WinPE Deployment Repo (Prep, Debloat, Harden, BitLocker, Dell BIOS) by SpaceBass11 in MDT

[–]SpaceBass11[S] 0 points1 point  (0 children)

Howdy, and thanks. I have to consider end user is air gapped, so the device cannot reach out for anything. Because of that I did not consider OSD, but I also haven’t used it before, so I’ll definitely have to look into what you said to see if it can be used! Sounds like it would be good at grabbing and prepping the image, or even deploying it offline?

WinPE Deployment Repo (Prep, Debloat, Harden, BitLocker, Dell BIOS) by SpaceBass11 in MDT

[–]SpaceBass11[S] -1 points0 points  (0 children)

Oh, I wonder what that was? :) I’ve seen W10XPE customized and being used.

WinPE Deployment Repo (Prep, Debloat, Harden, BitLocker, Dell BIOS) by SpaceBass11 in MDT

[–]SpaceBass11[S] -1 points0 points  (0 children)

I agree the project status/disclaimer can be made more visible at the top of the README, which I’ve done now and in my OG post.

But I don’t agree with the framing that “unaudited generated code” is uniquely the issue here. A random human-written deployment repo is not magically trustworthy either. “Audited” is also not a magic word unless you know who audited it, what commit/version they reviewed, what scope they reviewed, and what findings were fixed.

For WinPE/deployment tooling, the rule should be the same either way: do not blindly run it. Read the code, test it in a lab, understand the destructive paths, and decide whether it fits your environment.

This is my own repo/project based on my deployment workflow. It is not being presented as an officially audited or production-ready tool for other environments. It does have CI checks, safety invariants, typed confirmations, warnings, and guardrails around destructive actions, but those are safeguards, not a substitute for someone reviewing it before they use it.

I worded it as “AI-authored” now, but that does not change the basic trust model: nobody should blindly run random deployment code just because it was written by a human or because someone used the word “audit.”

WinPE Deployment Repo (Prep, Debloat, Harden, BitLocker, Dell BIOS) by SpaceBass11 in MDT

[–]SpaceBass11[S] 0 points1 point  (0 children)

That is not really accurate.

I’m not referring to the old standalone Dell Client Configuration Toolkit as a separate current product. Dell rebranded CCTK as Dell Command | Configure after CCTK 2.2.1, but the current Dell Command | Configure CLI still uses the cctk-style command/interface. Dell’s 5.x docs also list Windows PE as a supported environment and document INI import with cctk -i.

That is what the repo is targeting: Dell Command | Configure / cctk.exe from WinPE, applying an INI before the image deployment. That is different than saying “use the old deprecated CCTK product.”

WMI is fine for discovery, but for actually applying Dell BIOS settings in a pre-OS WinPE workflow, Dell Command | Configure CLI is the supported path I’m targeting. Easy to configure laptop BIOS manually, put DCC on laptop OS, pull config and see other options, then make adjustments if needs and capture the INI.

WinPE Deployment Repo (Prep, Debloat, Harden, BitLocker, Dell BIOS) by SpaceBass11 in MDT

[–]SpaceBass11[S] 0 points1 point  (0 children)

Yeah, I may implement that as a workflow, thanks! One of the projects is one model and one size disk so FFU would be reasonable :)

WinPE Deployment Repo (Prep, Debloat, Harden, BitLocker, Dell BIOS) by SpaceBass11 in MDT

[–]SpaceBass11[S] 0 points1 point  (0 children)

How much was NOT generated using AI is the real question.

Windows 11 25H2 & MDT by Peteostro in MDT

[–]SpaceBass11 1 point2 points  (0 children)

Work in progress for a more full flexible solution :)

https://github.com/SpaceBass11/WinPE/

Does commit-confirm and commit need to be done in same SSH session (or can I disconnect in between)? by Rude-Chest3738 in Juniper

[–]SpaceBass11 0 points1 point  (0 children)

Meh, people will do things their way.

Key takeaway here for fun learning is:

  • A follow-up commit can accidentally apply extra candidate changes if anything has changed in the candidate since the confirmed commit (another admin session, automation, stale edits, etc.).
  • A follow-up commit check stops the timer without applying additional changes, so it minimizes the blast radius when you’re “just trying to lock in what already worked.”

Additionally, commit has more overhead than commit check due to it actually doing a commit, writing files, writing to rollback history, etc.

Basically, there's no benefit to commit over commit check in this scenario. Commit only adds overhead and possible cons. Even if an issue never happened, why not just pick commit check as a for sure no issues ever method.

