Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
50 commits
Select commit Hold shift + click to select a range
b3995ee
chore: sync scripts [smart-sync]
limehawk Jul 10, 2026
8c73cf4
chore: backfill Level sidecars with description, timeout, readme and …
limehawk Jul 10, 2026
04be644
chore: sync scripts [smart-sync]
limehawk Jul 10, 2026
faaf04f
smoke: temp script with two runtime variables
limehawk Jul 10, 2026
48b8071
chore: sync scripts [smart-sync]
limehawk Jul 10, 2026
a06093e
smoke: change one variable, drop the other
limehawk Jul 10, 2026
c7b2606
smoke: change one variable, drop the other
limehawk Jul 10, 2026
17f97e0
smoke: relink + change one variable, drop the other
limehawk Jul 10, 2026
66f4aa5
chore: sync scripts [smart-sync]
limehawk Jul 10, 2026
16f8f5c
fix: remove mis-mapped script variables
limehawk Jul 10, 2026
b583095
chore: sync scripts [smart-sync]
limehawk Jul 10, 2026
1f1cd58
feat: add Windows 11 25H2 silent enablement install for Level
limehawk Jul 22, 2026
0009e2e
chore: sync scripts [smart-sync]
limehawk Jul 22, 2026
9dee4b4
fix(level): windows11_25h2_install timeout 7200s (2h)
limehawk Jul 22, 2026
defc8d6
chore: sync scripts [smart-sync]
limehawk Jul 22, 2026
817096e
fix(level): convert sidecar timeouts from SuperOps minutes to Level s…
limehawk Jul 22, 2026
7b5b015
chore: sync scripts [smart-sync]
limehawk Jul 22, 2026
9ff23f3
feat(level): windows11_25h2_install v1.1.0 path-aware upgrades
limehawk Jul 22, 2026
44e4221
chore: sync scripts [smart-sync]
limehawk Jul 22, 2026
70ac15d
fix(level): windows11_25h2_install v1.1.1 reboot after install defaul…
limehawk Jul 22, 2026
04320fd
fix(dism): stop false-positive RestoreHealth on healthy ScanHealth (v…
limehawk Jul 22, 2026
6347f41
chore: sync scripts [smart-sync]
limehawk Jul 22, 2026
77d8905
fix(bitlocker): rewrite bitlocker_enable to guarantee Protection On (…
limehawk Jul 23, 2026
649b1a7
chore: sync scripts [smart-sync]
limehawk Jul 23, 2026
6d6c306
merge main into level-sync-bootstrap: dism v2.1.1 reboot on fixed cor…
limehawk Jul 23, 2026
7f0c3c5
merge remote level-sync-bootstrap
limehawk Jul 23, 2026
5fa2b72
chore: sync scripts [smart-sync]
limehawk Jul 23, 2026
9d1bb69
chore: sync scripts [smart-sync]
limehawk Jul 23, 2026
6f4f7c3
merge: Level workstation rename port into level-sync-bootstrap
limehawk Jul 23, 2026
cab7596
chore: sync scripts [smart-sync]
limehawk Jul 23, 2026
c1b72eb
merge main: windows11_25h2_install v1.2.0 health preflight + resume
limehawk Jul 23, 2026
e17829b
chore: sync scripts [smart-sync]
limehawk Jul 23, 2026
3862dbb
merge main: windows11_iso_upgrade v1.0.0 (Fido ISO + compat gate)
limehawk Jul 24, 2026
a8a77da
chore: sync scripts [smart-sync]
limehawk Jul 24, 2026
3ace4ff
merge main: sentinelone_install v1.0.2 site token custom field
limehawk Jul 24, 2026
2fdca67
chore: acknowledge remote sentinelone_install content in sync sidecar
limehawk Jul 24, 2026
5e2a265
chore: sync scripts [smart-sync]
limehawk Jul 24, 2026
5f3cba0
merge main: windows11_iso_upgrade v1.0.1
limehawk Jul 28, 2026
5999a10
chore: sync scripts [smart-sync]
limehawk Jul 28, 2026
bb10cd7
merge main: workstation rename Level port v9.0.1
limehawk Jul 31, 2026
c42ab53
chore: sync scripts [smart-sync]
limehawk Jul 31, 2026
42e0110
merge main: rename prefix via cf_client_prefix v9.1.0
limehawk Jul 31, 2026
dc673bc
chore: sync scripts [smart-sync]
limehawk Jul 31, 2026
777a2a0
merge main: rename slot labelling v9.0.2/v9.1.1
limehawk Jul 31, 2026
dd3af70
chore: sync scripts [smart-sync]
limehawk Jul 31, 2026
295a757
merge main: macOS rename cf_client_prefix v2.1.0
limehawk Jul 31, 2026
ae2fc97
chore: sync scripts [smart-sync]
limehawk Jul 31, 2026
ea58bc3
Merge branch 'main' into level-sync-bootstrap
limehawk Aug 2, 2026
9bca63c
Merge branch 'main' into level-sync-bootstrap
limehawk Aug 2, 2026
dea7060
Merge branch 'main' into level-sync-bootstrap
limehawk Aug 2, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
30 changes: 30 additions & 0 deletions scripts/1password_install.level.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
name: "1password_install.ps1"
description: Downloads and silently installs 1Password using official MSI
shell: POWERSHELL
runAs: SYSTEM
timeout: 900
readme: |
Purpose
-------
Downloads and silently installs the latest version of 1Password for Windows using the official MSI installer with configurable deployment options.

