW,LocalsplOnly) APPLICATION PACKAGE AUTHORITY\ALL    APPLICATION PACKAGES BUILTIN\Administrators    \\PS01\Brother MFC-9320CW Printer S-1-5-21-356494474-603968661-3470298851-18619    (Brother MFC-9320CW Printer,LocalsplOnly) Everyone    APPLICATION PACKAGE AUTHORITY\ALL    APPLICATION PACKAGES BUILTIN\Administrators   

PROPRIETARY & CONFIDENTIAL PAGE 64 of 253 Full Detail Report NETWORK ASSESSMENT 7 - Network Shares

This section contains a listing of all network shares categorized first by domain or workgroup membership, and then by machine.

CORP.MYCO.COM

Hosted By Share UNC b2b-GW \\b2b-GW\ADMIN$, \\b2b-GW\C$, \\b2b-GW\IPC$, \\b2b-GW\accts betty-INSPIRON \\betty-INSPIRON\ADMIN$, \\betty-INSPIRON\C$, \\betty-INSPIRON\IPC$ Boppenheimer-PC \\Boppenheimer-PC\ADMIN$, \\Boppenheimer-PC\C$, \\Boppenheimer-PC\IPC$, \\Boppenheimer-PC\Shared, \\Boppenheimer-PC\sharedsub buildbox \\buildbox\ADMIN$, \\buildbox\C$, \\buildbox\IPC$ CERTEXAM \\CERTEXAM\ADMIN$, \\CERTEXAM\C$, \\CERTEXAM\IPC$ CONFERENCE-ROOM \\CONFERENCE-ROOM\ADMIN$, \\CONFERENCE-ROOM\C$, \\CONFERENCE-ROOM\IPC$ darkhorse \\darkhorse\ADMIN$, \\darkhorse\C$, \\darkhorse\IPC$, \\darkhorse\download, \\darkhorse\projects darren-PC \\darren-PC\ADMIN$, \\darren-PC\C$, \\darren-PC\D$, \\darren-PC\IPC$ DC03 \\DC03\ADMIN$, \\DC03\C$, \\DC03\IPC$, \\DC03\NETLOGON, \\DC03\SYSVOL, \\DC03\Tech, \\DC03\accts Ddouglas-WIN10 \\Ddouglas-WIN10\ADMIN$, \\Ddouglas-WIN10\C$, \\Ddouglas-WIN10\D$, \\Ddouglas-WIN10\IPC$ DESKTOP-N6S4H9A \\DESKTOP-N6S4H9A\ADMIN$, \\DESKTOP-N6S4H9A\C$, \\DESKTOP-N6S4H9A\IPC$ DESKTOP-UAE29E6 \\DESKTOP-UAE29E6\ADMIN$, \\DESKTOP-UAE29E6\C$, \\DESKTOP-UAE29E6\IPC$, \\DESKTOP- UAE29E6\print$ FILE2012-1 \\FILE2012-1\ADMIN$, \\FILE2012-1\Backups, \\FILE2012-1\C$, \\FILE2012-1\H$, \\FILE2012-1\Hyper-V, \\FILE2012-1\IPC$, \\FILE2012-1\Witness gordon-LT2 \\gordon-LT2\ADMIN$, \\gordon-LT2\C$, \\gordon-LT2\IPC$ HPDT-8CC5260NXY \\HPDT-8CC5260NXY\ADMIN$, \\HPDT-8CC5260NXY\C$, \\HPDT-8CC5260NXY\IPC$ HPLT-5CD4411D8Z \\HPLT-5CD4411D8Z\ADMIN$, \\HPLT-5CD4411D8Z\C$, \\HPLT-5CD4411D8Z\IPC$ HV00 \\HV00\ClusterStorage$, \\HV00\IPC$ HV02 \\HV02\ADMIN$, \\HV02\C$, \\HV02\H$, \\HV02\IPC$ HV04 \\HV04\ADMIN$, \\HV04\C$, \\HV04\H$, \\HV04\IPC$, \\HV04\Temp IRIDIUM \\IRIDIUM\ADMIN$, \\IRIDIUM\C$, \\IRIDIUM\IPC$

PROPRIETARY & CONFIDENTIAL PAGE 65 of 253 Full Detail Report NETWORK ASSESSMENT

Hosted By Share UNC ISTCORP-PC \\ISTCORP-PC\ADMIN$, \\ISTCORP-PC\Brother MFC-9320CW Printer, \\ISTCORP-PC\C$, \\ISTCORP-PC\IPC$, \\ISTCORP-PC\accts, \\ISTCORP-PC\print$ JIM-WIN8 \\JIM-WIN8\ADMIN$, \\JIM-WIN8\C$, \\JIM-WIN8\IPC$, \\JIM-WIN8\download, \\JIM-WIN8\print$ Lalexander-PC \\Lalexander-PC\ADMIN$, \\Lalexander-PC\C$, \\Lalexander-PC\D$, \\Lalexander-PC\IPC$ Mmichaels-HP \\Mmichaels-HP\ADMIN$, \\Mmichaels-HP\C$, \\Mmichaels-HP\D$, \\Mmichaels-HP\E$, \\Mmichaels-HP\IPC$, \\Mmichaels-HP\print$ Mwest-WIN864 \\Mwest-WIN864\ADMIN$, \\Mwest-WIN864\C$, \\Mwest-WIN864\IPC$, \\Mwest-WIN864\Share, \\Mwest- WIN864\print$, \\Mwest-WIN864\xdrive PANOPTICON \\PANOPTICON\ADMIN$, \\PANOPTICON\C$, \\PANOPTICON\IPC$ PITWDS12 \\PITWDS12\ADMIN$, \\PITWDS12\C$, \\PITWDS12\D$, \\PITWDS12\IPC$, \\PITWDS12\REMINST PKWIN8-VM \\PKWIN8-VM\ADMIN$, \\PKWIN8-VM\C$, \\PKWIN8-VM\IPC$, \\PKWIN8-VM\print$ PS01 \\PS01\ADMIN$, \\PS01\Brother HL-6180DW, \\PS01\Brother MFC-9320CW Printer, \\PS01\C$, \\PS01\IPC$, \\PS01\print$ Psolidad-PC \\Psolidad-PC\ADMIN$, \\Psolidad-PC\C$, \\Psolidad-PC\IPC$, \\Psolidad-PC\RFT_reports, \\Psolidad- PC\Reports, \\Psolidad-PC\accts, \\Psolidad-PC\print$, \\Psolidad-PC\share Psolidad-WIN764 \\Psolidad-WIN764\ADMIN$, \\Psolidad-WIN764\C$, \\Psolidad-WIN764\IPC$, \\Psolidad-WIN764\print$ QB01 \\QB01\ADMIN$, \\QB01\C$, \\QB01\Data, \\QB01\F$, \\QB01\IPC$, \\QB01\Packaged Programs REX \\REX\ADMIN$, \\REX\C$, \\REX\D$, \\REX\E$, \\REX\IPC$, \\REX\NDApplianceSetupFiles, \\REX\accts, \\REX\download, \\REX\print$, \\REX\soucesafe ROWBOT \\ROWBOT\ADMIN$, \\ROWBOT\C$, \\ROWBOT\IPC$, \\ROWBOT\J$, \\ROWBOT\K$ SARLACC \\SARLACC\ADMIN$, \\SARLACC\C$, \\SARLACC\IPC$ sourcesvr \\sourcesvr\ADMIN$, \\sourcesvr\C$, \\sourcesvr\IPC$ sourcesvrBUILD \\sourcesvrBUILD\ADMIN$, \\sourcesvrBUILD\C$, \\sourcesvrBUILD\IPC$, \\sourcesvrBUILD\X$ STORAGE01 \\STORAGE01\ADMIN$, \\STORAGE01\C$, \\STORAGE01\D$, \\STORAGE01\F$, \\STORAGE01\IPC$, \\STORAGE01\accts$ STORAGE12 \\STORAGE12\ADMIN$, \\STORAGE12\C$, \\STORAGE12\ClientApps, \\STORAGE12\Common, \\STORAGE12\D$, \\STORAGE12\IPC$ tarsis \\tarsis\ADMIN$, \\tarsis\C$, \\tarsis\IPC$ tywin-PC \\tywin-PC\ADMIN$, \\tywin-PC\C$, \\tywin-PC\IPC$, \\tywin-PC\Z$ UTIL12 \\UTIL12\ADMIN$, \\UTIL12\C$, \\UTIL12\IPC$ VPNGW \\VPNGW\ADMIN$, \\VPNGW\C$, \\VPNGW\IPC$

PROPRIETARY & CONFIDENTIAL PAGE 66 of 253 Full Detail Report NETWORK ASSESSMENT

Hosted By Share UNC WAMPA \\WAMPA\ADMIN$, \\WAMPA\C$, \\WAMPA\E$, \\WAMPA\F$, \\WAMPA\H$, \\WAMPA\IPC$, \\WAMPA\O$, \\WAMPA\marion WILLARD \\WILLARD\ADMIN$, \\WILLARD\C$, \\WILLARD\D$, \\WILLARD\IPC$

PROPRIETARY & CONFIDENTIAL PAGE 67 of 253 Full Detail Report NETWORK ASSESSMENT 8 - Major Applications

This section contains a listing of major applications with corresponding version numbers and the number of computers the application was detected on. Applications that appear on more than three computers are highlighted in gray for easy recognition.

CORP.MYCO.COM

Windows Applications

Application Name Version # Computers Computers 7-Zip 16.00 (x64) 16.00 1 Boppenheimer-PC 7-Zip 16.02 (x64 edition) 16.02 2 Boppenheimer-PC, WILLARD 7-Zip 16.02 (x64) 16.02 10 darkhorse, DESKTOP-N6S4H9A, JIM-WIN8, ... 7-Zip 16.04 (x64) 16.04 1 IRIDIUM 7-Zip 9.20 1 Psolidad-WIN764 7-Zip 9.20 (x64 edition) 9.20 1 Psolidad-WIN764 Acer eSettings Management 3.00 1 Psolidad-PC Acer Framework 3.00 1 Psolidad-PC Acer Office Manager Agent 1.00 1 Psolidad-PC Acer Office Manager Console 1.00 1 Psolidad-PC Acer Power Management 7.00 1 Psolidad-PC Acer Recovery Management 6.00 1 Psolidad-PC Acer reg 2.00 1 Psolidad-PC Acer SmartBoot 1.00 1 Psolidad-PC Active Directory Rights Management Services Client 2.1 1.0 1 sourcesvr Adam Instance ISASTGCTRL 1 ISA1 ADManager Plus Free Tools 4.0 1 Psolidad-WIN764 Administrative Templates (ADMX) for 1.0 1 darkhorse Adobe Acrobat 9 Pro - English, Français, Deutsch 9.0 1 REX

PROPRIETARY & CONFIDENTIAL PAGE 68 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers Adobe Acrobat 9 Pro - English, Français, Deutsch 9.5 1 Psolidad-WIN764 Adobe Acrobat 9.5.5 - CPSID_83708 1 Psolidad-WIN764 Adobe Acrobat DC 15.020 2 Ddouglas-WIN10, tywin-PC Adobe Acrobat Reader DC 15.020 3 HPDT-8CC5260NXY, ISTCORP-PC, Psolidad- PC Adobe Acrobat XI Pro 11.0 2 ISTCORP-PC, IRIDIUM Adobe AIR 1.5 1 Psolidad-WIN764 Adobe AIR 14.0 1 Mmichaels-HP Adobe AIR 23.0 2 JIM-WIN8, Psolidad-PC Adobe Community Help 3.0 3 JIM-WIN8, Psolidad-PC, Psolidad-WIN764 Adobe Community Help 3.4 1 Mmichaels-HP Adobe CreatePDF Desktop Printer 13.2 1 ISTCORP-PC Adobe Creative Cloud 3.3 1 Mmichaels-HP Adobe Creative Cloud 3.7 1 tywin-PC Adobe Creative Suite 5 Master Collection 5.0 3 JIM-WIN8, Psolidad-PC, Psolidad-WIN764 Adobe Download Assistant 1.2 1 ISTCORP-PC Adobe Dreamweaver CS5.5 11.5 1 Mmichaels-HP Adobe Flash Player 11 ActiveX 11.1 1 STORAGE01 Adobe Flash Player 11 ActiveX 11.3 1 QB01 Adobe Flash Player 11 Plugin 11.4 1 Psolidad-WIN764 Adobe Flash Player 17 ActiveX 17.0 1 gordon-LT2 Adobe Flash Player 23 NPAPI 23.0 2 ISTCORP-PC, JIM-WIN8 Adobe Illustrator CS 11 1 ISTCORP-PC Adobe InDesign CC 2015 11.3 1 tywin-PC Adobe Media Player 1.8 3 JIM-WIN8, Psolidad-PC, Psolidad-WIN764 Adobe Photoshop CC 14.0 1 Mmichaels-HP Adobe Photoshop CC 2014 15.1 1 Mmichaels-HP Adobe Photoshop CC 2015 16.1 1 tywin-PC Adobe Reader XI (11.0.17) 11.0 1 Mmichaels-HP

PROPRIETARY & CONFIDENTIAL PAGE 69 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers Adobe Reader XI (11.0.18) 11.0 1 JIM-WIN8 Adobe Reader XI (11.0.18) MUI 11.0 1 gordon-LT2 Adobe SVG Viewer 3.0 3.0 1 ISTCORP-PC Adobe Widget Browser 2.0 Build 230 1 Mmichaels-HP Advanced IP Scanner 2.4 2.4 1 Psolidad-PC AIM for Windows 1 tarsis Akamai NetSession Interface 1 ISTCORP-PC Alcor Micro USB Card Reader Driver 18.6 1 IRIDIUM ALPS Touch Pad Driver 8.1202 1 HPLT-5CD4411D8Z Altaro VM Backup 6.0 1 HV00 Altaro VM Backup 6.5 1 FILE2012-1 AMD Catalyst Control Center 1.00 1 Ddouglas-WIN10 AMD Catalyst Install Manager 8.0 3 Psolidad-WIN764, Mwest-WIN864, REX AnalogX Proxy 1 REX AnalogX Proxy 4.15 1 JIM-WIN8 Android SDK Tools 1.16 2 PANOPTICON, WILLARD APITester 1.0 1 Psolidad-PC AppFabric 1.1 for Windows Server 1.1 1 sourcesvr Apple Application Support 2.3 1 ISTCORP-PC Apple Application Support 3.0 1 Mmichaels-HP Apple Application Support (32-bit) 4.3 1 DESKTOP-N6S4H9A Apple Application Support (64-bit) 4.3 1 DESKTOP-N6S4H9A Apple Mobile Device Support 9.3 1 DESKTOP-N6S4H9A Apple Software Update 2.1 1 Mmichaels-HP Apple Software Update 2.2 1 DESKTOP-N6S4H9A Application Insights Tools for Visual Studio 2015 7.0 7 darkhorse, Mwest-WIN864, PANOPTICON, ... Application Verifier (x64) 4.0 1 REX Atheros Outlook Addin 2010 1.0 1 darkhorse

PROPRIETARY & CONFIDENTIAL PAGE 70 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers Audacity 2.1.0 2.1 1 DESKTOP-N6S4H9A Avast Free Antivirus 12.3 1 Boppenheimer-PC AWS Tools for Windows 3.9 1 WAMPA Belarc Advisor 8.5c 8.5 1 Boppenheimer-PC Bitdefender Endpoint Security Tools 6.2 1 UTIL12 BitTorrent 7.9 1 IRIDIUM BOINC 7.6 1 IRIDIUM Bomgar Representative Client [nsremote.westridge.com] 2 JIM-WIN8, Mwest-WIN864 Bonjour 3.0 3 ISTCORP-PC, Mmichaels-HP, Psolidad- WIN764 Bonjour 3.1 1 DESKTOP-N6S4H9A BovadaPoker 1 ISTCORP-PC BRAdmin Professional 3 3.47 1 ISTCORP-PC Broadcom NetXtreme II Driver Installer 15.6 1 HV00 Brother MFL-Pro Suite MFC-9320CW 1.0 1 ISTCORP-PC Brother MFL-Pro Suite MFC-9320CW 3.0 1 Psolidad-WIN764 Brother P-touch Editor 5.0 5.0 1 Psolidad-WIN764 Brother P-touch Update Software 1.0 1 Psolidad-WIN764 BrowserSafeguard with RocketTab 1 ISTCORP-PC Camtasia Studio 8 8.6 1 IRIDIUM Catalina Savings Printer 1.0 1 ISTCORP-PC Catalyst Control Center 1.00 1 REX CCleaner 4.12 1 JIM-WIN8 CCleaner 4.13 1 HV00 Cirrus Insight for Outlook 1.8 2 gordon-LT2, HPDT-8CC5260NXY Cisco AnyConnect VPN Client 2.5 1 Psolidad-WIN764 Cisco WebEx Meetings 6 Boppenheimer-PC, ISTCORP-PC, Mmichaels-HP, ...

PROPRIETARY & CONFIDENTIAL PAGE 71 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers Citrix Online Launcher 1.0 16 Mwest-WIN864, Psolidad-WIN764, JIM-WIN8, ISTCORP-PC, Mmichaels-HP, Psolidad-PC, Boppenheimer-PC, DESKTOP-N6S4H9A, gordon-LT2, ... Citrix Receiver 13.4 1 Psolidad-WIN764 Citrix Receiver 4.5 14.5 1 Psolidad-PC Clang with Microsoft CodeGen for Microsoft Visual Studio 2015 14.0 3 PANOPTICON, WILLARD, ROWBOT Classic Shell 4.3 1 Mwest-WIN864 ConnectWise Internet Client 64-bit 15.1 1 JIM-WIN8 ConnectWise Internet Client 64-bit 15.4 1 ISTCORP-PC ConnectWise Internet Client 64-bit 16.6 2 tarsis, WAMPA ConnectWise Outlook 2010 Add-in 14.3 1 ISTCORP-PC ContentManager 0.5 1 ISTCORP-PC control and Deployment Kit 8.59 1 STORAGE01 Coupon Printer for Windows 5.0 1 ISTCORP-PC Crystal Reports 2008 Runtime SP2 12.2 1 Psolidad-WIN764 Crystal Reports Basic for Visual Studio 2008 10.5 1 Mwest-WIN864 Crystal Reports Basic Runtime for Visual Studio 2008 (x64) 10.5 1 Mwest-WIN864 CrystalDiskmax 3.0.3a 3.0 1 FILE2012-1 Curse 6.0 1 IRIDIUM CyberLink DVD Suite 6.0 1 ISTCORP-PC CyberLink Media Suite Essentials 12 1 IRIDIUM CyberLink PowerDVD 12 12.0 1 Psolidad-PC CyberLink YouCam 2.0 1 ISTCORP-PC DAEMON Tools Lite 4.47 1 Psolidad-WIN764 Debugging Tools for Windows (x64) 6.11 1 REX Dell Customer Connect 1.4 1 IRIDIUM Dell dbre | Power Manager 2.1 1 gordon-LT2 Dell dbre | Update 2.1 1 gordon-LT2

PROPRIETARY & CONFIDENTIAL PAGE 72 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers Dell Digital Delivery 3.1 2 gordon-LT2, IRIDIUM Dell Edoc Viewer 1.0 1 gordon-LT2 Dell Foundation Services 3.3 1 gordon-LT2 Dell Foundation Services 3.4 1 IRIDIUM Dell Help & Support 2.3 1 IRIDIUM Dell OpenManage BMC Utilities 8.2 1 HV02 Dell OpenManage Systems Management Software (64-Bit) 7.3 1 HV00 Dell OpenManage Systems Management Software (64-Bit) 7.4 1 FILE2012-1 Dell OpenManage Systems Management Software (64-Bit) 8.2 1 HV02 Dell Product reg 3.0 1 IRIDIUM Dell Protected Workspace 4.0 1 gordon-LT2 Dell SupportAssist 1.2 1 IRIDIUM Dell Touchpad 18.1 1 gordon-LT2 Dell Update 1.7 1 gordon-LT2 Dell Update 1.9 1 IRIDIUM DevExpress Components 14.1 14.1 10 buildbox, darkhorse, Mwest-WIN864, ... DevExpress Documentation 1 Mwest-WIN864 DisplayLink Core Software 7.5 1 Mmichaels-HP DotRas v1.3 SDK 1.3 1 REX Download Updater (AOL Inc.) 1 tarsis Dropbox 12.4 4 IRIDIUM, Psolidad-PC, Psolidad-WIN764, ... DVD Shrink 3.2 1 Psolidad-WIN764 eFax Messenger 4.4 1 ISTCORP-PC Entity Framework 6.1.1 Tools for Visual Studio 2013 12.0 4 Mwest-WIN864, REX, SARLACC, ... Entity Framework 6.1.3 Tools for Visual Studio 2013 12.0 1 buildbox Entity Framework 6.1.3 Tools for Visual Studio 2015 Update 1 14.0 7 darkhorse, Mwest-WIN864, PANOPTICON, ... Epic Privacy Browser 48.0 1 WAMPA ExamDiff 1.9 (Build 1.9.0.2) 1.9 1 JIM-WIN8

PROPRIETARY & CONFIDENTIAL PAGE 73 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers Express Scribe 5.59 1 Psolidad-WIN764 ExtraPutty 0.22 0.22 1 Psolidad-WIN764 ffdshow v1.1.3800 [2011-03-28] 1.1 1 ISTCORP-PC Fiddler 4.6 2 WILLARD, Mwest-WIN864 Fiddler Syntax-Highlighting Addons 1 WILLARD File Type Assistant 2014.3 1 ISTCORP-PC FileZilla Client 3.10.3 3.10 1 Mmichaels-HP FileZilla Client 3.11.0.2 3.11 1 REX FileZilla Client 3.20.1 3.20 1 darkhorse FileZilla Client 3.21.0 3.21 1 tarsis FileZilla Client 3.7.4.1 3.7 1 JIM-WIN8 Getif 2.3.1 1 Psolidad-WIN764 GFI Business Agent 6.2 2 DC03, ISA1 GIMP 2.8.18 2.8 3 Mwest-WIN864, ROWBOT, tarsis Git version 2.9.2 2.9 4 darkhorse, PANOPTICON, ROWBOT, ... GitHub 3.0 1 REX Google Chrome 54.0 21 HPDT-8CC5260NXY, ISTCORP-PC, JIM- WIN8, Boppenheimer-PC, darkhorse, Ddouglas-WIN10, ... Google Drive 1.31 3 Psolidad-PC, Psolidad-WIN764, REX Google Talk (remove only) 1 Psolidad-WIN764 Google Toolbar for 1.0 1 Mmichaels-HP Google+ Auto Backup 1.0 1 ISTCORP-PC GoToMeeting 7.24.0.5636 7.24 12 Boppenheimer-PC, gordon-LT2, HPDT- 8CC5260NXY, ... GoToMeeting 7.25.0.5742 7.25 2 DESKTOP-N6S4H9A, HPLT-5CD4411D8Z GoToMyPC 9.1 1 ISTCORP-PC grepWin x64 1.6 1 Mwest-WIN864 HiDef Media Player 1.1.12 1.1 1 ISTCORP-PC

PROPRIETARY & CONFIDENTIAL PAGE 74 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers HP acct Guides 0148 1.01 1 ISTCORP-PC HP Advisor 3.2 1 ISTCORP-PC HP DVD Play 3.7 3.7 1 ISTCORP-PC HP Games 1.0 1 ISTCORP-PC HP My Display 2.07 1 Mmichaels-HP HP Officejet Pro 8600 Basic Device Software 28.0 1 tywin-PC HP Officejet Pro 8600 Help 28.0 1 tywin-PC HP Officejet Pro 8600 Product Improvement Study 28.0 1 tywin-PC HP Officejet Pro 8610 Basic Device Software 32.3 1 Ddouglas-WIN10 HP Officejet Pro 8610 Help 32.0 1 Ddouglas-WIN10 HP Product Detection 11.14 1 ISTCORP-PC HP Quick Launch Buttons 6.50 1 ISTCORP-PC HP Setup 1.2 1 ISTCORP-PC HP Smart Web Printing 4.60 4.60 1 ISTCORP-PC HP Support Assistant 8.3 1 tywin-PC HP Support Solutions Framework 12.5 2 HPLT-5CD4411D8Z, tywin-PC HP Update 5.001 1 ISTCORP-PC HP Update 5.005 2 Ddouglas-WIN10, tywin-PC HP Wireless Assistant 3.50 1 ISTCORP-PC HTC BMP USB Driver 1.0 1 ISTCORP-PC Hyper-V Integration Services (version 6.2.9600.16384) 3.9600 1 ISA1 I.R.I.S. OCR 12.3 2 Ddouglas-WIN10, tywin-PC ICCHelp 19.00 1 Ddouglas-WIN10 iCloud 4.0 1 Mmichaels-HP Iconix eMail ID 1.0 1 ISTCORP-PC Identity Card 2.00 1 Psolidad-PC IDrive Version - 6.0 6.0 1 Psolidad-WIN764 IDT Audio 1.0 1 ISTCORP-PC

PROPRIETARY & CONFIDENTIAL PAGE 75 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers Ignite UI 2014.1 14.1 1 Mwest-WIN864 Ignite UI 2014.1 Samples 14.1 1 Mwest-WIN864 IIS 10.0 Express 192.168 7 darkhorse, Mwest-WIN864, PANOPTICON, ... IIS 8.0 Express 8.0 4 buildbox, REX, SARLACC, ... IIS Express Application Compatibility Database for x64 10 buildbox, darkhorse, Mwest-WIN864, ... IIS Express Application Compatibility Database for x86 11 buildbox, darkhorse, Mwest-WIN864, ... ILMerge 2.12 2 darkhorse, REX Infragistics ASP.NET 2014.1 14.1 1 Mwest-WIN864 Infragistics ASP.NET 2014.1 Samples 14.1 1 Mwest-WIN864 Infragistics Developer Tools 2015.2 15.2 1 Mwest-WIN864 Infragistics NetAdvantage SharePoint 2012.2 12.2 1 Mwest-WIN864 Infragistics Reporting 2014.1 14.1 1 Mwest-WIN864 Infragistics Reporting 2014.1 Samples 14.1 1 Mwest-WIN864 Infragistics Silverlight 2014.1 14.1 1 Mwest-WIN864 Infragistics Silverlight 2014.1 Samples 14.1 1 Mwest-WIN864 Infragistics Version Utility 2014.1 14.1 1 Mwest-WIN864 Infragistics Visual Studio Extension 2014.1 14.1 1 Mwest-WIN864 Infragistics Windows Forms 2014.1 14.1 1 Mwest-WIN864 Infragistics Windows Forms 2014.1 Samples 14.1 1 Mwest-WIN864 Infragistics Windows UI - WinJS 2013.2 13.2 1 Mwest-WIN864 Infragistics Windows UI - XAML 2014.1 14.1 1 Mwest-WIN864 Infragistics WPF 2014.1 14.1 1 Mwest-WIN864 Infragistics WPF 2014.1 Samples 14.1 1 Mwest-WIN864 Intel(R) Control Center 1.2 1 Psolidad-PC Intel(R) Graphics Media Accelerator Driver 8.15 1 ISTCORP-PC Intel(R) Management Engine Components 11.0 2 HPLT-5CD4411D8Z, IRIDIUM Intel(R) Management Engine Components 192.168 1 gordon-LT2 Intel(R) Management Engine Components 9.0 1 Psolidad-PC

PROPRIETARY & CONFIDENTIAL PAGE 76 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers Intel(R) Processor Graphics 10.18 4 JIM-WIN8, Mmichaels-HP, Psolidad-PC, HPLT-5CD4411D8Z, ... Intel(R) Processor Graphics 20.19 3 gordon-LT2, HPDT-8CC5260NXY, darkhorse Intel(R) Processor Graphics 9.17 1 Mwest-WIN864 Intel(R) Rapid Storage Technology 12.6 1 Psolidad-PC Intel(R) Rapid Storage Technology 13.2 1 gordon-LT2 Intel(R) Rapid Storage Technology 14.5 4 darkhorse, PANOPTICON, tarsis, ... Intel(R) Rapid Storage Technology 14.8 1 IRIDIUM Intel(R) Ready Mode Technology 1.1 1 IRIDIUM Intel(R) redi Connections 18.1.59.0 18.1 1 Psolidad-PC Intel(R) redi Connections Drivers 20.2 1 IRIDIUM Intel(R) SDK for OpenCL - CPU Only Runtime Package 3.0 1 Psolidad-PC Intel(R) Serial IO 30.100 4 darkhorse, PANOPTICON, tarsis, ... Intel(R) Small Business Advantage 2.0 1 Psolidad-PC Intel(R) Update Manager 3.4 1 gordon-LT2 Intel(R) USB 3.0 eXtensible Host Controller Driver 3.0 1 gordon-LT2 Intel(R) WiDi 5.1 1 gordon-LT2 Intel(R) Wireless Bluetooth(R) 18.1 1 IRIDIUM Intel(R) Wireless Bluetooth(R)(patch version 17.1.1506.563) 17.1 1 gordon-LT2 Intel Driver Update Utility 2.6 1 Boppenheimer-PC Intel PROSet/Wireless Software 17.15 1 gordon-LT2 Intel PROSet/Wireless Software 18.32 1 IRIDIUM Intel Security Assist 1.0 2 HPLT-5CD4411D8Z, IRIDIUM Intuit SiteBuilder 1 ISTCORP-PC iSEEK AnswerWorks English Runtime 010.000 1 ISTCORP-PC iTunes 12.4 1 DESKTOP-N6S4H9A Java 7 Update 60 7.0 1 Psolidad-WIN764 Java 8 Update 111 8.0 1 PKWIN8-VM Java 8 Update 31 8.0 1 ISTCORP-PC

PROPRIETARY & CONFIDENTIAL PAGE 77 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers Java 8 Update 31 (64-bit) 8.0 1 ISTCORP-PC Java 8 Update 40 8.0 1 JIM-WIN8 Java 8 Update 73 8.0 1 Psolidad-PC Java SE Development Kit 7 Update 55 1.7 3 PANOPTICON, ROWBOT, WILLARD JavaFX 2.1.1 2.1 1 Psolidad-WIN764 join.me 1.16 1 JIM-WIN8 join.me 3.0 2 Mmichaels-HP, DESKTOP-N6S4H9A Juniper redis redi Connect 6.4.0 6.4 1 Psolidad-WIN764 Juniper redis Setup Client 2.0 2 JIM-WIN8, Psolidad-WIN764 Juniper redis Setup Client Activex Control 2.0 2 JIM-WIN8, Psolidad-WIN764 Kaspersky Security Scan 16.0 1 REX Kaspersky Software Updater Beta 1.5 1 REX Kernel for OST to PST ver 11.07.01 2 ISTCORP-PC, Psolidad-WIN764 LAME v3.99.3 (for Windows) 1 DESKTOP-N6S4H9A LightScribe System Software 1.18 1 ISTCORP-PC Lightshot-5.3.0.0 5.3 1 Boppenheimer-PC Lightshot-5.4.0.1 5.4 1 DESKTOP-N6S4H9A Live Updater 2.00 1 Psolidad-PC Logitech Gaming Software 8.83 8.83 1 Boppenheimer-PC LogMeIn 4.1 2 Mwest-WIN864, Psolidad-WIN764 LogMeIn Client 1.3 1 Mwest-WIN864 LSI HDA Modem 2.1 1 ISTCORP-PC Malwarebytes Anti-Malware version 2.0.3.1025 2.0 1 Mwest-WIN864 Malwarebytes Anti-Malware version 2.2.0.1024 2.2 2 REX, sourcesvr Managed Switch Port Mapping Tool 2.55 2.55 1 Psolidad-PC Memeo Backup Premium 1 ISTCORP-PC Memeo LifeAgent Explorer Extension 1 ISTCORP-PC Microsoft .NET Compact Framework 2.0 SP2 2.0 1 Mwest-WIN864

PROPRIETARY & CONFIDENTIAL PAGE 78 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers Microsoft .NET Compact Framework 3.5 3.5 1 Mwest-WIN864 Microsoft .NET Core 1.0.0 - SDK Preview 2 (x64) 1.0 1 ROWBOT Microsoft .NET Core 1.0.0 - VS 2015 Tooling Preview 2 1.0 1 ROWBOT Microsoft .NET Framework 2.0 SDK - ENU 1 WAMPA Microsoft .NET Framework 2.0 Service Pack 2 2.2 1 ISA1 Microsoft .NET Framework 3.0 Service Pack 2 3.2 1 ISA1 Microsoft .NET Framework 3.5 SP1 1 ISA1 Microsoft .NET Framework 4 Multi-Targeting Pack 4.0 4 JIM-WIN8, Mwest-WIN864, PS01, ... Microsoft .NET Framework 4.5 4.5 1 b2b-GW Microsoft .NET Framework 4.5 Multi-Targeting Pack 4.5 11 buildbox, darkhorse, Mwest-WIN864, ... Microsoft .NET Framework 4.5 SDK 4.5 5 buildbox, Mwest-WIN864, REX, ... Microsoft .NET Framework 4.5.1 Multi-Targeting Pack 4.5 11 buildbox, darkhorse, Mwest-WIN864, ... Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) 4.5 11 buildbox, darkhorse, Mwest-WIN864, ... Microsoft .NET Framework 4.5.1 SDK 4.5 11 buildbox, darkhorse, Mwest-WIN864, ... Microsoft .NET Framework 4.5.2 4.5 2 QB01, STORAGE01 Microsoft .NET Framework 4.5.2 Multi-Targeting Pack 4.5 7 darkhorse, Mwest-WIN864, PANOPTICON, ... Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (ENU) 4.5 7 darkhorse, Mwest-WIN864, PANOPTICON, ... Microsoft .NET Framework 4.6 SDK 4.6 7 darkhorse, Mwest-WIN864, PANOPTICON, ... Microsoft .NET Framework 4.6 Targeting Pack 4.6 7 darkhorse, Mwest-WIN864, PANOPTICON, ... Microsoft .NET Framework 4.6 Targeting Pack (ENU) 4.6 7 darkhorse, Mwest-WIN864, PANOPTICON, ... Microsoft .NET Framework 4.6.1 4.6 1 gordon-LT2 Microsoft .NET Framework 4.6.1 (Français) 4.6 1 gordon-LT2 Microsoft .NET Framework 4.6.1 SDK 4.6 7 darkhorse, Mwest-WIN864, PANOPTICON, ... Microsoft .NET Framework 4.6.1 Targeting Pack 4.6 7 darkhorse, Mwest-WIN864, PANOPTICON, ... Microsoft .NET Framework 4.6.1 Targeting Pack (ENU) 4.6 7 darkhorse, Mwest-WIN864, PANOPTICON, ... Microsoft .NET Framework 4.6.2 SDK 4.6 1 tarsis Microsoft .NET Framework 4.6.2 Targeting Pack 4.6 1 tarsis Microsoft .NET Version Manager (x64) 1.0.0-beta5 1.0 6 darkhorse, Mwest-WIN864, PANOPTICON, ...

PROPRIETARY & CONFIDENTIAL PAGE 79 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers Microsoft .NET Version Manager (x64) 1.0.0-rc1 1.0 1 ROWBOT Microsoft ASP.NET 2.0 AJAX Extensions 1.0 1.0 1 Mwest-WIN864 Microsoft ASP.NET 2.0 AJAX Templates for Visual Studio 2008 2.0 1 Mwest-WIN864 Microsoft ASP.NET MVC 2 2.0 1 Mwest-WIN864 Microsoft ASP.NET MVC 4 Runtime 4.0 4 Mwest-WIN864, REX, SARLACC, ... Microsoft Azure PowerShell - February 2016 1.2 1 Psolidad-PC Microsoft Azure PowerShell - September 2016 2.1 1 PKWIN8-VM Microsoft Baseline Security Analyzer 2.3 2.3 10 DC03, JIM-WIN8, Psolidad-WIN764, b2b-GW, Boppenheimer-PC, darkhorse, ... Microsoft CCR and DSS Runtime 2008 R3 2.2 1 sourcesvr Microsoft Device Emulator (64 bit) version 3.0 - ENU 9.0 1 Mwest-WIN864 Microsoft Document Explorer 2005 1 Mwest-WIN864 Microsoft Document Explorer 2008 2 Mwest-WIN864, REX Microsoft Emulator - Windows 192.168.14393.0 10.1 1 ROWBOT Microsoft Help Viewer 1.1 1.1 6 darkhorse, Mwest-WIN864, PS01, ... Microsoft Help Viewer 2.1 2.1 5 buildbox, Mwest-WIN864, REX, ... Microsoft Help Viewer 2.2 2.2 7 darkhorse, Mwest-WIN864, PANOPTICON, ... Microsoft Identity Extensions 2.0 1 sourcesvr Microsoft ISA Server 2006 5.0 1 ISA1 Microsoft Lync 2010 4.0 3 JIM-WIN8, Mwest-WIN864, Psolidad-WIN764 Microsoft Message Analyzer 4.0 1 PKWIN8-VM Microsoft Mouse and Keyboard Center 2.0 1 ISTCORP-PC Microsoft ODBC Driver 11 for SQL Server 12.0 2 PS01, WILLARD Microsoft ODBC Driver 11 for SQL Server 13.0 1 Mwest-WIN864 Microsoft ODBC Driver 13 for SQL Server 13.0 2 PANOPTICON, WAMPA Microsoft Office 365 - en-us 16.0 1 IRIDIUM Microsoft Office 365 ProPlus - en-us 15.0 4 JIM-WIN8, ISTCORP-PC, Mwest-WIN864, PKWIN8-VM, ...

