Thanks for that info, unfortunately I am not versed in the language and trying to put this together.
I think I can get what I want using the link you shared here https://bigfix.me/fixlet/details/3974
for last relevance how can I change it to check all 4 DOMAIN firewall inbound rules:
“File and Printer Sharing (SMB-In)”
“Remote Event Log Management (NP-In)”
“Remote Event Log Management (RPC)”
“Remote Event Log Management (RPC-EPMAP)”
The example they use is
not rule group currently enabled “Remote Desktop” of firewall
and I can replace Remote Desktop with a single service name such as
not rule group currently enabled “File and Printer Sharing (SMB-In)” of firewall