Usage Notes
-----------
- Validates input parameters before proceeding
- Downloads 1Password MSI installer to temp directory
- Builds MSI arguments based on deployment options and installs silently using msiexec
- Cleans up installer file after completion
- Download URL: https://downloads.1password.com/win/1PasswordSetup-latest.msi
- Prevent Restart: true
- Manage Updates: false
- Remove Other Installs: true

Requirements
------------
- Windows PowerShell 5.1 or later
- Administrator privileges
- Internet connectivity
groupId: Z2lkOi8vbGV2ZWwvU2NyaXB0R3JvdXAvNTQ2NDU
scriptId: Z2lkOi8vbGV2ZWwvU2NyaXB0LzEyNDIzMA
lastPushedChecksum: "sha256:4c5b17905ada8b19"
lastPushedMetaChecksum: "sha256:4cc2972b4f25ddeb"
31 changes: 31 additions & 0 deletions scripts/agent_startup_fix.level.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
name: agent_startup_fix.ps1
description: Fixes RMM agent service startup with recovery options and delayed start
shell: POWERSHELL
runAs: SYSTEM
timeout: 300
readme: |
Purpose
-------
Configures the RMM agent service with proper recovery options and delayed automatic start to prevent startup failures on slow or overloaded machines where services timeout during boot.

Usage Notes
-----------
- Locates the RMM agent service by name
- Reports current service status and startup type
- Sets service recovery options (restart on failure)
- Sets service to Automatic (Delayed Start) via registry
- Reports recent crash events from Event Viewer for diagnosis
- Default service name is "limehawk"; change $ServiceName for other RMM agents
- Recovery: restart after 60s, 60s, then 120s; reset failure count every 24 hours
- Uses registry for delayed start (compatible with Server 2019 PowerShell which lacks AutomaticDelayedStart enum)
- Event log lookback defaults to 3 days

Requirements
------------
- Windows OS
- Administrator privileges
- RMM agent installed
groupId: Z2lkOi8vbGV2ZWwvU2NyaXB0R3JvdXAvNTQ2NDU
scriptId: Z2lkOi8vbGV2ZWwvU2NyaXB0LzEyNDIzMQ
lastPushedChecksum: "sha256:5c55fbd2b948f152"
lastPushedMetaChecksum: "sha256:c4a125f9dc0cfecf"
30 changes: 30 additions & 0 deletions scripts/antivirus_status.level.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
name: antivirus_status.ps1
description: Reports third-party antivirus status to SuperOps custom fields
shell: POWERSHELL
runAs: SYSTEM
timeout: 900
readme: |
Purpose
-------
Checks for the presence and active status of third-party antivirus software on the system, excluding Windows/Microsoft Defender. Reports the active product name and boolean state to SuperOps custom fields for monitoring.