PROPRIETARY & CONFIDENTIAL PAGE 80 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers Microsoft Office 365 ProPlus - en-us 16.0 13 betty-INSPIRON, darkhorse, gordon-LT2, buildbox, Ddouglas-WIN10, IRIDIUM, ... Microsoft Office 365 Support and Recovery Assistant 16.0 1 Psolidad-PC Microsoft Office Developer Tools for Visual Studio 2013 12.0 1 buildbox Microsoft Office Professional Plus 2010 14.0 4 b2b-GW, ISTCORP-PC, JIM-WIN8, Psolidad- WIN764, ... Microsoft Office Professional Plus 2013 15.0 7 Boppenheimer-PC, DESKTOP-N6S4H9A, Mmichaels-HP, ... Microsoft Office Professional Plus 2016 - en-us 16.0 2 buildbox, ROWBOT Microsoft OneDrive 17.3 3 gordon-LT2, Psolidad-WIN764, REX Microsoft Online Services Module for Windows PowerShell 1.0 2 Mwest-WIN864, Psolidad-WIN764 Microsoft Online Services Sign In 1.0 1 ISTCORP-PC Microsoft Online Services Sign-in Assistant 7.250 11 Mwest-WIN864, ISTCORP-PC, Psolidad- WIN764, JIM-WIN8, b2b-GW, Boppenheimer- PC, darkhorse, ... Microsoft Project Professional 2013 15.0 1 tarsis Microsoft redi Monitor 3.4 3.4 1 DC03 Microsoft redi Monitor: rediMonitor Parsers 3.4 3.4 1 DC03 Microsoft Report Viewer 2012 Runtime 11.0 3 darkhorse, REX, sourcesvr Microsoft Report Viewer 2014 Runtime 12.0 2 PS01, WILLARD Microsoft Report Viewer for SQL Server 2016 13.0 2 PANOPTICON, WAMPA Microsoft Report Viewer for SQL Server 2016 CTP3.3 13.0 1 Mwest-WIN864 Microsoft Security Essentials 4.10 1 gordon-LT2 Microsoft SharePoint Foundation 2013 15.0 1 sourcesvr Microsoft Silverlight 5.1 17 buildbox, darkhorse, PANOPTICON, JIM- WIN8, Mwest-WIN864, PITWDS12, WAMPA, gordon-LT2, Psolidad-WIN764, QB01, ... Microsoft Silverlight 3 SDK 3.0 1 Mwest-WIN864 Microsoft Silverlight 4 SDK 4.0 1 Mwest-WIN864 Microsoft Silverlight 5 SDK 5.0 7 buildbox, Mwest-WIN864, PANOPTICON, ... Microsoft SQL Server 2016 Policies CTP3.3 13.0 1 Mwest-WIN864

PROPRIETARY & CONFIDENTIAL PAGE 81 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers Microsoft SQL Server 2016 T-SQL Language Service CTP3.3 13.0 1 Mwest-WIN864 Microsoft SQL Server 2005 2 Mwest-WIN864, STORAGE01 Microsoft SQL Server 2005 Compact Edition [ENU] 3.1 2 Ddouglas-WIN10, tywin-PC Microsoft SQL Server 2008 (64-bit) 1 Mwest-WIN864 Microsoft SQL Server 2008 Browser 10.1 1 Mwest-WIN864 Microsoft SQL Server 2008 Management Objects 192.168 2 PKWIN8-VM, STORAGE01 Microsoft SQL Server 2008 Native Client 10.1 1 Mwest-WIN864 Microsoft SQL Server 2008 R2 Data-Tier Application Framework 10.50 1 Mwest-WIN864 Microsoft SQL Server 2008 R2 Data-Tier Application Project 10.50 1 Mwest-WIN864 Microsoft SQL Server 2008 R2 Management Objects 10.50 1 Mwest-WIN864 Microsoft SQL Server 2008 R2 Management Objects 10.51 5 darkhorse, PS01, REX, ... Microsoft SQL Server 2008 R2 Management Objects (x64) 10.50 1 Mwest-WIN864 Microsoft SQL Server 2008 R2 Management Objects (x64) 10.51 3 HV02, STORAGE01, UTIL12 Microsoft SQL Server 2008 R2 Native Client 10.51 1 sourcesvr Microsoft SQL Server 2008 R2 Native Client 10.52 1 b2b-GW Microsoft SQL Server 2008 R2 Transact-SQL Language Service 10.50 1 Mwest-WIN864 Microsoft SQL Server 2008 Setup Support Files 10.1 5 darkhorse, Ddouglas-WIN10, Mwest- WIN864, ... Microsoft SQL Server 2008 Setup Support Files 10.3 2 PS01, WILLARD Microsoft SQL Server 2012 1 Ddouglas-WIN10 Microsoft SQL Server 2012 (64-bit) 3 darkhorse, REX, sourcesvr Microsoft SQL Server 2012 Data-Tier App Framework 11.1 6 sourcesvr, buildbox, Mwest-WIN864, REX, ... Microsoft SQL Server 2012 Data-Tier App Framework (x64) 11.1 4 buildbox, Mwest-WIN864, REX, ... Microsoft SQL Server 2012 dbre Line Utilities 11.0 6 darkhorse, PANOPTICON, ROWBOT, ... Microsoft SQL Server 2012 dbre Line Utilities 11.1 5 buildbox, Mwest-WIN864, REX, ... Microsoft SQL Server 2012 Express LocalDB 11.1 5 buildbox, Mwest-WIN864, SARLACC, REX, ... Microsoft SQL Server 2012 Management Objects 11.0 1 sourcesvr

PROPRIETARY & CONFIDENTIAL PAGE 82 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers Microsoft SQL Server 2012 Management Objects 11.1 5 buildbox, Mwest-WIN864, REX, ... Microsoft SQL Server 2012 Management Objects 11.2 1 Ddouglas-WIN10 Microsoft SQL Server 2012 Management Objects (x64) 11.0 1 sourcesvr Microsoft SQL Server 2012 Management Objects (x64) 11.1 4 buildbox, Mwest-WIN864, REX, ... Microsoft SQL Server 2012 Native Client 11.0 4 PS01, ROWBOT, tarsis, ... Microsoft SQL Server 2012 Native Client 11.1 6 buildbox, darkhorse, REX, ... Microsoft SQL Server 2012 Native Client 11.2 2 Ddouglas-WIN10, Mwest-WIN864 Microsoft SQL Server 2012 Native Client 11.3 2 PANOPTICON, WAMPA Microsoft SQL Server 2012 Policies 11.0 3 darkhorse, REX, sourcesvr Microsoft SQL Server 2012 RS Add-in for SharePoint 11.1 1 sourcesvr Microsoft SQL Server 2012 Setup (English) 11.1 4 WAMPA, darkhorse, REX, sourcesvr, ... Microsoft SQL Server 2012 Setup (English) 11.2 1 Ddouglas-WIN10 Microsoft SQL Server 2012 T-SQL Language Service 11.0 1 sourcesvr Microsoft SQL Server 2012 T-SQL Language Service 11.1 5 buildbox, Mwest-WIN864, REX, ... Microsoft SQL Server 2012 Transact-SQL Compiler Service 11.1 3 darkhorse, REX, sourcesvr Microsoft SQL Server 2012 Transact-SQL ScriptDom 11.1 7 buildbox, darkhorse, Mwest-WIN864, ... Microsoft SQL Server 2012 Transact-SQL ScriptDom 11.2 1 Ddouglas-WIN10 Microsoft SQL Server 2014 (64-bit) 2 PS01, WILLARD Microsoft SQL Server 2014 Express LocalDB 12.0 5 buildbox, darkhorse, PANOPTICON, WILLARD, ... Microsoft SQL Server 2014 Management Objects 12.0 9 buildbox, darkhorse, Mwest-WIN864, ... Microsoft SQL Server 2014 Management Objects (x64) 12.0 9 buildbox, darkhorse, Mwest-WIN864, ... Microsoft SQL Server 2014 Policies 12.0 2 PS01, WILLARD Microsoft SQL Server 2014 Setup (English) 12.0 2 PS01, WILLARD Microsoft SQL Server 2014 T-SQL Language Service 12.0 9 buildbox, darkhorse, Mwest-WIN864, ... Microsoft SQL Server 2014 Transact-SQL Compiler Service 12.0 2 PS01, WILLARD Microsoft SQL Server 2014 Transact-SQL ScriptDom 12.0 10 buildbox, darkhorse, Mwest-WIN864, ... Microsoft SQL Server 2016 2 PANOPTICON, WAMPA Microsoft SQL Server 2016 CTP3.3 1 Mwest-WIN864

PROPRIETARY & CONFIDENTIAL PAGE 83 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers Microsoft SQL Server 2016 LocalDB 13.0 7 darkhorse, Mwest-WIN864, PANOPTICON, ... Microsoft SQL Server 2016 Management Objects 13.0 7 darkhorse, Mwest-WIN864, PANOPTICON, ... Microsoft SQL Server 2016 Management Objects (x64) 13.0 7 darkhorse, Mwest-WIN864, PANOPTICON, ... Microsoft SQL Server 2016 Policies 13.0 2 PANOPTICON, WAMPA Microsoft SQL Server 2016 T-SQL Language Service 13.0 7 darkhorse, Mwest-WIN864, PANOPTICON, ... Microsoft SQL Server 2016 T-SQL ScriptDom 13.0 7 darkhorse, Mwest-WIN864, PANOPTICON, ... Microsoft SQL Server Compact 3.5 for Devices ENU 3.5 1 Mwest-WIN864 Microsoft SQL Server Compact 3.5 SP1 Design Tools English 3.5 1 Mwest-WIN864 Microsoft SQL Server Compact 3.5 SP2 ENU 3.5 1 Mwest-WIN864 Microsoft SQL Server Compact 3.5 SP2 x64 ENU 3.5 1 Mwest-WIN864 Microsoft SQL Server Compact 4.0 SP1 ENU 4.0 1 SARLACC Microsoft SQL Server Compact 4.0 SP1 x64 ENU 4.0 10 buildbox, darkhorse, Mwest-WIN864, ... Microsoft SQL Server Data Tools - enu (12.0.30919.1) 12.0 3 Mwest-WIN864, SARLACC, sourcesvrBUILD Microsoft SQL Server Data Tools - enu (12.0.41012.0) 12.0 2 buildbox, REX Microsoft SQL Server Data Tools - enu (14.0.60519.0) 14.0 7 darkhorse, Mwest-WIN864, PANOPTICON, ... Microsoft SQL Server Data Tools Build Utilities - enu (12.0.30919.1) 12.0 5 buildbox, Mwest-WIN864, REX, ... Microsoft SQL Server Data Tools – Database Projects – Web installer 10.3 2 REX, sourcesvr entry point Microsoft SQL Server Data-Tier Application Framework (x86) 13.0 3 Mwest-WIN864, PANOPTICON, WAMPA Microsoft SQL Server Database Publishing Wizard 1.3 192.168 1 Mwest-WIN864 Microsoft SQL Server Database Publishing Wizard 1.4 10.1 1 Mwest-WIN864 Microsoft SQL Server Desktop Engine (Microsoft ISA Server 2006 8.00 1 ISA1 instance) Microsoft SQL Server Management Studio - August 2016 13.0 2 PANOPTICON, WAMPA Microsoft SQL Server Management Studio - January 2016 13.0 1 Mwest-WIN864 Microsoft SQL Server Native Client 9.00 3 Mwest-WIN864, ISTCORP-PC, STORAGE01 Microsoft SQL Server Setup Support Files (English) 9.00 3 Mwest-WIN864, ISTCORP-PC, STORAGE01 Microsoft SQL Server System CLR Types 10.50 4 buildbox, SARLACC, sourcesvrBUILD, Mwest-WIN864, ...

PROPRIETARY & CONFIDENTIAL PAGE 84 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers Microsoft SQL Server System CLR Types 10.51 5 darkhorse, PS01, REX, ... Microsoft SQL Server System CLR Types (x64) 10.50 4 buildbox, REX, sourcesvrBUILD, Mwest- WIN864, ... Microsoft SQL Server System CLR Types (x64) 10.51 3 HV02, STORAGE01, UTIL12 Microsoft SQL Server VSS Writer 10.1 1 Mwest-WIN864 Microsoft SQL Server VSS Writer 9.00 2 ISTCORP-PC, STORAGE01 Microsoft Sync Framework Runtime v1.0 SP1 (x64) 1.0 2 Mwest-WIN864, sourcesvr Microsoft Sync Framework SDK v1.0 SP1 1.0 1 Mwest-WIN864 Microsoft Sync Framework Services v1.0 SP1 (x64) 1.0 1 Mwest-WIN864 Microsoft Sync Services for ADO.NET v2.0 SP1 (x64) 2.0 1 Mwest-WIN864 Microsoft System CLR Types for SQL Server 2012 11.0 1 sourcesvr Microsoft System CLR Types for SQL Server 2012 11.1 5 buildbox, Mwest-WIN864, REX, ... Microsoft System CLR Types for SQL Server 2012 11.2 1 Ddouglas-WIN10 Microsoft System CLR Types for SQL Server 2012 (x64) 11.1 6 darkhorse, sourcesvr, buildbox, Mwest- WIN864, REX, ... Microsoft System CLR Types for SQL Server 2014 12.0 10 buildbox, PS01, REX, darkhorse, Mwest- WIN864, PANOPTICON, ... Microsoft System CLR Types for SQL Server 2016 13.0 7 darkhorse, Mwest-WIN864, PANOPTICON, ... Microsoft Team Foundation Server 2010 Object Model - ENU 192.168 2 JIM-WIN8, Mwest-WIN864 Microsoft Team Foundation Server 2013 12.0 2 sourcesvr, sourcesvrBUILD Microsoft Visio Professional 2013 15.0 3 JIM-WIN8, Psolidad-PC, Psolidad-WIN764 Microsoft Visual Basic Power Packs 3.0 9.0 1 Mwest-WIN864 Microsoft Visual C++ 2005 Redistributable 8.0 10 Boppenheimer-PC, HV02, IRIDIUM, ... Microsoft Visual C++ 2005 Redistributable (x64) 8.0 7 FILE2012-1, HV02, ISTCORP-PC, Mmichaels-HP, STORAGE01, UTIL12, ... Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 9.0 1 Mwest-WIN864 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 9.0 2 IRIDIUM, REX Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 9.0 7 FILE2012-1, HV02, IRIDIUM, ... Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 9.0 10 Boppenheimer-PC, darkhorse, JIM-WIN8, ...

PROPRIETARY & CONFIDENTIAL PAGE 85 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 9.0 10 Boppenheimer-PC, ISTCORP-PC, JIM-WIN8, ... Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 9.0 2 JIM-WIN8, Mwest-WIN864 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 9.0 2 IRIDIUM, REX Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 9.0 10 FILE2012-1, HV02, IRIDIUM, ... Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 9.0 13 b2b-GW, Boppenheimer-PC, darkhorse, ... Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974 9.0 7 darkhorse, JIM-WIN8, Mwest-WIN864, ... Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 9.0 18 Boppenheimer-PC, DESKTOP-N6S4H9A, ISTCORP-PC, ... Microsoft Visual C++ 2010 x64 Designtime - 192.168.30319 192.168 1 Mwest-WIN864 Microsoft Visual C++ 2010 x64 Redistributable - 192.168.40219 192.168 23 Boppenheimer-PC, darkhorse, Ddouglas- WIN10, ... Microsoft Visual C++ 2010 x64 Runtime - 192.168.30319 192.168 1 JIM-WIN8 Microsoft Visual C++ 2010 x64 Runtime - 192.168.40219 192.168 1 Mwest-WIN864 Microsoft Visual C++ 2010 x86 Redistributable - 192.168.30319 192.168 1 b2b-GW Microsoft Visual C++ 2010 x86 Redistributable - 192.168.40219 192.168 25 Boppenheimer-PC, darkhorse, Ddouglas- WIN10, ... Microsoft Visual C++ 2010 x86 Runtime - 192.168.30319 192.168 1 JIM-WIN8 Microsoft Visual C++ 2010 x86 Runtime - 192.168.40219 192.168 6 darkhorse, Mwest-WIN864, PS01, ... Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 11.0 3 Ddouglas-WIN10, Mwest-WIN864, REX Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 11.0 11 buildbox, darkhorse, gordon-LT2, ... Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 11.0 5 IRIDIUM, Mmichaels-HP, Mwest-WIN864, ... Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 11.0 2 Ddouglas-WIN10, REX Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 11.0 12 buildbox, darkhorse, gordon-LT2, ... Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 11.0 8 Boppenheimer-PC, DESKTOP-N6S4H9A, IRIDIUM, ... Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 12.0 5 Mwest-WIN864, PANOPTICON, ROWBOT, ... Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 12.0 7 Boppenheimer-PC, darkhorse, Mmichaels- HP, ... Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 12.0 5 Mwest-WIN864, PANOPTICON, ROWBOT, ...

PROPRIETARY & CONFIDENTIAL PAGE 86 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 12.0 5 Boppenheimer-PC, Mmichaels-HP, ROWBOT, ... Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 14.0 1 tywin-PC Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24210 14.0 2 darkhorse, tarsis Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24212 14.0 4 darkhorse, Mwest-WIN864, PANOPTICON, ... Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 14.0 3 ROWBOT, WAMPA, WILLARD Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 14.0 1 tywin-PC Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24210 14.0 1 tarsis Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24212 14.0 4 darkhorse, Mwest-WIN864, PANOPTICON, ... Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 14.0 3 ROWBOT, WAMPA, WILLARD Microsoft Visual C++ Compilers 2008 Standard Edition - enu - x64 9.0 1 REX Microsoft Visual C++ Compilers 2008 Standard Edition - enu - x86 9.0 1 REX Microsoft Visual F# 2.0 Runtime 192.168 2 JIM-WIN8, Mwest-WIN864 Microsoft Visual F# 3.1.2 12.0 1 buildbox Microsoft Visual J# 2.0 Redistributable Package 1 ISTCORP-PC Microsoft Visual J# 2.0 Redistributable Package - SE (x64) 8 Boppenheimer-PC, darkhorse, JIM-WIN8, ... Microsoft Visual SourceSafe 2005 - ENU 1 Mwest-WIN864 Microsoft Visual Studio 2008 Professional Edition - ENU 1 Mwest-WIN864 Microsoft Visual Studio 2008 Remote Debugger - ENU 1 Mwest-WIN864 Microsoft Visual Studio 2008 Shell (integrated mode) - ENU 9.0 1 Mwest-WIN864 Microsoft Visual Studio 2008 Team Explorer - ENU 1 Mwest-WIN864 Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools 192.168 1 Mwest-WIN864 Microsoft Visual Studio 2010 Service Pack 1 192.168 1 Mwest-WIN864 Microsoft Visual Studio 2010 Shell (Integrated) - ENU 192.168 2 REX, sourcesvr Microsoft Visual Studio 2010 Shell (Isolated) - ENU 192.168 6 darkhorse, Mwest-WIN864, PS01, ... Microsoft Visual Studio 2010 Tools for Office Runtime (x64) 192.168 17 sourcesvrBUILD, Boppenheimer-PC, buildbox, darkhorse, ... Microsoft Visual Studio 2010 Tools for Office Runtime (x86) 192.168 1 SARLACC Microsoft Visual Studio 2013 SDK - ENU 12.0 1 REX

PROPRIETARY & CONFIDENTIAL PAGE 87 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers Microsoft Visual Studio 2015 Shell (Isolated) 14.0 2 PANOPTICON, WAMPA Microsoft Visual Studio Community 2015 with Updates 14.0 1 Mwest-WIN864 Microsoft Visual Studio Emulator for Android 1.1 3 PANOPTICON, ROWBOT, WILLARD Microsoft Visual Studio Macro Tools 9.0 2 JIM-WIN8, Mwest-WIN864 Microsoft Visual Studio Professional 2013 12.0 1 buildbox Microsoft Visual Studio Professional 2013 with Update 3 12.0 4 Mwest-WIN864, REX, SARLACC, ... Microsoft Visual Studio Professional 2015 with Updates 14.0 7 darkhorse, Mwest-WIN864, PANOPTICON, ... Microsoft Visual Studio Tools for Apache Cordova 14.0 3 PANOPTICON, ROWBOT, WILLARD Microsoft Visual Studio Tools for Applications Design-Time 3.0 192.168 2 REX, sourcesvr Microsoft Visual Studio Tools for Applications x64 Runtime 3.0 192.168 2 PS01, sourcesvr Microsoft Visual Studio Tools for Applications x86 Runtime 3.0 192.168 3 PS01, REX, sourcesvr Microsoft Visual Studio Web Authoring Component 12.0 1 Mwest-WIN864 Microsoft VSS Writer for SQL Server 2012 11.1 1 sourcesvr Microsoft VSS Writer for SQL Server 2012 11.2 1 Ddouglas-WIN10 Microsoft VSS Writer for SQL Server 2014 12.0 2 PS01, WILLARD Microsoft Web Deploy 3.5 3.1237 4 buildbox, REX, SARLACC, ... Microsoft Web Deploy 3.6 3.1238 7 darkhorse, Mwest-WIN864, PANOPTICON, ... Microsoft Web Platform Installer 5.0 5.0 3 buildbox, PKWIN8-VM, Psolidad-PC Microsoft Windows SDK for Visual Studio 2008 .NET Framework Tools 3.5 1 Mwest-WIN864 - enu Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries 6.1 1 Mwest-WIN864 Microsoft Windows SDK for Visual Studio 2008 SDK Reference 6.1 1 Mwest-WIN864 Assemblies and IntelliSense Microsoft Windows SDK for Visual Studio 2008 SP1 Tools 6.1 1 Mwest-WIN864 Microsoft Windows SDK for Visual Studio 2008 SP1 Win32 Tools 6.1 1 Mwest-WIN864 Microsoft Windows SDK for Windows 7 (7.0) 7.0 1 REX Microsoft Works 6-9 Converter 14.0 1 Psolidad-WIN764 Microsoft WSE 3.0 3.0 1 ISTCORP-PC MindFusion WinForms 1.0 10 buildbox, darkhorse, Mwest-WIN864, ...

PROPRIETARY & CONFIDENTIAL PAGE 88 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers MiniTool Partition Wizard Enterprise Edition 6.0 2 FILE2012-1, ISA1 MiniTool Partition Wizard Technician Edition 8.1.1 1 FILE2012-1 MiniTool Partition Wizard Technician Edition 9.0 1 STORAGE12 MiniTool Power Data Recovery 1 FILE2012-1 Motorola 2.5 1 Boppenheimer-PC Motorola Mobile Drivers Installation 6.4.0 6.4 1 Boppenheimer-PC Mozilla Firefox 42.0 (x86 en-US) 42.0 1 PKWIN8-VM Mozilla Firefox 45.0.2 (x86 en-US) 45.0 1 ISTCORP-PC Mozilla Firefox 49.0 (x86 en-US) 49.0 4 betty-INSPIRON, JIM-WIN8, Mwest-WIN864, ... Mozilla Firefox 49.0.1 (x86 en-US) 49.0 1 HPDT-8CC5260NXY Mozilla Firefox 49.0.2 (x86 en-US) 49.0 2 ISTCORP-PC, ROWBOT Mozilla Maintenance Service 42.0 1 PKWIN8-VM Mozilla Maintenance Service 49.0 7 betty-INSPIRON, JIM-WIN8, Mwest-WIN864, HPDT-8CC5260NXY, ROWBOT, ISTCORP- PC, ... MSN BackUp 1.3.2 1.3 1 ISTCORP-PC MSXML 4.0 SP2 Parser and SDK 4.20 2 ISTCORP-PC, Psolidad-WIN764 MSXML 4.0 SP3 Parser 4.30 2 Boppenheimer-PC, ISTCORP-PC myapp 3.0 1 b2b-GW myapp 4.0 3 JIM-WIN8, Psolidad-PC, Psolidad-WIN764 myapp - 1 3.0 1 b2b-GW myco Agent 10 b2b-GW, HV00, HV02, ... myco Explorer 2 Psolidad-PC, Psolidad-WIN764 myco Explorer 3.0 1 b2b-GW MySQL connections Net 6.4.3 6.4 2 Mwest-WIN864, REX MySQL connections/ODBC 3.51 3.51 1 Psolidad-WIN764 MySQL Installer - Community 1.4 1 WAMPA MySQL Workbench 6.3 CE 6.3 3 PANOPTICON, ROWBOT, WAMPA

PROPRIETARY & CONFIDENTIAL PAGE 89 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers NewBlue Video Essentials for Windows 3.0 1 IRIDIUM Nmap 7.12 7.12 1 Psolidad-PC Nmap 7.30 7.30 1 Boppenheimer-PC Node.js 0.12 3 PANOPTICON, ROWBOT, WILLARD Node.js Tools 1.1.1 for Visual Studio 2015 1.1 1 ROWBOT Node.js Tools 1.2 for Visual Studio 2015 1.2 1 PANOPTICON Notepad++ 6.9 3 Boppenheimer-PC, ROWBOT, WILLARD Notepad++ 7 1 JIM-WIN8 Nucleus Kernel Outlook Password Recovery ver 10.08.01 1 Psolidad-WIN764 NVIDIA 3D Vision Controller Driver 301.42 301.42 1 Psolidad-WIN764 NVIDIA 3D Vision Controller Driver 352.65 352.65 1 IRIDIUM NVIDIA 3D Vision Controller Driver 364.44 364.44 1 Boppenheimer-PC NVIDIA 3D Vision Controller Driver 369.04 369.04 1 ROWBOT NVIDIA 3D Vision Driver 306.97 306.97 1 Psolidad-WIN764 NVIDIA 3D Vision Driver 353.54 353.54 1 DESKTOP-N6S4H9A NVIDIA 3D Vision Driver 353.82 353.82 1 IRIDIUM NVIDIA 3D Vision Driver 365.19 365.19 1 Boppenheimer-PC NVIDIA 3D Vision Driver 372.54 372.54 1 ROWBOT NVIDIA GeForce Experience 2.11.3.5 2.11 1 Boppenheimer-PC NVIDIA GeForce Experience 2.11.4.0 2.11 2 ROWBOT, WILLARD NVIDIA Graphics Driver 306.97 306.97 1 Psolidad-WIN764 NVIDIA Graphics Driver 353.54 353.54 1 DESKTOP-N6S4H9A NVIDIA Graphics Driver 353.82 353.82 1 IRIDIUM NVIDIA Graphics Driver 365.19 365.19 1 Boppenheimer-PC NVIDIA Graphics Driver 372.54 372.54 1 ROWBOT NVIDIA Graphics Driver 372.70 372.70 1 WILLARD NVIDIA HD Audio Driver 1.3.16.0 1.3 1 Psolidad-WIN764 NVIDIA HD Audio Driver 1.3.34.15 1.3 1 ROWBOT

PROPRIETARY & CONFIDENTIAL PAGE 90 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers NVIDIA HD Audio Driver 1.3.34.3 1.3 2 DESKTOP-N6S4H9A, IRIDIUM NVIDIA HD Audio Driver 1.3.34.4 1.3 1 Boppenheimer-PC NVIDIA PhysX System Software 9.12.0213 9.12 1 Psolidad-WIN764 NVIDIA PhysX System Software 9.13.0604 9.13 1 Mmichaels-HP NVIDIA PhysX System Software 9.15.0428 9.15 2 Boppenheimer-PC, IRIDIUM NVIDIA PhysX System Software 9.16.0318 9.16 1 ROWBOT NVIDIA Update 1.10.8 1.10 1 Psolidad-WIN764 NVIDIA Update 1.14.17 1.14 1 Mmichaels-HP NVIDIA Update 10.4.0 10.4 2 DESKTOP-N6S4H9A, IRIDIUM NVM for Windows 1.1.1 1.1 1 ROWBOT Open XML SDK 2.0 for Microsoft Office 2.0 1 Mwest-WIN864 OpenOffice 4.1.2 4.12 1 Mwest-WIN864 Oracle VM VirtualBox 5.0.12 5.0 1 Psolidad-WIN764 OutfoxTV 1 ISTCORP-PC P@H-Protocol 3.0 1 ISTCORP-PC paint.net 4.0 1 WILLARD Pdfedit 4.5 1 Boppenheimer-PC PHP 5.3.27 5.3 1 JIM-WIN8 Picasa 3 3.9 1 ISTCORP-PC PicPick 4.1 1 REX Player Location Check 3.0 1 IRIDIUM PlaysTV 1.14 2 Mwest-WIN864, REX Power2Go 6.0 1 ISTCORP-PC PowerChute redi Shutdown 3.1 3 FILE2012-1, HV00, HV02 PowerDirector 7.0 1 ISTCORP-PC PowerISO 5.7 1 JIM-WIN8 Prerequisites for SSDT 11.0 1 sourcesvr Prerequisites for SSDT 11.1 2 SARLACC, sourcesvrBUILD

PROPRIETARY & CONFIDENTIAL PAGE 91 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers Prerequisites for SSDT 12.0 9 buildbox, darkhorse, Mwest-WIN864, ... Print@Home 2.0 1 ISTCORP-PC proDAD Adorage 3.0 3.0 1 IRIDIUM Product Improvement Study for HP Officejet Pro 8610 32.3 1 Ddouglas-WIN10 PuTTY 0.67 1 PANOPTICON PuTTY version 0.63 0.63 1 JIM-WIN8 Python 2.7.12 2.7 1 WILLARD Python 2.7.12 (64-bit) 2.7 1 PANOPTICON Python 3.5.2 (32-bit) 3.5 1 ROWBOT Python Launcher 3.5 1 ROWBOT Python Tools 2.2.5 for Visual Studio 2015 2.2 1 WILLARD qBittorrent 3.3.5 3.3 1 Boppenheimer-PC QLogic Drivers and Management Applications 18.10 1 HV02 Qualcomm Atheros Bluetooth Suite (64) 8.0 4 darkhorse, PANOPTICON, tarsis, ... Quick Screen Capture 3.0 3.0 5 b2b-GW, JIM-WIN8, Mwest-WIN864, ... QuickBooks File Doctor 3.5 1 Psolidad-WIN764 QuickBooks Premier: Contractor Edition 2012 22.0 1 Psolidad-WIN764 QuickBooks Premier: Professional Services Edition 2014 24.0 1 ISTCORP-PC QuickBooks Premier: Professional Services Edition 2015 25.0 2 Mmichaels-HP, QB01 QuickBooks Runtime Redistributable 1.00 3 ISTCORP-PC, Mmichaels-HP, QB01 Quicken 2010 19.1 1 ISTCORP-PC Quicken 2013 22.1 1 ISTCORP-PC QuickTime 7.60 1 DESKTOP-N6S4H9A QuickTime 7 7.79 1 ISTCORP-PC QuickTime Free Download Packages 1 ISTCORP-PC Raptr 5.2 2 Mwest-WIN864, REX Realtek 8136 8168 8169 Ethernet Driver 1.00 1 ISTCORP-PC Realtek Audio COM Components 1.0 1 gordon-LT2

PROPRIETARY & CONFIDENTIAL PAGE 92 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers Realtek Card Reader 192.168 2 Boppenheimer-PC, HPLT-5CD4411D8Z Realtek Card Reader 6.2 1 gordon-LT2 Realtek Ethernet Controller Driver 10.1 1 Boppenheimer-PC Realtek Ethernet Controller Driver 8.38 1 REX Realtek Ethernet Controller Driver For Windows 7 7.17 1 Psolidad-WIN764 Realtek High Definition Audio Driver 6.0 15 gordon-LT2, Psolidad-PC, betty-INSPIRON, Boppenheimer-PC, REX, ROWBOT, WILLARD, HPLT-5CD4411D8Z, darkhorse, PANOPTICON, tarsis, HPDT-8CC5260NXY, IRIDIUM, tywin-PC, ... Realtek USB 2.0 Card Reader 6.1 1 ISTCORP-PC Realtek USB Card Reader 6.2 1 Psolidad-PC redi Detective 2.2 1 b2b-GW redi Detective 3.0 5 Mmichaels-HP, STORAGE01, DC03, tarsis, Psolidad-WIN764, ... redi Detective 4.0 7 DESKTOP-N6S4H9A, HPDT-8CC5260NXY, IRIDIUM, JIM-WIN8, Psolidad-PC, WILLARD, ... redi Detective - 1 4.0 4 HPLT-5CD4411D8Z, ROWBOT, tarsis, Boppenheimer-PC, ... redi Detective - 2 4.0 1 HPLT-5CD4411D8Z Registry Workshop 1 Boppenheimer-PC Revo Uninstaller 1.95 1.95 1 sourcesvr Revo Uninstaller 2.0.1 2.0 1 Boppenheimer-PC Revo Uninstaller Pro 3.1.5 3.1 1 betty-INSPIRON Revo Uninstaller Pro 3.1.7 3.1 1 IRIDIUM RingCentral Meetings 4.2 1 DESKTOP-N6S4H9A RW-Everything v1.6.5.9 1 JIM-WIN8 Ryver 1.1 11 Boppenheimer-PC, DESKTOP-N6S4H9A, PANOPTICON, darkhorse, Mwest-WIN864, ROWBOT, ... Salesforce for Outlook 3.0 1 gordon-LT2

PROPRIETARY & CONFIDENTIAL PAGE 93 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers Salesforce for Outlook 3.1 1 HPLT-5CD4411D8Z Salesforce Outlook Edition 3 3.3 1 HPLT-5CD4411D8Z Samsung Data Migration 2.7 1 Mwest-WIN864 Samsung Easy Printer Manager 1.03 1 ISTCORP-PC Samsung Easy Wireless Setup 3.60 1 ISTCORP-PC Samsung M262x 282x Series 1.17 1 ISTCORP-PC (5/15/2013) Samsung M283x Series 1.10 1 Psolidad-WIN764 (11/6/2014) Samsung M283x Series 1.13 1 REX (12/16/2014) Samsung Printer Diagnostics 1.0 2 Psolidad-WIN764, REX Samsung Printer Live Update 1.01 4 ISTCORP-PC, Mwest-WIN864, Psolidad- WIN764, REX, ... Samsung SideSync 4.5 1 DESKTOP-N6S4H9A Samsung USB Driver for Mobile Phones 1.5 1 DESKTOP-N6S4H9A SavvyConnect 4.3 1 IRIDIUM ScreenConnect Client (2872323bbe412f4c) 5.4 5 Boppenheimer-PC, darkhorse, DESKTOP- N6S4H9A, ... ScreenConnect Client (2872323bbe412f4c) 6.0 13 betty-INSPIRON, Ddouglas-WIN10, gordon- LT2, ... Seagate docksys 1.1 1 ISTCORP-PC Seagate docksys 3.2 1 Mmichaels-HP ShadowSnap 1.1 6 Mwest-WIN864, REX, sourcesvr, ... ShadowSnap 3.4 2 QB01, STORAGE12 Shared C Run-time for x64 192.168 1 Psolidad-PC SharePoint Client Components 15.0 1 buildbox for Business Basic 2016 16.0 1 DESKTOP-N6S4H9A Skype 7.28 7.28 1 IRIDIUM Snagit 11 11.4 2 Mmichaels-HP, tarsis

PROPRIETARY & CONFIDENTIAL PAGE 94 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers Snagit 12 12.4 1 tywin-PC Softerra LDAP Browser 4.5 (64-bit) 4.5 1 JIM-WIN8 Software Assembler 2.00 1 Psolidad-PC SonicWALL Global VPN Client 4.6 1 Psolidad-WIN764 SourceGear DiffMerge 4.2.0.697.stable (x64) 4.2 1 WILLARD Spotify 1.0 2 DESKTOP-N6S4H9A, ROWBOT SQL Server Browser for SQL Server 2012 11.1 1 sourcesvr SQL Server Browser for SQL Server 2012 11.2 1 Ddouglas-WIN10 SQL Server Browser for SQL Server 2014 12.0 2 PS01, WILLARD SQL Server System CLR Types 192.168 2 PKWIN8-VM, STORAGE01 Squid 3.5 1 REX Stamps.com 1 ISTCORP-PC Stamps.com support for Microsoft Outlook 2000-2013 1 ISTCORP-PC Stamps.com support for Microsoft Outlook 97-2013 1 ISTCORP-PC Stamps.com support for Microsoft Word 2000-2013 1 ISTCORP-PC StorageCraft ShadowProtect 5.0 8 Mwest-WIN864, QB01, REX, ... Sublime Text 2.0.2 1 darkhorse Sublime Text Build 3083 1 WILLARD SupportSoft Assisted Service 15 1 ISTCORP-PC Synaptics Pointing 15.3 1 ISTCORP-PC TeamViewer 11 11.0 4 DESKTOP-N6S4H9A, Boppenheimer-PC, Psolidad-PC, tarsis, ... TeamViewer 9 9.0 2 JIM-WIN8, Psolidad-WIN764 Telerik 14.2 1 Mwest-WIN864 Telerik Fiddler 4.6 2 PANOPTICON, ROWBOT Telerik Reporting Q2 2014 SP1 8.1 1 Mwest-WIN864 Telerik Test Studio 2016.3 163.9 1 PANOPTICON Telerik UI for WinForms Q2 2014 SP1 14.2 1 Mwest-WIN864

PROPRIETARY & CONFIDENTIAL PAGE 95 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers Telerik UI for WPF Q2 2014 SP1 14.2 1 Mwest-WIN864 Terminals 2.0 1 Psolidad-WIN764 Terminals 3.3 1 JIM-WIN8 Terminals 3.6 5 darkhorse, Psolidad-PC, REX, ... Tracking The Eye.NET 1 ISTCORP-PC TreeSize Free V2.4 2.4 1 HV00 TreeSize Free V3.0.1 3.0 2 JIM-WIN8, STORAGE01 Trigger External Graphics Family 16.05.0819.0179 16.05 1 betty-INSPIRON TypeScript Tools for Microsoft Visual Studio 2015 2.0.2.0 Beta 2.0 1 PANOPTICON Uninstall Samsung Printer Software 4.0 2 Mwest-WIN864, ROWBOT Upromise RewardU Toolbar 1 ISTCORP-PC UPS WorldShip 19.0 1 Ddouglas-WIN10 USBPcap 1.1.0.0-g794bf26 1 REX USBPcap 1.1.0.0-g794bf26-3 1.1 1 darkhorse Vbsedit 7.4 1 Boppenheimer-PC Vbsedit 32-bit 7.4 1 Boppenheimer-PC VC12X64Redist 1.00 2 Mmichaels-HP, QB01 VC12X86Redist 1.00 2 Mmichaels-HP, QB01 Veriton ControlCenter 1.00 1 Psolidad-PC View User's Guide 3.60 1 ISTCORP-PC ViewSonic Monitor Drivers 1 Psolidad-WIN764 VIPRE Business Agent 7.5 1 HV00 VIPRE Business Agent 9.3 14 b2b-GW, betty-INSPIRON, JIM-WIN8, HPDT- 8CC5260NXY, Ddouglas-WIN10, HPLT- 5CD4411D8Z, ISTCORP-PC, ... VIPRE Business Premium 9.3 1 STORAGE01 VIPRE Hyper-V Agent 1.0 2 HV00, HV02 Visual C++ 2008 IA64 Runtime - v9.0.30729.01 9.0 1 Mwest-WIN864 Visual C++ 2008 x64 Runtime - v9.0.30729.01 9.0 1 Mwest-WIN864

PROPRIETARY & CONFIDENTIAL PAGE 96 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers Visual C++ 2008 x86 Runtime - v9.0.30729.01 9.0 1 Mwest-WIN864 Visual C++ 2008 x86 Runtime - v9.0.30729.4148 9.0 1 Mwest-WIN864 Visual C++ 2008 x86 Runtime - v9.0.30729.6161 9.0 1 Mwest-WIN864 Visual C++ 8.0 Runtime Setup Package (x64) 9.0 1 ISTCORP-PC Visual C++ for Mobile Development (Android support) 14.0 3 PANOPTICON, ROWBOT, WILLARD Visual C++ for Mobile Development (iOS support) 14.0 3 PANOPTICON, ROWBOT, WILLARD Visual CertExam Suite 1 Psolidad-WIN764 Visual Studio .NET Prerequisites - English 9.0 1 Mwest-WIN864 Visual Studio 2005 Tools for Office Second Edition Runtime 2 ISTCORP-PC, Mwest-WIN864 Visual Studio 2010 Prerequisites - English 192.168 7 JIM-WIN8, darkhorse, Mwest-WIN864, PS01, ... Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU 4.0 1 Mwest-WIN864 Visual Studio Extensions for Windows Library for JavaScript 2.1 1 buildbox 2.1.30324.52 Visual Studio Tools for the Office system 3.0 Runtime 2 ISTCORP-PC, Mwest-WIN864 VLC media player 2.2 2 DESKTOP-N6S4H9A, ISTCORP-PC VLC media player 2.0.0 2.0 1 Psolidad-WIN764 VMware OVF Tool 4.1 2 darkhorse, REX VMware Remote Console Plug-in 5.1 0.0 6 b2b-GW, Boppenheimer-PC, darkhorse, ... VMware vCenter Converter Standalone 6.1 2 REX, SARLACC VMware vSphere Client 5.0 5.0 2 JIM-WIN8, Psolidad-PC VMware vSphere Client 5.1 5.1 2 JIM-WIN8, REX VMware vSphere Client 5.5 5.5 5 Boppenheimer-PC, Psolidad-PC, JIM-WIN8, tarsis, WAMPA, ... VMware vSphere Client 6.0 6.0 4 Boppenheimer-PC, darkhorse, REX, ... VMware vSphere PowerCLI 6.3 6 b2b-GW, Boppenheimer-PC, darkhorse, ... Vocalocity Desktop 2 ISTCORP-PC, JIM-WIN8 Vulkan Run Time Libraries 1.0.11.1 1.0 3 Boppenheimer-PC, ROWBOT, WILLARD VyprVPN 2.8 1 Boppenheimer-PC

PROPRIETARY & CONFIDENTIAL PAGE 97 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers WCF Data Services 5.0 (OData v3) 5.0 1 sourcesvr WCF RIA Services V1.0 SP2 4.1 4 buildbox, Mwest-WIN864, REX, ... WeatherBug 192.168 1 tywin-PC Web Deployment Tool 1.1 1 Mwest-WIN864 WebHelp 19.00 1 Ddouglas-WIN10 Windows 10 for Mobile Image - 192.168.14393.0 10.1 1 ROWBOT Windows 7 USB/DVD Download Tool 1.0 1 Psolidad-WIN764 Windows Azure Active Directory Module for Windows PowerShell 1.0 8 b2b-GW, Boppenheimer-PC, darkhorse, ... Windows Driver Package - Android-Sync.com (WinUSB) 03/28/2012 1 ISTCORP-PC AndroidUsbDeviceClass (03/28/2012 4.0.0000.20328) 4.0 Control 4.6 1 REX Windows Imaging Component 3.0 1 ISA1 Windows Internet Explorer 8 20090308.140 1 ISA1 743 Windows Live Essentials 15.4 1 ISTCORP-PC Windows Live Essentials 16.4 2 Ddouglas-WIN10, tywin-PC Windows Live Mesh ActiveX Control for Remote Connections 15.4 1 ISTCORP-PC Windows Live Sync 14.0 1 ISTCORP-PC Firefox Plugin 1.0 1 ISTCORP-PC Windows Mobile 5.0 SDK R2 for Pocket PC 5.00 1 Mwest-WIN864 Windows Mobile 5.0 SDK R2 for Smartphone 5.00 1 Mwest-WIN864 Windows Phone 8.1 Emulators - ENU 12.0 3 sourcesvrBUILD, buildbox, ROWBOT Windows Resource Kit Tools - GPInventory.exe 1.0 1 Boppenheimer-PC Windows Resource Kit Tools - SubInAcl.exe 5.2 1 Boppenheimer-PC Windows SDK AddOn 10.1 2 ROWBOT, tarsis Windows Server AppFabric v1.1 CU1[KB 2671763]LDR 1.1 1 sourcesvr Windows Software Development Kit 8.59 1 REX Windows Software Development Kit - Windows 192.168.10586.212 10.1 1 ROWBOT Windows Software Development Kit - Windows 192.168.14393.33 10.1 2 ROWBOT, tarsis

PROPRIETARY & CONFIDENTIAL PAGE 98 of 253 Full Detail Report NETWORK ASSESSMENT

Application Name Version # Computers Computers Windows Software Development Kit - Windows 192.168.26624 192.168 1 ROWBOT WinMerge 2.14.0 2.14 1 Mwest-WIN864 WinPcap 4.1.3 4.1 3 darkhorse, Psolidad-PC, REX WinRAR 5.40 beta 3 (64-bit) 5.40 1 REX WinSCP 5.7.6 5.7 1 Psolidad-PC WinSCP 5.7.7 5.7 1 Mwest-WIN864 WinSCP 5.9.1 5.9 1 PANOPTICON WinZip Self-Extractor 2 darkhorse, WAMPA Wireshark 2.0.0 (64-bit) 2.0 1 REX Wireshark 2.0.5 (64-bit) 2.0 1 darkhorse WMI Tools 1.50 1 Boppenheimer-PC WMIX v3 3.02 1 Boppenheimer-PC Xamarin 4.1 3 PANOPTICON, WILLARD, ROWBOT XAMPP 1.8 1 JIM-WIN8 Xceed Components 4.5 1 Mwest-WIN864 Yahoo! Detect 1 ISTCORP-PC Zoom 3.5 3 JIM-WIN8, Mmichaels-HP, tarsis

PROPRIETARY & CONFIDENTIAL PAGE 99 of 253 Full Detail Report NETWORK ASSESSMENT 9 - System Password Strength Assessment

This section contains password strength analysis through MBSA in order to determine risk. Systems with security risks are highlighted in red.

MBSA

IP Address Computer Name Assessment 192.168.1.3 192.168.1.5 192.168.1.6 192.168.1.15 192.168.1.16 192.168.1.41 192.168.1.63 192.168.1.64 192.168.1.65 192.168.1.66 192.168.1.67 192.168.1.69 192.168.1.104 192.168.1.121 192.168.1.122 192.168.1.123 192.168.6.5 192.168.6.9 192.168.6.12 192.168.6.14 192.168.6.26 192.168.6.30

PROPRIETARY & CONFIDENTIAL PAGE 100 of 253 Full Detail Report NETWORK ASSESSMENT

IP Address Computer Name Assessment 192.168.6.37 192.168.6.44 192.168.6.45 192.168.6.52 192.168.6.56 192.168.6.63 192.168.6.67 192.168.6.80 192.168.6.81 192.168.6.85 192.168.6.100 192.168.6.105 192.168.6.108 192.168.6.109 192.168.6.112 192.168.6.117 192.168.6.120 192.168.6.125 192.168.6.132 192.168.6.133 192.168.6.134 192.168.6.136 192.168.6.142 192.168.6.159 192.168.6.161 192.168.6.165

PROPRIETARY & CONFIDENTIAL PAGE 101 of 253 Full Detail Report NETWORK ASSESSMENT

IP Address Computer Name Assessment 192.168.6.195 192.168.7.17 192.168.7.44 192.168.7.49 192.168.7.95 192.168.7.123

PROPRIETARY & CONFIDENTIAL PAGE 102 of 253 Full Detail Report NETWORK ASSESSMENT 10 - Patch Summary

This section contains the patching status of computers determined through the Microsoft Baseline Security Analyzer and . MBSA gathers data through a remote scan and looks primarily for Security Updates. Windows Update checks the local computer for all non-hidden updates. Missing updates in both areas are highlighted in red. Security and critical updates are bolded.