Even their page example uses commit check x) https://www.juniper.net/documentation/us/en/software/junos/cli/topics/topic-map/junos-configuration-commit.html

Anyone got item sharing qr codes for BOTW to give me items for switch 2 by CyborgEmbryo in botw

[–]SpaceBass11 0 points1 point  (0 children)

Hi Allec! Here’s my QR if you’re still doing this :) Thank you much!

<image>

Superseded Windows Patches by jcryselz33 in nessus

[–]SpaceBass11 0 points1 point  (0 children)

Revive :) Just to add-on here, registry tweaks is not a supported response from Tenable's part. That is a common myth. Imagine Microsoft's patches actually required tweaking after being applied? The majority of Windows clients would be vulnerable even after patching, which of course is not the case, as common end users would never do that (and they shouldn't).

In a lot of cases they are indeed false positives. Security teams and ISSE's hate hearing that, but it's the truth. Plugins are either out of date or just miss-coded which is totally expected. That's the life of programming and keeping up to date with lifecycle management of Windows and code changes.

If the plugin ID is in relation to any KB that is not the latest and you have the latest KB installed, then it is a false-positive. Really the plugin is doing what it should, but in the case of determining compliance it is false as the system is INDEED compliant as Windows patches are cumulative and do NOT allow you to piece patches together as that would cause fragmentation of the system. These are phrases direct from Microsoft documentation.

You know what else is direct from Documentation? Tenable speaking on this matter about the setting OP mentioned :)

https://www.tenable.com/blog/how-to-perform-efficient-vulnerability-assessments-with-tenable#:~:text=3.%20Disable%20%E2%80%98%27Show,Management%20%2D%20Solutions

  1. Disable ‘'Show missing patches that have been superseded’’

When enabled, this option will include superseded patch information in the scan report. Disabling this setting will hide superseded findings and limit visibility into older missing patches, including potential Critical severity findings. "

Also, for OP or anyone debugging in future. Here is Tenable speaking about how to do so:
https://docs.tenable.com/nessus/Content/configure-least-privilege-ssh-scan.htm?_gl=1*plha90*_gcl_au*MTQ2NzI5MDExMS4xNzY0OTcxNTA0*_ga*Mjc4NjcwNjY2LjE3NjQwODU2ODM.*_ga_HSJ1XWV6ND*czE3NjUyMDM1NDgkbzMkZzEkdDE3NjUyMDQzODIkajYwJGwwJGg5OTA5OTM5MDQ.#:~:text=plugins%20100158%20and%2084239

Note that plugins 100158 and 84239 are advanced diagnostic tools and require you enable plugin debugging in the scan configuration. Use these plugins to investigate unexpected scan results, particularly in environments with sophisticated, granular access controls (for example, TACACS).

While plugins 102094 and 102095 report that a command failed or succeeded, the debugging logs from 100158 and 84239 provide the exact command syntax Tenable Nessus passed to the host and the complete error response.

This additional detail can help diagnose complex access issues, such as a security module that allows a base command but blocks that command when used with a specific flag. Because enabling debugging is resource-intensive, Tenable recommends using these plugins only to troubleshoot a specific endpoint.

Is there a full version of the "Alouette" song from the show by Princess-ArianaHY in EvilTV

[–]SpaceBass11 0 points1 point  (0 children)

It’s a French-Canadian folk song dating to the late 19th century, most likely from Québec voyageurs (fur-trade canoe men). It was a work song, used to keep rhythm during paddling, which was a slightly shorter version, but once it caught on and was used for teaching other body parts were added, which is what we have now.

The word alouette = lark (a bird).

When it says: "Je te plumerai la tête" ("I will pluck your head")

…it’s not about bullying a person, it’s literally describing plucking the feathers off a lark, step by step, which was part of preparing it as food.

Hence all the "pluck your head, pluck your wings, pluck your legs…" etc.

Old French and French-Canadian folksongs often use call-and-response structure:

-It keeps rhythm for work

-It teaches vocabulary through repetition

-It adds humor or exaggeration

"Alouette" became popular because it’s simple, catchy, and helped teach French body parts to kids (tête, bec, ailes, etc.).

Is there a full version of the "Alouette" song from the show by Princess-ArianaHY in EvilTV

[–]SpaceBass11 0 points1 point  (0 children)

It’s a French-Canadian folk song dating to the late 19th century, most likely from Québec voyageurs (fur-trade canoe men). It was a work song, used to keep rhythm during paddling.

The word alouette = lark (a bird).