Usage Notes
-----------
- Validates that SuperOps module is available
- Detects OS type (client vs server)
- Queries installed AV products via SecurityCenter2 or registry fallback
- Checks enabled state via productState bitmask
- Ignores Windows Defender entries; only reports third-party AV
- Outputs AV name and enabled state (TRUE/FALSE) to SuperOps custom fields
- Confirms Windows Defender status in console output
- No configurable settings; all logic is fixed for third-party AV detection

Requirements
------------
- PowerShell 5.1 or later
- Access to root\SecurityCenter2 namespace (requires local admin or equivalent)
- SuperOps module available via $SuperOpsModule variable (provided by RMM)
groupId: Z2lkOi8vbGV2ZWwvU2NyaXB0R3JvdXAvNTQ2NDU
scriptId: Z2lkOi8vbGV2ZWwvU2NyaXB0LzEyNDIzMg
lastPushedChecksum: "sha256:1a20a2caeb5024b5"
lastPushedMetaChecksum: "sha256:6d2043db6f0128b0"
35 changes: 35 additions & 0 deletions scripts/antivirus_uninstall.level.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
name: antivirus_uninstall.ps1
description: Removes common third-party antivirus software (McAfee, Sophos, AVG, etc.)
shell: POWERSHELL
runAs: SYSTEM
timeout: 900
readme: |
Purpose
-------
Detects and uninstalls common third-party antivirus software from Windows systems including McAfee, Sophos, AVG, and Microsoft Security Essentials. Designed for scenarios where existing AV must be removed before deploying a new endpoint protection solution.

Usage Notes
-----------
- Validates execution environment (must run as Administrator)
- Detects each AV product using registry, services, file paths, packages, and WMI
- Stops services before uninstallation
- Attempts removal via multiple methods (packages, WMI, vendor-specific tools)
- Downloads MCPR (McAfee Consumer Product Removal) tool if needed
- Downloads AVG Clear tool if needed
- Uses silent/quiet uninstall methods where possible
- No reboot is forced, though some AV may require it for complete removal

Requirements
------------
- Windows PowerShell 5.1 or PowerShell 7+
- Administrator privileges
- Internet access (optional, for downloading MCPR and AVG Clear tools)

Security
--------
- Some antivirus may require tamper protection to be disabled first
- A reboot may be required after uninstallation for complete removal
groupId: Z2lkOi8vbGV2ZWwvU2NyaXB0R3JvdXAvNTQ2NDU
scriptId: Z2lkOi8vbGV2ZWwvU2NyaXB0LzEyNDIzMw
lastPushedChecksum: "sha256:20975b8efcf885c8"
lastPushedMetaChecksum: "sha256:be876ca8a3a8af7d"
28 changes: 28 additions & 0 deletions scripts/arch_update_verbose.level.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
name: arch_update_verbose.sh
description: Updates all packages on Arch Linux/Omarchy with verbose output
shell: BASH
runAs: SYSTEM
timeout: 5400
readme: |
Purpose
-------
Automates system package updates for Arch Linux and Omarchy systems with verbose output and error handling. Syncs package databases, upgrades all packages, removes orphaned dependencies, and cleans package cache. Provides color-coded status messages.

Usage Notes
-----------
- Run with sudo or as root
- Configure options at top of script:
- ENABLE_ORPHAN_REMOVAL: Remove orphaned packages after upgrade
- ENABLE_CACHE_CLEAN: Clean pacman cache to free disk space
- ENABLE_COLOR_OUTPUT: Use colored terminal output

Requirements
------------
- Root/sudo access required
- Arch Linux or Arch-based distribution (Omarchy, EndeavourOS, Manjaro, etc.)
- Network connectivity to package mirrors
- pacman package manager
groupId: Z2lkOi8vbGV2ZWwvU2NyaXB0R3JvdXAvNTQ2NDU
scriptId: Z2lkOi8vbGV2ZWwvU2NyaXB0LzEyNDIzNA
lastPushedChecksum: "sha256:132e3b80eb80e9b3"
lastPushedMetaChecksum: "sha256:e2851cf2c1bec96a"
33 changes: 6 additions & 27 deletions scripts/bitlocker_enable.level.yaml
Original file line number Diff line number Diff line change
@@ -1,30 +1,9 @@
name: bitlocker_enable.ps1
description: Enables BitLocker on the OS drive and guarantees Protection On
description: ""
shell: POWERSHELL
runAs: SYSTEM
timeout: 600
readme: |
Purpose
-------
Converges the OS drive to BitLocker "Protection On" from any starting state: fully decrypted, encrypted with protection suspended (the OOBE pre-provisioned clear-key state), or already protected. Prints the recovery password to the console for Level activity-log capture and fails loudly (exit 1) whenever protection cannot be activated, instead of reporting false success.