MBSA

IP Address Computer Name Issue Result Assessment

Windows Updates

IP Address Computer Name Issue Result Assessment 192.168.6.37 BETTY-INSPIRON Drivers, Windows 10 and later drivers Failed (non-critical) 1 update is missing. Feature Packs, Silverlight Failed (non-critical) 1 update is missing. 169.254.196.2 BOPPENHEIMER-PC Drivers, Windows 10 and later drivers Failed (non-critical) 2 updates are missing. 28, Drivers, Windows 10 Anniversary Failed (non-critical) 8 updates are missing. 169.254.57.9, Update and Later Servicing Drivers 192.168.6.109 Feature Packs, Silverlight Failed (non-critical) 1 update is missing. 192.168.6.5 CERTEXAM Feature Packs, Silverlight Failed (non-critical) 1 update is missing. Updates, Windows Server 2012 R2 Failed (non-critical) 6 updates are missing. 192.168.6.56 CONFERENCE- Drivers, Windows 10 and later drivers Failed (non-critical) 8 updates are missing. ROOM 192.168.6.134 DARREN-PC Drivers, Windows 10 and later drivers Failed (non-critical) 14 updates are missing. Feature Packs, Silverlight Failed (non-critical) 1 update is missing. 169.254.52.15 DC03 Critical Updates, Windows Server Failed (critical) 8 critical updates are missing. 0, 2012 R2 192.168.1.23, Feature Packs, Silverlight Failed (non-critical) 1 update is missing. 192.168.1.4, 192.168.1.3 Feature Packs, Windows Server 2012 Failed (non-critical) 1 update is missing. R2 Security Updates, Windows Server Failed (critical) 127 security updates are missing. 2012 R2

PROPRIETARY & CONFIDENTIAL PAGE 103 of 253 Full Detail Report NETWORK ASSESSMENT

IP Address Computer Name Issue Result Assessment Update Rollups, Windows Server 2012 Failed (non-critical) 3 updates are missing. R2 Updates, Windows Server 2012 R2 Failed (non-critical) 101 updates are missing. 169.254.93.61 DESKTOP-N6S4H9A Definition Updates, Windows Defender Failed (non-critical) 1 update is missing. , 192.168.6.85 Drivers, Windows 10 and later drivers Failed (non-critical) 3 updates are missing. Drivers, Windows 10 Anniversary Failed (non-critical) 4 updates are missing. Update and Later Servicing Drivers Feature Packs, Silverlight Failed (non-critical) 1 update is missing. 192.168.6.45 DESKTOP-UAE29E6 Definition Updates, Windows Defender Failed (non-critical) 1 update is missing. Updates, Windows 10 Failed (non-critical) 1 update is missing. 169.254.24.15 DARKHORSE Definition Updates, Windows Defender Failed (non-critical) 1 update is missing. 0, Drivers, Windows 10 and later drivers Failed (non-critical) 26 updates are missing. 169.254.58.23 6, Drivers, Windows 8.1 and later drivers Failed (non-critical) 2 updates are missing. 192.168.6.80 192.168.6.9 HPDT-8CC5260NXY Drivers, Windows 10 and later drivers Failed (non-critical) 12 updates are missing. 192.168.6.26 HPLT-5CD4411D8Z Drivers, Windows 10 and later drivers Failed (non-critical) 3 updates are missing. Drivers, Windows 10 Anniversary Failed (non-critical) 8 updates are missing. Update and Later Servicing Drivers Feature Packs, Silverlight Failed (non-critical) 1 update is missing. 169.254.234.2 HV04 Critical Updates, Windows Server Failed (critical) 8 critical updates are missing. 37, 2012 R2 169.254.99.16 Feature Packs, Silverlight Failed (non-critical) 1 update is missing. 1, 169.254.185.3 Feature Packs, Windows Server 2012 Failed (non-critical) 2 updates are missing. 0, R2 192.168.6.108 Security Updates, Windows Server Failed (critical) 102 security updates are missing. , 2012 R2 192.168.6.105 , Update Rollups, Windows Server 2012 Failed (non-critical) 3 updates are missing. 192.168.6.100 R2 , Updates, Windows Server 2012 R2 Failed (non-critical) 112 updates are missing. 192.168.1.104 192.168.6.165 IRIDIUM Definition Updates, Windows Defender Failed (non-critical) 1 update is missing. Drivers, Windows 10 and later drivers Failed (non-critical) 6 updates are missing.

PROPRIETARY & CONFIDENTIAL PAGE 104 of 253 Full Detail Report NETWORK ASSESSMENT

IP Address Computer Name Issue Result Assessment Drivers, Windows 10 Anniversary Failed (non-critical) 5 updates are missing. Update and Later Servicing Drivers 192.168.6.81 LALEXANDER-PC Drivers, Windows 10 and later drivers Failed (non-critical) 1 update is missing. Feature Packs, Silverlight Failed (non-critical) 1 update is missing. 192.168.6.30 MWEST-WIN864 Drivers, Windows 8 Failed (non-critical) 2 updates are missing. Feature Packs, Skype for Windows Failed (non-critical) 1 update is missing. Service Packs, SQL Server 2008 Failed (non-critical) 1 update is missing. Updates, Windows 8 Failed (non-critical) 2 updates are missing. 192.168.6.133 PANOPTICON Definition Updates, Windows Defender Failed (non-critical) 1 update is missing. Drivers, Windows 10 and later drivers Failed (non-critical) 17 updates are missing. Drivers, Windows 10 Anniversary Failed (non-critical) 6 updates are missing. Update and Later Servicing Drivers 192.168.199.3 PKWIN8-VM Definition Updates, Windows Defender Failed (non-critical) 1 update is missing. 4, Feature Packs, Silverlight Failed (non-critical) 1 update is missing. 192.168.6.120 Feature Packs, Skype for Windows Failed (non-critical) 1 update is missing. Updates, Windows 8.1 Failed (non-critical) 4 updates are missing. 169.254.197.1 PSOLIDAD-PC Drivers, Windows 10 and later drivers Failed (non-critical) 5 updates are missing. 12, Drivers, Windows 10 Anniversary Failed (non-critical) 3 updates are missing. 192.168.6.12 Update and Later Servicing Drivers Feature Packs, Silverlight Failed (non-critical) 1 update is missing. 192.168.6.14 PSOLIDAD-WIN764 Definition Updates, Windows Defender Failed (non-critical) 1 update is missing. Drivers, Windows 8.1 and later drivers Failed (non-critical) 1 update is missing. Drivers, Windows 8.1 Drivers Failed (non-critical) 1 update is missing. Feature Packs, Skype for Windows Failed (non-critical) 1 update is missing. Updates, Windows 8.1 Failed (non-critical) 7 updates are missing. 192.168.6.142 QB01 Updates, Windows Server 2008 R2 Failed (non-critical) 4 updates are missing. 169.254.7.13, BUILDBOX Definition Updates, Windows Defender Failed (non-critical) 1 update is missing. 192.168.6.63 192.168.6.161 ROWBOT Definition Updates, Windows Defender Failed (non-critical) 1 update is missing. Drivers, Windows 10 and later drivers Failed (non-critical) 6 updates are missing.

PROPRIETARY & CONFIDENTIAL PAGE 105 of 253 Full Detail Report NETWORK ASSESSMENT

IP Address Computer Name Issue Result Assessment Drivers, Windows 10 Anniversary Failed (non-critical) 7 updates are missing. Update and Later Servicing Drivers 192.168.6.132 SARLACC no issues Passed No updates missing. 192.168.6.195 TARSIS Definition Updates, Windows Defender Failed (non-critical) 1 update is missing. Drivers, Windows 10 and later drivers Failed (non-critical) 18 updates are missing. Drivers, Windows 10 Anniversary Failed (non-critical) 5 updates are missing. Update and Later Servicing Drivers 192.168.1.5, VPNGW Critical Updates, Windows Server Failed (critical) 8 critical updates are missing. 192.168.6.159 2012 R2 Feature Packs, Windows Server 2012 Failed (non-critical) 1 update is missing. R2 Security Updates, Windows Server Failed (critical) 15 security updates are missing. 2012 R2 Update Rollups, Windows Server 2012 Failed (non-critical) 2 updates are missing. R2 Updates, Windows Server 2012 R2 Failed (non-critical) 11 updates are missing. 192.168.6.125 WAMPA Definition Updates, Windows Defender Failed (non-critical) 1 update is missing. Drivers, Windows 10 and later drivers Failed (non-critical) 18 updates are missing. Drivers, Windows 10 Anniversary Failed (non-critical) 5 updates are missing. Update and Later Servicing Drivers 192.168.6.52 WILLARD Definition Updates, Windows Defender Failed (non-critical) 1 update is missing. Drivers, Windows 10 and later drivers Failed (non-critical) 5 updates are missing. Drivers, Windows 10 Anniversary Failed (non-critical) 7 updates are missing. Update and Later Servicing Drivers Microsoft SQL Server 2014, Service Failed (non-critical) 1 update is missing. Packs

PROPRIETARY & CONFIDENTIAL PAGE 106 of 253 Full Detail Report NETWORK ASSESSMENT 11 - Endpoint Security and Backup

This section contains a listing of detected anti-virus, anti-spyware, firewall, and backup information as detected through Security Center and/or Installed Services for major vendors, which is then categorized by domain or workgroup membership.

Values in the 'Name' column contain either the name of the product, None indicating the that machine returned information but no product was found, or indicating that information was not obtainable. Additionally, a status of  indicates 'yes',  indicates 'no', and indicates that a status was not available.

CORP.MYCO.COM

Anti-virus Anti-spyware Firewall Backup Computer Name Name On Current Name On Current Name On Name Current b2b-GW     Windows  None ThreatTrack ThreatTrack Firewall Security Security VIPRE VIPRE Business Business Agent Agent Windows   Defender betty-INSPIRON     Windows  None ThreatTrack ThreatTrack Firewall Security Security VIPRE VIPRE Business Business Agent Agent Windows   Windows   Defender Defender Boppenheimer-PC Avast   Avast   Windows  None Antivirus Antivirus Firewall Windows   Windows   Defender Defender buildbox Windows   Windows   Windows  None Defender Defender Firewall

PROPRIETARY & CONFIDENTIAL PAGE 107 of 253 Full Detail Report NETWORK ASSESSMENT

Anti-virus Anti-spyware Firewall Backup Computer Name Name On Current Name On Current Name On Name Current CERTEXAM None None Windows  None Firewall CONFERENCE-ROOM     Windows  None ThreatTrack ThreatTrack Firewall Security Security VIPRE VIPRE Business Business Agent Agent Windows   Windows   Defender Defender darkhorse Windows   Windows   Windows  None Defender Defender Firewall darren-PC     Windows  None ThreatTrack ThreatTrack Firewall Security Security VIPRE VIPRE Business Business Agent Agent Windows   Windows   Defender Defender DC03 GFI  GFI  Windows  None Languard Languard Firewall VIPRE  VIPRE  Ddouglas-PC

Ddouglas-WIN10     Windows  None ThreatTrack ThreatTrack Firewall Security Security VIPRE VIPRE Business Business Agent Agent Windows   Windows   Defender Defender

PROPRIETARY & CONFIDENTIAL PAGE 108 of 253 Full Detail Report NETWORK ASSESSMENT

Anti-virus Anti-spyware Firewall Backup Computer Name Name On Current Name On Current Name On Name Current DESKTOP-N6S4H9A Windows   Windows   Windows  None Defender Defender Firewall DESKTOP-UAE29E6 Windows   Windows   Windows  None Defender Defender Firewall FILE2012-1 None None Windows  None Firewall FT-LENOVO gordon-LT2 Microsoft   Microsoft   Windows  None Security Security Firewall Essentials Essentials Windows   Defender HPDT-8CC5260NXY     Windows  None ThreatTrack ThreatTrack Firewall Security Security VIPRE VIPRE Business Business Agent Agent Windows   Windows   Defender Defender HPLT-5CD4411D8Z     Windows  None ThreatTrack ThreatTrack Firewall Security Security VIPRE VIPRE Business Business Agent Agent Windows   Windows   Defender Defender HV00 VIPRE  VIPRE  Windows  None Firewall HV02 None None Windows  None Firewall

PROPRIETARY & CONFIDENTIAL PAGE 109 of 253 Full Detail Report NETWORK ASSESSMENT

Anti-virus Anti-spyware Firewall Backup Computer Name Name On Current Name On Current Name On Name Current HV04 VIPRE  VIPRE  Windows  None Firewall IRIDIUM Windows   Windows   Windows  None Defender Defender Firewall ISA1

ISTCORP-PC     Windows  None ThreatTrack ThreatTrack Firewall Security Security VIPRE VIPRE Business Business Agent Agent Windows   Windows   Defender Defender JIM-WIN8     Windows  None ThreatTrack ThreatTrack Firewall Security Security VIPRE VIPRE Business Business Agent Agent Windows   Windows   Defender Defender Lalexander-PC     Windows  None ThreatTrack ThreatTrack Firewall Security Security VIPRE VIPRE Business Business Agent Agent Windows   Windows   Defender Defender Mcarrier-ASUS

Mmichaels-HP Windows   Windows   Windows  None Defender Defender Firewall

PROPRIETARY & CONFIDENTIAL PAGE 110 of 253 Full Detail Report NETWORK ASSESSMENT

Anti-virus Anti-spyware Firewall Backup Computer Name Name On Current Name On Current Name On Name Current Mwest-WIN864     Windows   ThreatTrack ThreatTrack Firewall ShadowProtec Security Security t VIPRE VIPRE Business Business Agent Agent Windows   Windows    Defender Defender StorageCraft mwinchester NOBELIUM

PANOPTICON Windows   Windows   Windows  None Defender Defender Firewall PITWDS12 None None Windows  None Firewall PKWIN8-VM Windows   Windows   Windows  None Defender Defender Firewall porchanko-HOME

PS01 None None Windows  None Firewall Psolidad-PC     Windows  None ThreatTrack ThreatTrack Firewall Security Security VIPRE VIPRE Business Business Agent Agent Windows   Windows   Defender Defender Psolidad-WIN764 Windows   Windows   Windows  None Defender Defender Firewall QB01 VIPRE  VIPRE  Windows   Firewall ShadowProtec t

PROPRIETARY & CONFIDENTIAL PAGE 111 of 253 Full Detail Report NETWORK ASSESSMENT

Anti-virus Anti-spyware Firewall Backup Computer Name Name On Current Name On Current Name On Name Current  StorageCraft REMOTE

REX     Windows   ThreatTrack ThreatTrack Firewall ShadowProtec Security Security t VIPRE VIPRE Business Business Agent Agent Windows   Windows    Defender Defender StorageCraft ronald-LAPTOP

ROWBOT Windows   Windows   Windows  None Defender Defender Firewall SARLACC     Windows  None ThreatTrack ThreatTrack Firewall Security Security VIPRE VIPRE Business Business Agent Agent Windows   Windows   Defender Defender sourcesvr None None Windows   Firewall ShadowProtec t  StorageCraft sourcesvrBUILD None None Windows   Firewall ShadowProtec t  StorageCraft

PROPRIETARY & CONFIDENTIAL PAGE 112 of 253 Full Detail Report NETWORK ASSESSMENT

Anti-virus Anti-spyware Firewall Backup Computer Name Name On Current Name On Current Name On Name Current STORAGE01 VIPRE  VIPRE  None  ShadowProtec t  StorageCraft STORAGE12 None None Windows   Firewall ShadowProtec t  StorageCraft tarsis Windows   Windows   Windows  None Defender Defender Firewall Tneusome-HP Tneusome-LT tywin-PC     Windows  None ThreatTrack ThreatTrack Firewall Security Security VIPRE VIPRE Business Business Agent Agent Windows   Windows   Defender Defender UTIL12   Windows   BitDefender BitDefender Firewall ShadowProtec t  StorageCraft VPNGW None None Windows  None Firewall WAMPA Windows   Windows   Windows  None Defender Defender Firewall

PROPRIETARY & CONFIDENTIAL PAGE 113 of 253 Full Detail Report NETWORK ASSESSMENT

Anti-virus Anti-spyware Firewall Backup Computer Name Name On Current Name On Current Name On Name Current WILLARD Windows   Windows   Windows  None Defender Defender Firewall

PROPRIETARY & CONFIDENTIAL PAGE 114 of 253 Full Detail Report NETWORK ASSESSMENT 12 - Remote Listening Ports

This section contains a list of common ports/protocols assessed, and is categorized by domain or workgroup membership. Items with a red check indicate a potential risk.

CORP.MYCO.COM

IP Address Computer Name Telnet SMTP DNS HTTP HTTPS SQLServer RDP HTTP (23/TCP) (25/TCP) (53/TCP) (80/TCP) (443/TCP) (1433/TCP) (3389/TCP) (8080/TCP) 192.168.1.3 DC03   192.168.1.4 DC03   192.168.1.5 VPNGW    192.168.1.6 ISA1     192.168.1.15 UTIL12    192.168.1.16 SOURCESVR     192.168.1.21 RDGATEWAY    192.168.1.23 DC03   192.168.1.41 FILE2012-1    192.168.1.63 PITWDS12  192.168.1.64 PITWDS12  192.168.1.65 STORAGE12  192.168.1.66 STORAGE12  192.168.1.67 STORAGE12  192.168.1.69 STORAGE01    192.168.1.81 FINANCE    192.168.1.100 HV00  192.168.1.104 HV04  192.168.1.121 HV02   192.168.1.122 HV02   192.168.1.123 HV02   192.168.3.2 AMAZONROUTER    192.168.6.5 CERTEXAM    192.168.6.9 HPDT-8CC5260NXY  192.168.6.12 PSOLIDAD-PC  192.168.6.14 PSOLIDAD-WIN764  192.168.6.26 HPLT-5CD4411D8Z  192.168.6.30 MWEST-WIN864 

PROPRIETARY & CONFIDENTIAL PAGE 115 of 253 Full Detail Report NETWORK ASSESSMENT

IP Address Computer Name Telnet SMTP DNS HTTP HTTPS SQLServer RDP HTTP (23/TCP) (25/TCP) (53/TCP) (80/TCP) (443/TCP) (1433/TCP) (3389/TCP) (8080/TCP) 192.168.6.37 BETTY-INSPIRON  192.168.6.44 B2B-GW  192.168.6.45 DESKTOP-UAE29E6  192.168.6.52 WILLARD  192.168.6.56 CONFERENCE-ROOM  192.168.6.63 BUILDBOX  192.168.6.67 SOURCESVRBUILD  192.168.6.80 DARKHORSE  192.168.6.81 LALEXANDER-PC  192.168.6.100 HV04  192.168.6.105 HV04  192.168.6.108 HV04  192.168.6.109 BOPPENHEIMER-PC   192.168.6.112 REX   192.168.6.117 ISA1    192.168.6.120 PKWIN8-VM  192.168.6.123 HV01   192.168.6.124 HV01   192.168.6.125 WAMPA  192.168.6.132 SARLACC  192.168.6.133 PANOPTICON  192.168.6.134 DARREN-PC  192.168.6.136 GORDON-LT2  192.168.6.142 QB01    192.168.6.151 HV01   192.168.6.159 VPNGW    192.168.6.161 ROWBOT  192.168.6.165 IRIDIUM   192.168.6.195 TARSIS  192.168.7.17 DDOUGLAS-WIN10  192.168.7.44 JIM-WIN8  192.168.7.49 TYWIN-PC  192.168.7.68 REMOTE     192.168.7.95 MMICHAELS-HP  192.168.7.99 PS01    192.168.7.123 ISTCORP-PC 

PROPRIETARY & CONFIDENTIAL PAGE 116 of 253 Full Detail Report NETWORK ASSESSMENT

No Domain

IP Address Computer Name FTP SSH Telnet SMTP DNS HTTP HTTPS RDP VNC HTTP (21/TCP) (22/TCP) (23/TCP) (25/TCP) (53/TCP) (80/TCP) (443/TCP (3389/TC (5900/TC (8080/TC ) P) P) P) 192.168.0.1   192.168.0.2    192.168.0.3    192.168.0.11    192.168.0.241  192.168.0.242  192.168.1.1     192.168.1.24   192.168.1.31 HVFS  192.168.1.32 HVFS  192.168.1.33 HVFS  192.168.1.34 HVFS  192.168.1.50 MYCO-BDR    192.168.1.51    192.168.1.52    192.168.1.201     192.168.1.202     192.168.1.203     192.168.1.204     192.168.1.205     192.168.1.240    192.168.1.243 SEC30CDA792322C  192.168.1.244 BRN30055C36B0DA     192.168.1.245     192.168.3.5 MYCO-DC01  192.168.3.6 MYCO-DC02  192.168.5.1     192.168.6.3 FTWORK-PC   192.168.6.7   192.168.6.10 NEWBUILD  192.168.6.11 SVR1-99ZF   192.168.6.16 SVR1-65LI   192.168.6.21 SVR1-99ZO  

PROPRIETARY & CONFIDENTIAL PAGE 117 of 253 Full Detail Report NETWORK ASSESSMENT

IP Address Computer Name FTP SSH Telnet SMTP DNS HTTP HTTPS RDP VNC HTTP (21/TCP) (22/TCP) (23/TCP) (25/TCP) (53/TCP) (80/TCP) (443/TCP (3389/TC (5900/TC (8080/TC ) P) P) P) 192.168.6.34 SQUID  192.168.6.47 SVR1-99ZG   192.168.6.48 SVR1-99ZP   192.168.6.49     192.168.6.62 WORKSTATION-    DEV2 192.168.6.82 MINTLINUX  192.168.6.86 SVR1-00JY   192.168.6.87 SVR1-91OD   192.168.6.91 SVR1-14TA   192.168.6.92 SVR1-16CA   192.168.6.93 HP25833F   192.168.6.96 WORKSTATION-   POLY2 192.168.6.98 HV2016-PK  192.168.6.106 WORKSTATION-   MARION 192.168.6.107 SVR1-99ZB   192.168.6.119 SVR1-99ZR   192.168.6.128 EX6200   192.168.6.150 WORKSTATION-   TEST1 192.168.6.153 ILOMX280201WZ    192.168.6.154   192.168.6.163 HV05 

PROPRIETARY & CONFIDENTIAL PAGE 118 of 253 Full Detail Report NETWORK ASSESSMENT 13 - Internet Access

This section lists the latency between the computer and both Google and Yahoo, as well as a trace route to Google for further diagnostics if needed.

Internet Access Latency Tests: Retrieval time for Google.com: 49 ms Retrieval time for Yahoo.com: 188 ms

Internet trace route to Google.com: Tracing route to www.google.com [64.233.177.104] over a maximum of 30 hops:

11 ms10.0.0.1 21 ms10.0.1.1 35 ms50-248-236-190-static.hfc.comcastbusiness.net [50.248.236.190] 419 ms96.120.4.25 516 msxe-8-0-0-sur01.n4atlanta.ga.atlanta.comcast.net [68.86.110.137] 618 ms68.86.106.133 716 msbe-7725-cr02.56marietta.ga.ibone.comcast.net [68.86.93.125] 823 mshu-0-10-0-0-pe03.56marietta.ga.ibone.comcast.net [68.86.85.254] 956 ms23.30.207.254 1031 ms216.239.51.39 1118 ms209.85.247.150 1219 ms209.85.253.3 134584 ms 1420 msyx-in-f104.1e100.net [64.233.177.104]

Trace complete.

PROPRIETARY & CONFIDENTIAL PAGE 119 of 253 Full Detail Report NETWORK ASSESSMENT 14 - External Speed Test

This section displays upload and download speed.

Upload Speed: 15.16 Mb/s Download Speed: 55.29 Mb/s

PROPRIETARY & CONFIDENTIAL PAGE 120 of 253 Full Detail Report NETWORK ASSESSMENT

NDT Server Location Download Upload Slowest Link in End-to-End Path 64.86.200.203 CLOSEST (Atlanta_GA, US) 55.29 Mb/s 13.68 Mb/s 10 Mbps Ethernet or WiFi 11b subnet 83.212.4.24 Athens, Greece NDT server offline at time of run. 4.71.254.147 Atlanta, basergia 52.58 Mb/s 14.24 Mb/s 10 Mbps Ethernet or WiFi 11b subnet 4.71.251.147 Chicago, Illinois 17.92 Mb/s 11.44 Mb/s 10 Mbps Ethernet or WiFi 11b subnet 38.107.216.17 Dallas, Texas NDT server offline at time of run. 193.1.12.203 Dublin, Ireland 0.37 Mb/s 11.38 Mb/s 10 Mbps Ethernet or WiFi 11b subnet 80.239.142.203 Frankfurt, Germany 2.30 Mb/s 13.87 Mb/s 10 Mbps Ethernet or WiFi 11b subnet 213.244.128.139 London, United Kingdom 15.22 Mb/s 12.46 Mb/s 10 Mbps Ethernet or WiFi 11b subnet 38.98.51.20 Los Angeles, California 14.16 Mb/s 9.95 Mb/s 10 Mbps Ethernet or WiFi 11b subnet 213.200.103.139 Madrid, Spain 1.15 Mb/s 4.36 Mb/s 10 Mbps Ethernet or WiFi 11b subnet 4.71.210.211 Miami, Florida 30.34 Mb/s 15.16 Mb/s 10 Mbps Ethernet or WiFi 11b subnet 38.106.70.147 New York City, New York NDT server offline at time of run. 38.106.70.147 Newark, New Jersey NDT server offline at time of run. 80.239.168.203 Paris, France 8.02 Mb/s 9.24 Mb/s 10 Mbps Ethernet or WiFi 11b subnet 38.102.0.83 Seattle, Washington 9.69 Mb/s 8.28 Mb/s 10 Mbps Ethernet or WiFi 11b subnet 81.167.39.11 Stavanger, Norway 8.89 Mb/s 3.44 Mb/s 10 Mbps Ethernet or WiFi 11b subnet 175.45.79.11 Sydney, Australia NDT server offline at time of run. 203.178.130.203 Tokyo, Japan 3.20 Mb/s 2.12 Mb/s 10 Mbps Ethernet or WiFi 11b subnet 194.116.85.229 Torino, Italy 12.12 Mb/s 9.59 Mb/s 10 Mbps Ethernet or WiFi 11b subnet 213.208.152.11 Wien, Austria 11.25 Mb/s 4.12 Mb/s 10 Mbps Ethernet or WiFi 11b subnet

PROPRIETARY & CONFIDENTIAL PAGE 121 of 253 Full Detail Report NETWORK ASSESSMENT 15 - Internet Domain

This section contains the WHOIS and MX records for domains added to this assessment. WHOIS information helps determine domain ownership and renewal, while MX records indicate the server responsible for handling email requests (this may redirect elsewhere if acting as a spam filtering service).

microsoft.com

WHOIS Record Domain Name: microsoft.com Registry Domain ID: 2724960_DOMAIN_COM-VRSN Registrar WHOIS Server: whois.markmonitor.com Registrar URL: http://www.markmonitor.com Updated Date: 2014-10-15T04:00:12-0700 Creation Date: 1991-05-01T21:00:00-0700 Registrar Registration Expiration Date: 2021-05-02T21:00:00-0700 Registrar: MarkMonitor, Inc. Registrar IANA ID: 292 Registrar Abuse Contact Email: [email protected] Registrar Abuse Contact Phone: +1.2083895740 Domain Status: clientUpdateProhibited (https://www.icann.org/epp#clientUpdateProhibited) Domain Status: clientTransferProhibited (https://www.icann.org/epp#clientTransferProhibited) Domain Status: clientDeleteProhibited (https://www.icann.org/epp#clientDeleteProhibited) Domain Status: serverUpdateProhibited (https://www.icann.org/epp#serverUpdateProhibited) Domain Status: serverTransferProhibited (https://www.icann.org/epp#serverTransferProhibited) Domain Status: serverDeleteProhibited (https://www.icann.org/epp#serverDeleteProhibited) Registry Registrant ID: Registrant Name: Domain Administrator Registrant Organization: Microsoft Corporation Registrant Street: One Microsoft Way, Registrant City: Redmond Registrant State/Province: WA Registrant Postal Code: 98052 Registrant Country: US Registrant Phone: +1.4258828080 Registrant Phone Ext: Registrant Fax: +1.4259367329 Registrant Fax Ext: Registrant Email: [email protected] Registry Admin ID:

PROPRIETARY & CONFIDENTIAL PAGE 122 of 253 Full Detail Report NETWORK ASSESSMENT

WHOIS Record Admin Name: Domain Administrator Admin Organization: Microsoft Corporation Admin Street: One Microsoft Way, Admin City: Redmond Admin State/Province: WA Admin Postal Code: 98052 Admin Country: US Admin Phone: +1.4258828080 Admin Phone Ext: Admin Fax: +1.4259367329 Admin Fax Ext: Admin Email: [email protected] Registry Tech ID: Tech Name: MSN Hostmaster Tech Organization: Microsoft Corporation Tech Street: One Microsoft Way, Tech City: Redmond Tech State/Province: WA Tech Postal Code: 98052 Tech Country: US Tech Phone: +1.4258828080 Tech Phone Ext: Tech Fax: +1.4259367329 Tech Fax Ext: Tech Email: [email protected] Name Server: ns1.msft.net Name Server: ns3.msft.net Name Server: ns2.msft.net Name Server: ns4.msft.net DNSSEC: unsigned URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/ >>> Last update of WHOIS database: 2017-01-13T06:53:24-0800 <<<

The Data in MarkMonitor.com's WHOIS database is provided by MarkMonitor.com for information purposes, and to assist persons in obtaining information about or related to a domain name registration record. MarkMonitor.com does not guarantee its accuracy. By submitting a WHOIS query, you agree that you will use this Data only for lawful purposes and that, under no circumstances will you use this Data to: (1) allow, enable, or otherwise support the transmission of mass unsolicited, commercial advertising or solicitations via e-mail (spam); or (2) enable high volume, automated, electronic processes that apply to MarkMonitor.com (or its systems).

PROPRIETARY & CONFIDENTIAL PAGE 123 of 253 Full Detail Report NETWORK ASSESSMENT

WHOIS Record MarkMonitor.com reserves the right to modify these terms at any time. By submitting this query, you agree to abide by this policy.

For more information on Whois status codes, please visit https://www.icann.org/resources/pages/epp-status-codes-2014-06-16-en --

Registrar: MARKMONITOR INC. Whois Server: whois.markmonitor.com Creation Date: 02-MAY-1991 Updated Date: 09-OCT-2014 Expiration Date: 03-MAY-2021

Nameserver: NS1.MSFT.NET Nameserver: NS2.MSFT.NET Nameserver: NS3.MSFT.NET Nameserver: NS4.MSFT.NET

Registry Status: clientDeleteProhibited Registry Status: clientTransferProhibited Registry Status: clientUpdateProhibited Registry Status: serverDeleteProhibited Registry Status: serverTransferProhibited Registry Status: serverUpdateProhibited

MXMailServer (Preference) TTL microsoft-com.mail.protection.outlook.com (10) 3019

PROPRIETARY & CONFIDENTIAL PAGE 124 of 253 Full Detail Report NETWORK ASSESSMENT 16 - External Security Vulnerabilities

This section contains an overview of external vulnerabilities detected during the scan, with items in red indicating a risk.

External IP Address Risk High Risk Medium Risk Low Risk Port and Protocol 51.28.232.182 (static.hfc.comcastbusiness.net) Medium 0 3 1 , 443/tcp (https)

PROPRIETARY & CONFIDENTIAL PAGE 125 of 253 Full Detail Report NETWORK ASSESSMENT Appendix I: Detailed Computer Analysis

This section provides additional information on the servers, workstations, and devices in this report. Details are obtained via RPC, WMI or local scan.

CORP.MYCO.COM

Computer Operating System CPU RAM Analysis Name b2b-GW Windows 7 Intel(R) 1024 Last 5 System Error Msgs: Enterprise Xeon(R) CPU MB 10-25-2016 7:20:37 AM 3221227489 The server was unable to allocate from the system L5639 @ nonpaged pool because the server reached the configured limit for nonpaged pool allocations. 2.13GHz 10-24-2016 9:48:36 PM 3221227489 The server was unable to allocate from the system nonpaged pool because the server reached the configured limit for nonpaged pool allocations. 10-24-2016 9:46:36 PM 3221227489 The server was unable to allocate from the system nonpaged pool because the server reached the configured limit for nonpaged pool allocations. 10-23-2016 11:08:42 PM 3221227489 The server was unable to allocate from the system nonpaged pool because the server reached the configured limit for nonpaged pool allocations. 10-22-2016 6:12:36 AM 3221227489 The server was unable to allocate from the system nonpaged pool because the server reached the configured limit for nonpaged pool allocations. Last 5 Application Error Msgs: 10-5-2016 12:07:50 AM 2248220674 The client-side extension could not apply computer policy settings for 'Enable WinRM {EDF5A72E-E57C-4D27-B0F4-61A94F723698}' because it failed with error code '0x80070043 The network name cannot be found.' See trace file for more details. 10-5-2016 12:07:50 AM 2248220674 The client-side extension could not apply computer policy settings for 'PITTech - Local Administrator Account {2EBC1A56-6A4D-4BED-97E1- 7A9302FFB911}' because it failed with error code '0x80070043 The network name cannot be found.' See trace file for more details. 10-5-2016 12:07:50 AM 2248220674 The client-side extension could not apply computer policy settings for 'Common Disk Access {AB5F62C8-8CAF-49B5-A8ED-4A8E73691D55}' because it failed with error code '0x80070043 The network name cannot be found.' See trace file for more details. 10-5-2016 12:07:46 AM 10 Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. 9-26-2016 3:27:18 AM 10 Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor"

PROPRIETARY & CONFIDENTIAL PAGE 126 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Scheduled Tasks: RunPAUI VIPRE Roaming Agent Upgrade Task {E8D72B80-99A1-432F-9982-A9F90F789CA4} Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 126.9 GB, 24.92 GB free, 80.36% used Service Tag: 7242-6114-4960-1418-0345-9017-97 CPU Count: 1 CPU Core Count: 4 : BBBBB-JDJX7-VJ2AF-DDDD9-HCFC6 Other License Keys: Internet Explorer 55041-006-2483512-86608 (ends with HCXPK) Office Professional Plus 2010 82603-018-0000106-48008 (ends with HCXPK) PowerShell 89383-100-0001260-04379 Windows 7 Enterprise 55041-006-2445512-86648 (ends with HCXK) Make and Model: Microsoft Corporation/Virtual Machine Memory Banks: M0 : Unknown-Unknown-1024 Mb-unknown MHz 32 CPUs: Intel(R) Xeon(R) CPU L5639 @ 2.13GHz : CPU0-4 NICs: : -RasSstp-[00000000] WAN Miniport (SSTP) : -RasAgileVpn-[00000001] WAN Miniport (IKEv2) : -Rasl2tp-[00000002] WAN Miniport (L2TP) : -PptpMiniport-[00000003] WAN Miniport (PPTP) : -RasPppoe-[00000004] WAN Miniport (PPPOE) : -NdisWan-[00000005] WAN Miniport (IPv6) : -NdisWan-[00000006] WAN Miniport (redi Monitor) : -dc21x4VM-[00000007] Intel 21140-Based PCI Fast Ethernet Adapter (Emulated) : -NdisWan-[00000008] WAN Miniport (IP)

PROPRIETARY & CONFIDENTIAL PAGE 127 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name : -tunnel-[00000009] Microsoft ISATAP Adapter 20:41:53:59:4E:FF : -AsyncMac-[00000010] RAS Async Adapter : -netvsc-[00000011] Microsoft Virtual Machine Bus redi Adapter : -tunnel-[00000012] Microsoft Teredo Tunneling Adapter 00:15:5D:07:37:0F : 192.168.6.44;fe80::31d8:b72b:fab4:af25-netvsc-[00000013] Microsoft Hyper-V redi Adapter : -tunnel-[00000014] Microsoft ISATAP Adapter DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 6.1.7601 Service Pack 1 (Build 7601) OS Caption: Microsoft Windows 7 Enterprise OS Architecture: 64-bit OS Virtual Memory: 5840 MB OS System Directory: C:\Windows\system32 OS Windows Directory: C:\Windows OS Install Date: 8/12/2013 8:57:44 AM PAE Enabled: True Active Anti-virus: ThreatTrack Security VIPRE Business Agent Active Anti-spyware: ThreatTrack Security VIPRE Business Agent Active Firewall: Windows Firewall betty-INSPIRON Windows 10 Pro Intel(R) 4096 Last 5 System Error Msgs: Core(TM) i3 MB 10-24-2016 4:04:36 PM 10016 The application-specific permission settings do not grant Local CPU M 380 @ Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- 2.53GHz A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-24-2016 2:20:40 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the

PROPRIETARY & CONFIDENTIAL PAGE 128 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-24-2016 12:17:26 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46- 4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-22-2016 6:55:04 AM 36884 The certificate received from the remote server does not contain the expected name. It is therefore not possible to determine whether we are connecting to the correct server. The server name we were expecting is sip.myco.com. The TLS connection request has failed. The attached data contains the server certificate. 10-22-2016 6:55:04 AM 36884 The certificate received from the remote server does not contain the expected name. It is therefore not possible to determine whether we are connecting to the correct server. The server name we were expecting is sip.myco.com. The TLS connection request has failed. The attached data contains the server certificate. Last 5 Application Error Msgs: 10-25-2016 6:59:56 PM 3221226480 The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. 10-25-2016 4:48:01 PM 0 10-25-2016 9:03:58 AM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-24-2016 6:51:45 PM 3221226480 The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. 10-24-2016 4:47:56 PM 0 Scheduled Tasks: OneDrive Standalone Update Task acct_Feed_Synchronization-{2589D638-D8AD-4D2A-AE11-5FA8013F0BF0} acct_Feed_Synchronization-{47D0AC01-2F42-4B15-B690-00A6C18710BF} VIPRE Roaming Agent Upgrade Task Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 232.4 GB, 192.84 GB free, 17.02% used Service Tag: 5LCZZP1 CPU Count: 1

PROPRIETARY & CONFIDENTIAL PAGE 129 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name CPU Core Count: 2 Windows Key: TH4CG-JDJX7-VJ2AF-DY4X9-HCFC6 Other License Keys: Internet Explorer 55041-006-2483512-86608 (ends with HCXPK) Office Professional Plus 2010 82603-018-0000106-48008 (ends with HCXPK) PowerShell 89383-100-0001260-04379 Windows 7 Enterprise 55041-006-2445512-86648 (ends with HCXK) Make and Model: Dell Inc./Inspiron N4010 Memory Banks: DIMM_A : SODIMM-Synchronous-2048 Mb-1333 MHz DIMM_B : SODIMM-Synchronous-2048 Mb-1333 MHz CPUs: Intel(R) Core(TM) i3 CPU M 380 @ 2.53GHz : CPU0-2 System Slots: System Slot0 : PEG Slot J6B2-Available-OK System Slot1 : PCI Express Slot J6B1-Available-OK System Slot2 : PCI Express Slot J6D1-In Use-OK System Slot3 : PCI Express Slot J8B3-Unknown-Unknown System Slot4 : PCI Express Slot J8D1-Unknown-Unknown System Slot5 : PCI Express Slot J7B1-Unknown-Unknown System Slot6 : PCI Express Slot 6-Available-OK NICs: : -kdnic-[00000000] Microsoft Kernel Debug redi Adapter 14:FE:B5:AB:4C:BA : 192.168.6.37;fe80::20f8:5e55:c35f:ca0c-L1C-[00000001] Qualcomm Atheros AR8152 PCI-E Fast Ethernet Controller (NDIS 6.30) C0:F8:DA:38:24:3C : -BCM43XX-[00000002] DW1501 Wireless-N WLAN Half-Mini Card C0:F8:DA:38:24:3C : -vwifimp-[00000003] Microsoft Hosted redi Virtual Adapter : -tunnel-[00000004] Microsoft ISATAP Adapter DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 192.168.14393 unknown (Build 14393) OS Caption: Microsoft Windows 10 Pro OS Architecture:

PROPRIETARY & CONFIDENTIAL PAGE 130 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 64-bit OS Virtual Memory: 5696 MB OS System Directory: C:\WINDOWS\system32 OS Windows Directory: C:\WINDOWS OS Install Date: 9/20/2016 5:52:31 AM PAE Enabled: True Active Anti-virus: ThreatTrack Security VIPRE Business Agent Active Anti-spyware: ThreatTrack Security VIPRE Business Agent Active Firewall: Windows Firewall Boppenheimer- Windows 10 Pro Intel(R) 12288 Last 5 System Error Msgs: PC Core(TM) i7- MB 10-25-2016 5:57:18 PM 10016 The application-specific permission settings do not grant Local 4770 CPU @ Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- 3.40GHz A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 5:14:16 PM 3221232502 The PST Service service is maxed as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. 10-25-2016 2:40:55 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 1:28:07 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 1:24:07 PM 10010 The server {F3B4E234-7A68-4E43-B813-E4BA55A065F6} did not register with DCOM within the required timeout. Last 5 Application Error Msgs:

PROPRIETARY & CONFIDENTIAL PAGE 131 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 10-25-2016 5:13:49 PM 8193 Volume Service error: Unexpected error calling routine QueryFullProcessImageNameW. hr = 0x80070006, The handle is invalid. . Operation: Executing Asynchronous Operation Context: Current State: DoSnapshotSet 10-25-2016 5:13:19 PM 513 Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol. System Error: Access is denied. . 10-25-2016 10:24:52 AM 1026 Application: 709D.tmp.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.IO.FileNotFoundException at toast.Program.InstallShortcut(System.String) at toast.Program.TryCreateShortcut() at toast.Program.Main(System.String[]) 10-25-2016 9:57:05 AM 1026 Application: 709D.tmp.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.IO.FileNotFoundException at toast.Program.InstallShortcut(System.String) at toast.Program.TryCreateShortcut() at toast.Program.Main(System.String[]) 10-25-2016 9:55:48 AM 1026 Application: 709D.tmp.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.IO.FileNotFoundException at toast.Program.InstallShortcut(System.String) at toast.Program.TryCreateShortcut() at toast.Program.Main(System.String[]) Scheduled Tasks: avast! Emergency Update G2MUpdateTask-S-1-5-21-356494474-603968661-3470298851-18623 G2MUploadTask-S-1-5-21-356494474-603968661-3470298851-18623 GoogleUpdateTaskMachineCore GoogleUpdateTaskMachineUA Motorola Device Manager Initial Update Motorola Device Manager Update OneDrive Standalone Update Task Optimize Cache Files-S-1-5-21-2930951861-1219518358-2329501235-1001 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-18623 SafeZone timingd Autoupdate 1464889670 SafeZone timingd Autoupdate 1472504919 update-S-1-5-21-356494474-603968661-3470298851-18623 update-sys acct_ESRV_SVC_WILLAMETTE acct_Feed_Synchronization-{08813E9F-835D-4DCC-9E4B-8014F94DBCAF} acct_Feed_Synchronization-{A63DD391-2F94-4314-AAB0-CFFC35EB63E2} Remote Listening Ports: HTTP (80/TCP) RDP (3389/TCP) Disk Capacity: C: 930.56 GB, 750.68 GB free, 19.33% used

PROPRIETARY & CONFIDENTIAL PAGE 132 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name CPU Count: 1 CPU Core Count: 4 Windows Key: TH4CG-JDJX7-VJ2AF-DYBB9-HCFC6 Other License Keys: Internet Explorer 55041-006-2483512-86608 (ends with HRXPK) Office Professional Plus 2010 82303-018-0000106-48008 (ends with HEXPK) PowerShell 89383-100-001260-04339 Windows 7 Enterprise 55041-006-2445512-86648 (ends with HDXK) Make and Model: Acer/Aspire TC-605 Memory Banks: DIMM1 : DIMM-Synchronous-8192 Mb-1600 MHz DIMM2 : DIMM-Synchronous-4096 Mb-1600 MHz CPUs: Intel(R) Core(TM) i7-4770 CPU @ 3.40GHz : CPU0-4 System Slots: System Slot0 : PCIE16X1-In Use-OK System Slot1 : PCIE1X1-Available-OK System Slot2 : MINI_PCIE1-In Use-OK NICs: : -kdnic-[00000000] Microsoft Kernel Debug redi Adapter 00:FF:28:95:BB:E9 : -tapvyprvpn-[00000001] TAP-VyprVPN Adapter V9 44:8A:5B:64:1E:49 : -rt640x64-[00000002] Realtek PCIe GBE Family Controller 28:E3:47:A1:53:5E : -athr-[00000003] Qualcomm Atheros AR5BWB222 Wireless redi Adapter : -RFCOMM-[00000004] Bluetooth Device (RFCOMM Protocol TDI) 28:E3:47:A1:6A:6A : -BthPan-[00000005] Bluetooth Device (Personal Area redi) : -vwifimp-[00000006] Microsoft Wi-Fi Direct Virtual Adapter 1A:E3:47:A1:53:5E : -vwifimp-[00000007] Microsoft Wi-Fi Direct Virtual Adapter 00:15:5D:06:6D:0C : 169.254.57.9;fe80::2d5f:95:f2a2:3909-VMSMP-[00000008] Hyper-V Virtual Ethernet Adapter 00:15:5D:06:6D:01 : 169.254.196.228;fe80::15a3:dab0:3be9:c4e4-VMSMP-[00000009] Hyper- V Virtual Ethernet Adapter 00:15:5D:06:6D:00 : -VMSMP-[00000010] Hyper-V Virtual Ethernet Adapter : -VMSMP-[00000011] Hyper-V Virtual Switch Extension Adapter 28:E3:47:A1:53:5E : -VMSMP-[00000012] Hyper-V Virtual Ethernet Adapter : -VMSMP-[00000013] Hyper-V Virtual Switch Extension Adapter : -VMSMP-[00000014] Hyper-V Virtual Switch Extension Adapter

