Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Introduction

...

This document outlines the system requirements and prerequisites necessary for installing the GYTPOL dsRequester component. This component facilitates the retrieval of data from CIS/NIST (only GYTPOL on-prem) and Active Directory / Group Policy Security and Operational sources (both on-prem and SaaS).

Checklist

Ensure that the following GYTPOL requirements are satisfied before initiating the installation of the GYTPOL Validator software:

  • Server sizing and OSVerify compatibility with the GYTPOL dsRequester server.

  • Users and GroupsValidate configurations in Active Directory and the GYTPOL dsRequester server for seamless integration.

  • PortsConfirm that the required ports are open on both the server and client sensor sides to facilitate proper communication.

  • AntivirusTake precautions to prevent any interference from antivirus software that could impede the GYTPOL Validator's correct execution.

...

Type

Name

Permission set

AD User

GytpolSvc (or any other suitable naming convention)

Domain level:

Member of Domain Group: “Performance Log Users”

GYTPOL Server local settings:

  1. Local admin on GYTPOL dsRequester server

  2. Logon as a batch job

Ports

From

To

Port number

Purpose

GYTPOL dsRequester server

DC’s

389, 9389, 636, 135, 138-139, 445, 464, 53, 3268, 3269 +

Dynamic ports (49152-65535)

Group Policy PowerShell queries +

Group Policy modeling queries

GYTPOL dsRequester server

GYTPOL AWS Cloud

During the onboarding process, GYTPOL team will supply the URLs for reference.

443

Group Policy PowerShell reporting +

Group Policy modeling reporting

Antivirus

If whitelisting is required, ensure that the following paths and their subfolders and files are included:

...

Pay attention to the results:

  • Red X sign (error): Indicates a critical error that requires resolution before proceeding with the installation. Hover over the question mark (?) for guidance on the necessary actions.

  • Yellow Exclamation mark (warning): Represents a failed check that is not critical for immediate resolution. However, consider addressing warnings for optimal performance.

  • Defender icon: Denotes a successful check, confirming that the specific aspect has passed verification.

...

Please restart the server before the installation.

Here’s a video that demonstrates the Checker running its tests during the check process.

If you cannot see the results screen at the end or if the Checker is "killed" during execution, please ensure there are no EDR restrictions or other interferences affecting the Checker’s flow.

...

dsRequester installation / update

...

The presence of gytpolServer tasks in the Task Scheduler Library indicates a successful installation.

Info

Please note, that the tasks will run as the GYTPOLSVC user that was created earlier.

...