Usage Notes
-----------
- Requires a present and ready TPM (fails otherwise)
- Ensures exactly one RecoveryPassword protector and a TPM protector
- Starts encryption via manage-bde (xts_aes256, used space only, no hardware test) when the volume is FullyDecrypted
- Activates protectors (manage-bde -protectors -enable) when the volume is encrypted but Protection Status is Off
- manage-bde exit codes are checked; failures exit 1 instead of reporting false success
- Target drive default: C:

Requirements
------------
- PowerShell 5.1 or later
- Windows 10/11 Pro or Enterprise with BitLocker feature
- Level: run as System; timeout 600 seconds
- TPM present and ready

Security
--------
- Recovery password is printed to console by design (Level activity log is the key escrow record)
- No other secrets in logs
timeout: 100
groupId: Z2lkOi8vbGV2ZWwvU2NyaXB0R3JvdXAvNTQ2NDU
scriptId: Z2lkOi8vbGV2ZWwvU2NyaXB0LzM1NDg3
lastPushedChecksum: "sha256:3aed65cd22ff6767"
lastPushedMetaChecksum: "sha256:dddc42444529721f"
36 changes: 36 additions & 0 deletions scripts/bitlocker_superops_enable.level.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
name: bitlocker_superops_enable.ps1
description: Enables BitLocker with TPM and syncs recovery key to SuperOps
shell: POWERSHELL
runAs: SYSTEM
timeout: 900
readme: |
Purpose
-------
Enables BitLocker on the OS drive using TPM and Recovery Password protectors. Ensures protectors are not duplicated, prints recovery key to console for RMM log capture, and syncs the recovery key to SuperOps custom fields.

Usage Notes
-----------
- Validates administrative privileges and SuperOps module
- Ensures BDESVC (BitLocker Service) is running and set to Automatic
- Checks TPM status and adds TPM protector if available
- Rotates Recovery Password protector when Force is true (default)
- Initiates encryption with XTS-AES 256, used-space-only mode
- No reboot required to start encryption (skip hardware test enabled)
- Retrieves and displays recovery key, then syncs to SuperOps custom fields
- Target drive default: C:

Requirements
------------
- PowerShell 5.1 or later
- Windows 10/11 Pro or Enterprise with BitLocker feature enabled
- Administrator privileges
- SuperOps module available via $SuperOpsModule

Security
--------
- Recovery Password is printed to console (captured by RMM logs)
- Recovery Password is synced to SuperOps custom fields
groupId: Z2lkOi8vbGV2ZWwvU2NyaXB0R3JvdXAvNTQ2NDU
scriptId: Z2lkOi8vbGV2ZWwvU2NyaXB0LzEyNDIzNQ
lastPushedChecksum: "sha256:5bb054e2cc26dc88"
lastPushedMetaChecksum: "sha256:5f4065d7380dd69d"
29 changes: 29 additions & 0 deletions scripts/canon_mf455dw_driver_install.level.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
name: canon_mf455dw_driver_install.ps1
description: Downloads and installs Canon imageCLASS MF455dw printer drivers
shell: POWERSHELL
runAs: SYSTEM
timeout: 900
readme: |
Purpose
-------
Downloads the Canon imageCLASS MF455dw MF Driver package from Canon's CDN, extracts it, and installs the UFR II LT printer driver to the Windows driver store using pnputil. Optionally creates a TCP/IP printer queue if an IP address is specified.

Usage Notes
-----------
- Downloads Canon MF Driver package from official CDN
- Extracts driver files and installs UFR II LT driver via pnputil
- Creates TCP/IP printer port and queue if printer IP is specified
- Leave $printerIp empty to install driver only without creating a queue
- Driver extracts to C:\Temp\CanonMF455dw and is cleaned up after install
- Configurable variables: $driverUrl, $printerIp, $printerName, $installScanner

Requirements
------------
- Windows 10/11 or Windows Server 2016+
- Administrator privileges
- Network connectivity to Canon CDN (gdlp01.c-wss.com)
- curl.exe (included in Windows 10 1803+)
groupId: Z2lkOi8vbGV2ZWwvU2NyaXB0R3JvdXAvNTQ2NDU
scriptId: Z2lkOi8vbGV2ZWwvU2NyaXB0LzEyNDIzNg
lastPushedChecksum: "sha256:9422dc3b1c79a3bf"
lastPushedMetaChecksum: "sha256:687afe0072c4a24b"
25 changes: 25 additions & 0 deletions scripts/choco_upgrade_all.level.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
name: choco_upgrade_all.ps1
description: Upgrades all Chocolatey-managed packages to latest versions
shell: POWERSHELL
runAs: SYSTEM
timeout: 900
readme: |
Purpose
-------
Upgrades all Chocolatey-managed packages to their latest versions using the choco upgrade all command with automatic confirmation.