PROPRIETARY & CONFIDENTIAL PAGE 133 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 44:8A:5B:64:1E:49 : 192.168.6.109;fe80::81df:a1f5:e6e9:2a42-VMSMP-[00000015] Hyper-V Virtual Ethernet Adapter : -tunnel-[00000016] Microsoft ISATAP Adapter : -tunnel-[00000017] Microsoft ISATAP Adapter : -tunnel-[00000018] Microsoft ISATAP Adapter : -RasSstp-[00000019] WAN Miniport (SSTP) : -RasAgileVpn-[00000020] WAN Miniport (IKEv2) : -Rasl2tp-[00000021] WAN Miniport (L2TP) : -PptpMiniport-[00000022] WAN Miniport (PPTP) : -RasPppoe-[00000023] WAN Miniport (PPPOE) AA:E2:20:52:41:53 : -NdisWan-[00000024] WAN Miniport (IP) A4:AE:20:52:41:53 : -NdisWan-[00000025] WAN Miniport (IPv6) A4:5E:20:52:41:53 : -NdisWan-[00000026] WAN Miniport (redi Monitor) : -tunnel-[00000028] Microsoft ISATAP Adapter DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 192.168.14393 unknown (Build 14393) OS Caption: Microsoft Windows 10 Pro OS Architecture: 64-bit OS Virtual Memory: 14080 MB OS System Directory: C:\WINDOWS\system32 OS Windows Directory: C:\WINDOWS OS Install Date: 9/29/2016 10:38:10 AM PAE Enabled: True Active Anti-virus: Avast Antivirus Active Anti-spyware: Avast Antivirus Active Firewall: Windows Firewall buildbox Windows 10 Pro Intel(R) 4096 Last 5 System Error Msgs: Xeon(R) CPU MB 10-25-2016 11:31:42 AM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-

PROPRIETARY & CONFIDENTIAL PAGE 134 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name L5639 @ 4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to 2.13GHz the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 11:28:34 AM 2 The VM and host networking components failed to negotiate protocol version '6.0' 10-25-2016 11:28:34 AM 2 The VM and host networking components failed to negotiate protocol version '6.1' 10-25-2016 10:38:13 AM 10016 The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {C2F03A33-21F5-47FA- B4BB-156362A2F239} and APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} to the user PIT\abrown SID (S-1-5-21-356494474-603968661-3470298851-40677) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2- 1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool. 10-25-2016 10:37:46 AM 10016 The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {C2F03A33-21F5-47FA- B4BB-156362A2F239} and APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} to the user PIT\abrown SID (S-1-5-21-356494474-603968661-3470298851-40677) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2- 1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool. Last 5 Application Error Msgs: 10-25-2016 6:07:54 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-25-2016 6:07:53 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-25-2016 11:31:45 AM 3221233670 License Activation (slui.exe) failed with the following error code: hr=0x8007139F dbre-line arguments: RuleId=31e71c49-8da7-4a2f-ad92- 45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e- d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8- e3cce27b9f2c;NotificationInterval=1440;Trigger=rediAvailable 10-25-2016 11:31:44 AM 3221226486 Acquisition of End acct License failed. hr=0xC004C008 Sku Id=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c 10-25-2016 11:31:44 AM 3221233672 License acquisition failure details. hr=0xC004C008 Scheduled Tasks: OneDrive Standalone Update Task Report QA Automation Send Report QA E-Mail

PROPRIETARY & CONFIDENTIAL PAGE 135 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 126.51 GB, 70.48 GB free, 44.29% used Service Tag: 1268-2914-8398-6674-9792-4482-17 CPU Count: 1 CPU Core Count: 1 Windows Key: TH4CG-JDJX7-VJ2AF-DYBB9-HCFC6 Other License Keys: Internet Explorer 55041-006-2483512-86608 (ends with HRXPK) Office Professional Plus 2010 82303-018-0000106-48008 (ends with HEXPK) PowerShell 89383-100-001260-04339 Windows 7 Enterprise 55041-006-2445512-86648 (ends with HDXK) Make and Model: Microsoft Corporation/Virtual Machine Memory Banks: M0 : Unknown-Unknown-3968 Mb-unknown MHz M1 : Unknown-Unknown-128 Mb-unknown MHz 32 CPUs: Intel(R) Xeon(R) CPU L5639 @ 2.13GHz : CPU0-1 NICs: 00:15:5D:07:37:4D : 192.168.6.63;fe80::8966:eb6:55a8:ac9f-dc21x4VM-[00000000] Intel 21140-Based PCI Fast Ethernet Adapter (Emulated) : -kdnic-[00000001] Microsoft Kernel Debug redi Adapter 00:15:5D:07:37:4C : 169.254.7.13;fe80::8416:b129:9737:70d-netvsc-[00000002] Microsoft Hyper-V redi Adapter : -tunnel-[00000003] Microsoft ISATAP Adapter : -tunnel-[00000004] Microsoft ISATAP Adapter DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 192.168.14393 unknown (Build 14393) OS Caption: Microsoft Windows 10 Pro

PROPRIETARY & CONFIDENTIAL PAGE 136 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name OS Architecture: 64-bit OS Virtual Memory: 4800 MB OS System Directory: C:\WINDOWS\system32 OS Windows Directory: C:\WINDOWS OS Install Date: 9/19/2016 4:50:35 AM PAE Enabled: True Active Anti-virus: Windows Defender Active Anti-spyware: Windows Defender Active Firewall: Windows Firewall CERTEXAM Windows Server Intel(R) 1024 Last 5 System Error Msgs: 2012 R2 Standard Xeon(R) CPU MB 10-25-2016 9:45:38 PM 36888 A fatal alert was generated and sent to the remote endpoint. L5639 @ This may result in termination of the connection. The TLS protocol defined fatal error code is 2.13GHz 40. The Windows SChannel error state is 1205. 10-25-2016 9:45:38 PM 36874 An TLS 1.2 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed. 10-25-2016 9:45:38 PM 36888 A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 1205. 10-25-2016 9:45:38 PM 36874 An TLS 1.1 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed. 10-25-2016 9:45:38 PM 36888 A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 1205. Last 5 Application Error Msgs: 10-24-2016 4:34:25 AM 2147483905 The volume Recovery was not optimized because an error was encountered: The parameter is incorrect. (0x80070057) 10-23-2016 2:35:09 AM 2147483905 The volume Recovery was not optimized because an error was encountered: The parameter is incorrect. (0x80070057) 10-17-2016 2:13:23 AM 2147483905 The volume Recovery was not optimized because an error was encountered: The parameter is incorrect. (0x80070057) 10-16-2016 2:41:33 AM 2147483905 The volume Recovery was not optimized because an error was encountered: The parameter is incorrect. (0x80070057)

PROPRIETARY & CONFIDENTIAL PAGE 137 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 10-12-2016 12:37:14 AM 3221226480 The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. Scheduled Tasks: Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-1114 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-1230 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-18623 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-40613 Remote Listening Ports: HTTP (80/TCP) HTTPS (443/TCP) RDP (3389/TCP) Disk Capacity: C: 126.48 GB, 108.9 GB free, 13.9% used Service Tag: 1341-6755-7201-7500-4880-8259-16 CPU Count: 1 CPU Core Count: 4 Windows Key: BBBBB-BBBBB-BBBBB-BBBBB-BBBBB Make and Model: Microsoft Corporation/Virtual Machine Memory Banks: M00 : Unknown-Unknown-1024 Mb-unknown MHz 1 CPUs: Intel(R) Xeon(R) CPU L5639 @ 2.13GHz : CPU0-4 NICs: : -Rasl2tp-[00000000] WAN Miniport (L2TP) : -RasSstp-[00000001] WAN Miniport (SSTP) : -RasAgileVpn-[00000002] WAN Miniport (IKEv2) : -PptpMiniport-[00000003] WAN Miniport (PPTP) : -RasPppoe-[00000004] WAN Miniport (PPPOE) : -NdisWan-[00000005] WAN Miniport (IP) : -NdisWan-[00000006] WAN Miniport (IPv6) : -NdisWan-[00000007] WAN Miniport (redi Monitor) : -kdnic-[00000008] Microsoft Kernel Debug redi Adapter 00:15:5D:7A:59:11 : 192.168.6.5;fe80::1509:e668:f2a6:e2ea-netvsc-[00000010] Microsoft Hyper-V redi Adapter

PROPRIETARY & CONFIDENTIAL PAGE 138 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name : -tunnel-[00000011] Microsoft ISATAP Adapter DEP: On for All programs and services except those I select OS Manufacturer: Microsoft Corporation OS Version: 6.3.9600 unknown (Build 9600) OS Caption: Microsoft Windows Server 2012 R2 Standard OS Architecture: 64-bit OS Virtual Memory: 6816 MB OS System Directory: C:\Windows\system32 OS Windows Directory: C:\Windows OS Install Date: 7/28/2014 8:38:10 PM PAE Enabled: True Active Anti-virus: N/A Active Anti-spyware: N/A Active Firewall: Windows Firewall CONFERENCE- Windows 10 Pro Intel(R) 4096 Last 5 System Error Msgs: ROOM Core(TM) i5- MB 10-25-2016 10:55:51 AM 10016 The machine-default permission settings do not grant Local 4570T CPU @ Activation permission for the COM Server application with CLSID {C2F03A33-21F5-47FA- 2.90GHz B4BB-156362A2F239} and APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} to the acct NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 10:55:51 AM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {6B3B8D23-FA8D- 40B9-8DBD-B950333E2C52} and APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} to the acct NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 10:55:51 AM 10016 The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {C2F03A33-21F5-47FA- B4BB-156362A2F239} and APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} to the

PROPRIETARY & CONFIDENTIAL PAGE 139 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name acct NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 10:55:51 AM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {6B3B8D23-FA8D- 40B9-8DBD-B950333E2C52} and APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} to the acct NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 10:54:13 AM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {8D8F4F83-3594- 4F07-8369-FC3C3CAE4919} and APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Last 5 Application Error Msgs: 10-25-2016 4:51:21 PM 3221228576 Enumerating acct sessions to generate filter pools failed. Details: (HRESULT : 0x80040210) (0x80040210) 10-25-2016 4:51:21 PM 3221228576 Enumerating acct sessions to generate filter pools failed. Details: (HRESULT : 0x80040210) (0x80040210) 10-25-2016 1:51:21 PM 3221228576 Enumerating acct sessions to generate filter pools failed. Details: (HRESULT : 0x80040210) (0x80040210) 10-25-2016 1:51:21 PM 3221228576 Enumerating acct sessions to generate filter pools failed. Details: (HRESULT : 0x80040210) (0x80040210) 10-25-2016 10:56:04 AM 3238068259 Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0". Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0". Please use sxstrace.exe for detailed diagnosis. Scheduled Tasks: OneDrive Standalone Update Task RtHDVBg_LENOVO_MICPKEY RTKCPL acct_Feed_Synchronization-{C657A256-81D2-49A4-84C7-0FE823B538A7} VIPRE Roaming Agent Upgrade Task Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 255.45 GB, 219.14 GB free, 14.21% used

PROPRIETARY & CONFIDENTIAL PAGE 140 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name Service Tag: MG006P4N CPU Count: 1 CPU Core Count: 2 Windows Key: BBBBB-JDJX7-VJ2AF-DDDD9-HCFC6 Make and Model: LENOVO/10AB000KUS Memory Banks: ChannelB-DIMM0 : SODIMM-Synchronous-4096 Mb-1600 MHz CPUs: Intel(R) Core(TM) i5-4570T CPU @ 2.90GHz : CPU0-2 System Slots: System Slot0 : J6B2-In Use-OK System Slot1 : J6B1-In Use-OK System Slot2 : J6D1-In Use-OK System Slot3 : J7B1-In Use-OK NICs: 00:23:24:6C:C7:EF : 192.168.6.56;fe80::ad41:cacc:ac6e:e041-e1iexpress-[00000000] Intel(R) Ethernet Connection I217-LM B8:8A:60:1F:9E:14 : -NETwNe64-[00000001] Intel(R) Centrino(R) Wireless-N 105 Driver : -kdnic-[00000002] Microsoft Kernel Debug redi Adapter B8:8A:60:1F:9E:15 : -vwifimp-[00000003] Microsoft Wi-Fi Direct Virtual Adapter : -tunnel-[00000004] Microsoft ISATAP Adapter : -vwifimp-[00000005] Microsoft Wi-Fi Direct Virtual Adapter : -RFCOMM-[00000006] Bluetooth Device (RFCOMM Protocol TDI) : -RasSstp-[00000007] WAN Miniport (SSTP) : -RasAgileVpn-[00000008] WAN Miniport (IKEv2) : -Rasl2tp-[00000009] WAN Miniport (L2TP) : -PptpMiniport-[00000010] WAN Miniport (PPTP) : -RasPppoe-[00000011] WAN Miniport (PPPOE) : -NdisWan-[00000012] WAN Miniport (IP) : -NdisWan-[00000013] WAN Miniport (IPv6) : -NdisWan-[00000014] WAN Miniport (redi Monitor) 00:1B:DC:06:A6:47 : -BthPan-[00000015] Bluetooth Device (Personal Area redi) DEP: On for essential Windows programs and services only OS Manufacturer:

PROPRIETARY & CONFIDENTIAL PAGE 141 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name Microsoft Corporation OS Version: 192.168.14393 unknown (Build 14393) OS Caption: Microsoft Windows 10 Pro OS Architecture: 64-bit OS Virtual Memory: 4688 MB OS System Directory: C:\Windows\system32 OS Windows Directory: C:\Windows OS Install Date: 9/20/2016 8:47:44 PM PAE Enabled: True Active Anti-virus: ThreatTrack Security VIPRE Business Agent Active Anti-spyware: ThreatTrack Security VIPRE Business Agent Active Firewall: Windows Firewall darkhorse Windows 10 Pro Intel(R) 16384 Last 5 System Error Msgs: Core(TM) i7- MB 10-25-2016 6:34:24 PM 3221232506 The Software Protection service terminated 6700K CPU @ unexpectedly. It has done this 43 time(s). 4.00GHz 10-25-2016 1:39:10 PM 3221232495 The Intel(R) Content Protection HECI Service service terminated with the following error: Invalid handle 10-25-2016 1:39:10 PM 3221232495 The Intel(R) Content Protection HECI Service service terminated with the following error: Invalid handle 10-25-2016 1:39:10 PM 3221232495 The Intel(R) Content Protection HECI Service service terminated with the following error: Invalid handle 10-25-2016 1:39:09 PM 3221232495 The Intel(R) Content Protection HECI Service service terminated with the following error: Invalid handle Last 5 Application Error Msgs: 10-25-2016 6:06:25 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-25-2016 6:06:25 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-25-2016 1:39:09 PM 1000 Faulting application name: LogonUI.exe, version: 192.168.10586.0, time stamp: 0x5632d88c Faulting module name: Windows.UI.Logon.dll, version: 192.168.10586.589, time stamp: 0x57cf94b6 Exception code: 0xc0000005 Fault offset: 0x000000000001945c Faulting process id: 0x56ec Faulting application start time:

PROPRIETARY & CONFIDENTIAL PAGE 142 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 0x01d22ee6b0df68ec Faulting application path: C:\windows\system32\LogonUI.exe Faulting module path: C:\windows\system32\Windows.UI.Logon.dll Report Id: 20cdbb21-a285-4ca1- a44e-7c5fc37135cd Faulting package full name: Faulting package-relative application ID: 10-25-2016 1:02:43 PM 1000 Faulting application name: LogonUI.exe, version: 192.168.10586.0, time stamp: 0x5632d88c Faulting module name: Windows.UI.Logon.dll, version: 192.168.10586.589, time stamp: 0x57cf94b6 Exception code: 0xc0000005 Fault offset: 0x000000000001945c Faulting process id: 0x2f94 Faulting application start time: 0x01d22ee199b76597 Faulting application path: C:\windows\system32\LogonUI.exe Faulting module path: C:\windows\system32\Windows.UI.Logon.dll Report Id: b53aa902-840d-4bd1- bdd3-f4930b02ee4e Faulting package full name: Faulting package-relative application ID: 10-25-2016 11:55:49 AM 0 Scheduled Tasks: GoogleUpdateTaskMachineCore GoogleUpdateTaskMachineUA OneDrive Standalone Update Task acct_Feed_Synchronization-{395F77FC-09C7-4CE1-8257-AF892CCE46BB} Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 476.12 GB, 253.3 GB free, 46.8% used Service Tag: PS CPU Count: 1 CPU Core Count: 4 Windows Key: TH4CG-JDJX7-VJ2AF-DYBB9-HCFC6 Other License Keys: Internet Explorer 55041-006-2483512-86608 (ends with HRXPK) Office Professional Plus 2010 82303-018-0000106-48008 (ends with HEXPK) PowerShell 89383-100-001260-04339 Windows 7 Enterprise 55041-006-2445512-86648 (ends with HDXK) Make and Model: PowerSpec/Gseries Memory Banks: ChannelA-DIMM1 : DIMM-Synchronous-8192 Mb-3200 MHz ChannelB-DIMM1 : DIMM-Synchronous-8192 Mb-3200 MHz CPUs:

PROPRIETARY & CONFIDENTIAL PAGE 143 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name Intel(R) Core(TM) i7-6700K CPU @ 4.00GHz : CPU0-4 System Slots: System Slot0 : J6B2-In Use-OK System Slot1 : J6B1-In Use-OK System Slot2 : J6D1-In Use-OK System Slot3 : J7B1-In Use-OK System Slot4 : J8B4-In Use-OK System Slot5 : J8D1-In Use-OK System Slot6 : J8B3-In Use-OK NICs: : -kdnic-[00000000] Microsoft Kernel Debug redi Adapter 30:10:B3:4A:8D:ED : -athr-[00000001] Qualcomm Atheros AR5BWB222 Wireless redi Adapter 4C:CC:6A:25:7D:6D : -rt640x64-[00000002] Realtek PCIe GBE Family Controller 12:10:B3:4A:8D:ED : -vwifimp-[00000003] Microsoft Wi-Fi Direct Virtual Adapter : -tunnel-[00000004] Microsoft ISATAP Adapter : -vwifimp-[00000005] Microsoft Wi-Fi Direct Virtual Adapter : -RFCOMM-[00000006] Bluetooth Device (RFCOMM Protocol TDI) : -BthPan-[00000007] Bluetooth Device (Personal Area redi) : -RFCOMM-[00000008] Bluetooth Device (RFCOMM Protocol TDI) 30:10:B3:4A:A0:AD : -BthPan-[00000009] Bluetooth Device (Personal Area redi) : -VMSMP-[00000010] Hyper-V Virtual Switch Extension Adapter 4C:CC:6A:25:7D:6D : 192.168.6.80;fe80::c42:9dab:83a1:ea7f-VMSMP-[00000011] Hyper-V Virtual Ethernet Adapter : -tunnel-[00000012] Microsoft ISATAP Adapter : -VMSMP-[00000013] Hyper-V Virtual Switch Extension Adapter 00:15:5D:06:50:00 : 169.254.24.150;fe80::59f3:9394:d4fe:1896-VMSMP-[00000014] Hyper-V Virtual Ethernet Adapter : -tunnel-[00000015] Microsoft ISATAP Adapter : -VMSMP-[00000016] Hyper-V Virtual Switch Extension Adapter 00:15:5D:06:50:05 : 169.254.58.236;fe80::a8a8:6c1c:2b2c:3aec-VMSMP-[00000017] Hyper-V Virtual Ethernet Adapter : -tunnel-[00000018] Microsoft ISATAP Adapter DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 192.168.10586 unknown (Build 10586) OS Caption: Microsoft Windows 10 Pro OS Architecture:

PROPRIETARY & CONFIDENTIAL PAGE 144 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 64-bit OS Virtual Memory: 18704 MB OS System Directory: C:\windows\system32 OS Windows Directory: C:\windows OS Install Date: 8/4/2016 6:33:57 AM PAE Enabled: True Active Anti-virus: Windows Defender Active Anti-spyware: Windows Defender Active Firewall: Windows Firewall darren-PC Windows 10 Pro Intel(R) 8192 Last 5 System Error Msgs: Core(TM) i3- MB 10-25-2016 7:13:03 PM 10016 The application-specific permission settings do not grant Local 4170 CPU @ Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- 3.70GHz A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 6:44:36 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {8D8F4F83-3594-4F07- 8369-FC3C3CAE4919} and APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 6:44:36 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {6B3B8D23-FA8D-40B9- 8DBD-B950333E2C52} and APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} to the acct NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 6:44:36 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {6B3B8D23-FA8D-40B9- 8DBD-B950333E2C52} and APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} to the acct NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

PROPRIETARY & CONFIDENTIAL PAGE 145 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 10-25-2016 6:24:09 PM 10010 The server App.AppXryc2qd338f5728r9gzzazav8206ba77s.mca did not register with DCOM within the required timeout. Last 5 Application Error Msgs: 10-25-2016 6:44:43 PM 3221233670 License Activation (slui.exe) failed with the following error code: hr=0xC004C008 dbre-line arguments: RuleId=31e71c49-8da7-4a2f-ad92- 45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e- d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8- e3cce27b9f2c;NotificationInterval=1440;Trigger=acctLogon;SessionId=7 10-25-2016 6:44:43 PM 3221226486 Acquisition of End acct License failed. hr=0xC004C008 Sku Id=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c 10-25-2016 6:44:43 PM 3221233672 License acquisition failure details. hr=0xC004C008 10-25-2016 6:35:39 PM 3221233670 License Activation (slui.exe) failed with the following error code: hr=0x8007139F dbre-line arguments: RuleId=31e71c49-8da7-4a2f-ad92- 45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e- d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8- e3cce27b9f2c;NotificationInterval=1440;Trigger=rediAvailable 10-25-2016 6:35:39 PM 3221226486 Acquisition of End acct License failed. hr=0xC004C008 Sku Id=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c Scheduled Tasks: Adobe Acrobat Update Task DropboxUpdateTaskMachineCore DropboxUpdateTaskMachineUA G2MUpdateTask-S-1-5-21-356494474-603968661-3470298851-42182 G2MUploadTask-S-1-5-21-356494474-603968661-3470298851-42182 GoogleUpdateTaskMachineCore GoogleUpdateTaskMachineUA OneDrive Standalone Update Task VIPRE Roaming Agent Upgrade Task Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 912.26 GB, 874.79 GB free, 4.11% used D: 17.82 GB, 2.25 GB free, 87.37% used CPU Count: 1 CPU Core Count: 2 Windows Key: BBBBB-JDJX7-VJ2AF-DDDD9-HCFC6 Make and Model:

PROPRIETARY & CONFIDENTIAL PAGE 146 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name HP/550-110 Memory Banks: DIMM2 : DIMM-Synchronous-8192 Mb-1600 MHz CPUs: Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz : CPU0-2 System Slots: System Slot0 : PCI Express x16 Slot-In Use-OK System Slot1 : PCI Express x1 Slot 1-Available-OK System Slot2 : Mini Card Slot 1-In Use-OK NICs: : -kdnic-[00000000] Microsoft Kernel Debug redi Adapter DC:FE:07:0A:6D:7D : 192.168.6.134;fe80::2508:aae8:1619:22e1-rt640x64-[00000001] Realtek PCIe GBE Family Controller 48:E2:44:CB:95:FF : -BCMWL63A-[00000002] Broadcom BCM43142 802.11 bgn Wi-Fi Adapter : -vwifimp-[00000003] Microsoft Wi-Fi Direct Virtual Adapter : -RFCOMM-[00000004] Bluetooth Device (RFCOMM Protocol TDI) 48:E2:44:CB:96:00 : -BthPan-[00000005] Bluetooth Device (Personal Area redi) 4A:E2:44:CB:95:FF : -vwifimp-[00000006] Microsoft Wi-Fi Direct Virtual Adapter : -tunnel-[00000007] Microsoft ISATAP Adapter DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 192.168.14393 unknown (Build 14393) OS Caption: Microsoft Windows 10 Pro OS Architecture: 64-bit OS Virtual Memory: 9440 MB OS System Directory: C:\WINDOWS\system32 OS Windows Directory: C:\WINDOWS OS Install Date: 10/10/2016 11:37:34 AM PAE Enabled: True

PROPRIETARY & CONFIDENTIAL PAGE 147 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name Active Anti-virus: ThreatTrack Security VIPRE Business Agent, Windows Defender Active Anti-spyware: ThreatTrack Security VIPRE Business Agent, Windows Defender Active Firewall: Windows Firewall DC03 Windows Server Intel(R) 1024 Last 5 System Error Msgs: 2012 R2 Datacenter Xeon(R) CPU MB 10-25-2016 7:34:57 PM 5719 This computer was not able to set up a secure session with a L5639 @ domain controller in domain SUPPORT due to the following: There are currently no logon 2.13GHz servers available to service the logon request. This may lead to authentication problems. Make sure that this computer is connected to the redi. If the problem persists, please contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain. 10-25-2016 7:34:40 PM 5719 This computer was not able to set up a secure session with a domain controller in domain HQ due to the following: There are currently no logon servers available to service the logon request. This may lead to authentication problems. Make sure that this computer is connected to the redi. If the problem persists, please contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain. 10-25-2016 3:34:29 PM 5719 This computer was not able to set up a secure session with a domain controller in domain HQ due to the following: There are currently no logon servers available to service the logon request. This may lead to authentication problems. Make sure that this computer is connected to the redi. If the problem persists, please contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain. 10-25-2016 3:34:08 PM 5719 This computer was not able to set up a secure session with a domain controller in domain SUPPORT due to the following: There are currently no logon servers available to service the logon request. This may lead to authentication problems. Make sure that this computer is connected to the redi. If the problem persists, please contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain. 10-25-2016 2:26:03 PM 10028 DCOM was unable to communicate with the computer pilotRootAuth.Corp.myco.com using any of the configured protocols; requested by PID 117c (C:\Windows\system32\taskhost.exe). Last 5 Application Error Msgs:

PROPRIETARY & CONFIDENTIAL PAGE 148 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 10-25-2016 2:26:03 PM 1073741830 Automatic certificate enrollment for local system failed (0x800706ba) The RPC server is unavailable. . 10-25-2016 2:26:03 PM 3260678157 Certificate enrollment for Local system failed to enroll for a DomainController certificate with request ID N/A from pilotRootAuth.Corp.myco.com\myco Enterprise Root CA (The RPC server is unavailable. 0x800706ba (WIN32: 1722 RPC_S_SERVER_UNAVAILABLE)). 10-25-2016 2:26:03 PM 2186936402 Certificate enrollment for Local system failed in authentication to all urls for enrollment server associated with policy id: {80B1C0A2-44EE- 4C9A-87F8-F1009ECEE682} (The RPC server is unavailable. 0x800706ba (WIN32: 1722 RPC_S_SERVER_UNAVAILABLE)). Failed to enroll for template: DomainController 10-25-2016 6:26:02 AM 1073741830 Automatic certificate enrollment for local system failed (0x800706ba) The RPC server is unavailable. . 10-25-2016 6:26:02 AM 3260678157 Certificate enrollment for Local system failed to enroll for a DomainController certificate with request ID N/A from pilotRootAuth.Corp.myco.com\myco Enterprise Root CA (The RPC server is unavailable. 0x800706ba (WIN32: 1722 RPC_S_SERVER_UNAVAILABLE)). Scheduled Tasks: Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-1114 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-1115 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-1117 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-1118 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-1182 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-1230 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-1244 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-18623 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-29609 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-40613 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-40659 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-500 Remote Listening Ports: DNS (53/TCP) RDP (3389/TCP) Disk Capacity: C: 126.48 GB, 104.38 GB free, 17.47% used Service Tag: 8969-2496-9219-1613-4999-3630-25 CPU Count: 1 CPU Core Count: 4 Windows Key:

PROPRIETARY & CONFIDENTIAL PAGE 149 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name TH4CG-JDJX7-VJ2AF-DYBB9-HCFC6 Other License Keys: Internet Explorer 55041-006-2483512-86608 (ends with HRXPK) Office Professional Plus 2010 82303-018-0000106-48008 (ends with HEXPK) PowerShell 89383-100-001260-04339 Windows 7 Enterprise 55041-006-2445512-86648 (ends with HDXK) Make and Model: Microsoft Corporation/Virtual Machine Memory Banks: M00 : Unknown-Unknown-1024 Mb-unknown MHz 1 CPUs: Intel(R) Xeon(R) CPU L5639 @ 2.13GHz : CPU0-4 NICs: : -Rasl2tp-[00000000] WAN Miniport (L2TP) : -RasSstp-[00000001] WAN Miniport (SSTP) : -RasAgileVpn-[00000002] WAN Miniport (IKEv2) : -PptpMiniport-[00000003] WAN Miniport (PPTP) : -RasPppoe-[00000004] WAN Miniport (PPPOE) : -NdisWan-[00000005] WAN Miniport (IP) : -NdisWan-[00000006] WAN Miniport (IPv6) : -NdisWan-[00000007] WAN Miniport (redi Monitor) : -kdnic-[00000008] Microsoft Kernel Debug redi Adapter : -tunnel-[00000009] Microsoft Teredo Tunneling Adapter 00:15:0A:00:01:03 : 192.168.1.23;192.168.1.4;192.168.1.3;fe80::b59a:c6dc:c17b:15b9-netvsc- [00000010] Microsoft Hyper-V redi Adapter : -tunnel-[00000011] Microsoft ISATAP Adapter 00:15:5D:7A:59:18 : -netvsc-[00000012] Microsoft Hyper-V redi Adapter : -tunnel-[00000013] Microsoft ISATAP Adapter DEP: On for All programs and services except those I select OS Manufacturer: Microsoft Corporation OS Version: 6.3.9600 unknown (Build 9600) OS Caption: Microsoft Windows Server 2012 R2 Datacenter OS Architecture: 64-bit OS Virtual Memory: 8192 MB

PROPRIETARY & CONFIDENTIAL PAGE 150 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name OS System Directory: C:\Windows\system32 OS Windows Directory: C:\Windows OS Install Date: 1/30/2014 12:16:06 AM PAE Enabled: True Active Anti-virus: GFI Languard Active Anti-spyware: GFI Languard Active Firewall: N/A Ddouglas-PC Windows 8.1 Enterprise Ddouglas- Windows 10 Pro AMD 6144 Last 5 System Error Msgs: WIN10 Phenom(tm) II MB 10-25-2016 7:36:14 PM 10016 The application-specific permission settings do not grant Local X4 945 Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- Processor A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-24-2016 7:26:11 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-24-2016 9:36:19 AM 10010 The server {E844CD23-864D-4921-B18B-ED60A150E112} did not register with DCOM within the required timeout. 10-24-2016 9:35:49 AM 10010 The server {E844CD23-864D-4921-B18B-ED60A150E112} did not register with DCOM within the required timeout. 10-24-2016 9:25:50 AM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {8D8F4F83-3594-4F07- 8369-FC3C3CAE4919} and APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Last 5 Application Error Msgs: 10-25-2016 5:31:58 PM 1000 Faulting application name: dwm.exe, version: 192.168.14393.0, time stamp: 0x578999ab Faulting module name: dwmcore.dll, version: 192.168.14393.187, time stamp: 0x57cf99aa Exception code: 0xc0000005 Fault offset: 0x0000000000144cc4

PROPRIETARY & CONFIDENTIAL PAGE 151 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name Faulting process id: 0x3f4 Faulting application start time: 0x01d22df9f7b5107f Faulting application path: C:\Windows\system32\dwm.exe Faulting module path: C:\Windows\system32\dwmcore.dll Report Id: 33ee3dee-10d7-45a7-8f4f-0408c608afd7 Faulting package full name: Faulting package-relative application ID: 10-25-2016 1:52:56 PM 3221226495 Windows cannot load the extensible counter DLL SQLAgent$UPSWS2012SERVER. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-25-2016 9:30:30 AM 3221226495 Windows cannot load the extensible counter DLL MSSQL$UPSWS2012SERVER. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-25-2016 9:25:54 AM 3221233670 License Activation (slui.exe) failed with the following error code: hr=0xC004C008 dbre-line arguments: RuleId=31e71c49-8da7-4a2f-ad92- 45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e- d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8- e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEvent 10-25-2016 9:25:54 AM 3221226486 Acquisition of End acct License failed. hr=0xC004C008 Sku Id=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 126.81 GB, 89.69 GB free, 29.27% used D: 468.87 GB, 468.67 GB free, 0.04% used CPU Count: 1 CPU Core Count: 4 Windows Key: BBBBB-JDJX7-VJ2AF-DDDD9-HCFC6 Make and Model: Gateway/DX4320 Memory Banks: DIMM0 : DIMM-Synchronous-1024 Mb-533 MHz DIMM1 : DIMM-Synchronous-1024 Mb-533 MHz DIMM2 : DIMM-Synchronous-2048 Mb-533 MHz DIMM3 : DIMM-Synchronous-2048 Mb-533 MHz CPUs: AMD Phenom(tm) II X4 945 Processor : CPU0-4 System Slots: System Slot0 : PCIE1-In Use-OK System Slot1 : PCIE2-Available-OK

PROPRIETARY & CONFIDENTIAL PAGE 152 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name System Slot2 : PCIE3-In Use-OK System Slot3 : PCI1-Available-OK NICs: : -kdnic-[00000000] Microsoft Kernel Debug redi Adapter 00:1B:21:6E:3E:08 : -e1iexpress-[00000001] Intel(R) Gigabit CT Desktop Adapter 90:FB:A6:8A:96:B6 : 192.168.7.17;fe80::e981:7238:cc6c:51cd-rt640x64-[00000002] Realtek PCIe GBE Family Controller : -tunnel-[00000003] Microsoft ISATAP Adapter DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 192.168.14393 unknown (Build 14393) OS Caption: Microsoft Windows 10 Pro OS Architecture: 64-bit OS Virtual Memory: 7808 MB OS System Directory: C:\Windows\system32 OS Windows Directory: C:\Windows OS Install Date: 10/23/2016 1:33:07 PM Active Anti-virus: ThreatTrack Security VIPRE Business Agent Active Anti-spyware: ThreatTrack Security VIPRE Business Agent Active Firewall: Windows Firewall DESKTOP- Windows 10 Pro Intel(R) 16384 Last 5 System Error Msgs: N6S4H9A Core(TM) i7- MB 10-25-2016 6:19:45 PM 5719 This computer was not able to set up a secure session with a 4770 CPU @ domain controller in domain PIT due to the following: There are currently no logon servers 3.40GHz available to service the logon request. This may lead to authentication problems. Make sure that this computer is connected to the redi. If the problem persists, please contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain. 10-25-2016 5:40:22 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-

PROPRIETARY & CONFIDENTIAL PAGE 153 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 1:22:34 PM 5719 This computer was not able to set up a secure session with a domain controller in domain PIT due to the following: There are currently no logon servers available to service the logon request. This may lead to authentication problems. Make sure that this computer is connected to the redi. If the problem persists, please contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain. 10-25-2016 8:40:44 AM 5719 This computer was not able to set up a secure session with a domain controller in domain PIT due to the following: There are currently no logon servers available to service the logon request. This may lead to authentication problems. Make sure that this computer is connected to the redi. If the problem persists, please contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain. 10-24-2016 5:41:00 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Last 5 Application Error Msgs: 10-25-2016 4:55:13 PM 3238068302 Activation context generation failed for "C:\Program Files (x86)\Samsung\SideSync4\SideSync.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common- controls_6595b64144ccf1df_6.0.14393.0_none_2d0f50fcbdb171b8.manifest. Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common- controls_6595b64144ccf1df_6.0.14393.0_none_74bc87d3d22d9abe.manifest. 10-25-2016 9:03:43 AM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-24-2016 5:10:04 PM 1000 Faulting application name: rediDetective.exe, version: 2.0.16.0, time stamp: 0x57f29d2b Faulting module name: KERNELBASE.dll, version: 192.168.14393.321, time stamp: 0x57f4c4f0 Exception code: 0xc000041d Fault offset: 0x0000000000017788 Faulting process id: 0x1c8c Faulting application start time:

PROPRIETARY & CONFIDENTIAL PAGE 154 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 0x01d22e39c75d1fd7 Faulting application path: C:\accts\pmaloney\AppData\Local\Apps\2.0\ZEZ7Z28H.GWM\L8MBX14L.8HW\netw..tion_8b0 e2e275ac2c625_0004.0000_49c4b89b8ca33d20\rediDetective.exe Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll Report Id: 095df7c7-249a-41e1-af84- b67073a1d08f Faulting package full name: Faulting package-relative application ID: 10-24-2016 5:10:02 PM 1000 Faulting application name: rediDetective.exe, version: 2.0.16.0, time stamp: 0x57f29d2b Faulting module name: KERNELBASE.dll, version: 192.168.14393.321, time stamp: 0x57f4c4f0 Exception code: 0xe0434352 Fault offset: 0x0000000000017788 Faulting process id: 0x1c8c Faulting application start time: 0x01d22e39c75d1fd7 Faulting application path: C:\accts\pmaloney\AppData\Local\Apps\2.0\ZEZ7Z28H.GWM\L8MBX14L.8HW\netw..tion_8b0 e2e275ac2c625_0004.0000_49c4b89b8ca33d20\rediDetective.exe Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll Report Id: c74ffdd1-e10f-425c-b048- d0c6dc5a5185 Faulting package full name: Faulting package-relative application ID: 10-24-2016 10:10:23 AM 513 Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol. System Error: Access is denied. . Scheduled Tasks: G2MUpdateTask-S-1-5-21-356494474-603968661-3470298851-42224 G2MUploadTask-S-1-5-21-356494474-603968661-3470298851-42224 GoogleUpdateTaskMachineCore GoogleUpdateTaskMachineUA OneDrive Standalone Update Task update-S-1-5-21-356494474-603968661-3470298851-42224 update-S-1-5-21-509862780-2876472002-2229649970-1001 update-sys acct_Feed_Synchronization-{429D0A21-75E5-4400-A964-52F2F6786984} Disk Capacity: C: 931.02 GB, 850.48 GB free, 8.65% used CPU Count: 1 CPU Core Count: 4 Windows Key: TH4CG-JDJX7-VJ2AF-DYBB9-HCFC6 Other License Keys: Internet Explorer 55041-006-2483512-86608 (ends with HRXPK) Office Professional Plus 2010 82303-018-0000106-48008 (ends with HEXPK) PowerShell 89383-100-001260-04339 Windows 7 Enterprise 55041-006-2445512-86648 (ends with HDXK) Make and Model:

PROPRIETARY & CONFIDENTIAL PAGE 155 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name Acer/Veriton M6630G Memory Banks: DIMM1 : DIMM-Synchronous-4096 Mb-1600 MHz DIMM2 : DIMM-Synchronous-4096 Mb-1600 MHz DIMM3 : DIMM-Synchronous-4096 Mb-1333 MHz DIMM4 : DIMM-Synchronous-4096 Mb-1600 MHz CPUs: Intel(R) Core(TM) i7-4770 CPU @ 3.40GHz : CPU0-4 System Slots: System Slot0 : PCIE16X_1-In Use-OK System Slot1 : PCIE1X-Available-OK System Slot2 : PCI-Available-OK System Slot3 : PCIE16X_2-Available-OK NICs: : -kdnic-[00000000] Microsoft Kernel Debug redi Adapter C0:3F:D5:5E:F2:D3 : -e1iexpress-[00000001] Intel(R) Ethernet Connection I217-LM 00:15:5D:06:55:00 : 169.254.93.61;fe80::8cb3:404b:e5b6:5d3d-VMSMP-[00000002] Hyper-V Virtual Ethernet Adapter C0:3F:D5:5E:F2:D3 : 192.168.6.85;fe80::2939:588a:4461:8b92-VMSMP-[00000003] Hyper-V Virtual Ethernet Adapter : -VMSMP-[00000004] Hyper-V Virtual Switch Extension Adapter : -VMSMP-[00000005] Hyper-V Virtual Switch Extension Adapter : -tunnel-[00000006] Microsoft ISATAP Adapter : -tunnel-[00000007] Microsoft ISATAP Adapter : -usb_rndisx-[00000008] Remote NDIS based Internet Sharing Device : -RasSstp-[00000009] WAN Miniport (SSTP) : -RasAgileVpn-[00000010] WAN Miniport (IKEv2) : -Rasl2tp-[00000011] WAN Miniport (L2TP) : -PptpMiniport-[00000012] WAN Miniport (PPTP) : -RasPppoe-[00000013] WAN Miniport (PPPOE) 56:9A:20:52:41:53 : -NdisWan-[00000014] WAN Miniport (IP) 68:FA:20:52:41:53 : -NdisWan-[00000015] WAN Miniport (IPv6) 68:FA:20:52:41:53 : -NdisWan-[00000016] WAN Miniport (redi Monitor) 20:41:53:59:4E:FF : -AsyncMac-[00000017] RAS Async Adapter : -tunnel-[00000018] Microsoft ISATAP Adapter DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version:

PROPRIETARY & CONFIDENTIAL PAGE 156 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 192.168.14393 unknown (Build 14393) OS Caption: Microsoft Windows 10 Pro OS Architecture: 64-bit OS Virtual Memory: 18848 MB OS System Directory: C:\WINDOWS\system32 OS Windows Directory: C:\WINDOWS OS Install Date: 9/2/2016 9:23:35 AM PAE Enabled: True Active Anti-virus: Windows Defender Active Anti-spyware: Windows Defender Active Firewall: Windows Firewall DESKTOP- Windows 10 Pro Intel(R) 8192 Last 5 System Error Msgs: UAE29E6 Xeon(R) CPU MB 10-25-2016 8:03:43 PM 10028 DCOM was unable to communicate with the computer L5639 @ 192.168.6.117 using any of the configured protocols; requested by PID 53c (C:\Program Files 2.13GHz (x86)\bestrmm\bin\bestrmm-finder.exe). 10-25-2016 8:03:43 PM 10028 DCOM was unable to communicate with the computer 192.168.6.117 using any of the configured protocols; requested by PID 53c (C:\Program Files (x86)\bestrmm\bin\bestrmm-finder.exe). 10-25-2016 8:03:43 PM 10028 DCOM was unable to communicate with the computer 192.168.6.117 using any of the configured protocols; requested by PID 53c (C:\Program Files (x86)\bestrmm\bin\bestrmm-finder.exe). 10-25-2016 8:03:43 PM 10028 DCOM was unable to communicate with the computer 192.168.6.117 using any of the configured protocols; requested by PID 53c (C:\Program Files (x86)\bestrmm\bin\bestrmm-finder.exe). 10-25-2016 8:03:42 PM 10028 DCOM was unable to communicate with the computer 192.168.6.117 using any of the configured protocols; requested by PID 53c (C:\Program Files (x86)\bestrmm\bin\bestrmm-finder.exe). Last 5 Application Error Msgs: 10-25-2016 2:11:54 PM 3221233670 License Activation (slui.exe) failed with the following error code: hr=0x8007139F dbre-line arguments: RuleId=31e71c49-8da7-4a2f-ad92- 45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e- d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8- e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEvent

PROPRIETARY & CONFIDENTIAL PAGE 157 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 10-25-2016 2:11:54 PM 3221226486 Acquisition of End acct License failed. hr=0xC004C008 Sku Id=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c 10-25-2016 2:11:54 PM 3221233672 License acquisition failure details. hr=0xC004C008 10-25-2016 9:03:57 AM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-25-2016 6:07:59 AM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. Scheduled Tasks: OneDrive Standalone Update Task Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 126.45 GB, 107.13 GB free, 15.28% used Service Tag: 6216-8409-2851-5114-6726-6440-55 CPU Count: 1 CPU Core Count: 4 Windows Key: BBBBB-JDJX7-VJ2AF-DDDD9-HCFC6 Make and Model: Microsoft Corporation/Virtual Machine Memory Banks: M0 : Unknown-Unknown-3968 Mb-unknown MHz M1 : Unknown-Unknown-4224 Mb-unknown MHz M2 : Unknown-Unknown-0 Mb-unknown MHz 1 CPUs: Intel(R) Xeon(R) CPU L5639 @ 2.13GHz : CPU0-4 NICs: 00:15:5D:07:37:4E : 192.168.6.45;fe80::a1de:172c:ae6f:b810-netvsc-[00000000] Microsoft Hyper-V redi Adapter : -kdnic-[00000001] Microsoft Kernel Debug redi Adapter : -tunnel-[00000002] Microsoft ISATAP Adapter DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 192.168.10240 unknown (Build 10240)

PROPRIETARY & CONFIDENTIAL PAGE 158 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name OS Caption: Microsoft Windows 10 Pro OS Architecture: 64-bit OS Virtual Memory: 9472 MB OS System Directory: C:\Windows\system32 OS Windows Directory: C:\Windows OS Install Date: 8/21/2016 8:55:55 PM PAE Enabled: True Active Anti-virus: Windows Defender Active Anti-spyware: Windows Defender Active Firewall: Windows Firewall FILE2012-1 Windows Server Intel(R) 8192 Last 5 System Error Msgs: 2012 R2 Standard Xeon(R) CPU MB 10-25-2016 7:30:29 AM 36888 A fatal alert was generated and sent to the remote endpoint. E5320 @ This may result in termination of the connection. The TLS protocol defined fatal error code is 1.86GHz 40. The Windows SChannel error state is 1205. 10-25-2016 7:30:29 AM 36874 An TLS 1.2 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed. 10-25-2016 7:30:29 AM 36888 A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 1205. 10-25-2016 7:30:29 AM 36874 An TLS 1.2 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed. 10-25-2016 7:30:29 AM 36888 A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 1205. Last 5 Application Error Msgs: 10-25-2016 1:00:38 PM 3221226480 The Open Procedure for service "ASP.NET_64_2.0.50727" in DLL "C:\Windows\Microsoft.NET\Framework64\v2.0.50727\aspnet_perf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.