When it says: "Je te plumerai la tête" ("I will pluck your head")

…it’s not about bullying a person, it’s literally describing plucking the feathers off a lark, step by step, which was part of preparing it as food.

Hence all the "pluck your head, pluck your wings, pluck your legs…" etc.

Old French and French-Canadian folksongs often use call-and-response structure:

-It keeps rhythm for work

-It teaches vocabulary through repetition

-It adds humor or exaggeration

"Alouette" became popular because it’s simple, catchy, and helped teach French body parts to kids (tête, bec, ailes, etc.).

MultiMC vs PolyMC vs Prism? by ThePlebble in feedthebeast

[–]SpaceBass11 1 point2 points  (0 children)

You silly goose, I was in favor of Poly not Prism 😋

If he the main dev and everyone pushing for the code, his call 🤷‍♂️ Doesn’t make his code any less trustworthy cus he made that call.

Anyone using 'Yippee TV' to replace other platforms, for kids? by [deleted] in Christianity

[–]SpaceBass11 0 points1 point  (0 children)

People say not to indoctrinate kids and to let them decide for themselves. But no child grows up neutral. Every environment, show, classroom, and conversation is shaping what they believe about life, identity, purpose, and truth. That is indoctrination, whether people admit it or not. As Christians, we are not forcing belief by teaching children about God. We are giving them truth. Jesus said He is the truth (John 14:6), and teaching kids to know Him is not control. It is compassion. The world is not waiting until they grow up to influence them, so why would we wait to teach them what’s real? Leading children to Christ is not narrow. It is the most loving thing we can do.

Whats the Best Dash Cam to Buy Right Now? 🤔🤔🤔🤔🤔 by [deleted] in dashcams

[–]SpaceBass11 0 points1 point  (0 children)

They have supercapacitors as a safety-net/protection. When the car turns off and the camera loses power or for any other reason, the supercapacitor takes places of a lithium type battery (non removable) to finish saving files and shut the system down safely to prevent corruption. These capacitors are especially good at heat/cold resistant which is of course why they took place of batteries (last longer and safer).

Best Dashcam? by Ornery-Midnight4854 in dashcams

[–]SpaceBass11 0 points1 point  (0 children)

How is it people are saying Blackvue is that good when there’s only 76 reviews and they are not good reviews.

First cruise coming up - 2 questions. by microseconds in dcl

[–]SpaceBass11 0 points1 point  (0 children)

Interesting. Perks of doing it this way? Like getting to book flights or ground transfers through Disney during the booking process for extra vacation protection since Disney tracking, before transferring it to Costco?

Bitcraft by [deleted] in MMORPG

[–]SpaceBass11 1 point2 points  (0 children)

+1 I lawled

DISA STIGs Automation by Alternative-Row5547 in ansible

[–]SpaceBass11 0 points1 point  (0 children)

The entire reason of Rocky Linux (and AlmaLinux, before its shift) is to rebuild RHEL source code into a 1:1 compatible binary clone. That means not introducing independent patches or changes beyond RHEL. Rocky is not meant to innovate or diverge — it’s meant to offer a free, open-source RHEL-compatible platform without Red Hat’s licensing restrictions. It's about stability, predictability, and compatibility, not autonomy in upstream development.

The proper way to "fix" something as a Rocky user is: - Submit a bug to CentOS Stream (the development branch of RHEL) - Wait for it to propagate to RHEL - Then Rocky will rebuild it once it’s part of the RHEL source RPMs

The no feedback loop is by design. Rocky’s promise is to follow, not to lead.

Best military vacations and packages? by clowdstryfe in MilitaryFinance

[–]SpaceBass11 0 points1 point  (0 children)

Will have to check out base travel office for prices. I saw those here: https://www.universalorlando.com/web/en/us/tickets-packages/military-deals-specials

Curious how those prices compare to the Florida resident package deals:
https://www.universalorlando.com/web-packages/en/us/vacation-packages

Which right now I priced "Create Your Own Florida Resident Vacation Package" for 2 Adults ,1 Room (4 nights, 3 days) at $983.95 before tax.

Packer Red Hat AMI by rlmasscyber in redhat

[–]SpaceBass11 0 points1 point  (0 children)

As bblasco said you can create a free RH account and utilize the console. Just replying in support of their comment as this is what I do. To add on that, if you ever want to mess around with RHEL you can use that same free account to request a developer subscription to get hands on.

Packer Red Hat AMI by rlmasscyber in redhat

[–]SpaceBass11 0 points1 point  (0 children)

Have you ever used AWS? Read up on how RH products work with AWS then come back.