Usage Notes
-----------
- Checks if Chocolatey is installed before proceeding
- Runs choco upgrade all with auto-confirmation flag (-y) for unattended operation
- Operates on all installed Chocolatey packages; no configuration required

Requirements
------------
- Windows OS
- Administrator privileges
- Chocolatey package manager installed
groupId: Z2lkOi8vbGV2ZWwvU2NyaXB0R3JvdXAvNTQ2NDU
scriptId: Z2lkOi8vbGV2ZWwvU2NyaXB0LzEyNDIzNw
lastPushedChecksum: "sha256:bf35638a77698431"
lastPushedMetaChecksum: "sha256:26c49d38afabc76f"
41 changes: 41 additions & 0 deletions scripts/cloudflared_install.level.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
name: cloudflared_install.ps1
description: Installs cloudflared via winget and registers the tunnel service
shell: POWERSHELL
runAs: SYSTEM
timeout: 900
readme: |
Purpose
-------
Onboards a Windows endpoint to a Cloudflare named tunnel by installing the Cloudflare.cloudflared package via winget and registering the Cloudflare Tunnel service with a connector token supplied through SuperOps runtime replacement. The connector token is treated as a secret and is masked on any output path.

Usage Notes
-----------
- Validates connector token is present and was replaced by SuperOps
- Resolves winget.exe (SYSTEM-aware path resolution)
- Installs Cloudflare.cloudflared via winget (treats already-installed exit codes as success)
- Resolves the cloudflared.exe binary
- Removes any pre-existing Cloudflare Tunnel service registration
- Registers the service with the connector token
- Polls the service for Running state up to 10 seconds
- Reports success or masked failure (token never echoed)
- Package Id is Cloudflare.cloudflared
- Service name is Cloudflare Tunnel
- Winget flags --exact --silent --accept-package-agreements --accept-source-agreements

Requirements
------------
- CloudflaredTunnelToken runtime variable (required, non-empty)
- Windows 10 1809+ / Windows Server 2019+
- SYSTEM or Administrator privileges
- Winget installed (run winget_setup.ps1 first if missing)
- Outbound internet connectivity to Cloudflare edge (port 7844)

Security
--------
- No secrets in logs
- Connector token is never printed; if it appears in an error message it is masked as ****<last4>
- Runtime variable validated against unreplaced placeholder
groupId: Z2lkOi8vbGV2ZWwvU2NyaXB0R3JvdXAvNTQ2NDU
scriptId: Z2lkOi8vbGV2ZWwvU2NyaXB0LzEyNDIzOA
lastPushedChecksum: "sha256:13f478410f8c5064"
lastPushedMetaChecksum: "sha256:456e101d5dc58bfa"
32 changes: 32 additions & 0 deletions scripts/cloudflared_status.level.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
name: cloudflared_status.ps1
description: Reports cloudflared binary, service, and tunnel connectivity state
shell: POWERSHELL
runAs: SYSTEM
timeout: 900
readme: |
Purpose
-------
Field-triage view of a Windows endpoint's Cloudflare Tunnel connector. Reports the cloudflared binary version and install path, the Cloudflare Tunnel service Status and StartType, and a best-effort tunnel connectivity verdict pulled from the Windows Event Log with an outbound-socket fallback signal. Always exits 0 - absence of target is itself a valid status, not an error.

Usage Notes
-----------
- Resolves cloudflared.exe; if absent reports Not installed and exits 0
- Reports binary version and install path
- Reports service Status and StartType
- Reads recent Application log entries for tunnel connector events
- If no event log signal, falls back to Get-NetTCPConnection / Get-NetUDPEndpoint on port 7844
- Always prints which signal was used so the field tech knows the basis
- Service name is Cloudflare Tunnel
- Event log window is last 15 minutes
- Event log source is cloudflared (verify on a registered host with Get-WinEvent -ListProvider *cloud*)
- Connector port is 7844 (TCP and UDP)

Requirements
------------
- Windows 10 1809+ / Windows Server 2019+
- Read access to the Application Event Log
- PowerShell 5.1 or later
groupId: Z2lkOi8vbGV2ZWwvU2NyaXB0R3JvdXAvNTQ2NDU
scriptId: Z2lkOi8vbGV2ZWwvU2NyaXB0LzEyNDIzOQ
lastPushedChecksum: "sha256:e7d61d1e9ee15f74"
lastPushedMetaChecksum: "sha256:4547fac1dace91c5"
Loading