PROPRIETARY & CONFIDENTIAL PAGE 159 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 10-24-2016 10:00:12 PM 5002 Guest VM Name: Storage12 Backup Result: Failed Backup - When processing the operation request an error occurred. This could have occurred if the Host is unavailable, or the connection to the host failed. (ALTERR_JOBBATCHER_006) ALTERR_VIRTUALMACHINELOCATORPROVIDER_001 Backup operation started at: Today at 22:00 10-24-2016 10:00:12 PM 5002 Guest VM Name: DC03 Backup Result: Failed Backup - When processing the operation request an error occurred. This could have occurred if the Host is unavailable, or the connection to the host failed. (ALTERR_JOBBATCHER_006) ALTERR_VIRTUALMACHINELOCATORPROVIDER_001 Backup operation started at: Today at 22:00 10-24-2016 12:51:45 PM 3221226480 The Open Procedure for service "ASP.NET_64_2.0.50727" in DLL "C:\Windows\Microsoft.NET\Framework64\v2.0.50727\aspnet_perf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. 10-23-2016 12:47:50 PM 3221226480 The Open Procedure for service "ASP.NET_64_2.0.50727" in DLL "C:\Windows\Microsoft.NET\Framework64\v2.0.50727\aspnet_perf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. Remote Listening Ports: HTTP (80/TCP) HTTPS (443/TCP) RDP (3389/TCP) Disk Capacity: C: 127.65 GB, 110.92 GB free, 13.11% used H: 12909.37 GB, 4939.84 GB free, 61.73% used Service Tag: CMHX5D1 CPU Count: 1 CPU Core Count: 4 Windows Key: BBBBB-JDJX7-VJ2AF-DDDD9-HCFC6 Make and Model: Dell Inc./PowerEdge 1900 Memory Banks: DIMM1 : unknown-Synchronous-4096 Mb-667 MHz DIMM2 : unknown-Synchronous-4096 Mb-667 MHz

PROPRIETARY & CONFIDENTIAL PAGE 160 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name CPUs: Intel(R) Xeon(R) CPU E5320 @ 1.86GHz : CPU0-4 System Slots: System Slot0 : PCI1-Available-OK System Slot1 : PCI2-Available-OK System Slot2 : PCI3-In Use-OK System Slot3 : PCI4-Available-OK System Slot4 : PCI5-Available-OK System Slot5 : PCI6-Available-OK NICs: : -Rasl2tp-[00000000] WAN Miniport (L2TP) : -RasSstp-[00000001] WAN Miniport (SSTP) : -RasAgileVpn-[00000002] WAN Miniport (IKEv2) : -PptpMiniport-[00000003] WAN Miniport (PPTP) : -RasPppoe-[00000004] WAN Miniport (PPPOE) : -NdisWan-[00000005] WAN Miniport (IP) : -NdisWan-[00000006] WAN Miniport (IPv6) : -NdisWan-[00000007] WAN Miniport (redi Monitor) : -kdnic-[00000008] Microsoft Kernel Debug redi Adapter 90:E2:BA:01:37:EE : -e1qexpress-[00000010] Intel(R) Gigabit ET Dual Port Server Adapter 90:E2:BA:01:37:EF : -e1qexpress-[00000011] Intel(R) Gigabit ET Dual Port Server Adapter 00:19:B9:CD:D3:22 : -l2nd-[00000012] Broadcom BCM5708C NetXtreme II GigE (NDIS VBD Client) 02:81:8E:7E:E0:CD : -Netft-[00000013] Microsoft Failover Cluster Virtual Adapter : -tunnel-[00000014] Microsoft ISATAP Adapter : -NdisImPlatformMp-[00000016] Microsoft redi Adapter Multiplexor Default Miniport 90:E2:BA:01:37:EE : 192.168.1.41;fe80::28eb:a4d9:d7be:3de;2603:3001:2d00:4300:28eb:a4d9:d7be:3de- NdisImPlatformMp-[00000017] Microsoft redi Adapter Multiplexor Driver DEP: On for All programs and services except those I select OS Manufacturer: Microsoft Corporation OS Version: 6.3.9600 unknown (Build 9600) OS Caption: Microsoft Windows Server 2012 R2 Standard OS Architecture:

PROPRIETARY & CONFIDENTIAL PAGE 161 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 64-bit OS Virtual Memory: 10512 MB OS System Directory: C:\Windows\system32 OS Windows Directory: C:\Windows OS Install Date: 3/28/2014 4:46:39 PM FT-LENOVO Windows 8.1 Enterprise gordon-LT2 Windows 7 Intel(R) 12288 Last 5 System Error Msgs: Professional Core(TM) i5- MB 10-25-2016 3:25:57 PM 3221233475 The master browser has received a server 5200U CPU @ announcement from the computer FT-LENOVO that believes that it is the master browser for 2.20GHz the domain on transport NetBT_Tcpip_{4D7C3B4B-5655-4555-9E1E-53F937589ABD}. The master browser is stopping or an election is being forced. 10-25-2016 7:30:03 AM 3221227489 The server was unable to allocate from the system nonpaged pool because the server reached the configured limit for nonpaged pool allocations. 10-24-2016 9:49:01 PM 3221227489 The server was unable to allocate from the system nonpaged pool because the server reached the configured limit for nonpaged pool allocations. 10-24-2016 9:46:01 PM 3221227489 The server was unable to allocate from the system nonpaged pool because the server reached the configured limit for nonpaged pool allocations. 10-24-2016 12:30:59 PM 3221227489 The server was unable to allocate from the system nonpaged pool because the server reached the configured limit for nonpaged pool allocations. Last 5 Application Error Msgs: 10-25-2016 1:01:01 AM 0 10-24-2016 1:01:01 AM 0 10-23-2016 1:01:01 AM 0 10-22-2016 1:01:01 AM 0 10-21-2016 1:01:01 AM 0 Scheduled Tasks: Adobe Acrobat Update Task Adobe Flash Player Updater G2MUpdateTask-S-1-5-21-356494474-603968661-3470298851-40650 G2MUploadTask-S-1-5-21-356494474-603968661-3470298851-40650 GoogleUpdateTaskMachineCore GoogleUpdateTaskMachineUA IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon RtHDVBg_PushButton

PROPRIETARY & CONFIDENTIAL PAGE 162 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 453.99 GB, 379.24 GB free, 16.47% used Service Tag: 4GC5042 CPU Count: 1 CPU Core Count: 2 Windows Key: TH4CG-JDJX7-VJ2AF-DYBB9-HCFC6 Other License Keys: Internet Explorer 55041-006-2483512-86608 (ends with HRXPK) Office Professional Plus 2010 82303-018-0000106-48008 (ends with HEXPK) PowerShell 89383-100-001260-04339 Windows 7 Enterprise 55041-006-2445512-86648 (ends with HDXK) Make and Model: Dell Inc./Latitude 3550 Memory Banks: DIMM A : SODIMM-Synchronous-8192 Mb-1600 MHz DIMM B : SODIMM-Synchronous-4096 Mb-1600 MHz CPUs: Intel(R) Core(TM) i5-5200U CPU @ 2.20GHz : CPU0-2 System Slots: System Slot0 : J6B2-In Use-OK System Slot1 : J6B1-In Use-OK System Slot2 : J6D1-In Use-OK System Slot3 : J7B1-In Use-OK System Slot4 : J8B4-In Use-OK NICs: : -RasSstp-[00000000] WAN Miniport (SSTP) : -RasAgileVpn-[00000001] WAN Miniport (IKEv2) : -Rasl2tp-[00000002] WAN Miniport (L2TP) : -PptpMiniport-[00000003] WAN Miniport (PPTP) : -RasPppoe-[00000004] WAN Miniport (PPPOE) : -NdisWan-[00000005] WAN Miniport (IPv6) : -NdisWan-[00000006] WAN Miniport (redi Monitor) 44:A8:42:F5:7F:C1 : -RTL8167-[00000007] Realtek PCIe GBE Family Controller : -NdisWan-[00000008] WAN Miniport (IP)

PROPRIETARY & CONFIDENTIAL PAGE 163 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name : -tunnel-[00000009] Microsoft ISATAP Adapter 20:41:53:59:4E:FF : -AsyncMac-[00000010] RAS Async Adapter DC:53:60:D9:27:62 : -BthPan-[00000011] Bluetooth Device (Personal Area redi) : -tunnel-[00000014] Microsoft 6to4 Adapter DC:53:60:D9:27:5E : 192.168.6.136;fe80::899b:6b81:d2ea:3128-NETwNs64-[00000015] Intel(R) Dual Band Wireless-N 7265 : -tunnel-[00000016] Microsoft ISATAP Adapter DE:53:60:D9:27:5F : -vwifimp-[00000017] Microsoft Virtual WiFi Miniport Adapter DE:53:60:D9:27:5E : -vwifimp-[00000018] Microsoft Virtual WiFi Miniport Adapter : -tunnel-[00000020] Microsoft ISATAP Adapter : -tunnel-[00000021] Microsoft Teredo Tunneling Adapter DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 6.1.7601 Service Pack 1 (Build 7601) OS Caption: Microsoft Windows 7 Professional OS Architecture: 64-bit OS Virtual Memory: 24384 MB OS System Directory: C:\Windows\system32 OS Windows Directory: C:\Windows OS Install Date: 2/11/2016 2:47:18 PM PAE Enabled: True Active Anti-virus: Microsoft Security Essentials Active Anti-spyware: Microsoft Security Essentials Active Firewall: Windows Firewall HPDT- Windows 10 Pro Intel(R) 12288 Last 5 System Error Msgs: 8CC5260NXY Core(TM) i3- MB 10-25-2016 5:29:50 PM 10016 The application-specific permission settings do not grant Local 4170T CPU @ Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- 3.20GHz A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running

PROPRIETARY & CONFIDENTIAL PAGE 164 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 4:05:00 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 11:38:51 AM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46- 4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-24-2016 5:29:43 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-24-2016 1:20:09 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Last 5 Application Error Msgs: 10-25-2016 9:07:11 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-25-2016 6:09:04 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-25-2016 11:59:28 AM 0 10-24-2016 6:07:17 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-24-2016 6:07:17 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. Scheduled Tasks: Adobe Acrobat Update Task G2MUpdateTask-S-1-5-21-356494474-603968661-3470298851-42236 G2MUploadTask-S-1-5-21-356494474-603968661-3470298851-42236 GoogleUpdateTaskMachineCore

PROPRIETARY & CONFIDENTIAL PAGE 165 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name GoogleUpdateTaskMachineUA OneDrive Standalone Update Task acct_Feed_Synchronization-{D9ADA563-CDD6-4A09-892B-12B7D1AA22AA} VIPRE Roaming Agent Upgrade Task Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 252.52 GB, 223.85 GB free, 11.35% used Service Tag: 8CC5260NXY CPU Count: 1 CPU Core Count: 2 Windows Key: TH4CG-JDJX7-VJ2AF-DYBB9-HCFC6 Other License Keys: Internet Explorer 55041-006-2483512-86608 (ends with HRXPK) Office Professional Plus 2010 82303-018-0000106-48008 (ends with HEXPK) PowerShell 89383-100-001260-04339 Windows 7 Enterprise 55041-006-2445512-86648 (ends with HDXK) Make and Model: Hewlett-Packard/23-q026 Memory Banks: ChannelA-DIMM0 : SODIMM-Synchronous-8192 Mb-1333 MHz ChannelB-DIMM0 : SODIMM-Synchronous-4096 Mb-1600 MHz CPUs: Intel(R) Core(TM) i3-4170T CPU @ 3.20GHz : CPU0-2 System Slots: System Slot0 : J6B2-In Use-OK System Slot1 : J6B1-In Use-OK System Slot2 : J6D1-In Use-OK System Slot3 : J7B1-In Use-OK System Slot4 : J8B4-In Use-OK NICs: D8:5D:E2:8B:E1:8B : -BCM43XX-[00000000] Broadcom 802.11n redi Adapter 3C:A8:2A:B2:02:60 : 192.168.6.9;fe80::3976:6b9e:2f9b:bf97-rt640x64-[00000001] Realtek PCIe GBE Family Controller : -kdnic-[00000002] Microsoft Kernel Debug redi Adapter DA:5D:E2:8B:E1:8B : -vwifimp-[00000003] Microsoft Wi-Fi Direct Virtual Adapter

PROPRIETARY & CONFIDENTIAL PAGE 166 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name : -tunnel-[00000004] Microsoft ISATAP Adapter D8:5D:E2:8B:E1:8C : -BthPan-[00000005] Bluetooth Device (Personal Area redi) : -RFCOMM-[00000006] Bluetooth Device (RFCOMM Protocol TDI) : -vwifimp-[00000007] Microsoft Wi-Fi Direct Virtual Adapter : -tunnel-[00000008] Microsoft ISATAP Adapter DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 192.168.14393 unknown (Build 14393) OS Caption: Microsoft Windows 10 Pro OS Architecture: 64-bit OS Virtual Memory: 14080 MB OS System Directory: C:\Windows\system32 OS Windows Directory: C:\Windows OS Install Date: 9/20/2016 8:27:01 PM PAE Enabled: True Active Anti-virus: ThreatTrack Security VIPRE Business Agent Active Anti-spyware: ThreatTrack Security VIPRE Business Agent Active Firewall: Windows Firewall HPLT- Windows 10 Pro Intel(R) 8192 Last 5 System Error Msgs: 5CD4411D8Z Core(TM) i3- MB 10-25-2016 4:57:09 PM 10016 The application-specific permission settings do not grant Local 4030U CPU @ Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- 1.90GHz A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 11:53:19 AM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46- 4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC)

PROPRIETARY & CONFIDENTIAL PAGE 167 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-24-2016 5:49:28 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-24-2016 4:29:13 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-24-2016 1:52:31 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Last 5 Application Error Msgs: 10-25-2016 3:06:09 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-25-2016 3:06:09 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-25-2016 10:08:29 AM 3221226480 The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. 10-25-2016 5:16:35 AM 0 10-24-2016 3:06:01 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. Scheduled Tasks: G2MUpdateTask-S-1-5-21-356494474-603968661-3470298851-40657 G2MUploadTask-S-1-5-21-356494474-603968661-3470298851-40657 OneDrive Standalone Update Task acct_Feed_Synchronization-{237C5D3C-5B85-4E0C-8CB0-1332E07C958F} acct_Feed_Synchronization-{BD780479-9774-4620-B00B-D64E10302BED} VIPRE Roaming Agent Upgrade Task Remote Listening Ports: RDP (3389/TCP) Disk Capacity:

PROPRIETARY & CONFIDENTIAL PAGE 168 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name C: 254.51 GB, 219.41 GB free, 13.79% used Service Tag: Chassis Serial Number CPU Count: 1 CPU Core Count: 2 Windows Key: TH4CG-JDJX7-VJ2AF-DYBB9-HCFC6 Other License Keys: Internet Explorer 55041-006-2483512-86608 (ends with HRXPK) Office Professional Plus 2010 82303-018-0000106-48008 (ends with HEXPK) PowerShell 89383-100-001260-04339 Windows 7 Enterprise 55041-006-2445512-86648 (ends with HDXK) Make and Model: Hewlett-Packard/HP Pavilion 14 Notebook PC Memory Banks: Bottom-Slot 1(left) : SODIMM-unknown-8192 Mb-1600 MHz CPUs: Intel(R) Core(TM) i3-4030U CPU @ 1.90GHz : CPU0-2 System Slots: System Slot0 : PCI Express Slot 3-Available-OK NICs: 38:B1:DB:A3:C4:E4 : -RTWlanE-[00000000] Realtek RTL8188EE 802.11 bgn Wi-Fi Adapter : -kdnic-[00000001] Microsoft Kernel Debug redi Adapter 8C:DC:D4:8A:23:45 : 192.168.6.26;fe80::46c:aed6:f88f:7c1d-rt640x64-[00000002] Realtek PCIe FE Family Controller 3A:B1:DB:A3:C4:E4 : -vwifimp-[00000003] Microsoft Wi-Fi Direct Virtual Adapter : -tunnel-[00000004] Microsoft ISATAP Adapter : -tunnel-[00000005] Microsoft ISATAP Adapter : -vwifimp-[00000006] Microsoft Wi-Fi Direct Virtual Adapter : -RasSstp-[00000007] WAN Miniport (SSTP) : -RasAgileVpn-[00000008] WAN Miniport (IKEv2) : -Rasl2tp-[00000009] WAN Miniport (L2TP) : -PptpMiniport-[00000010] WAN Miniport (PPTP) : -RasPppoe-[00000011] WAN Miniport (PPPOE) : -NdisWan-[00000012] WAN Miniport (IP) : -NdisWan-[00000013] WAN Miniport (IPv6) : -NdisWan-[00000014] WAN Miniport (redi Monitor) : -AsyncMac-[00000015] RAS Async Adapter

PROPRIETARY & CONFIDENTIAL PAGE 169 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name : -tunnel-[00000016] Microsoft Teredo Tunneling Adapter : -tunnel-[00000017] Microsoft ISATAP Adapter : -tunnel-[00000018] Microsoft ISATAP Adapter DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 192.168.14393 unknown (Build 14393) OS Caption: Microsoft Windows 10 Pro OS Architecture: 64-bit OS Virtual Memory: 9408 MB OS System Directory: C:\WINDOWS\system32 OS Windows Directory: C:\WINDOWS OS Install Date: 9/27/2016 4:24:57 AM PAE Enabled: True Active Anti-virus: ThreatTrack Security VIPRE Business Agent Active Anti-spyware: ThreatTrack Security VIPRE Business Agent Active Firewall: Windows Firewall HV00 Windows Server Intel(R) 73728 Last 5 System Error Msgs: 2012 R2 Datacenter Xeon(R) CPU MB 10-25-2016 9:39:36 PM 1196 Cluster network name resource 'Cluster Name' failed registration L5639 @ of one or more associated DNS name(s) for the following reason: This operation returned 2.13GHz because the timeout period expired. . Ensure that the network adapters associated with dependent IP address resources are configured with at least one accessible DNS server. 10-25-2016 9:21:05 PM 1196 Cluster network name resource 'Cluster Name' failed registration of one or more associated DNS name(s) for the following reason: This operation returned because the timeout period expired. . Ensure that the network adapters associated with dependent IP address resources are configured with at least one accessible DNS server. 10-25-2016 9:02:35 PM 1196 Cluster network name resource 'Cluster Name' failed registration of one or more associated DNS name(s) for the following reason: This operation returned because the timeout period expired. . Ensure that the network adapters associated with dependent IP address resources are configured with at least one accessible DNS server.

PROPRIETARY & CONFIDENTIAL PAGE 170 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 10-25-2016 8:44:04 PM 1196 Cluster network name resource 'Cluster Name' failed registration of one or more associated DNS name(s) for the following reason: This operation returned because the timeout period expired. . Ensure that the network adapters associated with dependent IP address resources are configured with at least one accessible DNS server. 10-25-2016 8:25:33 PM 1196 Cluster network name resource 'Cluster Name' failed registration of one or more associated DNS name(s) for the following reason: This operation returned because the timeout period expired. . Ensure that the network adapters associated with dependent IP address resources are configured with at least one accessible DNS server. Last 5 Application Error Msgs: 10-24-2016 10:05:13 PM 5002 Guest VM Name: QB01 Backup Result: Failed Backup - Unable to get a list of the VMs files which need to be backed up using the VSS Provider. (ALTERR_JOBBATCHER_011) This request operation sent to net.tcp://localhost:35108/AltaroSubAgentService did not receive a reply within the configured timeout (00:05:00). The time allotted to this operation may have been a portion of a longer timeout. This may be because the service is still processing the operation or because the service was unable to send a reply message. Please consider increasing the operation timeout (by casting the channel/proxy to IContextChannel and setting the OperationTimeout property) and ensure that the service is able to connect to the client. Backup operation started at: Today at 22:05 10-22-2016 8:05:21 PM 5002 Guest VM Name: RDGateway (old) Backup Result: Failed Backup - Unable to get a list of the VMs files which need to be backed up using the VSS Provider. (ALTERR_JOBBATCHER_011) This request operation sent to net.tcp://localhost:35108/AltaroSubAgentService did not receive a reply within the configured timeout (00:05:00). The time allotted to this operation may have been a portion of a longer timeout. This may be because the service is still processing the operation or because the service was unable to send a reply message. Please consider increasing the operation timeout (by casting the channel/proxy to IContextChannel and setting the OperationTimeout property) and ensure that the service is able to connect to the client. Backup operation started at: Today at 20:05 10-21-2016 10:05:27 PM 5002 Guest VM Name: QB01 Backup Result: Failed Backup - Unable to get a list of the VMs files which need to be backed up using the VSS Provider. (ALTERR_JOBBATCHER_011) This request operation sent to net.tcp://localhost:35108/AltaroSubAgentService did not receive a reply within the configured timeout (00:05:00). The time allotted to this operation may have been a portion of a longer timeout. This may be because the service is still processing the operation or because the service was unable to send a reply message. Please consider increasing the operation timeout (by casting the channel/proxy to IContextChannel and setting the OperationTimeout property) and ensure that the service is able to connect to the client. Backup operation started at: Today at 22:05 10-20-2016 10:05:31 PM 5002 Guest VM Name: QB01 Backup Result: Failed Backup - Unable to get a list of the VMs files which need to be backed up using the VSS Provider.

PROPRIETARY & CONFIDENTIAL PAGE 171 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name (ALTERR_JOBBATCHER_011) This request operation sent to net.tcp://localhost:35108/AltaroSubAgentService did not receive a reply within the configured timeout (00:05:00). The time allotted to this operation may have been a portion of a longer timeout. This may be because the service is still processing the operation or because the service was unable to send a reply message. Please consider increasing the operation timeout (by casting the channel/proxy to IContextChannel and setting the OperationTimeout property) and ensure that the service is able to connect to the client. Backup operation started at: Today at 22:05 10-19-2016 10:05:06 PM 5002 Guest VM Name: QB01 Backup Result: Failed Backup - Unable to get a list of the VMs files which need to be backed up using the VSS Provider. (ALTERR_JOBBATCHER_011) This request operation sent to net.tcp://localhost:35108/AltaroSubAgentService did not receive a reply within the configured timeout (00:05:00). The time allotted to this operation may have been a portion of a longer timeout. This may be because the service is still processing the operation or because the service was unable to send a reply message. Please consider increasing the operation timeout (by casting the channel/proxy to IContextChannel and setting the OperationTimeout property) and ensure that the service is able to connect to the client. Backup operation started at: Today at 22:05 Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 127.66 GB, 21.62 GB free, 83.06% used H: 3595.87 GB, 2481.04 GB free, 31% used Service Tag: 6V8DVL1 CPU Count: 2 CPU Core Count: 12 Windows Key: BBBBB-JDJX7-VJ2AF-DDDD9-HCFC6 Make and Model: Dell Inc./PowerEdge R710 Memory Banks: DIMM_A1 : DIMM-unknown-4096 Mb-1333 MHz DIMM_A2 : DIMM-unknown-4096 Mb-1333 MHz DIMM_B2 : DIMM-unknown-4096 Mb-1333 MHz DIMM_B3 : DIMM-unknown-4096 Mb-1333 MHz DIMM_B4 : DIMM-unknown-4096 Mb-1333 MHz DIMM_B5 : DIMM-unknown-4096 Mb-1333 MHz

PROPRIETARY & CONFIDENTIAL PAGE 172 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name DIMM_B6 : DIMM-unknown-4096 Mb-1333 MHz DIMM_B7 : DIMM-unknown-4096 Mb-1333 MHz DIMM_B8 : DIMM-unknown-4096 Mb-1333 MHz DIMM_B9 : DIMM-unknown-4096 Mb-1333 MHz DIMM_A3 : DIMM-unknown-4096 Mb-1333 MHz DIMM_A4 : DIMM-unknown-4096 Mb-1333 MHz DIMM_A5 : DIMM-unknown-4096 Mb-1333 MHz DIMM_A6 : DIMM-unknown-4096 Mb-1333 MHz DIMM_A7 : DIMM-unknown-4096 Mb-1333 MHz DIMM_A8 : DIMM-unknown-4096 Mb-1333 MHz DIMM_A9 : DIMM-unknown-4096 Mb-1333 MHz DIMM_B1 : DIMM-unknown-4096 Mb-1333 MHz CPUs: Intel(R) Xeon(R) CPU L5639 @ 2.13GHz : CPU0-6 Intel(R) Xeon(R) CPU L5639 @ 2.13GHz : CPU1-6 System Slots: System Slot0 : PCI1-Available-OK System Slot1 : PCI2-Available-OK System Slot2 : PCI3-Available-OK System Slot3 : PCI4-Available-OK NICs: : -Rasl2tp-[00000000] WAN Miniport (L2TP) : -RasSstp-[00000001] WAN Miniport (SSTP) : -RasAgileVpn-[00000002] WAN Miniport (IKEv2) : -PptpMiniport-[00000003] WAN Miniport (PPTP) : -RasPppoe-[00000004] WAN Miniport (PPPOE) : -NdisWan-[00000005] WAN Miniport (IP) : -NdisWan-[00000006] WAN Miniport (IPv6) : -NdisWan-[00000007] WAN Miniport (redi Monitor) : -kdnic-[00000008] Microsoft Kernel Debug redi Adapter : -VMSMP-[00000009] Hyper-V Virtual Switch Extension Adapter 00:26:B9:5B:BF:10 : -l2nd-[00000010] Broadcom BCM5709C NetXtreme II GigE (NDIS VBD Client) 00:26:B9:5B:BF:12 : -l2nd-[00000011] Broadcom BCM5709C NetXtreme II GigE (NDIS VBD Client) 00:26:B9:5B:BF:0C : -l2nd-[00000012] Broadcom BCM5709C NetXtreme II GigE (NDIS VBD Client) 00:26:B9:5B:BF:0E : -l2nd-[00000013] Broadcom BCM5709C NetXtreme II GigE (NDIS VBD Client) : -VMSMP-[00000014] Hyper-V Virtual Ethernet Adapter : -VMSMP-[00000015] Hyper-V Virtual Switch Extension Adapter

PROPRIETARY & CONFIDENTIAL PAGE 173 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 00:26:B9:5B:BF:0E : 192.168.1.100;192.168.1.104;fe80::5:63b:4d3f:8-VMSMP-[00000016] Hyper-V Virtual Ethernet Adapter 00:15:5D:01:E0:9F : 169.254.185.30;fe80::509:87e7:645f:b91e-VMSMP-[00000017] Hyper-V Virtual Ethernet Adapter : -VMSMP-[00000018] Hyper-V Virtual Switch Extension Adapter 00:15:5D:01:E0:A9 : 192.168.6.100;fe80::edf7:37ef:5bd0:1ef2-VMSMP-[00000019] Hyper-V Virtual Ethernet Adapter : -tunnel-[00000020] Microsoft ISATAP Adapter 00:15:5D:01:E0:AA : 192.168.6.105;fe80::c816:f63e:3756:f45c-VMSMP-[00000021] Hyper-V Virtual Ethernet Adapter : -tunnel-[00000022] Microsoft ISATAP Adapter 00:15:5D:01:E0:AB : 192.168.6.108;fe80::31c1:2aac:ddc0:2f34-VMSMP-[00000023] Hyper-V Virtual Ethernet Adapter 00:15:5D:01:E0:AE : 169.254.99.161;fe80::3dea:a06f:b703:63a1-VMSMP-[00000024] Hyper-V Virtual Ethernet Adapter : -tunnel-[00000025] Microsoft ISATAP Adapter : -VMSMP-[00000026] Hyper-V Virtual Switch Extension Adapter 00:15:5D:01:E0:B4 : 169.254.234.237;fe80::b154:892c:8aff:eaed-VMSMP-[00000027] Hyper- V Virtual Ethernet Adapter : -tunnel-[00000028] Microsoft ISATAP Adapter 02:DC:09:15:CD:12 : -Netft-[00000031] Microsoft Failover Cluster Virtual Adapter : -tunnel-[00000032] Microsoft ISATAP Adapter : -NdisImPlatformMp-[00000033] Microsoft redi Adapter Multiplexor Default Miniport 00:26:B9:5B:BF:0C : -NdisImPlatformMp-[00000034] Microsoft redi Adapter Multiplexor Driver DEP: On for All programs and services except those I select OS Manufacturer: Microsoft Corporation OS Version: 6.3.9600 unknown (Build 9600) OS Caption: Microsoft Windows Server 2012 R2 Datacenter OS Architecture: 64-bit OS Virtual Memory: 84480 MB OS System Directory: C:\Windows\system32 OS Windows Directory: C:\Windows OS Install Date:

PROPRIETARY & CONFIDENTIAL PAGE 174 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 7/10/2014 4:39:32 AM Active Anti-virus: VIPRE Active Anti-spyware: VIPRE Active Firewall: Windows Firewall HV02 Windows Server Intel(R) 73728 Last 5 System Error Msgs: 2012 R2 Standard Xeon(R) CPU MB 10-22-2016 5:37:39 AM 36888 A fatal alert was generated and sent to the remote endpoint. L5639 @ This may result in termination of the connection. The TLS protocol defined fatal error code is 2.13GHz 40. The Windows SChannel error state is 1205. 10-22-2016 5:37:39 AM 36874 An TLS 1.2 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed. 10-22-2016 5:37:39 AM 36888 A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 1205. 10-22-2016 5:37:39 AM 36874 An TLS 1.2 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed. 10-22-2016 5:37:39 AM 36888 A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 1205. Last 5 Application Error Msgs: 10-21-2016 2:11:46 PM 1000 Faulting application name: ScreenConnect.WindowsClient.exe, version: 6.0.11299.6071, time stamp: 0x57b1c981 Faulting module name: KERNELBASE.dll, version: 6.3.9600.16408, time stamp: 0x523d557d Exception code: 0xc06d007e Fault offset: 0x000000000000ab78 Faulting process id: 0x2290 Faulting application start time: 0x01d22bc695ac3dc7 Faulting application path: C:\Program Files (x86)\ScreenConnect Client (2872323bbe412f4c)\ScreenConnect.WindowsClient.exe Faulting module path: C:\Windows\system32\KERNELBASE.dll Report Id: d37eef7c-97b9-11e6-80ce-0026b95c2ae2 Faulting package full name: Faulting package-relative application ID: 10-12-2016 12:13:15 AM 3221226480 The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. 10-11-2016 12:12:48 AM 3221226480 The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. 10-10-2016 12:09:30 AM 3221226480 The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.

PROPRIETARY & CONFIDENTIAL PAGE 175 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 10-9-2016 12:06:04 AM 3221226480 The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. Remote Listening Ports: HTTP (80/TCP) RDP (3389/TCP) Disk Capacity: C: 127.66 GB, 36.47 GB free, 71.43% used H: 3595.87 GB, 1193.66 GB free, 66.8% used Service Tag: GDCDVL1 CPU Count: 2 CPU Core Count: 12 Windows Key: BBBBB-BBBBB-BBBBB-BBBBB-BBBBB Make and Model: Dell Inc./PowerEdge R710 Memory Banks: DIMM_A1 : DIMM-unknown-4096 Mb-1333 MHz DIMM_A2 : DIMM-unknown-4096 Mb-1333 MHz DIMM_B2 : DIMM-unknown-4096 Mb-1333 MHz DIMM_B3 : DIMM-unknown-4096 Mb-1333 MHz DIMM_B4 : DIMM-unknown-4096 Mb-1333 MHz DIMM_B5 : DIMM-unknown-4096 Mb-1333 MHz DIMM_B6 : DIMM-unknown-4096 Mb-1333 MHz DIMM_B7 : DIMM-unknown-4096 Mb-1333 MHz DIMM_B8 : DIMM-unknown-4096 Mb-1333 MHz DIMM_B9 : DIMM-unknown-4096 Mb-1333 MHz DIMM_A3 : DIMM-unknown-4096 Mb-1333 MHz DIMM_A4 : DIMM-unknown-4096 Mb-1333 MHz DIMM_A5 : DIMM-unknown-4096 Mb-1333 MHz DIMM_A6 : DIMM-unknown-4096 Mb-1333 MHz DIMM_A7 : DIMM-unknown-4096 Mb-1333 MHz DIMM_A8 : DIMM-unknown-4096 Mb-1333 MHz DIMM_A9 : DIMM-unknown-4096 Mb-1333 MHz DIMM_B1 : DIMM-unknown-4096 Mb-1333 MHz CPUs: Intel(R) Xeon(R) CPU L5639 @ 2.13GHz : CPU0-6

PROPRIETARY & CONFIDENTIAL PAGE 176 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name Intel(R) Xeon(R) CPU L5639 @ 2.13GHz : CPU1-6 System Slots: System Slot0 : PCI1-Available-OK System Slot1 : PCI2-Available-OK System Slot2 : PCI3-Available-OK System Slot3 : PCI4-Available-OK NICs: : -Rasl2tp-[00000000] WAN Miniport (L2TP) : -RasSstp-[00000001] WAN Miniport (SSTP) : -RasAgileVpn-[00000002] WAN Miniport (IKEv2) : -PptpMiniport-[00000003] WAN Miniport (PPTP) : -RasPppoe-[00000004] WAN Miniport (PPPOE) : -NdisWan-[00000005] WAN Miniport (IP) : -NdisWan-[00000006] WAN Miniport (IPv6) : -NdisWan-[00000007] WAN Miniport (redi Monitor) : -kdnic-[00000008] Microsoft Kernel Debug redi Adapter : -VMSMP-[00000009] Hyper-V Virtual Switch Extension Adapter 00:26:B9:5C:2A:DC : -l2nd-[00000010] QLogic BCM5709C Gigabit Ethernet (NDIS VBD Client) 00:26:B9:5C:2A:E2 : -l2nd-[00000011] QLogic BCM5709C Gigabit Ethernet (NDIS VBD Client) 00:26:B9:5C:2A:E0 : -l2nd-[00000012] QLogic BCM5709C Gigabit Ethernet (NDIS VBD Client) 00:26:B9:5C:2A:DE : -l2nd-[00000013] QLogic BCM5709C Gigabit Ethernet (NDIS VBD Client) 00:15:5D:07:37:47 : 169.254.103.179;fe80::5877:b159:37c8:67b3-VMSMP-[00000014] Hyper- V Virtual Ethernet Adapter : -VMSMP-[00000015] Hyper-V Virtual Ethernet Adapter : -VMSMP-[00000016] Hyper-V Virtual Switch Extension Adapter 00:26:B9:5C:2A:DE : 192.168.1.121;fe80::4942:d202:d8e7:bf74-VMSMP-[00000017] Hyper-V Virtual Ethernet Adapter : -NdisImPlatformMp-[00000018] Microsoft redi Adapter Multiplexor Default Miniport 00:26:B9:5C:2A:DC : -NdisImPlatformMp-[00000019] Microsoft redi Adapter Multiplexor Driver : -tunnel-[00000020] Microsoft ISATAP Adapter 00:15:5D:07:37:42 : 192.168.1.122;fe80::d920:afb0:9c0e:114c-VMSMP-[00000021] Hyper-V Virtual Ethernet Adapter : -tunnel-[00000022] Microsoft ISATAP Adapter 00:15:5D:07:37:43 : 192.168.1.123;fe80::9535:f3a7:39b4:ed1d-VMSMP-[00000023] Hyper-V Virtual Ethernet Adapter : -tunnel-[00000024] Microsoft ISATAP Adapter : -VMSMP-[00000025] Hyper-V Virtual Switch Extension Adapter 00:15:5D:07:37:04 : 192.168.1.12;fe80::57a:aa42:5166:2945-VMSMP-[00000026] Hyper-V Virtual Ethernet Adapter

PROPRIETARY & CONFIDENTIAL PAGE 177 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name : -tunnel-[00000027] Microsoft ISATAP Adapter : -tunnel-[00000028] Microsoft ISATAP Adapter DEP: On for All programs and services except those I select OS Manufacturer: Microsoft Corporation OS Version: 6.3.9600 unknown (Build 9600) OS Caption: Microsoft Windows Server 2012 R2 Standard OS Architecture: 64-bit OS Virtual Memory: 84480 MB OS System Directory: C:\Windows\system32 OS Windows Directory: C:\Windows OS Install Date: 12/5/2013 3:55:52 PM HV04 Windows Server Intel(R) 73728 Last 5 System Error Msgs: 2012 R2 Datacenter Xeon(R) CPU MB 10-25-2016 9:39:36 PM 1196 Cluster network name resource 'Cluster Name' failed registration L5639 @ of one or more associated DNS name(s) for the following reason: This operation returned 2.13GHz because the timeout period expired. . Ensure that the network adapters associated with dependent IP address resources are configured with at least one accessible DNS server. 10-25-2016 9:21:05 PM 1196 Cluster network name resource 'Cluster Name' failed registration of one or more associated DNS name(s) for the following reason: This operation returned because the timeout period expired. . Ensure that the network adapters associated with dependent IP address resources are configured with at least one accessible DNS server. 10-25-2016 9:02:35 PM 1196 Cluster network name resource 'Cluster Name' failed registration of one or more associated DNS name(s) for the following reason: This operation returned because the timeout period expired. . Ensure that the network adapters associated with dependent IP address resources are configured with at least one accessible DNS server. 10-25-2016 8:44:04 PM 1196 Cluster network name resource 'Cluster Name' failed registration of one or more associated DNS name(s) for the following reason: This operation returned because the timeout period expired. . Ensure that the network adapters associated with dependent IP address resources are configured with at least one accessible DNS server. 10-25-2016 8:25:33 PM 1196 Cluster network name resource 'Cluster Name' failed registration of one or more associated DNS name(s) for the following reason: This operation returned

PROPRIETARY & CONFIDENTIAL PAGE 178 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name because the timeout period expired. . Ensure that the network adapters associated with dependent IP address resources are configured with at least one accessible DNS server. Last 5 Application Error Msgs: 10-24-2016 10:05:13 PM 5002 Guest VM Name: QB01 Backup Result: Failed Backup - Unable to get a list of the VMs files which need to be backed up using the VSS Provider. (ALTERR_JOBBATCHER_011) This request operation sent to net.tcp://localhost:35108/AltaroSubAgentService did not receive a reply within the configured timeout (00:05:00). The time allotted to this operation may have been a portion of a longer timeout. This may be because the service is still processing the operation or because the service was unable to send a reply message. Please consider increasing the operation timeout (by casting the channel/proxy to IContextChannel and setting the OperationTimeout property) and ensure that the service is able to connect to the client. Backup operation started at: Today at 22:05 10-22-2016 8:05:21 PM 5002 Guest VM Name: RDGateway (old) Backup Result: Failed Backup - Unable to get a list of the VMs files which need to be backed up using the VSS Provider. (ALTERR_JOBBATCHER_011) This request operation sent to net.tcp://localhost:35108/AltaroSubAgentService did not receive a reply within the configured timeout (00:05:00). The time allotted to this operation may have been a portion of a longer timeout. This may be because the service is still processing the operation or because the service was unable to send a reply message. Please consider increasing the operation timeout (by casting the channel/proxy to IContextChannel and setting the OperationTimeout property) and ensure that the service is able to connect to the client. Backup operation started at: Today at 20:05 10-21-2016 10:05:27 PM 5002 Guest VM Name: QB01 Backup Result: Failed Backup - Unable to get a list of the VMs files which need to be backed up using the VSS Provider. (ALTERR_JOBBATCHER_011) This request operation sent to net.tcp://localhost:35108/AltaroSubAgentService did not receive a reply within the configured timeout (00:05:00). The time allotted to this operation may have been a portion of a longer timeout. This may be because the service is still processing the operation or because the service was unable to send a reply message. Please consider increasing the operation timeout (by casting the channel/proxy to IContextChannel and setting the OperationTimeout property) and ensure that the service is able to connect to the client. Backup operation started at: Today at 22:05 10-20-2016 10:05:31 PM 5002 Guest VM Name: QB01 Backup Result: Failed Backup - Unable to get a list of the VMs files which need to be backed up using the VSS Provider. (ALTERR_JOBBATCHER_011) This request operation sent to net.tcp://localhost:35108/AltaroSubAgentService did not receive a reply within the configured timeout (00:05:00). The time allotted to this operation may have been a portion of a longer timeout. This may be because the service is still processing the operation or because the service was unable to send a reply message. Please consider increasing the operation timeout (by casting the channel/proxy to IContextChannel and setting the OperationTimeout property)

PROPRIETARY & CONFIDENTIAL PAGE 179 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name and ensure that the service is able to connect to the client. Backup operation started at: Today at 22:05 10-19-2016 10:05:06 PM 5002 Guest VM Name: QB01 Backup Result: Failed Backup - Unable to get a list of the VMs files which need to be backed up using the VSS Provider. (ALTERR_JOBBATCHER_011) This request operation sent to net.tcp://localhost:35108/AltaroSubAgentService did not receive a reply within the configured timeout (00:05:00). The time allotted to this operation may have been a portion of a longer timeout. This may be because the service is still processing the operation or because the service was unable to send a reply message. Please consider increasing the operation timeout (by casting the channel/proxy to IContextChannel and setting the OperationTimeout property) and ensure that the service is able to connect to the client. Backup operation started at: Today at 22:05 Scheduled Tasks: CCleanerSkipUAC Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-1114 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-1230 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-1244 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-29609 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-40613 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-500 VIPRE Roaming Agent Upgrade Task Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 127.66 GB, 21.58 GB free, 83.1% used H: 3595.87 GB, 2481.88 GB free, 30.98% used Service Tag: 6V8DVL1 CPU Count: 2 CPU Core Count: 12 Windows Key: BBBBB-JDJX7-VJ2AF-DDDD9-HCFC6 Make and Model: Dell Inc./PowerEdge R710 Memory Banks: DIMM_A1 : DIMM-unknown-4096 Mb-1333 MHz DIMM_A2 : DIMM-unknown-4096 Mb-1333 MHz DIMM_B2 : DIMM-unknown-4096 Mb-1333 MHz

PROPRIETARY & CONFIDENTIAL PAGE 180 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name DIMM_B3 : DIMM-unknown-4096 Mb-1333 MHz DIMM_B4 : DIMM-unknown-4096 Mb-1333 MHz DIMM_B5 : DIMM-unknown-4096 Mb-1333 MHz DIMM_B6 : DIMM-unknown-4096 Mb-1333 MHz DIMM_B7 : DIMM-unknown-4096 Mb-1333 MHz DIMM_B8 : DIMM-unknown-4096 Mb-1333 MHz DIMM_B9 : DIMM-unknown-4096 Mb-1333 MHz DIMM_A3 : DIMM-unknown-4096 Mb-1333 MHz DIMM_A4 : DIMM-unknown-4096 Mb-1333 MHz DIMM_A5 : DIMM-unknown-4096 Mb-1333 MHz DIMM_A6 : DIMM-unknown-4096 Mb-1333 MHz DIMM_A7 : DIMM-unknown-4096 Mb-1333 MHz DIMM_A8 : DIMM-unknown-4096 Mb-1333 MHz DIMM_A9 : DIMM-unknown-4096 Mb-1333 MHz DIMM_B1 : DIMM-unknown-4096 Mb-1333 MHz CPUs: Intel(R) Xeon(R) CPU L5639 @ 2.13GHz : CPU0-6 Intel(R) Xeon(R) CPU L5639 @ 2.13GHz : CPU1-6 System Slots: System Slot0 : PCI1-Available-OK System Slot1 : PCI2-Available-OK System Slot2 : PCI3-Available-OK System Slot3 : PCI4-Available-OK NICs: : -Rasl2tp-[00000000] WAN Miniport (L2TP) : -RasSstp-[00000001] WAN Miniport (SSTP) : -RasAgileVpn-[00000002] WAN Miniport (IKEv2) : -PptpMiniport-[00000003] WAN Miniport (PPTP) : -RasPppoe-[00000004] WAN Miniport (PPPOE) : -NdisWan-[00000005] WAN Miniport (IP) : -NdisWan-[00000006] WAN Miniport (IPv6) : -NdisWan-[00000007] WAN Miniport (redi Monitor) : -kdnic-[00000008] Microsoft Kernel Debug redi Adapter : -VMSMP-[00000009] Hyper-V Virtual Switch Extension Adapter 00:26:B9:5B:BF:10 : -l2nd-[00000010] Broadcom BCM5709C NetXtreme II GigE (NDIS VBD Client) 00:26:B9:5B:BF:12 : -l2nd-[00000011] Broadcom BCM5709C NetXtreme II GigE (NDIS VBD Client) 00:26:B9:5B:BF:0C : -l2nd-[00000012] Broadcom BCM5709C NetXtreme II GigE (NDIS VBD Client)

PROPRIETARY & CONFIDENTIAL PAGE 181 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 00:26:B9:5B:BF:0E : -l2nd-[00000013] Broadcom BCM5709C NetXtreme II GigE (NDIS VBD Client) : -VMSMP-[00000014] Hyper-V Virtual Ethernet Adapter : -VMSMP-[00000015] Hyper-V Virtual Switch Extension Adapter 00:26:B9:5B:BF:0E : 192.168.1.100;192.168.1.104;fe80::5:63b:4d3f:8-VMSMP-[00000016] Hyper-V Virtual Ethernet Adapter 00:15:5D:01:E0:9F : 169.254.185.30;fe80::509:87e7:645f:b91e-VMSMP-[00000017] Hyper-V Virtual Ethernet Adapter : -VMSMP-[00000018] Hyper-V Virtual Switch Extension Adapter 00:15:5D:01:E0:A9 : 192.168.6.100;fe80::edf7:37ef:5bd0:1ef2-VMSMP-[00000019] Hyper-V Virtual Ethernet Adapter : -tunnel-[00000020] Microsoft ISATAP Adapter 00:15:5D:01:E0:AA : 192.168.6.105;fe80::c816:f63e:3756:f45c-VMSMP-[00000021] Hyper-V Virtual Ethernet Adapter : -tunnel-[00000022] Microsoft ISATAP Adapter 00:15:5D:01:E0:AB : 192.168.6.108;fe80::31c1:2aac:ddc0:2f34-VMSMP-[00000023] Hyper-V Virtual Ethernet Adapter 00:15:5D:01:E0:AE : 169.254.99.161;fe80::3dea:a06f:b703:63a1-VMSMP-[00000024] Hyper-V Virtual Ethernet Adapter : -tunnel-[00000025] Microsoft ISATAP Adapter : -VMSMP-[00000026] Hyper-V Virtual Switch Extension Adapter 00:15:5D:01:E0:B4 : 169.254.234.237;fe80::b154:892c:8aff:eaed-VMSMP-[00000027] Hyper- V Virtual Ethernet Adapter : -tunnel-[00000028] Microsoft ISATAP Adapter 02:DC:09:15:CD:12 : -Netft-[00000031] Microsoft Failover Cluster Virtual Adapter : -tunnel-[00000032] Microsoft ISATAP Adapter : -NdisImPlatformMp-[00000033] Microsoft redi Adapter Multiplexor Default Miniport 00:26:B9:5B:BF:0C : -NdisImPlatformMp-[00000034] Microsoft redi Adapter Multiplexor Driver DEP: On for All programs and services except those I select OS Manufacturer: Microsoft Corporation OS Version: 6.3.9600 unknown (Build 9600) OS Caption: Microsoft Windows Server 2012 R2 Datacenter OS Architecture: 64-bit OS Virtual Memory: 84480 MB OS System Directory:

PROPRIETARY & CONFIDENTIAL PAGE 182 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name C:\Windows\system32 OS Windows Directory: C:\Windows OS Install Date: 7/10/2014 4:39:32 AM PAE Enabled: True Active Anti-virus: VIPRE Active Anti-spyware: VIPRE Active Firewall: Windows Firewall IRIDIUM Windows 10 Pro Intel(R) 16384 Last 5 System Error Msgs: Core(TM) i7- MB 10-25-2016 2:40:55 PM 10016 The application-specific permission settings do not grant Local 6700 CPU @ Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- 3.40GHz A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 12:06:34 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46- 4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-24-2016 3:43:17 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-24-2016 10:26:20 AM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46- 4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-24-2016 10:10:10 AM 3221618724 The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a acct imposed limit. Last 5 Application Error Msgs: 10-25-2016 12:22:09 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code.

PROPRIETARY & CONFIDENTIAL PAGE 183 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 10-24-2016 12:10:52 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-24-2016 10:22:46 AM 513 Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol. System Error: Access is denied. . 10-23-2016 12:09:53 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-22-2016 12:07:51 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. Scheduled Tasks: CLMLSvc_P2G8 CLVDLauncher DropboxUpdateTaskMachineCore DropboxUpdateTaskMachineUA G2MUpdateTask-S-1-5-21-356494474-603968661-3470298851-42173 G2MUploadTask-S-1-5-21-356494474-603968661-3470298851-42173 baseComplyUpdateTaskMachineCore baseComplyUpdateTaskMachineUA GoogleUpdateTaskMachineCore GoogleUpdateTaskMachineUA OneDrive Standalone Update Task PCDDataUploadTask PCDEventLauncherTask PCDoctorBackgroundMonitorTask StartSCUIOnLogon SystemToolsDailyTest SystemToolsDailyTest-Retry Remote Listening Ports: HTTP (80/TCP) HTTPS (443/TCP) Disk Capacity: C: 917.3 GB, 832.58 GB free, 9.24% used Service Tag: CZ60SD2 CPU Count: 1 CPU Core Count: 4 Windows Key: TH4CG-JDJX7-VJ2AF-DYBB9-HCFC6 Other License Keys:

PROPRIETARY & CONFIDENTIAL PAGE 184 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name Internet Explorer 55041-006-2483512-86608 (ends with HRXPK) Office Professional Plus 2010 82303-018-0000106-48008 (ends with HEXPK) PowerShell 89383-100-001260-04339 Windows 7 Enterprise 55041-006-2445512-86648 (ends with HDXK) Make and Model: Dell Inc./XPS 8900 Memory Banks: DIMM1 : DIMM-Synchronous-8192 Mb-2133 MHz DIMM2 : DIMM-Synchronous-8192 Mb-2133 MHz CPUs: Intel(R) Core(TM) i7-6700 CPU @ 3.40GHz : CPU0-4 System Slots: System Slot0 : SLOT1-In Use-OK System Slot1 : SLOT3-Available-OK System Slot2 : SLOT4-Available-OK NICs: : -kdnic-[00000000] Microsoft Kernel Debug redi Adapter 18:66:DA:3E:A0:D6 : 192.168.6.165;fe80::a51c:74ae:208b:d920-e1dexpress-[00000001] Intel(R) Ethernet Connection (2) I219-V 84:EF:18:68:61:04 : -Netwtw04-[00000002] Intel(R) Dual Band Wireless-AC 3165 84:EF:18:68:61:05 : -vwifimp-[00000003] Microsoft Wi-Fi Direct Virtual Adapter : -RFCOMM-[00000004] Bluetooth Device (RFCOMM Protocol TDI) 84:EF:18:68:61:08 : -BthPan-[00000005] Bluetooth Device (Personal Area redi) : -tunnel-[00000006] Microsoft ISATAP Adapter : -tunnel-[00000007] Microsoft ISATAP Adapter : -RasSstp-[00000008] WAN Miniport (SSTP) : -RasAgileVpn-[00000009] WAN Miniport (IKEv2) : -Rasl2tp-[00000010] WAN Miniport (L2TP) : -PptpMiniport-[00000011] WAN Miniport (PPTP) : -RasPppoe-[00000012] WAN Miniport (PPPOE) : -NdisWan-[00000013] WAN Miniport (IP) : -NdisWan-[00000014] WAN Miniport (IPv6) : -NdisWan-[00000015] WAN Miniport (redi Monitor) DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 192.168.14393 unknown (Build 14393)

PROPRIETARY & CONFIDENTIAL PAGE 185 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name OS Caption: Microsoft Windows 10 Pro OS Architecture: 64-bit OS Virtual Memory: 18768 MB OS System Directory: C:\WINDOWS\system32 OS Windows Directory: C:\WINDOWS OS Install Date: 10/8/2016 4:20:16 AM PAE Enabled: True Active Anti-virus: Windows Defender Active Anti-spyware: Windows Defender Active Firewall: Windows Firewall ISA1 Windows Server Intel(R) Remote Listening Ports: 2003 Xeon(R) CPU Telnet (23/TCP) L5639 @ HTTP (80/TCP) 2.13GHz RDP (3389/TCP) HTTP (8080/TCP) Windows Key: BBBBB-JDJX7-VJ2AF-DDDD9-HCFC6 ISTCORP-PC Windows 8.1 Pro Intel(R) 4096 Last 5 System Error Msgs: Core(TM)2 MB 10-25-2016 7:42:41 AM 10010 The server {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} did Duo CPU not register with DCOM within the required timeout. T6600 @ 10-25-2016 6:39:04 AM 36888 A fatal alert was generated and sent to the remote endpoint. 2.20GHz This may result in termination of the connection. The TLS protocol defined fatal error code is 51. The Windows SChannel error state is 808. 10-25-2016 6:39:04 AM 36888 A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 51. The Windows SChannel error state is 808. 10-25-2016 5:13:57 AM 10010 The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did not register with DCOM within the required timeout. 10-25-2016 1:58:48 AM 3221232472 The Microsoft Office Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Last 5 Application Error Msgs:

PROPRIETARY & CONFIDENTIAL PAGE 186 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 10-25-2016 9:52:11 PM 3221226473 STMON BrtSTMON: [2016/10/25 21:52:11.857]: [00005764]: Don't Create FileMapping!!!! 10-25-2016 9:52:11 PM 3221226473 STMON BrtSTMON: [2016/10/25 21:52:11.857]: [00005764]: FrendlyName : Brother MFC-9320CW Printer 10-25-2016 9:52:11 PM 3221226473 STMON BrtSTMON: [2016/10/25 21:52:11.856]: [00005764]: Error : ExecMonitor() 10-25-2016 9:50:11 PM 3221226473 STMON BrtSTMON: [2016/10/25 21:50:11.849]: [00005764]: Don't Create FileMapping!!!! 10-25-2016 9:50:11 PM 3221226473 STMON BrtSTMON: [2016/10/25 21:50:11.849]: [00005764]: FrendlyName : Brother MFC-9320CW Printer Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 223.43 GB, 35.11 GB free, 84.29% used Service Tag: None CPU Count: 1 CPU Core Count: 2 Windows Key: BBBBB-JDJX7-VJ2AF-DDDD9-HCFC6 Make and Model: Hewlett-Packard/HP G71 Notebook PC Memory Banks: DIMM0 : SODIMM-Synchronous-2048 Mb-800 MHz DIMM2 : SODIMM-Synchronous-2048 Mb-800 MHz CPUs: Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz : CPU0-2 System Slots: System Slot0 : PCI Express Graphic X16-Available-OK System Slot1 : PCI Express-0-Available-OK System Slot2 : PCI Express-1-Available-OK System Slot3 : PCI Express-2-Available-OK System Slot4 : PCI Express-3-Available-OK System Slot5 : PCI Express-4-Available-OK NICs: C8:0A:A9:06:FE:64 : 192.168.7.123;fe80::81a7:389:37b8:abe2-RTL8168-[00000000] Realtek PCIe FE Family Controller : -kdnic-[00000001] Microsoft Kernel Debug redi Adapter

PROPRIETARY & CONFIDENTIAL PAGE 187 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 00:26:C7:04:74:96 : -NETwNs64-[00000002] Intel(R) Centrino(R) Wireless-N 1000 : -tunnel-[00000003] Microsoft ISATAP Adapter 00:26:C7:04:74:97 : -vwifimp-[00000020] Microsoft Hosted redi Virtual Adapter : -AsyncMac-[00000029] RAS Async Adapter DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 6.3.9600 unknown (Build 9600) OS Caption: Microsoft Windows 8.1 Pro OS Architecture: 64-bit OS Virtual Memory: 8096 MB OS System Directory: C:\WINDOWS\system32 OS Windows Directory: C:\WINDOWS OS Install Date: 11/22/2013 3:12:45 PM Active Anti-virus: ThreatTrack Security VIPRE Business Agent Active Anti-spyware: ThreatTrack Security VIPRE Business Agent Active Firewall: Windows Firewall JIM-WIN8 Windows 8.1 Intel(R) 12288 Last 5 System Error Msgs: Enterprise Core(TM) i5- MB 10-25-2016 6:19:53 AM 10010 The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did 3330S CPU @ not register with DCOM within the required timeout. 2.70GHz 10-25-2016 6:19:23 AM 10010 The server {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} did not register with DCOM within the required timeout. 10-24-2016 4:20:46 AM 10010 The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did not register with DCOM within the required timeout. 10-24-2016 4:20:16 AM 10010 The server {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} did not register with DCOM within the required timeout. 10-23-2016 6:37:36 AM 10010 The server {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} did not register with DCOM within the required timeout. Last 5 Application Error Msgs: 10-25-2016 6:19:29 AM 3238068257 Activation context generation failed for "C:\Program Files (x86)\Adobe\Adobe Encore CS5\SetupRoyalty\resources\libraries\ARKEngine.dll". Dependent Assembly

PROPRIETARY & CONFIDENTIAL PAGE 188 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found. Please use sxstrace.exe for detailed diagnosis. 10-25-2016 6:19:29 AM 3238068257 Activation context generation failed for "C:\Program Files (x86)\Adobe\Adobe Encore CS5\SetupRoyalty\resources\libraries\ARKCmdFS.dll". Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found. Please use sxstrace.exe for detailed diagnosis. 10-25-2016 6:19:29 AM 3238068257 Activation context generation failed for "C:\Program Files (x86)\Adobe\Adobe Encore CS5\SetupRoyalty\resources\libraries\ARKCmdDefrag.dll". Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found. Please use sxstrace.exe for detailed diagnosis. 10-25-2016 6:19:29 AM 3238068257 Activation context generation failed for "C:\Program Files (x86)\Adobe\Adobe Encore CS5\SetupRoyalty\resources\libraries\ARKCmdCaps.dll". Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found. Please use sxstrace.exe for detailed diagnosis. 10-24-2016 4:21:47 AM 3238068257 Activation context generation failed for "C:\Program Files (x86)\Adobe\Adobe Encore CS5\SetupRoyalty\resources\libraries\ARKEngine.dll". Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found. Please use sxstrace.exe for detailed diagnosis. Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 931 GB, 795.39 GB free, 14.57% used CPU Count: 1 CPU Core Count: 4 Windows Key: BBBBB-BBBBB-BBBBB-BBBBB-BBBBB Make and Model: Hewlett-Packard/700-027c Memory Banks: DIMM1 : DIMM-Synchronous-4096 Mb-1600 MHz DIMM2 : DIMM-Synchronous-8192 Mb-1600 MHz CPUs: Intel(R) Core(TM) i5-3330S CPU @ 2.70GHz : CPU0-4 System Slots:

PROPRIETARY & CONFIDENTIAL PAGE 189 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name System Slot0 : PCI Express x16 Slot-Available-OK System Slot1 : PCI Express x1 Slot #1-Available-OK System Slot2 : PCI Express x1 Slot #2-Available-OK System Slot3 : PCI Express x1 Slot #3-Available-OK System Slot4 : Mini Card Slot-In Use-OK NICs: 74:46:A0:96:9D:27 : 192.168.7.44;fe80::c18b:1a25:db41:7e4c-RTL8168-[00000000] Realtek PCIe GBE Family Controller : -kdnic-[00000001] Microsoft Kernel Debug redi Adapter 0C:84:DC:3B:F6:23 : -netr28x-[00000002] Ralink RT3290 802.11bgn Wi-Fi Adapter : -tunnel-[00000004] Microsoft ISATAP Adapter 0C:84:DC:3B:F6:25 : -vwifimp-[00000007] Microsoft Wi-Fi Direct Virtual Adapter : -AsyncMac-[00000013] RAS Async Adapter DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 6.3.9600 unknown (Build 9600) OS Caption: Microsoft Windows 8.1 Enterprise OS Architecture: 64-bit OS Virtual Memory: 14032 MB OS System Directory: C:\WINDOWS\system32 OS Windows Directory: C:\WINDOWS OS Install Date: 11/21/2013 10:07:40 AM Active Anti-virus: ThreatTrack Security VIPRE Business Agent Active Anti-spyware: ThreatTrack Security VIPRE Business Agent Active Firewall: N/A Lalexander-PC Windows 10 Pro AMD 3072 Last 5 System Error Msgs: Athlon(tm) II MB 10-25-2016 3:55:06 PM 10016 The application-specific permission settings do not grant Local X2 260 Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- Processor A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running

PROPRIETARY & CONFIDENTIAL PAGE 190 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 2:52:12 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 10:40:31 AM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46- 4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-24-2016 1:06:42 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-24-2016 11:35:30 AM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46- 4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Last 5 Application Error Msgs: 10-25-2016 1:22:58 PM 1002 The program OUTLOOK.EXE version 16.0.6741.2071 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the control panel. Process ID: 4bc8 Start Time: 01d22e0dacb080c1 Termination Time: 0 Application Path: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Report Id: a0792e74-9ad7-11e6- 8d8e-78acc0a9bbf9 Faulting package full name: Faulting package-relative application ID: 10-25-2016 12:22:16 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-25-2016 1:06:56 AM 0 10-24-2016 12:10:47 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-24-2016 1:06:53 AM 0 Scheduled Tasks: G2MUpdateTask-S-1-5-21-356494474-603968661-3470298851-42169

PROPRIETARY & CONFIDENTIAL PAGE 191 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name G2MUploadTask-S-1-5-21-356494474-603968661-3470298851-42169 GoogleUpdateTaskMachineCore GoogleUpdateTaskMachineUA OneDrive Standalone Update Task acct_Feed_Synchronization-{1575DB3B-EBD2-4F7D-96FE-30F7430404F0} acct_Feed_Synchronization-{320DBB31-B66E-43E0-8221-BAB7934087A7} VIPRE Roaming Agent Upgrade Task Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 685.2 GB, 625.53 GB free, 8.71% used D: 12.9 GB, 1.56 GB free, 87.91% used CPU Count: 1 CPU Core Count: 2 Windows Key: BBBBB-JDJX7-VJ2AF-DDDD9-HCFC6 Make and Model: Hewlett-Packard/s5710f Memory Banks: DIMM3 : DIMM-Synchronous-1024 Mb-1333 MHz DIMM4 : DIMM-Synchronous-2048 Mb-1333 MHz CPUs: AMD Athlon(tm) II X2 260 Processor : CPU0-2 System Slots: System Slot0 : PCI-E x1-Available-OK System Slot1 : PCI-E x1-Available-OK NICs: : -kdnic-[00000000] Microsoft Kernel Debug redi Adapter 78:AC:C0:A9:BB:F9 : 192.168.6.81;fe80::7194:3d73:8692:109a-rt640x64-[00000001] Realtek PCIe FE Family Controller : -tunnel-[00000002] Microsoft ISATAP Adapter DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 192.168.14393 unknown (Build 14393) OS Caption:

PROPRIETARY & CONFIDENTIAL PAGE 192 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name Microsoft Windows 10 Pro OS Architecture: 64-bit OS Virtual Memory: 6736 MB OS System Directory: C:\WINDOWS\system32 OS Windows Directory: C:\WINDOWS OS Install Date: 9/22/2016 4:27:06 AM PAE Enabled: True Active Anti-virus: ThreatTrack Security VIPRE Business Agent Active Anti-spyware: ThreatTrack Security VIPRE Business Agent Active Firewall: Windows Firewall Mcarrier-ASUS Windows 10 Pro Mmichaels-HP Windows 8.1 Intel(R) 8192 Last 5 System Error Msgs: Enterprise Core(TM) i5- MB 10-25-2016 4:47:41 AM 10010 The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did 4570T CPU @ not register with DCOM within the required timeout. 2.90GHz 10-25-2016 4:47:11 AM 10010 The server {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} did not register with DCOM within the required timeout. 10-24-2016 4:35:32 AM 10010 The server {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} did not register with DCOM within the required timeout. 10-24-2016 4:35:02 AM 10010 The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did not register with DCOM within the required timeout. 10-23-2016 9:35:51 PM 36887 A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 70. Last 5 Application Error Msgs: 10-25-2016 7:24:06 AM 100 DNS Message from 10.0.6.62:57371 to 10.0.7.95:5353 length 0 too short 10-25-2016 7:24:06 AM 100 DNS Message from 10.0.6.62:57369 to 10.0.7.95:5353 length 0 too short 10-25-2016 7:24:06 AM 100 DNS Message from 10.0.6.62:57346 to 10.0.7.95:5353 length 0 too short 10-25-2016 4:49:04 AM 3221226495 Windows cannot load the extensible counter DLL WmiApRpl. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-24-2016 7:46:57 PM 1024 Product: Adobe Reader XI (11.0.18) - Update 'Adobe Reader XI (11.0.18)' could not be installed. Error code 1603. can create logs to help

PROPRIETARY & CONFIDENTIAL PAGE 193 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127 Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 909.7 GB, 760.23 GB free, 16.43% used D: 19.89 GB, 2.45 GB free, 87.68% used E: 1397.26 GB, 1279.37 GB free, 8.44% used Service Tag: 4CS3380405 CPU Count: 1 CPU Core Count: 2 Windows Key: BBBBB-BBBBB-BBBBB-BBBBB-BBBBB Make and Model: Hewlett-Packard/23-k027c Memory Banks: ChannelB-DIMM0 : SODIMM-Synchronous-8192 Mb-1600 MHz CPUs: Intel(R) Core(TM) i5-4570T CPU @ 2.90GHz : CPU0-2 System Slots: System Slot0 : J6B2-In Use-OK System Slot1 : J6B1-In Use-OK System Slot2 : J6D1-In Use-OK System Slot3 : J7B1-In Use-OK System Slot4 : J8B4-In Use-OK NICs: 48:D2:24:9E:03:C4 : -BCM43XX-[00000000] Broadcom 802.11n redi Adapter : -kdnic-[00000001] Microsoft Kernel Debug redi Adapter 08:9E:01:E2:62:FF : 192.168.7.95;fe80::2855:d52f:3748:b91b-RTL8168-[00000002] Realtek PCIe GBE Family Controller : -tunnel-[00000003] Microsoft ISATAP Adapter 4A:D2:24:9E:03:C4 : -vwifimp-[00000004] Microsoft Wi-Fi Direct Virtual Adapter : -RasSstp-[00000005] WAN Miniport (SSTP) B0:05:94:ED:36:8E : -BthPan-[00000007] Bluetooth Device (Personal Area redi) : -Rasl2tp-[00000008] WAN Miniport (L2TP) : -tunnel-[00000009] Microsoft Teredo Tunneling Adapter : -RasPppoe-[00000010] WAN Miniport (PPPOE)

PROPRIETARY & CONFIDENTIAL PAGE 194 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name : -PptpMiniport-[00000011] WAN Miniport (PPTP) : -RasAgileVpn-[00000012] WAN Miniport (IKEv2) : -NdisWan-[00000013] WAN Miniport (IP) : -NdisWan-[00000014] WAN Miniport (IPv6) : -NdisWan-[00000015] WAN Miniport (redi Monitor) DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 6.3.9600 unknown (Build 9600) OS Caption: Microsoft Windows 8.1 Enterprise OS Architecture: 64-bit OS Virtual Memory: 9408 MB OS System Directory: C:\WINDOWS\system32 OS Windows Directory: C:\WINDOWS OS Install Date: 3/26/2014 4:46:56 PM Active Anti-virus: Windows Defender Active Anti-spyware: Windows Defender Active Firewall: Windows Firewall Mwest-WIN864 Windows 8 Intel(R) 16384 Last 5 System Error Msgs: Enterprise Core(TM) i7- MB 10-25-2016 4:06:31 PM 3758425347 Flush-and-hold state was released while snapping due to 4770K CPU @ timeout on \Device\HarddiskVolume4, cancelling snapping 3.50GHz 10-25-2016 4:06:31 PM 3221618696 The flush and hold writes operation on volume C: timed out while waiting for a release writes dbre. 10-25-2016 5:24:30 AM 3758425347 Flush-and-hold state was released while snapping due to timeout on \Device\HarddiskVolume4, cancelling snapping 10-25-2016 5:24:30 AM 3221618696 The flush and hold writes operation on volume C: timed out while waiting for a release writes dbre. 10-25-2016 3:20:48 AM 3758425347 Flush-and-hold state was released while snapping due to timeout on \Device\HarddiskVolume4, cancelling snapping Last 5 Application Error Msgs:

PROPRIETARY & CONFIDENTIAL PAGE 195 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 10-25-2016 9:51:46 PM 513 Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: TraverseDir : Unable to push subdirectory. System Error: Unspecified error . 10-25-2016 9:48:10 PM 513 Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: TraverseDir : Unable to push subdirectory. System Error: Unspecified error . 10-25-2016 9:39:00 PM 513 Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: TraverseDir : Unable to push subdirectory. System Error: Unspecified error . 10-25-2016 9:35:44 PM 513 Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: TraverseDir : Unable to push subdirectory. System Error: Unspecified error . 10-25-2016 9:28:09 PM 513 Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: TraverseDir : Unable to push subdirectory. System Error: Unspecified error . Scheduled Tasks: billingSFTP G2MUpdateTask-S-1-5-21-356494474-603968661-3470298851-16619 G2MUploadTask-S-1-5-21-356494474-603968661-3470298851-16619 GoogleUpdateTaskMachineCore GoogleUpdateTaskMachineUA Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-1115 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-1221 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-16619 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-2134 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-42161 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-42230 Telerik Control Panel Notifier PIT_rpilzner VIPRE Roaming Agent Upgrade Task Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 476.13 GB, 288.01 GB free, 39.51% used Service Tag: To Be Filled By O.E.M. CPU Count: 1 CPU Core Count: 4 Windows Key: TH4CG-JDJX7-VJ2AF-DYBB9-HCFC6

PROPRIETARY & CONFIDENTIAL PAGE 196 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name Other License Keys: Internet Explorer 55041-006-2483512-86608 (ends with HRXPK) Office Professional Plus 2010 82303-018-0000106-48008 (ends with HEXPK) PowerShell 89383-100-001260-04339 Windows 7 Enterprise 55041-006-2445512-86648 (ends with HDXK) Make and Model: MSI/MS-7850 Memory Banks: ChannelA-DIMM0 : DIMM-Synchronous-4096 Mb-1333 MHz ChannelA-DIMM1 : DIMM-Synchronous-4096 Mb-1333 MHz ChannelB-DIMM0 : DIMM-Synchronous-4096 Mb-1333 MHz ChannelB-DIMM1 : DIMM-Synchronous-4096 Mb-1333 MHz CPUs: Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz : CPU0-4 System Slots: System Slot0 : J6B2-In Use-OK System Slot1 : J6B1-In Use-OK System Slot2 : J6D1-In Use-OK System Slot3 : J7B1-In Use-OK System Slot4 : J8B4-In Use-OK System Slot5 : J8D1-In Use-OK System Slot6 : J8B3-In Use-OK NICs: : -Rasl2tp-[00000000] WAN Miniport (L2TP) : -RasSstp-[00000001] WAN Miniport (SSTP) : -RasAgileVpn-[00000002] WAN Miniport (IKEv2) : -PptpMiniport-[00000003] WAN Miniport (PPTP) : -RasPppoe-[00000004] WAN Miniport (PPPOE) : -NdisWan-[00000005] WAN Miniport (IP) : -NdisWan-[00000006] WAN Miniport (IPv6) : -NdisWan-[00000007] WAN Miniport (redi Monitor) : -kdnic-[00000008] Microsoft Kernel Debug redi Adapter : -AsyncMac-[00000009] RAS Async Adapter : -e1iexpress-[00000010] Intel(R) 82579V Gigabit redi Connection : -athr-[00000011] Qualcomm Atheros AR5BWB222 Wireless redi Adapter : -BthPan-[00000012] Bluetooth Device (Personal Area redi) : -tunnel-[00000014] Microsoft ISATAP Adapter : -tunnel-[00000015] Microsoft ISATAP Adapter DC:85:DE:00:0A:C6 : -netr28ux-[00000017] 802.11bgn 1T1R Wireless Adapter

PROPRIETARY & CONFIDENTIAL PAGE 197 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name D4:3D:7E:F7:33:12 : 192.168.6.30;fe80::7977:c113:9a24:40a1-RTL8168-[00000018] Realtek PCIe GBE Family Controller DC:85:DE:00:0A:C0 : -vwifimp-[00000019] Microsoft Wi-Fi Direct Virtual Adapter DC:85:DE:00:0A:C7 : -vwifimp-[00000020] Microsoft Hosted redi Virtual Adapter 94:DB:C9:96:7B:7F : -BthPan-[00000021] Bluetooth Device (Personal Area redi) : -tunnel-[00000023] Microsoft Teredo Tunneling Adapter : -tunnel-[00000032] Microsoft ISATAP Adapter : -tunnel-[00000033] Microsoft ISATAP Adapter : -vwifimp-[00000034] Microsoft Wi-Fi Direct Virtual Adapter DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 6.2.9200 unknown (Build 9200) OS Caption: Microsoft Windows 8 Enterprise OS Architecture: 64-bit OS Virtual Memory: 21184 MB OS System Directory: C:\Windows\system32 OS Windows Directory: C:\Windows OS Install Date: 11/28/2012 8:17:17 AM PAE Enabled: True Active Anti-virus: ThreatTrack Security VIPRE Business Agent Active Anti-spyware: ThreatTrack Security VIPRE Business Agent Active Firewall: Windows Firewall mwinchester Windows 10 Pro NOBELIUM Windows 8 Enterprise PANOPTICON Windows 10 Pro Intel(R) 16384 Last 5 System Error Msgs: Core(TM) i7- MB 10-25-2016 4:20:37 PM 10016 The application-specific permission settings do not grant Local 6700K CPU @ Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- 4.00GHz A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the

PROPRIETARY & CONFIDENTIAL PAGE 198 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 3:26:35 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-24-2016 4:32:00 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-24-2016 11:41:36 AM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46- 4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-24-2016 10:36:21 AM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46- 4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Last 5 Application Error Msgs: 10-25-2016 1:31:46 PM 1000 Faulting application name: devenv.exe, version: 14.0.25420.1, time stamp: 0x57685d85 Faulting module name: clr.dll, version: 4.6.1586.0, time stamp: 0x575a139f Exception code: 0xc0000005 Fault offset: 0x004e6c4e Faulting process id: 0x1f28 Faulting application start time: 0x01d22b0bc7c925ee Faulting application path: C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe Faulting module path: C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll Report Id: ca6bb768-0df6-49e0-aef7- cb38e476c55b Faulting package full name: Faulting package-relative application ID: 10-25-2016 1:31:44 PM 1023 Application: devenv.exe Framework Version: v4.0.30319 Description: The process was terminated due to an itable error in the .NET Runtime at IP 74116C4E (73C30000) with exit code 80131506. 10-25-2016 1:30:17 PM 0 10-25-2016 7:17:30 AM 100 DNS Message from 192.168.6.62:49526 to 192.168.6.133:5353 length 0 too short

PROPRIETARY & CONFIDENTIAL PAGE 199 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 10-25-2016 7:17:29 AM 100 DNS Message from 192.168.6.62:49489 to 192.168.6.133:5353 length 0 too short Scheduled Tasks: billingSFTP G2MUpdateTask-S-1-5-21-356494474-603968661-3470298851-42161 G2MUploadTask-S-1-5-21-356494474-603968661-3470298851-42161 GoogleUpdateTaskMachineCore GoogleUpdateTaskMachineUA OneDrive Standalone Update Task StartListener acct_Feed_Synchronization-{82FB14FC-199A-4C23-A6D7-E437EA9F02BF} Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 475.68 GB, 329.76 GB free, 30.68% used Service Tag: PS CPU Count: 1 CPU Core Count: 4 Windows Key: TH4CG-JDJX7-VJ2AF-DYBB9-HCFC6 Other License Keys: Internet Explorer 55041-006-2483512-86608 (ends with HRXPK) Office Professional Plus 2010 82303-018-0000106-48008 (ends with HEXPK) PowerShell 89383-100-001260-04339 Windows 7 Enterprise 55041-006-2445512-86648 (ends with HDXK) Make and Model: PowerSpec/Gseries Memory Banks: ChannelA-DIMM1 : DIMM-Synchronous-8192 Mb-3200 MHz ChannelB-DIMM1 : DIMM-Synchronous-8192 Mb-3200 MHz CPUs: Intel(R) Core(TM) i7-6700K CPU @ 4.00GHz : CPU0-4 System Slots: System Slot0 : J6B2-In Use-OK System Slot1 : J6B1-In Use-OK System Slot2 : J6D1-In Use-OK

PROPRIETARY & CONFIDENTIAL PAGE 200 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name System Slot3 : J7B1-In Use-OK System Slot4 : J8B4-In Use-OK System Slot5 : J8D1-In Use-OK System Slot6 : J8B3-In Use-OK NICs: D8:CB:8A:C6:C2:DE : -rt640x64-[00000000] Realtek PCIe GBE Family Controller : -kdnic-[00000001] Microsoft Kernel Debug redi Adapter : -athr-[00000002] Qualcomm Atheros AR5BWB222 Wireless redi Adapter 30:10:B3:4A:A5:85 : -BthPan-[00000003] Bluetooth Device (Personal Area redi) : -RFCOMM-[00000004] Bluetooth Device (RFCOMM Protocol TDI) : -NdisImPlatformMp-[00000005] Microsoft redi Adapter Multiplexor Driver : -vwifimp-[00000006] Microsoft Wi-Fi Direct Virtual Adapter : -vwifimp-[00000007] Microsoft Wi-Fi Direct Virtual Adapter : -VMSMP-[00000008] Hyper-V Virtual Ethernet Adapter : -VMSMP-[00000009] Hyper-V Virtual Ethernet Adapter : -VMSMP-[00000010] Hyper-V Virtual Switch Extension Adapter D8:CB:8A:C6:C2:DE : 192.168.6.133;fe80::a4a0:5c06:b6d4:d020-VMSMP-[00000011] Hyper- V Virtual Ethernet Adapter : -VMSMP-[00000012] Hyper-V Virtual Switch Extension Adapter : -VMSMP-[00000013] Hyper-V Virtual Switch Extension Adapter : -tunnel-[00000014] Microsoft ISATAP Adapter : -tunnel-[00000015] Microsoft ISATAP Adapter : -RasSstp-[00000016] WAN Miniport (SSTP) : -RasAgileVpn-[00000017] WAN Miniport (IKEv2) : -Rasl2tp-[00000018] WAN Miniport (L2TP) : -PptpMiniport-[00000019] WAN Miniport (PPTP) : -RasPppoe-[00000020] WAN Miniport (PPPOE) : -NdisWan-[00000021] WAN Miniport (IP) : -NdisWan-[00000022] WAN Miniport (IPv6) : -NdisWan-[00000023] WAN Miniport (redi Monitor) DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 192.168.14393 unknown (Build 14393) OS Caption: Microsoft Windows 10 Pro OS Architecture: 64-bit OS Virtual Memory:

PROPRIETARY & CONFIDENTIAL PAGE 201 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 28032 MB OS System Directory: C:\WINDOWS\system32 OS Windows Directory: C:\WINDOWS OS Install Date: 9/26/2016 4:40:16 AM PAE Enabled: True Active Anti-virus: Windows Defender Active Anti-spyware: Windows Defender Active Firewall: Windows Firewall PITWDS12 Windows Server Intel(R) 1024 Last 5 System Error Msgs: 2012 R2 Datacenter Xeon(R) CPU MB 10-25-2016 6:32:56 AM 36888 A fatal alert was generated and sent to the remote endpoint. L5639 @ This may result in termination of the connection. The TLS protocol defined fatal error code is 2.13GHz 40. The Windows SChannel error state is 1205. 10-25-2016 6:32:56 AM 36874 An TLS 1.2 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed. 10-25-2016 6:32:56 AM 36888 A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 1205. 10-25-2016 6:32:56 AM 36874 An TLS 1.2 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed. 10-25-2016 6:32:56 AM 36888 A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 1205. Last 5 Application Error Msgs: 10-25-2016 12:23:28 PM 3221226480 The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. 10-24-2016 12:11:47 PM 3221226480 The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. 10-23-2016 11:58:46 AM 3221226480 The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. 10-23-2016 3:19:24 AM 2147483905 The volume Recovery was not optimized because an error was encountered: The parameter is incorrect. (0x80070057)

PROPRIETARY & CONFIDENTIAL PAGE 202 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 10-22-2016 12:14:20 PM 3238331655 An error occurred while trying to enumerate Boot Images from directory D:\RemoteInstall\Boot\arm\Images for architecture arm. Error Information: 0x3 Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 126.48 GB, 101.04 GB free, 20.11% used D: 199.87 GB, 109.14 GB free, 45.39% used Service Tag: 6984-2833-8919-4854-6590-2857-62 CPU Count: 1 CPU Core Count: 4 Windows Key: BBBBB-JDJX7-VJ2AF-DDDD9-HCFC6 Make and Model: Microsoft Corporation/Virtual Machine Memory Banks: M00 : Unknown-Unknown-1024 Mb-unknown MHz 1 CPUs: Intel(R) Xeon(R) CPU L5639 @ 2.13GHz : CPU0-4 NICs: : -Rasl2tp-[00000000] WAN Miniport (L2TP) : -RasSstp-[00000001] WAN Miniport (SSTP) : -RasAgileVpn-[00000002] WAN Miniport (IKEv2) : -PptpMiniport-[00000003] WAN Miniport (PPTP) : -RasPppoe-[00000004] WAN Miniport (PPPOE) : -NdisWan-[00000005] WAN Miniport (IP) : -NdisWan-[00000006] WAN Miniport (IPv6) : -NdisWan-[00000007] WAN Miniport (redi Monitor) : -kdnic-[00000008] Microsoft Kernel Debug redi Adapter 00:15:5D:7A:59:0B : 192.168.1.64;fe80::20ae:593f:c5e4:9c2d-netvsc-[00000010] Microsoft Hyper-V redi Adapter 00:15:5D:7A:59:0C : 192.168.1.63;fe80::e15f:1056:8c90:e961-netvsc-[00000012] Microsoft Hyper-V redi Adapter : -tunnel-[00000013] Microsoft ISATAP Adapter : -tunnel-[00000014] Microsoft ISATAP Adapter DEP: On for All programs and services except those I select

PROPRIETARY & CONFIDENTIAL PAGE 203 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name OS Manufacturer: Microsoft Corporation OS Version: 6.3.9600 unknown (Build 9600) OS Caption: Microsoft Windows Server 2012 R2 Datacenter OS Architecture: 64-bit OS Virtual Memory: 5920 MB OS System Directory: C:\Windows\system32 OS Windows Directory: C:\Windows OS Install Date: 6/27/2016 1:17:57 PM Active Anti-virus: N/A Active Anti-spyware: N/A Active Firewall: Windows Firewall PKWIN8-VM Windows 8.1 Pro Intel(R) 1024 Last 5 System Error Msgs: Xeon(R) CPU MB 10-22-2016 11:24:39 AM 10010 The server {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} L5639 @ did not register with DCOM within the required timeout. 2.13GHz 10-22-2016 7:03:54 AM 36888 A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 1205. 10-22-2016 7:03:54 AM 36874 An TLS 1.2 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed. 10-22-2016 7:03:54 AM 36888 A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 1205. 10-22-2016 7:03:54 AM 36874 An TLS 1.2 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed. Last 5 Application Error Msgs: 10-25-2016 6:07:10 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-25-2016 6:07:10 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code.

PROPRIETARY & CONFIDENTIAL PAGE 204 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 10-25-2016 2:32:27 AM 2147483905 The volume Recovery was not optimized because an error was encountered: The parameter is incorrect. (0x80070057) 10-24-2016 6:05:19 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-24-2016 4:51:38 AM 2147483905 The volume Recovery was not optimized because an error was encountered: The parameter is incorrect. (0x80070057) Scheduled Tasks: GoogleUpdateTaskMachineCore GoogleUpdateTaskMachineUA Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-1118 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-1230 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-29609 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-40613 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-40626 acct_Feed_Synchronization-{1D0C8F29-710E-4362-BF0B-4033207BA9B2} acct_Feed_Synchronization-{5A029B66-266A-4558-AAEF-AE0D89069A65} acct_Feed_Synchronization-{EF1CD4B4-90BE-47F1-9A98-2E15776C940A} Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 126.48 GB, 84.38 GB free, 33.29% used Service Tag: 7023-0101-8892-0937-6588-8690-01 CPU Count: 1 CPU Core Count: 4 Windows Key: TH4CG-JDJX7-VJ2AF-DYBB9-HCFC6 Other License Keys: Internet Explorer 55041-006-2483512-86608 (ends with HRXPK) Office Professional Plus 2010 82303-018-0000106-48008 (ends with HEXPK) PowerShell 89383-100-001260-04339 Windows 7 Enterprise 55041-006-2445512-86648 (ends with HDXK) Make and Model: Microsoft Corporation/Virtual Machine Memory Banks: M00 : Unknown-Unknown-1024 Mb-unknown MHz 1 CPUs: Intel(R) Xeon(R) CPU L5639 @ 2.13GHz : CPU0-4

PROPRIETARY & CONFIDENTIAL PAGE 205 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name NICs: 00:15:5D:01:E0:8C : 192.168.6.120;fe80::25ca:4556:3551:9e23-netvsc-[00000000] Microsoft Hyper-V redi Adapter : -kdnic-[00000001] Microsoft Kernel Debug redi Adapter 00:15:5D:01:E0:8D : 192.168.199.34;fe80::5d0f:a0de:55fa:48c4-netvsc-[00000002] Microsoft Hyper-V redi Adapter : -tunnel-[00000003] Microsoft ISATAP Adapter : -AsyncMac-[00000014] RAS Async Adapter : -tunnel-[00000015] Microsoft ISATAP Adapter DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 6.3.9600 unknown (Build 9600) OS Caption: Microsoft Windows 8.1 Pro OS Architecture: 64-bit OS Virtual Memory: 4048 MB OS System Directory: C:\Windows\system32 OS Windows Directory: C:\Windows OS Install Date: 3/3/2014 1:09:54 PM PAE Enabled: True Active Anti-virus: Windows Defender Active Anti-spyware: Windows Defender Active Firewall: Windows Firewall porchanko- Windows 8.1 HOME Enterprise PS01 Windows Server Intel(R) 1024 Last 5 System Error Msgs: 2012 R2 Standard Xeon(R) CPU MB 10-25-2016 8:18:49 PM 5719 This computer was not able to set up a secure session with a L5639 @ domain controller in domain PIT due to the following: There are currently no logon servers 2.13GHz available to service the logon request. This may lead to authentication problems. Make sure that this computer is connected to the redi. If the problem persists, please contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller for the specified

PROPRIETARY & CONFIDENTIAL PAGE 206 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain. 10-25-2016 4:18:48 PM 5719 This computer was not able to set up a secure session with a domain controller in domain PIT due to the following: There are currently no logon servers available to service the logon request. This may lead to authentication problems. Make sure that this computer is connected to the redi. If the problem persists, please contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain. 10-25-2016 12:18:48 PM 5719 This computer was not able to set up a secure session with a domain controller in domain PIT due to the following: There are currently no logon servers available to service the logon request. This may lead to authentication problems. Make sure that this computer is connected to the redi. If the problem persists, please contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain. 10-25-2016 8:18:47 AM 5719 This computer was not able to set up a secure session with a domain controller in domain PIT due to the following: There are currently no logon servers available to service the logon request. This may lead to authentication problems. Make sure that this computer is connected to the redi. If the problem persists, please contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain. 10-25-2016 4:18:47 AM 5719 This computer was not able to set up a secure session with a domain controller in domain PIT due to the following: There are currently no logon servers available to service the logon request. This may lead to authentication problems. Make sure that this computer is connected to the redi. If the problem persists, please contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain. Last 5 Application Error Msgs: 10-25-2016 8:01:53 PM 3221226480 The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.

PROPRIETARY & CONFIDENTIAL PAGE 207 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 10-24-2016 7:04:18 PM 3221226480 The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. 10-23-2016 7:02:18 PM 3221226480 The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. 10-22-2016 7:01:44 PM 3221226480 The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. 10-22-2016 8:01:15 AM 3221243308 Length specified in redi packet payload did not match number of bytes read; the connection has been closed. Please contact the vendor of the client library. [CLIENT: 192.168.6.104] Remote Listening Ports: HTTP (80/TCP) SQLServer (1433/TCP) RDP (3389/TCP) Disk Capacity: C: 59.48 GB, 28.27 GB free, 52.47% used Service Tag: 8106-2199-5440-4619-9468-0535-04 CPU Count: 1 CPU Core Count: 2 Windows Key: BBBBB-JDJX7-VJ2AF-DDDD9-HCFC6 Make and Model: Microsoft Corporation/Virtual Machine Memory Banks: M00 : Unknown-Unknown-1024 Mb-unknown MHz 1 CPUs: Intel(R) Xeon(R) CPU L5639 @ 2.13GHz : CPU0-2 NICs: : -Rasl2tp-[00000000] WAN Miniport (L2TP) : -RasSstp-[00000001] WAN Miniport (SSTP) : -RasAgileVpn-[00000002] WAN Miniport (IKEv2) : -PptpMiniport-[00000003] WAN Miniport (PPTP) : -RasPppoe-[00000004] WAN Miniport (PPPOE) : -NdisWan-[00000005] WAN Miniport (IP) : -NdisWan-[00000006] WAN Miniport (IPv6)

PROPRIETARY & CONFIDENTIAL PAGE 208 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name : -NdisWan-[00000007] WAN Miniport (redi Monitor) : -kdnic-[00000008] Microsoft Kernel Debug redi Adapter 00:15:5D:01:E0:5D : 192.168.7.99;fe80::850d:e5b2:61d3:15d6-netvsc-[00000010] Microsoft Hyper-V redi Adapter : -tunnel-[00000012] Microsoft ISATAP Adapter : -tunnel-[00000014] Microsoft ISATAP Adapter : -tunnel-[00000015] Microsoft ISATAP Adapter DEP: On for All programs and services except those I select OS Manufacturer: Microsoft Corporation OS Version: 6.3.9600 unknown (Build 9600) OS Caption: Microsoft Windows Server 2012 R2 Standard OS Architecture: 64-bit OS Virtual Memory: 5280 MB OS System Directory: C:\Windows\system32 OS Windows Directory: C:\Windows OS Install Date: 6/24/2014 11:49:15 AM Psolidad-PC Windows 10 Pro Intel(R) 10240 Last 5 System Error Msgs: Core(TM) i7- MB 10-25-2016 4:07:20 PM 10016 The application-specific permission settings do not grant Local 4770 CPU @ Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- 3.40GHz A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 2:39:07 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 1:29:24 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-

PROPRIETARY & CONFIDENTIAL PAGE 209 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 11:58:46 AM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46- 4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 11:54:42 AM 10010 The server {F3B4E234-7A68-4E43-B813-E4BA55A065F6} did not register with DCOM within the required timeout. Last 5 Application Error Msgs: 10-25-2016 9:52:23 PM 10 Event filter with query "SELECT * FROM __InstanceOperationEvent WITHIN 10 WHERE (TargetInstance ISA 'Msvm_ExternalEthernetPort') OR (TargetInstance ISA 'Msvm_VmLANEndpoint') OR (TargetInstance ISA 'Msvm_SyntheticEthernetPort') OR (TargetInstance ISA 'Msvm_ComputerSystem') OR (TargetInstance ISA 'Msvm_VLANEndpointSettingData')" could not be reactivated in namespace "//./root/virtualization" because of error 0x80041010. Events cannot be delivered through this filter until the problem is corrected. 10-25-2016 9:52:12 PM 10 Event filter with query "SELECT * FROM __InstanceOperationEvent WITHIN 10 WHERE (TargetInstance ISA 'Msvm_ExternalEthernetPort') OR (TargetInstance ISA 'Msvm_VmLANEndpoint') OR (TargetInstance ISA 'Msvm_SyntheticEthernetPort') OR (TargetInstance ISA 'Msvm_ComputerSystem') OR (TargetInstance ISA 'Msvm_VLANEndpointSettingData')" could not be reactivated in namespace "//./root/virtualization" because of error 0x80041010. Events cannot be delivered through this filter until the problem is corrected. 10-25-2016 9:52:01 PM 10 Event filter with query "SELECT * FROM __InstanceOperationEvent WITHIN 10 WHERE (TargetInstance ISA 'Msvm_ExternalEthernetPort') OR (TargetInstance ISA 'Msvm_VmLANEndpoint') OR (TargetInstance ISA 'Msvm_SyntheticEthernetPort') OR (TargetInstance ISA 'Msvm_ComputerSystem') OR (TargetInstance ISA 'Msvm_VLANEndpointSettingData')" could not be reactivated in namespace "//./root/virtualization" because of error 0x80041010. Events cannot be delivered through this filter until the problem is corrected. 10-25-2016 9:51:50 PM 10 Event filter with query "SELECT * FROM __InstanceOperationEvent WITHIN 10 WHERE (TargetInstance ISA 'Msvm_ExternalEthernetPort') OR (TargetInstance ISA 'Msvm_VmLANEndpoint') OR (TargetInstance ISA 'Msvm_SyntheticEthernetPort') OR (TargetInstance ISA 'Msvm_ComputerSystem') OR (TargetInstance ISA 'Msvm_VLANEndpointSettingData')" could not be reactivated in namespace "//./root/virtualization" because of error 0x80041010. Events cannot be delivered through this filter until the problem is corrected.

PROPRIETARY & CONFIDENTIAL PAGE 210 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 10-25-2016 9:51:39 PM 10 Event filter with query "SELECT * FROM __InstanceOperationEvent WITHIN 10 WHERE (TargetInstance ISA 'Msvm_ExternalEthernetPort') OR (TargetInstance ISA 'Msvm_VmLANEndpoint') OR (TargetInstance ISA 'Msvm_SyntheticEthernetPort') OR (TargetInstance ISA 'Msvm_ComputerSystem') OR (TargetInstance ISA 'Msvm_VLANEndpointSettingData')" could not be reactivated in namespace "//./root/virtualization" because of error 0x80041010. Events cannot be delivered through this filter until the problem is corrected. Scheduled Tasks: Adobe Acrobat Update Task AdobeAAMUpdater-1.0-myco-psolidad ALU ALUAgent DropboxUpdateTaskMachineCore DropboxUpdateTaskMachineUA G2MUpdateTask-S-1-5-21-356494474-603968661-3470298851-1114 G2MUploadTask-S-1-5-21-356494474-603968661-3470298851-1114 GoogleUpdateTaskMachineCore GoogleUpdateTaskMachineUA basergeTask NDDC OneDrive Standalone Update Task Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-1114 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-18623 Optimize Start Menu Cache Files-S-1-5-21-565975575-75717821-296142214-1001 Optimize Start Menu Cache Files-S-1-5-21-565975575-75717821-296142214-500 Power Management update-S-1-5-21-356494474-603968661-3470298851-1114 update-sys acct_Feed_Synchronization-{C06E9232-7C73-4463-9B3B-9311D28AE640} VIPRE Roaming Agent Upgrade Task {3A7E5591-34A2-4C80-A182-8E39BA54D481} Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 890.26 GB, 591.62 GB free, 33.55% used CPU Count: 1 CPU Core Count: 4 Windows Key: TH4CG-JDJX7-VJ2AF-DY4X9-HCFC6

PROPRIETARY & CONFIDENTIAL PAGE 211 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name Other License Keys: Internet Explorer 55041-006-2483512-86608 (ends with HCXPK) Office Professional Plus 2010 82603-018-0000106-48008 (ends with HCXPK) PowerShell 89383-100-0001260-04379 Windows 7 Enterprise 55041-006-2445512-86648 (ends with HCXK) Make and Model: Acer/Veriton M6630G Memory Banks: DIMM1 : DIMM-Synchronous-4096 Mb-1600 MHz DIMM2 : DIMM-Synchronous-4096 Mb-1600 MHz DIMM3 : DIMM-Synchronous-1024 Mb-1333 MHz DIMM4 : DIMM-Synchronous-1024 Mb-1333 MHz CPUs: Intel(R) Core(TM) i7-4770 CPU @ 3.40GHz : CPU0-4 System Slots: System Slot0 : PCIE16X_1-Available-OK System Slot1 : PCIE1X-Available-OK System Slot2 : PCI-Available-OK System Slot3 : PCIE16X_2-Available-OK NICs: : -kdnic-[00000000] Microsoft Kernel Debug redi Adapter C0:3F:D5:5E:F3:D9 : -e1iexpress-[00000001] Intel(R) Ethernet Connection I217-LM : -VMSMP-[00000002] Hyper-V Virtual Switch Extension Adapter 00:15:5D:06:28:24 : 169.254.197.112;fe80::4016:d634:6959:c570-VMSMP-[00000003] Hyper- V Virtual Ethernet Adapter : -VMSMP-[00000004] Hyper-V Virtual Switch Extension Adapter C0:3F:D5:5E:F3:D9 : 192.168.6.12;fe80::9c83:ca9d:1a7d:7f24-VMSMP-[00000005] Hyper-V Virtual Ethernet Adapter : -tunnel-[00000006] Microsoft ISATAP Adapter : -tunnel-[00000007] Microsoft ISATAP Adapter : -RasSstp-[00000008] WAN Miniport (SSTP) : -RasAgileVpn-[00000009] WAN Miniport (IKEv2) : -Rasl2tp-[00000010] WAN Miniport (L2TP) : -PptpMiniport-[00000011] WAN Miniport (PPTP) : -RasPppoe-[00000012] WAN Miniport (PPPOE) : -NdisWan-[00000013] WAN Miniport (IP) : -NdisWan-[00000014] WAN Miniport (IPv6) : -NdisWan-[00000015] WAN Miniport (redi Monitor) DEP: On for essential Windows programs and services only

PROPRIETARY & CONFIDENTIAL PAGE 212 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name OS Manufacturer: Microsoft Corporation OS Version: 192.168.14393 unknown (Build 14393) OS Caption: Microsoft Windows 10 Pro OS Architecture: 64-bit OS Virtual Memory: 13632 MB OS System Directory: C:\WINDOWS\system32 OS Windows Directory: C:\WINDOWS OS Install Date: 9/2/2016 6:24:05 AM PAE Enabled: True Active Anti-virus: ThreatTrack Security VIPRE Business Agent Active Anti-spyware: ThreatTrack Security VIPRE Business Agent Active Firewall: Windows Firewall Psolidad- Windows 8.1 AMD 4096 Last 5 System Error Msgs: WIN764 Enterprise Phenom(tm) II MB 10-25-2016 5:08:41 AM 10010 The server {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} did X4 945 not register with DCOM within the required timeout. Processor 10-25-2016 5:08:11 AM 10010 The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did not register with DCOM within the required timeout. 10-24-2016 4:50:07 AM 10010 The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did not register with DCOM within the required timeout. 10-24-2016 4:49:37 AM 10010 The server {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} did not register with DCOM within the required timeout. 10-23-2016 5:41:55 AM 10010 The server {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} did not register with DCOM within the required timeout. Last 5 Application Error Msgs: 10-25-2016 6:07:06 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-25-2016 6:07:06 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-25-2016 7:16:25 AM 100 DNS Message from 192.168.6.62:49807 to 192.168.6.14:5353 length 0 too short

PROPRIETARY & CONFIDENTIAL PAGE 213 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 10-25-2016 7:16:25 AM 100 DNS Message from 192.168.6.62:49806 to 192.168.6.14:5353 length 0 too short 10-25-2016 12:50:03 AM 0 Scheduled Tasks: AdobeAAMUpdater-1.0-myco-jaddair AdobeAAMUpdater-1.0-myco-psolidad DropboxUpdateTaskMachineCore DropboxUpdateTaskMachineUA GoogleUpdateTaskMachineCore GoogleUpdateTaskMachineUA Microsoft OneDrive Auto Update Task-S-1-5-21-356494474-603968661-3470298851-1114 OneDrive Standalone Update Task Optimize Start Menu Cache Files-S-1-5-21-3051448146-2100132198-645567491-1000 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-1114 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-1117 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-40614 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-40677 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-42173 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-42184 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-42238 acct_Feed_Synchronization-{65D4DEDB-9A5B-4EB3-AD79-20DDD59D8C65} acct_Feed_Synchronization-{9128AB44-A327-4BF2-9041-61CAAC47019D} acct_Feed_Synchronization-{912FECF4-DE74-481C-9188-03CDA818EEF6} acct_Feed_Synchronization-{E5E4C2BD-0514-4E8E-8E76-60562208D10E} {8C0A4A52-47C3-4706-9B34-9C67E85153E7} {A4F663C4-30DE-4C03-808F-25A0A0DD4056} Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 913.35 GB, 680.76 GB free, 25.47% used CPU Count: 1 CPU Core Count: 4 Windows Key: TH4CG-JDJX7-VJ2AF-DY4X9-HCFC6 Other License Keys: Internet Explorer 55041-006-2483512-86608 (ends with HCXPK) Office Professional Plus 2010 82603-018-0000106-48008 (ends with HCXPK) PowerShell 89383-100-0001260-04379 Windows 7 Enterprise 55041-006-2445512-86648 (ends with HCXK)

PROPRIETARY & CONFIDENTIAL PAGE 214 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name Make and Model: Gateway/DX4320 Memory Banks: DIMM2 : DIMM-Synchronous-2048 Mb-533 MHz DIMM3 : DIMM-Synchronous-2048 Mb-533 MHz CPUs: AMD Phenom(tm) II X4 945 Processor : CPU0-4 System Slots: System Slot0 : PCIE1-In Use-OK System Slot1 : PCIE2-Available-OK System Slot2 : PCIE3-Available-OK System Slot3 : PCI1-Available-OK NICs: 90:FB:A6:8A:9C:2B : 192.168.6.14;fe80::20dd:cdd2:c1bf:95dc-RTL8168-[00000000] Realtek PCIe GBE Family Controller : -kdnic-[00000001] Microsoft Kernel Debug redi Adapter 00:FF:40:9A:35:DE : -dsNcAdpt-[00000002] Juniper redi Connect Virtual Adapter : -vpnva-[00000003] Cisco AnyConnect VPN Virtual Miniport Adapter for Windows x64 : -tunnel-[00000004] Microsoft ISATAP Adapter : -tunnel-[00000005] Microsoft ISATAP Adapter : -RasSstp-[00000006] WAN Miniport (SSTP) : -VBoxNetAdp-[00000007] VirtualBox Host-Only Ethernet Adapter : --[00000008] Deterministic redi Enhancer Miniport : -RasPppoe-[00000009] WAN Miniport (PPPOE) : --[00000010] Deterministic redi Enhancer Miniport : -Rasl2tp-[00000011] WAN Miniport (L2TP) : -PptpMiniport-[00000012] WAN Miniport (PPTP) : -RasAgileVpn-[00000013] WAN Miniport (IKEv2) : -NdisWan-[00000014] WAN Miniport (IP) : --[00000015] Deterministic redi Enhancer Miniport : -NdisWan-[00000016] WAN Miniport (IPv6) : -NdisWan-[00000017] WAN Miniport (redi Monitor) : --[00000018] Deterministic redi Enhancer Miniport : --[00000019] Deterministic redi Enhancer Miniport 00:FF:40:9A:35:DE : --[00000020] Deterministic redi Enhancer Miniport 90:FB:A6:8A:9C:2B : --[00000021] Deterministic redi Enhancer Miniport : --[00000022] Deterministic redi Enhancer Miniport : --[00000023] Deterministic redi Enhancer Miniport : -SWVNIC-[00000024] SonicWALL Virtual NIC

PROPRIETARY & CONFIDENTIAL PAGE 215 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name : --[00000025] Deterministic redi Enhancer Miniport : --[00000026] Deterministic redi Enhancer Miniport : --[00000027] Deterministic redi Enhancer Miniport : --[00000028] Deterministic redi Enhancer Miniport : --[00000029] Deterministic redi Enhancer Miniport : --[00000030] Deterministic redi Enhancer Miniport : --[00000031] Deterministic redi Enhancer Miniport : -AsyncMac-[00000032] RAS Async Adapter : --[00000033] Deterministic redi Enhancer Miniport : --[00000034] Deterministic redi Enhancer Miniport : --[00000035] Deterministic redi Enhancer Miniport : --[00000036] Deterministic redi Enhancer Miniport : --[00000037] Deterministic redi Enhancer Miniport : --[00000038] Deterministic redi Enhancer Miniport : --[00000039] Deterministic redi Enhancer Miniport : --[00000040] Deterministic redi Enhancer Miniport DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 6.3.9600 unknown (Build 9600) OS Caption: Microsoft Windows 8.1 Enterprise OS Architecture: 64-bit OS Virtual Memory: 8176 MB OS System Directory: C:\WINDOWS\system32 OS Windows Directory: C:\WINDOWS OS Install Date: 11/21/2013 1:32:55 PM PAE Enabled: True Active Anti-virus: Windows Defender Active Anti-spyware: Windows Defender Active Firewall: Windows Firewall

PROPRIETARY & CONFIDENTIAL PAGE 216 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name QB01 Windows Server Intel(R) 2048 Last 5 System Error Msgs: 2008 R2 Enterprise Xeon(R) CPU MB 10-25-2016 9:48:23 PM 36888 The following fatal alert was generated: 40. The itable error L5639 @ state is 1205. 2.13GHz 10-25-2016 9:48:23 PM 36874 An TLS 1.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed. 10-25-2016 9:48:23 PM 36888 The following fatal alert was generated: 40. The itable error state is 1205. 10-25-2016 9:48:23 PM 36874 An SSL 3.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed. 10-25-2016 9:43:03 PM 1073741828 The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server rdgateway$. The target name used was RPCSS/RDGateway. This indicates that the target server failed to decrypt the myapp provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Please ensure that the target SPN is registered on, and only registered on, the account used by the server. This error can also happen when the target service is using a different password for the target service account than what the Kerberos Key Distribution Center (KDC) has for the target service account. Please ensure that the service on the server and the KDC are both updated to use the current password. If the server name is not fully qualified, and the target domain (CORE.myco.COM) is different from the client domain (CORP.myco.COM), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. Last 5 Application Error Msgs: 10-25-2016 8:59:18 AM 4 An unexpected error has occured in "QuickBooks: Premier Professional Services Edition 2015": V25.0D R6 (M=1066, L=335, C=249, V=0 (0)) 10-24-2016 2:28:04 PM 4 An unexpected error has occured in "QuickBooks: Premier Professional Services Edition 2015": DMError Information:-6120Additional Info:The maximum number of accts allowed to access the company file has already been reached. 10-24-2016 1:28:05 PM 4 An unexpected error has occured in "QuickBooks: Premier Professional Services Edition 2015": DMError Information:-6120Additional Info:The maximum number of accts allowed to access the company file has already been reached. 10-24-2016 1:17:57 PM 4 An unexpected error has occured in "QuickBooks: Premier Professional Services Edition 2015": V25.0D R6 (M=1066, L=335, C=249, V=0 (0)) 10-24-2016 1:17:13 PM 4 An unexpected error has occured in "QuickBooks: Premier Professional Services Edition 2015": V25.0D R6 (M=1066, L=335, C=249, V=0 (0)) Scheduled Tasks: Adobe Flash Player Updater ShadowCopyVolume{ee50fa41-6158-11e5-8160-00155d01e081} VIPRE Roaming Agent Upgrade Task Remote Listening Ports:

PROPRIETARY & CONFIDENTIAL PAGE 217 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name HTTP (80/TCP) HTTPS (443/TCP) RDP (3389/TCP) Disk Capacity: C: 126.9 GB, 62.94 GB free, 50.4% used F: 127 GB, 102.87 GB free, 19% used Service Tag: 4083-2766-0581-8944-5947-8736-07 CPU Count: 1 CPU Core Count: 4 Windows Key: TH4CG-JDJX7-VJ2AF-DY4X9-HCFC6 Other License Keys: Internet Explorer 55041-006-2483512-86608 (ends with HCXPK) Office Professional Plus 2010 82603-018-0000106-48008 (ends with HCXPK) PowerShell 89383-100-0001260-04379 Windows 7 Enterprise 55041-006-2445512-86648 (ends with HCXK) Make and Model: Microsoft Corporation/Virtual Machine Memory Banks: M0 : Unknown-Unknown-2048 Mb-unknown MHz 32 CPUs: Intel(R) Xeon(R) CPU L5639 @ 2.13GHz : CPU0-4 NICs: : -RasSstp-[00000000] WAN Miniport (SSTP) : -RasAgileVpn-[00000001] WAN Miniport (IKEv2) : -Rasl2tp-[00000002] WAN Miniport (L2TP) : -PptpMiniport-[00000003] WAN Miniport (PPTP) : -RasPppoe-[00000004] WAN Miniport (PPPOE) : -NdisWan-[00000005] WAN Miniport (IPv6) : -NdisWan-[00000006] WAN Miniport (redi Monitor) : -dc21x4VM-[00000007] Intel 21140-Based PCI Fast Ethernet Adapter (Emulated) : -tunnel-[00000008] Microsoft ISATAP Adapter : -NdisWan-[00000009] WAN Miniport (IP) 00:15:5D:01:E0:81 : 192.168.6.142;fe80::c96c:9b21:9265:d258-netvsc-[00000010] Microsoft Hyper-V redi Adapter 20:41:53:59:4E:FF : -AsyncMac-[00000011] RAS Async Adapter : -tunnel-[00000012] Microsoft ISATAP Adapter

PROPRIETARY & CONFIDENTIAL PAGE 218 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name DEP: On for All programs and services except those I select OS Manufacturer: Microsoft Corporation OS Version: 6.1.7601 Service Pack 1 (Build 7601) OS Caption: Microsoft Windows Server 2008 R2 Enterprise OS Architecture: 64-bit OS Virtual Memory: 11040 MB OS System Directory: C:\Windows\system32 OS Windows Directory: C:\Windows OS Install Date: 9/22/2015 2:28:21 PM PAE Enabled: True Active Anti-virus: VIPRE Active Anti-spyware: VIPRE Active Firewall: Windows Firewall REMOTE Windows 2000 Server REX Windows 8.1 Intel(R) 8192 Last 5 System Error Msgs: Enterprise Core(TM) i7- MB 10-25-2016 6:46:38 AM 10010 The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did 4770K CPU @ not register with DCOM within the required timeout. 3.50GHz 10-25-2016 6:46:08 AM 10010 The server {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} did not register with DCOM within the required timeout. 10-24-2016 3:05:51 AM 10010 The server {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} did not register with DCOM within the required timeout. 10-24-2016 3:05:21 AM 10010 The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did not register with DCOM within the required timeout. 10-23-2016 5:33:19 AM 10010 The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did not register with DCOM within the required timeout. Last 5 Application Error Msgs: 10-25-2016 6:07:03 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code.

PROPRIETARY & CONFIDENTIAL PAGE 219 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 10-25-2016 6:07:02 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-25-2016 6:54:13 AM 513 Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol. System Error: Access is denied. . 10-25-2016 6:45:39 AM 2147483905 The volume Data (D:) was not optimized because an error was encountered: The parameter is incorrect. (0x80070057) 10-25-2016 6:45:38 AM 2147483905 The volume System Reserved was not optimized because an error was encountered: The parameter is incorrect. (0x80070057) Remote Listening Ports: HTTP (80/TCP) RDP (3389/TCP) Disk Capacity: C: 223.23 GB, 44.81 GB free, 79.93% used D: 0.39 GB, 0.29 GB free, 25.64% used E: 232.88 GB, 26.22 GB free, 88.74% used Service Tag: To Be Filled By O.E.M. CPU Count: 1 CPU Core Count: 4 Windows Key: BBBBB-BBBBB-BBBBB-BBBBB-BBBBB Make and Model: MSI/MS-7850 Memory Banks: ChannelA-DIMM1 : DIMM-Synchronous-4096 Mb-1333 MHz ChannelB-DIMM1 : DIMM-Synchronous-4096 Mb-1333 MHz CPUs: Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz : CPU0-4 System Slots: System Slot0 : J6B2-In Use-OK System Slot1 : J6B1-In Use-OK System Slot2 : J6D1-In Use-OK System Slot3 : J7B1-In Use-OK System Slot4 : J8B4-In Use-OK System Slot5 : J8D1-In Use-OK System Slot6 : J8B3-In Use-OK

PROPRIETARY & CONFIDENTIAL PAGE 220 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name NICs: 00:1B:2F:BF:0A:F8 : -RTL8168-[00000000] Realtek PCI GBE Family Controller : -kdnic-[00000001] Microsoft Kernel Debug redi Adapter DC:85:DE:4A:55:28 : -netr28ux-[00000002] 802.11bgn 1T1R Wireless Adapter : -BthPan-[00000004] Bluetooth Device (Personal Area redi) : -VMSMP-[00000005] Hyper-V Virtual Ethernet Adapter : -VMSMP-[00000006] Hyper-V Virtual Switch Extension Adapter 00:1B:2F:BF:0A:F8 : 192.168.6.112;fe80::c9c6:d510:8c2b:45fc-VMSMP-[00000007] Hyper-V Virtual Ethernet Adapter : -VMSMP-[00000008] Hyper-V Virtual Switch Extension Adapter DC:85:DE:4A:55:2A : -vwifimp-[00000009] Microsoft Wi-Fi Direct Virtual Adapter 00:15:5D:06:70:84 : 169.254.220.232;fe80::4445:8042:6d8f:dce8-VMSMP-[00000010] Hyper- V Virtual Ethernet Adapter DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 6.3.9600 unknown (Build 9600) OS Caption: Microsoft Windows 8.1 Enterprise OS Architecture: 64-bit OS Virtual Memory: 10432 MB OS System Directory: C:\WINDOWS\system32 OS Windows Directory: C:\WINDOWS OS Install Date: 11/17/2015 10:42:10 AM Active Anti-virus: ThreatTrack Security VIPRE Business Agent Active Anti-spyware: ThreatTrack Security VIPRE Business Agent Active Firewall: N/A ronald-LAPTOP Windows 10 Pro ROWBOT Windows 10 Intel(R) 12288 Last 5 System Error Msgs: Enterprise Core(TM) i7- MB 10-25-2016 3:51:46 PM 10016 The application-specific permission settings do not grant Local 4790 CPU @ Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- 3.60GHz A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running

PROPRIETARY & CONFIDENTIAL PAGE 221 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 2:05:35 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-24-2016 3:46:51 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-24-2016 11:41:22 AM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46- 4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-24-2016 10:31:43 AM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46- 4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Last 5 Application Error Msgs: 10-25-2016 6:07:09 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-25-2016 6:07:08 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-25-2016 3:03:25 PM 1002 The program MySQLWorkbench.exe version 6.3.7.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 88a0 Start Time: 01d22e213cea3e9c Termination Time: 16 Application Path: C:\Program Files\MySQL\MySQL Workbench 6.3 CE\MySQLWorkbench.exe Report Id: b1769fc1-9ae5- 11e6-be5b-64006a509980 Faulting package full name: Faulting package-relative application ID: 10-25-2016 7:12:19 AM 100 DNS Message from 192.168.6.62:54448 to 192.168.6.161:5353 length 0 too short

PROPRIETARY & CONFIDENTIAL PAGE 222 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 10-25-2016 7:12:18 AM 100 DNS Message from 192.168.6.62:54429 to 192.168.6.161:5353 length 0 too short Scheduled Tasks: GoogleUpdateTaskMachineCore GoogleUpdateTaskMachineUA OneDrive Standalone Update Task StartBatAtStartUp acct_Feed_Synchronization-{12281465-64F9-4317-88D2-A01793BE4D52} Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 465.21 GB, 250.62 GB free, 46.13% used J: 127.46 GB, 3.47 GB free, 97.28% used K: 803.53 GB, 769.2 GB free, 4.27% used Service Tag: 49ZCG52 CPU Count: 1 CPU Core Count: 4 Windows Key: TH4CG-JDJX7-VJ2AF-DY4X9-HCFC6 Other License Keys: Internet Explorer 55041-006-2483512-86608 (ends with HCXPK) Office Professional Plus 2010 82603-018-0000106-48008 (ends with HCXPK) PowerShell 89383-100-0001260-04379 Windows 7 Enterprise 55041-006-2445512-86648 (ends with HCXK) Make and Model: Dell Inc./XPS 8700 Memory Banks: DIMM3 : DIMM-Synchronous-2048 Mb-1600 MHz DIMM1 : DIMM-Synchronous-4096 Mb-1600 MHz DIMM4 : DIMM-Synchronous-2048 Mb-1600 MHz DIMM2 : DIMM-Synchronous-4096 Mb-1600 MHz CPUs: Intel(R) Core(TM) i7-4790 CPU @ 3.60GHz : CPU0-4 System Slots: System Slot0 : PCIE1-In Use-OK System Slot1 : PCIE2-Available-OK System Slot2 : PCIE3-Available-OK

PROPRIETARY & CONFIDENTIAL PAGE 223 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name System Slot3 : PCIE4-Available-OK NICs: AC:D1:B8:D9:6E:B5 : -BCM43XX-[00000000] Broadcom 802.11n redi Adapter : -kdnic-[00000001] Microsoft Kernel Debug redi Adapter AE:D1:B8:D9:6E:B5 : -vwifimp-[00000002] Microsoft Wi-Fi Direct Virtual Adapter 64:00:6A:50:99:80 : 192.168.6.161;fe80::454:2408:32d3:2968-rt640x64-[00000003] Realtek PCIe GBE Family Controller : -tunnel-[00000004] Microsoft ISATAP Adapter : -RasSstp-[00000007] WAN Miniport (SSTP) : -RasAgileVpn-[00000008] WAN Miniport (IKEv2) : -Rasl2tp-[00000009] WAN Miniport (L2TP) : -PptpMiniport-[00000010] WAN Miniport (PPTP) : -RasPppoe-[00000011] WAN Miniport (PPPOE) D4:EF:20:52:41:53 : -NdisWan-[00000012] WAN Miniport (IP) D4:B4:20:52:41:53 : -NdisWan-[00000013] WAN Miniport (IPv6) D2:C4:20:52:41:53 : -NdisWan-[00000014] WAN Miniport (redi Monitor) DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 192.168.14393 unknown (Build 14393) OS Caption: Microsoft Windows 10 Enterprise OS Architecture: 64-bit OS Virtual Memory: 14960 MB OS System Directory: C:\Windows\system32 OS Windows Directory: C:\Windows OS Install Date: 8/16/2016 5:05:26 PM PAE Enabled: True Active Anti-virus: Windows Defender Active Anti-spyware: Windows Defender Active Firewall: Windows Firewall

PROPRIETARY & CONFIDENTIAL PAGE 224 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name SARLACC Windows 10 Intel(R) 6144 Last 5 System Error Msgs: Enterprise Xeon(R) CPU MB 10-23-2016 12:18:40 PM 3221232504 The tried to take a corrective L5639 @ action (Restart the service) after the unexpected termination of the VIPRE Edge Protection 2.13GHz service, but this action failed with the following error: An instance of the service is already running. 10-23-2016 12:18:40 PM 3221232503 The VIPRE Edge Protection service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 200 milliseconds: Restart the service. 10-23-2016 12:17:29 PM 3221232506 The VIPRE Business Agent service terminated unexpectedly. It has done this 1 time(s). 10-22-2016 7:15:22 AM 36874 An TLS 1.2 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The TLS connection request has failed. 10-22-2016 7:15:22 AM 36874 An TLS 1.2 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The TLS connection request has failed. Last 5 Application Error Msgs: 10-25-2016 2:42:51 AM 3221226480 The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. 10-24-2016 2:29:52 AM 3221226480 The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. 10-23-2016 12:18:35 PM 1000 Faulting application name: VipreEdgeProtection.exe, version: 2.3.4.7, time stamp: 0x562108ae Faulting module name: combase.dll, version: 192.168.10586.589, time stamp: 0x57cf9470 Exception code: 0xc0000005 Fault offset: 0x000c3fdc Faulting process id: 0x290 Faulting application start time: 0x01d22690419b2575 Faulting application path: C:\Program Files\VIPRE Business Agent\VipreEdgeProtection.exe Faulting module path: C:\WINDOWS\system32\combase.dll Report Id: 4c23cb54-19d8-4fa0- a35a-e102a38bc995 Faulting package full name: Faulting package-relative application ID: 10-23-2016 12:16:31 PM 1000 Faulting application name: SBAMSvc.exe, version: 9.4.0.74, time stamp: 0x56ec7b8c Faulting module name: BDUpdateServiceCom.DLL, version: 3.0.0.70, time stamp: 0x54b68add Exception code: 0xc0000005 Fault offset: 0x0004eac2 Faulting process id: 0xe30 Faulting application start time: 0x01d2269012a66943 Faulting application path: C:\Program Files\VIPRE Business Agent\SBAMSvc.exe Faulting module path: C:\Program Files\VIPRE Business Agent\BDUpdateServiceCom.DLL Report Id: 53229e2f-13e9-475c-a463-7343f120fe3a Faulting package full name: Faulting package- relative application ID: 10-23-2016 2:24:47 AM 3221226480 The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.

PROPRIETARY & CONFIDENTIAL PAGE 225 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name Scheduled Tasks: CreateExplorerShellUnelevatedTask VIPRE Roaming Agent Upgrade Task Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 255.51 GB, 201.8 GB free, 21.02% used Service Tag: 3798-8162-8209-6968-7930-1461-05 CPU Count: 1 CPU Core Count: 1 Windows Key: BBBBB-JDJX7-VJ2AF-DDDD9-HCFC6 Other License Keys: Internet Explorer 55041-006-2483512-86608 (ends with HCXPK) Office Professional Plus 2010 82603-018-0000106-48008 (ends with HCXPK) PowerShell 89383-100-0001260-04379 Windows 7 Enterprise 55041-006-2445512-86648 (ends with HCXK) Make and Model: Microsoft Corporation/Virtual Machine Memory Banks: M0 : Unknown-Unknown-3968 Mb-unknown MHz M1 : Unknown-Unknown-2176 Mb-unknown MHz 32 CPUs: Intel(R) Xeon(R) CPU L5639 @ 2.13GHz : CPU0-1 NICs: : -kdnic-[00000000] Microsoft Kernel Debug redi Adapter 00:15:5D:07:37:36 : 192.168.6.132;fe80::8193:586d:e05d:7355-netvsc-[00000001] Microsoft Hyper-V redi Adapter : -tunnel-[00000002] Microsoft ISATAP Adapter DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 192.168.10586 unknown (Build 10586) OS Caption: Microsoft Windows 10 Enterprise

PROPRIETARY & CONFIDENTIAL PAGE 226 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name OS Architecture: 32-bit OS Virtual Memory: 4672 MB OS System Directory: C:\WINDOWS\system32 OS Windows Directory: C:\WINDOWS OS Install Date: 12/23/2015 5:10:11 PM PAE Enabled: True Active Anti-virus: ThreatTrack Security VIPRE Business Agent Active Anti-spyware: ThreatTrack Security VIPRE Business Agent Active Firewall: Windows Firewall sourcesvr Windows Server Intel(R) 8192 Last 5 System Error Msgs: 2012 Standard Xeon(R) CPU MB 10-22-2016 4:43:09 AM 36888 A fatal alert was generated and sent to the remote endpoint. L5639 @ This may result in termination of the connection. The TLS protocol defined fatal error code is 2.13GHz 40. The Windows SChannel error state is 1205. 10-22-2016 4:43:09 AM 36874 An TLS 1.2 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed. 10-22-2016 4:43:09 AM 36888 A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 1205. 10-22-2016 4:43:09 AM 36874 An TLS 1.2 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed. 10-22-2016 4:43:09 AM 36888 A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 1205. Last 5 Application Error Msgs: 10-25-2016 9:30:33 PM 6398 The Execute method of job definition Microsoft.TeamFoundation.SharePoint.docksyss.TimerJob.docksysUpdateJob (ID d32f3bbf- 8599-4450-bc20-14c1b3d8ab09) threw an exception. More information is included below. An exception occurred while scanning docksys sites. Please see the SharePoint log for detailed exceptions. 10-25-2016 9:00:33 PM 6398 The Execute method of job definition Microsoft.TeamFoundation.SharePoint.docksyss.TimerJob.docksysUpdateJob (ID d32f3bbf- 8599-4450-bc20-14c1b3d8ab09) threw an exception. More information is included below. An

PROPRIETARY & CONFIDENTIAL PAGE 227 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name exception occurred while scanning docksys sites. Please see the SharePoint log for detailed exceptions. 10-25-2016 8:57:13 PM 6398 The Execute method of job definition Microsoft.SharePoint.Administration.SPAppStateQueryJobDefinition (ID 9bb95232-c304-47e2- b475-9a4de7e365b6) threw an exception. More information is included below. An update conflict has occurred, and you must re-try this action. The object SPAppStateTimerJobState Name=SPAppStateTimerJobState6ef990ea-b4ba-47f4-9f6e-a53e206d70bb was updated by myco\administrator, in the OWSTIMER (6836) process, on machine sourcesvr. View the tracing log for more information about the conflict. 10-25-2016 8:30:33 PM 6398 The Execute method of job definition Microsoft.TeamFoundation.SharePoint.docksyss.TimerJob.docksysUpdateJob (ID d32f3bbf- 8599-4450-bc20-14c1b3d8ab09) threw an exception. More information is included below. An exception occurred while scanning docksys sites. Please see the SharePoint log for detailed exceptions. 10-25-2016 8:00:33 PM 6398 The Execute method of job definition Microsoft.TeamFoundation.SharePoint.docksyss.TimerJob.docksysUpdateJob (ID d32f3bbf- 8599-4450-bc20-14c1b3d8ab09) threw an exception. More information is included below. An exception occurred while scanning docksys sites. Please see the SharePoint log for detailed exceptions. Remote Listening Ports: HTTP (80/TCP) SQLServer (1433/TCP) RDP (3389/TCP) HTTP (8080/TCP) Disk Capacity: C: 511.66 GB, 292.81 GB free, 42.77% used Service Tag: 3501-4818-3030-9352-5763-1092-21 CPU Count: 1 CPU Core Count: 6 Windows Key: BBBBB-BBBBB-BBBBB-BBBBB-BBBBB Make and Model: Microsoft Corporation/Virtual Machine Memory Banks: M0 : Unknown-Unknown-3968 Mb-unknown MHz M1 : Unknown-Unknown-4224 Mb-unknown MHz 32 CPUs:

PROPRIETARY & CONFIDENTIAL PAGE 228 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name Intel(R) Xeon(R) CPU L5639 @ 2.13GHz : CPU0-6 NICs: : -Rasl2tp-[00000000] WAN Miniport (L2TP) : -RasSstp-[00000001] WAN Miniport (SSTP) : -RasAgileVpn-[00000002] WAN Miniport (IKEv2) : -PptpMiniport-[00000003] WAN Miniport (PPTP) : -RasPppoe-[00000004] WAN Miniport (PPPOE) : -NdisWan-[00000005] WAN Miniport (IP) : -NdisWan-[00000006] WAN Miniport (IPv6) : -NdisWan-[00000007] WAN Miniport (redi Monitor) : -kdnic-[00000008] Microsoft Kernel Debug redi Adapter : -AsyncMac-[00000009] RAS Async Adapter : -dc21x4VM-[00000010] Intel 21140-Based PCI Fast Ethernet Adapter (Emulated) : -netvsc-[00000011] Microsoft Hyper-V redi Adapter : -tunnel-[00000012] Microsoft ISATAP Adapter : -tunnel-[00000013] Microsoft Teredo Tunneling Adapter : -tunnel-[00000014] Microsoft ISATAP Adapter 00:15:5D:01:E0:63 : 192.168.1.16;fe80::992a:b564:1825:ac38-netvsc-[00000015] Microsoft Hyper-V redi Adapter DEP: On for All programs and services except those I select OS Manufacturer: Microsoft Corporation OS Version: 6.2.9200 unknown (Build 9200) OS Caption: Microsoft Windows Server 2012 Standard OS Architecture: 64-bit OS Virtual Memory: 12800 MB OS System Directory: C:\Windows\system32 OS Windows Directory: C:\Windows OS Install Date: 11/21/2013 10:29:42 AM sourcesvrBUILD Windows Server Intel(R) 4096 Last 5 System Error Msgs: 2012 R2 Standard Xeon(R) CPU MB

PROPRIETARY & CONFIDENTIAL PAGE 229 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name L5639 @ 10-22-2016 6:26:57 AM 36888 A fatal alert was generated and sent to the remote endpoint. 2.13GHz This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 1205. 10-22-2016 6:26:57 AM 36874 An TLS 1.2 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed. 10-22-2016 6:26:57 AM 36888 A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 1205. 10-22-2016 6:26:57 AM 36874 An TLS 1.2 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed. 10-22-2016 6:26:57 AM 36888 A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 1205. Last 5 Application Error Msgs: 10-25-2016 9:05:39 AM 3221226480 The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. 10-25-2016 12:07:58 AM 3221233670 License Activation (slui.exe) failed with the following error code: hr=0x8007232B dbre-line arguments: RuleId=eeba1977-569e-4571-b639- 7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e- d6ec3f16059f;SkuId=b3ca044e-a358-4d68-9883- aaa2941aca99;NotificationInterval=1440;Trigger=TimerEvent 10-24-2016 9:05:22 AM 3221226480 The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. 10-24-2016 12:07:57 AM 3221233670 License Activation (slui.exe) failed with the following error code: hr=0x8007232B dbre-line arguments: RuleId=eeba1977-569e-4571-b639- 7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e- d6ec3f16059f;SkuId=b3ca044e-a358-4d68-9883- aaa2941aca99;NotificationInterval=1440;Trigger=TimerEvent 10-23-2016 9:03:48 AM 3221226480 The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. Scheduled Tasks: Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-1182 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-29609 Remote Listening Ports: RDP (3389/TCP) Disk Capacity:

PROPRIETARY & CONFIDENTIAL PAGE 230 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name C: 122.66 GB, 80.78 GB free, 34.14% used X: 4 GB, 3.96 GB free, 1% used Service Tag: 7355-1702-9012-7399-3206-8771-93 CPU Count: 1 CPU Core Count: 4 Windows Key: TH4CG-JDJX7-VJ2AF-DY4X9-HCFC6 Other License Keys: Internet Explorer 55041-006-2483512-86608 (ends with HCXPK) Office Professional Plus 2010 82603-018-0000106-48008 (ends with HCXPK) PowerShell 89383-100-0001260-04379 Windows 7 Enterprise 55041-006-2445512-86648 (ends with HCXK) Make and Model: Microsoft Corporation/Virtual Machine Memory Banks: M0 : Unknown-Unknown-3968 Mb-unknown MHz M1 : Unknown-Unknown-128 Mb-unknown MHz 32 CPUs: Intel(R) Xeon(R) CPU L5639 @ 2.13GHz : CPU0-4 NICs: : -Rasl2tp-[00000000] WAN Miniport (L2TP) : -RasSstp-[00000001] WAN Miniport (SSTP) : -RasAgileVpn-[00000002] WAN Miniport (IKEv2) : -PptpMiniport-[00000003] WAN Miniport (PPTP) : -RasPppoe-[00000004] WAN Miniport (PPPOE) : -NdisWan-[00000005] WAN Miniport (IP) : -NdisWan-[00000006] WAN Miniport (IPv6) : -NdisWan-[00000007] WAN Miniport (redi Monitor) : -kdnic-[00000008] Microsoft Kernel Debug redi Adapter : -tunnel-[00000012] Microsoft ISATAP Adapter 00:15:5D:07:37:25 : 192.168.6.67;fe80::55d4:f030:5179:3678-netvsc-[00000013] Microsoft Hyper-V redi Adapter DEP: On for All programs and services except those I select OS Manufacturer: Microsoft Corporation OS Version:

PROPRIETARY & CONFIDENTIAL PAGE 231 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 6.3.9600 unknown (Build 9600) OS Caption: Microsoft Windows Server 2012 R2 Standard OS Architecture: 64-bit OS Virtual Memory: 11008 MB OS System Directory: C:\Windows\system32 OS Windows Directory: C:\Windows OS Install Date: 11/19/2014 7:20:16 AM PAE Enabled: True Active Anti-virus: N/A Active Anti-spyware: N/A Active Firewall: Windows Firewall STORAGE01 Windows Server Intel(R) 2048 Last 5 System Error Msgs: 2008 R2 Enterprise Xeon(R) CPU MB 10-25-2016 2:26:56 PM 36888 The following fatal alert was generated: 40. The itable error L5639 @ state is 1205. 2.13GHz 10-25-2016 2:26:56 PM 36874 An TLS 1.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed. 10-25-2016 2:26:56 PM 36888 The following fatal alert was generated: 40. The itable error state is 1205. 10-25-2016 2:26:56 PM 36874 An SSL 3.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed. 10-25-2016 12:22:02 PM 36888 The following fatal alert was generated: 40. The itable error state is 1205. Last 5 Application Error Msgs: 10-25-2016 9:50:50 PM 3328585732 The groveler on partition D:\ has failed due to a database error. See ESENT event log entries, if any, for details. 10-25-2016 9:34:50 PM 3328585732 The groveler on partition D:\ has failed due to a database error. See ESENT event log entries, if any, for details. 10-25-2016 9:26:50 PM 3328585732 The groveler on partition D:\ has failed due to a database error. See ESENT event log entries, if any, for details. 10-25-2016 9:22:40 PM 3328585732 The groveler on partition D:\ has failed due to a database error. See ESENT event log entries, if any, for details.

PROPRIETARY & CONFIDENTIAL PAGE 232 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 10-25-2016 9:20:30 PM 3328585732 The groveler on partition D:\ has failed due to a database error. See ESENT event log entries, if any, for details. Remote Listening Ports: HTTP (80/TCP) HTTPS (443/TCP) RDP (3389/TCP) Disk Capacity: C: 123.92 GB, 75.78 GB free, 38.85% used D: 1738.99 GB, 1533.32 GB free, 11.83% used Service Tag: 8177-0837-7685-3284-9846-8452-69 CPU Count: 1 CPU Core Count: 6 Windows Key: BBBBB-BBBBB-BBBBB-BBBBB-BBBBB Make and Model: Microsoft Corporation/Virtual Machine Memory Banks: M0 : Unknown-Unknown-2048 Mb-unknown MHz 32 CPUs: Intel(R) Xeon(R) CPU L5639 @ 2.13GHz : CPU0-6 NICs: : -RasSstp-[00000000] WAN Miniport (SSTP) : -RasAgileVpn-[00000001] WAN Miniport (IKEv2) : -Rasl2tp-[00000002] WAN Miniport (L2TP) : -PptpMiniport-[00000003] WAN Miniport (PPTP) : -RasPppoe-[00000004] WAN Miniport (PPPOE) : -NdisWan-[00000005] WAN Miniport (IPv6) : -NdisWan-[00000006] WAN Miniport (redi Monitor) 00:15:5D:01:E0:AC : 10.200.2.59;fe80::94d9:3e70:b7f7:3885-netvsc-[00000007] Microsoft Hyper-V redi Adapter : -tunnel-[00000008] Microsoft ISATAP Adapter : -NdisWan-[00000009] WAN Miniport (IP) 20:41:53:59:4E:FF : -AsyncMac-[00000011] RAS Async Adapter : -netvsc-[00000012] Microsoft Hyper-V redi Adapter : -tunnel-[00000013] Microsoft Teredo Tunneling Adapter : -tunnel-[00000014] Microsoft ISATAP Adapter : -tunnel-[00000017] Microsoft ISATAP Adapter

PROPRIETARY & CONFIDENTIAL PAGE 233 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name : -E1G60-[00000018] Intel(R) PRO/1000 MT Desktop Adapter 02:19:B9:E4:BA:92 : -Netft-[00000019] Microsoft Failover Cluster Virtual Adapter : -tunnel-[00000020] Microsoft ISATAP Adapter : -netvsc-[00000021] Microsoft Hyper-V redi Adapter 00:15:5D:01:E0:8A : 192.168.1.69;fe80::60bf:b010:a074:43e7-netvsc-[00000022] Microsoft Hyper-V redi Adapter DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 6.1.7601 Service Pack 1 (Build 7601) OS Caption: Microsoft Windows Server 2008 R2 Enterprise OS Architecture: 64-bit OS Virtual Memory: 7408 MB OS System Directory: C:\Windows\system32 OS Windows Directory: C:\Windows OS Install Date: 1/28/2011 4:42:28 PM Active Anti-virus: VIPRE Active Anti-spyware: VIPRE Active Firewall: N/A STORAGE12 Windows Server Intel(R) Last 5 System Error Msgs: 2012 R2 Datacenter Xeon(R) CPU 10-25-2016 6:11:59 PM 3221618696 The flush and hold writes operation on volume D: timed L5639 @ out while waiting for a release writes dbre. 2.13GHz 10-25-2016 6:11:59 PM 3221618696 The flush and hold writes operation on volume C: timed out while waiting for a release writes dbre. 10-25-2016 6:11:49 PM 3758425347 Flush-and-hold state was released while snapping due to timeout on \Device\HarddiskVolume4, cancelling snapping 10-25-2016 3:02:26 PM 3758425347 Flush-and-hold state was released while snapping due to timeout on \Device\HarddiskVolume6, cancelling snapping 10-25-2016 3:02:24 PM 3221618696 The flush and hold writes operation on volume C: timed out while waiting for a release writes dbre. Last 5 Application Error Msgs:

PROPRIETARY & CONFIDENTIAL PAGE 234 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 10-25-2016 6:11:59 PM 12298 Volume Shadow Copy Service error: The I/O writes cannot be held during the shadow copy creation period on volume \\?\Volume{8aea720b-bab6-47b4- 8b4c-2651cb5b0a04}\. The volume index in the shadow copy set is 0. Error details: Open[0x00000000, The operation completed successfully. ], Flush[0x00000000, The operation completed successfully. ], Release[0x80042314, The shadow copy provider timed out while holding writes to the volume being shadow copied. This is probably due to excessive activity on the volume by an application or a system service. Try again later when activity on the volume is reduced. ], OnRun[0x00000000, The operation completed successfully. ]. Operation: Executing Asynchronous Operation Context: Current State: DoSnapshotSet 10-25-2016 6:11:59 PM 12293 Volume Shadow Copy Service error: Error calling a routine on a Shadow Copy Provider {00000000-0000-0000-0000-000000000000}. Routine details CommitSnapshots [hr = 0x80070079, The semaphore timeout period has expired. ]. Operation: Executing Asynchronous Operation Context: Current State: DoSnapshotSet 10-25-2016 3:02:26 PM 12298 Volume Shadow Copy Service error: The I/O writes cannot be held during the shadow copy creation period on volume \\?\Volume{8aea720b-bab6-47b4- 8b4c-2651cb5b0a04}\. The volume index in the shadow copy set is 0. Error details: Open[0x00000000, The operation completed successfully. ], Flush[0x00000000, The operation completed successfully. ], Release[0x80042314, The shadow copy provider timed out while holding writes to the volume being shadow copied. This is probably due to excessive activity on the volume by an application or a system service. Try again later when activity on the volume is reduced. ], OnRun[0x00000000, The operation completed successfully. ]. Operation: Executing Asynchronous Operation Context: Current State: DoSnapshotSet 10-25-2016 3:02:26 PM 12293 Volume Shadow Copy Service error: Error calling a routine on a Shadow Copy Provider {00000000-0000-0000-0000-000000000000}. Routine details CommitSnapshots [hr = 0x80070079, The semaphore timeout period has expired. ]. Operation: Executing Asynchronous Operation Context: Current State: DoSnapshotSet 10-25-2016 12:00:30 PM 7001 VssAdmin: Unable to create a shadow copy: Either the specified volume was not found or it is not a local volume. Command-line: 'C:\Windows\system32\vssadmin.exe Create Shadow /AutoRetry=15 /For=\\?\Volume{7308a34e-3be3-11e6-80bf-00155d7a5908}\'. Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 126.48 GB, 113.94 GB free, 9.91% used D: 1023.87 GB, 519.99 GB free, 49.21% used Service Tag: 6267-6596-5842-0280-5205-4454-98 CPU Count: 1 CPU Core Count: 4

PROPRIETARY & CONFIDENTIAL PAGE 235 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name Windows Key: BBBBB-J73D3-C7CAC-4KBDD-GFDD6 Make and Model: Microsoft Corporation/Virtual Machine Memory Banks: 1 CPUs: Intel(R) Xeon(R) CPU L5639 @ 2.13GHz : CPU0-4 NICs: : -Rasl2tp-[00000000] WAN Miniport (L2TP) : -RasSstp-[00000001] WAN Miniport (SSTP) : -RasAgileVpn-[00000002] WAN Miniport (IKEv2) : -PptpMiniport-[00000003] WAN Miniport (PPTP) : -RasPppoe-[00000004] WAN Miniport (PPPOE) : -NdisWan-[00000005] WAN Miniport (IP) : -NdisWan-[00000006] WAN Miniport (IPv6) : -NdisWan-[00000007] WAN Miniport (redi Monitor) : -kdnic-[00000008] Microsoft Kernel Debug redi Adapter 00:15:5D:5B:2C:05 : 192.168.1.65;fe80::c893:506a:d760:22ba-netvsc-[00000010] Microsoft Hyper-V redi Adapter : -tunnel-[00000012] Microsoft ISATAP Adapter 00:15:5D:5B:2C:07 : 192.168.1.66;fe80::35f5:7dbc:5b6f:33c2-netvsc-[00000013] Microsoft Hyper-V redi Adapter 00:15:5D:5B:2C:06 : 192.168.1.67;fe80::1a:d9e9:8808:cd2e-netvsc-[00000014] Microsoft Hyper-V redi Adapter : -tunnel-[00000015] Microsoft ISATAP Adapter : -tunnel-[00000016] Microsoft ISATAP Adapter DEP: On for All programs and services except those I select OS Manufacturer: Microsoft Corporation OS Version: 6.3.9600 unknown (Build 9600) OS Caption: Microsoft Windows Server 2012 R2 Datacenter OS Architecture: 64-bit OS Virtual Memory: 3392 MB OS System Directory: C:\Windows\system32

PROPRIETARY & CONFIDENTIAL PAGE 236 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name OS Windows Directory: C:\Windows OS Install Date: 6/25/2016 2:46:16 AM Active Anti-virus: N/A Active Anti-spyware: N/A Active Firewall: Windows Firewall tarsis Windows 10 Pro Intel(R) 16384 Last 5 System Error Msgs: Core(TM) i7- MB 10-25-2016 10:02:12 PM 10028 DCOM was unable to communicate with the computer 6700K CPU @ 192.168.6.254 using any of the configured protocols; requested by PID 5780 4.00GHz (C:\accts\wpayne\Desktop\Sample Report Data Collection\rediDetectivePushDeployTool - Copy\rediDetectivePushDeployTool.exe). 10-25-2016 10:02:12 PM 10028 DCOM was unable to communicate with the computer 192.168.6.252 using any of the configured protocols; requested by PID 5780 (C:\accts\wpayne\Desktop\Sample Report Data Collection\rediDetectivePushDeployTool - Copy\rediDetectivePushDeployTool.exe). 10-25-2016 10:02:12 PM 10028 DCOM was unable to communicate with the computer 192.168.6.253 using any of the configured protocols; requested by PID 5780 (C:\accts\wpayne\Desktop\Sample Report Data Collection\rediDetectivePushDeployTool - Copy\rediDetectivePushDeployTool.exe). 10-25-2016 10:02:04 PM 10028 DCOM was unable to communicate with the computer 192.168.6.251 using any of the configured protocols; requested by PID 5780 (C:\accts\wpayne\Desktop\Sample Report Data Collection\rediDetectivePushDeployTool - Copy\rediDetectivePushDeployTool.exe). 10-25-2016 10:02:00 PM 10028 DCOM was unable to communicate with the computer 192.168.6.250 using any of the configured protocols; requested by PID 5780 (C:\accts\wpayne\Desktop\Sample Report Data Collection\rediDetectivePushDeployTool - Copy\rediDetectivePushDeployTool.exe). Last 5 Application Error Msgs: 10-25-2016 9:50:17 PM 513 Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol. System Error: Access is denied. . 10-25-2016 3:12:13 AM 0 10-25-2016 12:12:22 AM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-24-2016 11:11:15 AM 5973 Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: The app didn't start. See the Microsoft-Windows-TWinUI/Operational log for additional information.

PROPRIETARY & CONFIDENTIAL PAGE 237 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 10-24-2016 11:11:15 AM 5973 Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: The app didn't start in the required time. See the Microsoft-Windows-TWinUI/Operational log for additional information. Scheduled Tasks: G2MUpdateTask-S-1-5-21-356494474-603968661-3470298851-1115 G2MUploadTask-S-1-5-21-356494474-603968661-3470298851-1115 GoogleUpdateTaskMachineCore GoogleUpdateTaskMachineUA Microsoft Office 15 Sync Maintenance for {862c090f-7740-4e27-9595-e1282f0d909d} tarsis.Corp.myco.com OneDrive Standalone Update Task TechSmith Updater acct_Feed_Synchronization-{74E9FB18-669F-46E8-8FF9-A74F317C1754} Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 475.68 GB, 339.91 GB free, 28.54% used Service Tag: PS CPU Count: 1 CPU Core Count: 4 Windows Key: TH4CG-JDJX7-VJ2AF-DY4X9-HCFC6 Other License Keys: Internet Explorer 55041-006-2483512-86608 (ends with HCXPK) Office Professional Plus 2010 82603-018-0000106-48008 (ends with HCXPK) PowerShell 89383-100-0001260-04379 Windows 7 Enterprise 55041-006-2445512-86648 (ends with HCXK) Make and Model: PowerSpec/Gseries Memory Banks: ChannelA-DIMM1 : DIMM-Synchronous-8192 Mb-3200 MHz ChannelB-DIMM1 : DIMM-Synchronous-8192 Mb-3200 MHz CPUs: Intel(R) Core(TM) i7-6700K CPU @ 4.00GHz : CPU0-4 System Slots: System Slot0 : J6B2-In Use-OK

PROPRIETARY & CONFIDENTIAL PAGE 238 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name System Slot1 : J6B1-In Use-OK System Slot2 : J6D1-In Use-OK System Slot3 : J7B1-In Use-OK System Slot4 : J8B4-In Use-OK System Slot5 : J8D1-In Use-OK System Slot6 : J8B3-In Use-OK NICs: : -kdnic-[00000000] Microsoft Kernel Debug redi Adapter D8:CB:8A:C6:C3:22 : 192.168.6.195;fe80::6cc2:c951:fb29:80e3-rt640x64-[00000001] Realtek PCIe GBE Family Controller 30:10:B3:4A:92:BC : -athr-[00000002] Qualcomm Atheros AR5BWB222 Wireless redi Adapter : -RFCOMM-[00000003] Bluetooth Device (RFCOMM Protocol TDI) 30:10:B3:4A:A5:7C : -BthPan-[00000004] Bluetooth Device (Personal Area redi) : -vwifimp-[00000005] Microsoft Wi-Fi Direct Virtual Adapter 12:10:B3:4A:92:BC : -vwifimp-[00000006] Microsoft Wi-Fi Direct Virtual Adapter : -tunnel-[00000007] Microsoft ISATAP Adapter DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 192.168.14393 unknown (Build 14393) OS Caption: Microsoft Windows 10 Pro OS Architecture: 64-bit OS Virtual Memory: 18704 MB OS System Directory: C:\WINDOWS\system32 OS Windows Directory: C:\WINDOWS OS Install Date: 9/25/2016 8:08:00 PM PAE Enabled: True Active Anti-virus: Windows Defender Active Anti-spyware: Windows Defender Active Firewall: Windows Firewall Tneusome-HP Windows 10 Pro

PROPRIETARY & CONFIDENTIAL PAGE 239 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name Tneusome-LT Windows 10 Pro tywin-PC Windows 10 Pro Intel(R) 8192 Last 5 System Error Msgs: Core(TM) i5- MB 10-25-2016 6:03:56 PM 10016 The application-specific permission settings do not grant Local 4440 CPU @ Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- 3.10GHz A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 3:02:43 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 10:39:17 AM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46- 4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-24-2016 7:01:32 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-24-2016 6:12:39 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Last 5 Application Error Msgs: 10-25-2016 2:43:15 AM 0 10-24-2016 2:43:15 AM 0 10-23-2016 2:43:15 AM 0 10-22-2016 2:43:15 AM 0 10-21-2016 2:43:14 AM 0 Remote Listening Ports: RDP (3389/TCP)

PROPRIETARY & CONFIDENTIAL PAGE 240 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name Disk Capacity: C: 930.56 GB, 728.01 GB free, 21.77% used Z: 0.09 GB, 0.07 GB free, 22.22% used Service Tag: 2XNLDZ1 CPU Count: 1 CPU Core Count: 4 Windows Key: BBBBB-J73D3-C7CAC-4KBDD-GFDD6 Make and Model: Dell Inc./Inspiron 3847 Memory Banks: DIMM1 : DIMM-Synchronous-4096 Mb-1600 MHz DIMM2 : DIMM-Synchronous-4096 Mb-1600 MHz CPUs: Intel(R) Core(TM) i5-4440 CPU @ 3.10GHz : CPU0-4 System Slots: System Slot0 : PCIEX16-In Use-OK System Slot1 : PCIEX1-In Use-OK System Slot2 : PCIEX1-In Use-OK System Slot3 : PCIEX1-In Use-OK NICs: : -kdnic-[00000000] Microsoft Kernel Debug redi Adapter 48:5A:B6:85:98:6D : -athr-[00000001] Dell Wireless 1705 802.11b|g|n (2.4GHZ) C8:1F:66:37:46:A3 : 192.168.7.49;fe80::9025:a2b5:3454:bddb-rt640x64-[00000002] Realtek PCIe GBE Family Controller : -vwifimp-[00000003] Microsoft Wi-Fi Direct Virtual Adapter : -RFCOMM-[00000004] Bluetooth Device (RFCOMM Protocol TDI) 48:5A:B6:85:98:6E : -BthPan-[00000005] Bluetooth Device (Personal Area redi) 1A:5A:B6:85:98:6D : -vwifimp-[00000006] Microsoft Wi-Fi Direct Virtual Adapter : -tunnel-[00000007] Microsoft ISATAP Adapter : -RasSstp-[00000008] WAN Miniport (SSTP) : -RasAgileVpn-[00000009] WAN Miniport (IKEv2) : -Rasl2tp-[00000010] WAN Miniport (L2TP) : -PptpMiniport-[00000011] WAN Miniport (PPTP) : -RasPppoe-[00000012] WAN Miniport (PPPOE) 6C:5B:20:52:41:53 : -NdisWan-[00000013] WAN Miniport (IP) 6C:C7:20:52:41:53 : -NdisWan-[00000014] WAN Miniport (IPv6)

PROPRIETARY & CONFIDENTIAL PAGE 241 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 6C:71:20:52:41:53 : -NdisWan-[00000015] WAN Miniport (redi Monitor) DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 192.168.14393 unknown (Build 14393) OS Caption: Microsoft Windows 10 Pro OS Architecture: 64-bit OS Virtual Memory: 16384 MB OS System Directory: C:\WINDOWS\system32 OS Windows Directory: C:\WINDOWS OS Install Date: 9/27/2016 2:41:54 PM Active Anti-virus: ThreatTrack Security VIPRE Business Agent Active Anti-spyware: ThreatTrack Security VIPRE Business Agent Active Firewall: Windows Firewall UTIL12 Windows Server Intel(R) 1024 Last 5 System Error Msgs: 2012 R2 Standard Xeon(R) CPU MB 10-25-2016 11:43:19 AM 36888 A fatal alert was generated and sent to the remote endpoint. L5639 @ This may result in termination of the connection. The TLS protocol defined fatal error code is 2.13GHz 40. The Windows SChannel error state is 1205. 10-25-2016 11:43:19 AM 36874 An TLS 1.1 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed. 10-25-2016 11:43:19 AM 36888 A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 1205. 10-25-2016 11:43:19 AM 36874 An TLS 1.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed. 10-25-2016 11:43:19 AM 36888 A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 1205. Last 5 Application Error Msgs:

PROPRIETARY & CONFIDENTIAL PAGE 242 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 10-22-2016 6:01:06 PM 1 SQLVDI: Loc=TriggerAbort. Desc=invoked. ErrorCode=(0). Process=3456. Thread=4988. Server. Instance=MICROSOFT##WID. VD=Global\{D07ED238- ADF5-4A51-A433-9DD7C4B9F310}4_SQLVDIMemoryName_0. 10-22-2016 6:01:06 PM 1 SQLVDI: Loc=TriggerAbort. Desc=invoked. ErrorCode=(0). Process=3456. Thread=4592. Server. Instance=MICROSOFT##WID. VD=Global\{D07ED238- ADF5-4A51-A433-9DD7C4B9F310}3_SQLVDIMemoryName_0. 10-22-2016 6:01:06 PM 3221228513 BACKUP failed to complete the dbre BACKUP DATABASE master. Check the backup application log for detailed messages. 10-22-2016 6:01:06 PM 3221228513 BACKUP failed to complete the dbre BACKUP DATABASE RDCms. Check the backup application log for detailed messages. 10-22-2016 6:01:06 PM 3221228513 BACKUP failed to complete the dbre BACKUP DATABASE model. Check the backup application log for detailed messages. Remote Listening Ports: HTTP (80/TCP) HTTPS (443/TCP) RDP (3389/TCP) Disk Capacity: C: 126.48 GB, 104.44 GB free, 17.43% used Service Tag: 4540-8574-1891-7758-5785-9003-87 CPU Count: 1 CPU Core Count: 4 Windows Key: BBBBB-J73D3-C7CAC-4KBDD-GFDD6 Make and Model: Microsoft Corporation/Virtual Machine Memory Banks: M00 : Unknown-Unknown-1024 Mb-unknown MHz 1 CPUs: Intel(R) Xeon(R) CPU L5639 @ 2.13GHz : CPU0-4 NICs: : -Rasl2tp-[00000000] WAN Miniport (L2TP) : -RasSstp-[00000001] WAN Miniport (SSTP) : -RasAgileVpn-[00000002] WAN Miniport (IKEv2) : -PptpMiniport-[00000003] WAN Miniport (PPTP) : -RasPppoe-[00000004] WAN Miniport (PPPOE) : -NdisWan-[00000005] WAN Miniport (IP) : -NdisWan-[00000006] WAN Miniport (IPv6)

PROPRIETARY & CONFIDENTIAL PAGE 243 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name : -NdisWan-[00000007] WAN Miniport (redi Monitor) : -kdnic-[00000008] Microsoft Kernel Debug redi Adapter 00:15:5D:7A:59:14 : 192.168.1.15;fe80::fdce:8642:bfa6:b516-netvsc-[00000010] Microsoft Hyper-V redi Adapter : -tunnel-[00000012] Microsoft ISATAP Adapter DEP: On for All programs and services except those I select OS Manufacturer: Microsoft Corporation OS Version: 6.3.9600 unknown (Build 9600) OS Caption: Microsoft Windows Server 2012 R2 Standard OS Architecture: 64-bit OS Virtual Memory: 8656 MB OS System Directory: C:\Windows\system32 OS Windows Directory: C:\Windows OS Install Date: 3/4/2014 9:23:32 PM Active Anti-virus: BitDefender Active Anti-spyware: BitDefender Active Firewall: Windows Firewall VPNGW Windows Server Intel(R) 1024 Last 5 System Error Msgs: 2012 R2 Standard Xeon(R) CPU MB 10-25-2016 9:53:41 PM 36888 A fatal alert was generated and sent to the remote endpoint. L5639 @ This may result in termination of the connection. The TLS protocol defined fatal error code is 2.13GHz 40. The Windows SChannel error state is 1205. 10-25-2016 9:53:41 PM 36874 An TLS 1.1 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed. 10-25-2016 9:53:41 PM 36888 A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 1205. 10-25-2016 9:53:41 PM 36874 An TLS 1.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed.

PROPRIETARY & CONFIDENTIAL PAGE 244 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 10-25-2016 9:53:41 PM 36888 A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 1205. Last 5 Application Error Msgs: 10-25-2016 10:18:28 AM 3221226480 The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. 10-25-2016 12:04:33 AM 3221233670 License Activation (slui.exe) failed with the following error code: hr=0x8007232B dbre-line arguments: RuleId=eeba1977-569e-4571-b639- 7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e- d6ec3f16059f;SkuId=b3ca044e-a358-4d68-9883- aaa2941aca99;NotificationInterval=1440;Trigger=TimerEvent 10-24-2016 10:03:37 AM 3221226480 The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. 10-24-2016 12:04:33 AM 3221233670 License Activation (slui.exe) failed with the following error code: hr=0x8007232B dbre-line arguments: RuleId=eeba1977-569e-4571-b639- 7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e- d6ec3f16059f;SkuId=b3ca044e-a358-4d68-9883- aaa2941aca99;NotificationInterval=1440;Trigger=TimerEvent 10-23-2016 9:49:29 AM 3221226480 The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. Scheduled Tasks: Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-1114 Optimize Start Menu Cache Files-S-1-5-21-356494474-603968661-3470298851-1230 Remote Listening Ports: HTTP (80/TCP) HTTPS (443/TCP) RDP (3389/TCP) Disk Capacity: C: 126.48 GB, 108.47 GB free, 14.24% used Service Tag: 9183-7054-6046-1361-0149-6849-11 CPU Count: 1 CPU Core Count: 4 Windows Key: TH4CG-JDJX7-VJ2AF-DY4X9-HCFC6 Other License Keys:

PROPRIETARY & CONFIDENTIAL PAGE 245 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name Internet Explorer 55041-006-2483512-86608 (ends with HCXPK) Office Professional Plus 2010 82603-018-0000106-48008 (ends with HCXPK) PowerShell 89383-100-0001260-04379 Windows 7 Enterprise 55041-006-2445512-86648 (ends with HCXK) Make and Model: Microsoft Corporation/Virtual Machine Memory Banks: M00 : Unknown-Unknown-1024 Mb-unknown MHz 1 CPUs: Intel(R) Xeon(R) CPU L5639 @ 2.13GHz : CPU0-4 NICs: : -Rasl2tp-[00000000] WAN Miniport (L2TP) : -RasSstp-[00000001] WAN Miniport (SSTP) : -RasAgileVpn-[00000002] WAN Miniport (IKEv2) : -PptpMiniport-[00000003] WAN Miniport (PPTP) : -RasPppoe-[00000004] WAN Miniport (PPPOE) : -NdisWan-[00000005] WAN Miniport (IP) : -NdisWan-[00000006] WAN Miniport (IPv6) : -NdisWan-[00000007] WAN Miniport (redi Monitor) : -kdnic-[00000008] Microsoft Kernel Debug redi Adapter 00:15:5D:01:E0:9A : 192.168.1.5;fe80::5106:35a5:8930:9e7e-netvsc-[00000010] Microsoft Hyper-V redi Adapter : -tunnel-[00000012] Microsoft ISATAP Adapter : -tunnel-[00000013] Microsoft ISATAP Adapter DEP: On for All programs and services except those I select OS Manufacturer: Microsoft Corporation OS Version: 6.3.9600 unknown (Build 9600) OS Caption: Microsoft Windows Server 2012 R2 Standard OS Architecture: 64-bit OS Virtual Memory: 8016 MB OS System Directory: C:\Windows\system32 OS Windows Directory: C:\Windows

PROPRIETARY & CONFIDENTIAL PAGE 246 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name OS Install Date: 9/19/2014 4:10:34 AM PAE Enabled: True Active Anti-virus: N/A Active Anti-spyware: N/A Active Firewall: Windows Firewall WAMPA Windows 10 Pro Intel(R) 16384 Last 5 System Error Msgs: Core(TM) i7- MB 10-25-2016 3:19:09 PM 10016 The application-specific permission settings do not grant Local 6700K CPU @ Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- 4.00GHz A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 11:00:24 AM 5719 This computer was not able to set up a secure session with a domain controller in domain PIT due to the following: There are currently no logon servers available to service the logon request. This may lead to authentication problems. Make sure that this computer is connected to the redi. If the problem persists, please contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain. 10-25-2016 8:14:22 AM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-24-2016 3:32:29 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-24-2016 8:13:26 AM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

PROPRIETARY & CONFIDENTIAL PAGE 247 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name Last 5 Application Error Msgs: 10-25-2016 3:07:29 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-25-2016 3:07:28 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-25-2016 11:00:25 AM 1000 Faulting application name: vmware-vmrc.exe, version: 9.0.0.35586, time stamp: 0x55e0fb1f Faulting module name: MSVCR90.dll, version: 9.0.30729.9247, time stamp: 0x56fa38aa Exception code: 0x40000015 Fault offset: 0x0005beae Faulting process id: 0x7b50 Faulting application start time: 0x01d22ecac18057fc Faulting application path: C:\Program Files (x86)\Common Files\VMware\VMware Remote Console Plug-in 5.5\Internet Explorer\vmware-vmrc.exe Faulting module path: C:\WINDOWS\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_50 90cb78bcba4a35\MSVCR90.dll Report Id: 6aa738a1-c344-400f-94df-ff85fcb3ffd4 Faulting package full name: Faulting package-relative application ID: 10-25-2016 1:59:16 AM 0 10-24-2016 3:07:23 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. Scheduled Tasks: Account Disabler docksys Updater billing Dunning GoogleUpdateTaskMachineCore GoogleUpdateTaskMachineUA redi Detective Sales Report OneDrive Standalone Update Task Sync Salesforce Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 475.68 GB, 372.74 GB free, 21.64% used E: 0.39 GB, 0.28 GB free, 28.21% used F: 0.1 GB, 0.06 GB free, 40% used H: 931.41 GB, 560.11 GB free, 39.86% used O: 232.49 GB, 54.52 GB free, 76.55% used Service Tag: PS CPU Count: 1 CPU Core Count: 4 Windows Key:

PROPRIETARY & CONFIDENTIAL PAGE 248 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name TH4CG-JDJX7-VJ2AF-DY4X9-HCFC6 Other License Keys: Internet Explorer 55041-006-2483512-86608 (ends with HCXPK) Office Professional Plus 2010 82603-018-0000106-48008 (ends with HCXPK) PowerShell 89383-100-0001260-04379 Windows 7 Enterprise 55041-006-2445512-86648 (ends with HCXK) Make and Model: PowerSpec/Gseries Memory Banks: ChannelA-DIMM1 : DIMM-Synchronous-8192 Mb-3200 MHz ChannelB-DIMM1 : DIMM-Synchronous-8192 Mb-3200 MHz CPUs: Intel(R) Core(TM) i7-6700K CPU @ 4.00GHz : CPU0-4 System Slots: System Slot0 : J6B2-In Use-OK System Slot1 : J6B1-In Use-OK System Slot2 : J6D1-In Use-OK System Slot3 : J7B1-In Use-OK System Slot4 : J8B4-In Use-OK System Slot5 : J8D1-In Use-OK System Slot6 : J8B3-In Use-OK NICs: D8:CB:8A:C6:C3:2B : 192.168.6.125;fe80::a568:a9c:b4a6:14c3-rt640x64-[00000000] Realtek PCIe GBE Family Controller : -kdnic-[00000001] Microsoft Kernel Debug redi Adapter : -athr-[00000002] Qualcomm Atheros AR5BWB222 Wireless redi Adapter : -RFCOMM-[00000003] Bluetooth Device (RFCOMM Protocol TDI) 30:10:B3:4A:A9:D0 : -BthPan-[00000004] Bluetooth Device (Personal Area redi) : -vwifimp-[00000005] Microsoft Wi-Fi Direct Virtual Adapter : -vwifimp-[00000006] Microsoft Wi-Fi Direct Virtual Adapter : -tunnel-[00000007] Microsoft ISATAP Adapter : -tunnel-[00000008] Microsoft ISATAP Adapter : -tunnel-[00000009] Microsoft ISATAP Adapter DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 192.168.14393 unknown (Build 14393)

PROPRIETARY & CONFIDENTIAL PAGE 249 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name OS Caption: Microsoft Windows 10 Pro OS Architecture: 64-bit OS Virtual Memory: 18704 MB OS System Directory: C:\WINDOWS\system32 OS Windows Directory: C:\WINDOWS OS Install Date: 10/5/2016 4:09:43 AM PAE Enabled: True Active Anti-virus: Windows Defender Active Anti-spyware: Windows Defender Active Firewall: Windows Firewall WILLARD Windows 10 Intel(R) 12288 Last 5 System Error Msgs: Enterprise Core(TM) i7- MB 10-25-2016 5:27:30 PM 10016 The application-specific permission settings do not grant Local 4790 CPU @ Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- 3.60GHz A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 5:26:17 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 4:23:49 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 3:06:49 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running

PROPRIETARY & CONFIDENTIAL PAGE 250 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 10-25-2016 1:28:42 PM 10016 The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990- A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the acct NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Last 5 Application Error Msgs: 10-25-2016 3:07:38 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-25-2016 3:07:37 PM 3221226495 Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. 10-25-2016 7:13:43 AM 100 DNS Message from 192.168.6.62:64241 to 192.168.6.52:5353 length 0 too short 10-25-2016 7:13:41 AM 100 DNS Message from 192.168.6.62:64227 to 192.168.6.52:5353 length 0 too short 10-25-2016 7:13:41 AM 100 DNS Message from 192.168.6.62:64218 to 192.168.6.52:5353 length 0 too short Scheduled Tasks: GoogleUpdateTaskMachineCore GoogleUpdateTaskMachineUA Remote Listening Ports: RDP (3389/TCP) Disk Capacity: C: 465.76 GB, 363.22 GB free, 22.02% used D: 626.95 GB, 479.85 GB free, 23.46% used Service Tag: 4NZHR52 CPU Count: 1 CPU Core Count: 4 Windows Key: TH4CG-JDJX7-VJ2AF-DY4X9-HCFC6 Other License Keys: Internet Explorer 55041-006-2483512-86608 (ends with HCXPK) Office Professional Plus 2010 82603-018-0000106-48008 (ends with HCXPK) PowerShell 89383-100-0001260-04379 Windows 7 Enterprise 55041-006-2445512-86648 (ends with HCXK) Make and Model:

PROPRIETARY & CONFIDENTIAL PAGE 251 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name Dell Inc./XPS 8700 Memory Banks: DIMM3 : DIMM-Synchronous-2048 Mb-1600 MHz DIMM1 : DIMM-Synchronous-4096 Mb-1600 MHz DIMM4 : DIMM-Synchronous-2048 Mb-1600 MHz DIMM2 : DIMM-Synchronous-4096 Mb-1600 MHz CPUs: Intel(R) Core(TM) i7-4790 CPU @ 3.60GHz : CPU0-4 System Slots: System Slot0 : PCIE1-In Use-OK System Slot1 : PCIE2-Available-OK System Slot2 : PCIE3-Available-OK System Slot3 : PCIE4-Available-OK NICs: : -kdnic-[00000000] Microsoft Kernel Debug redi Adapter : -athr-[00000001] Dell Wireless 1703 802.11b|g|n (2.4GHz) 98:90:96:DC:65:30 : -rt640x64-[00000002] Realtek PCIe GBE Family Controller : -RFCOMM-[00000005] Bluetooth Device (RFCOMM Protocol TDI) AC:D1:B8:AE:B8:58 : -BthPan-[00000006] Bluetooth Device (Personal Area redi) : -VMSMP-[00000015] Hyper-V Virtual Switch Extension Adapter 98:90:96:DC:65:30 : 192.168.6.52;fe80::c015:b490:31f4:12be-VMSMP-[00000016] Hyper-V Virtual Ethernet Adapter : -tunnel-[00000017] Microsoft ISATAP Adapter DEP: On for essential Windows programs and services only OS Manufacturer: Microsoft Corporation OS Version: 192.168.14393 unknown (Build 14393) OS Caption: Microsoft Windows 10 Enterprise OS Architecture: 64-bit OS Virtual Memory: 15440 MB OS System Directory: C:\Windows\system32 OS Windows Directory: C:\Windows OS Install Date:

PROPRIETARY & CONFIDENTIAL PAGE 252 of 253 Full Detail Report NETWORK ASSESSMENT

Computer Operating System CPU RAM Analysis Name 8/3/2016 2:53:18 PM PAE Enabled: True Active Anti-virus: Windows Defender Active Anti-spyware: Windows Defender Active Firewall: Windows Firewall

PROPRIETARY & CONFIDENTIAL PAGE 253 of 253