The relevance check below is returning ‘true’ for all endpoints but doing manual check using PowerShell proves the check return false.
Basically we have to do a lot of this kind of activity, where the Authority sends us a list of malicious MD5, SHA1 and SHA256 hashes, we have to check through all the files of all the computers to see if there is a match. I had created BigFix analyses, simple one, most of the time it returns false, but one particular list of MD5 hashes has returned true for all the endpoints, which is alarming.
Is there anything wrong with the relevance below?
exists descendant whose (md5 of it as lowercase = “baa93d47220682c04d92f7797d9224ce” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “23041caef38d4991296ffbe42743c691” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “da701d0e0ab6bfbddd747feebed96546” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “d41d8cd98f00b204e9800998ecf8427e” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “efcb51d4d8a55d441d194e80899bb2b0” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “231617ad2dc2a0c3f2d8e3241c57626f” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “92a0680fea369ae11f900c1a92e5499c” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “cf68e5165e3b89c0ece9b4905abf861a” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “5c0a4f9e67ced69eaea17092444b2c1a” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “22f49b12cb818728d293ae43082d8949” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “01c0e5316c7bba2ebdc00754a1d83f2a” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “5e501430acba545b719c0887357226dd” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “37fabfab797e631603a696b7ac2296d7” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “c10780e19363abda168c5861ce481635” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “671f4fb0c657d89c924064db6be0442e” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “a425d258e0ddf17fe412040b81d41aac” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “9cfb80616de943facef57fabbece780a” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “55e1897e20dbef5db7b4a718fd539ef7” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “83734ab1f8e17720271dc4b429ea0f6c” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “18f194fd3ae2455d8e26aad2e0dd6685” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “5fa71bdf383d16a6b25955bff53efb90” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “5af578a4785cc0683866fa19e262eb4d” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “e31fd661c75ca688e967a8cb3acaf667” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “ee501cdb0da38b6674f2156044a7c4fa” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “01772205e022a2ffd1809a471bd44333” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “6292ff91b59460d11cb00c8553b79b2d” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “c8d0ecf5c22d5806a5af87953844408c” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “7db95ed8565bbdbfc5ed4c5e80c68a4f” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “387bb23a8901baa300e42ce92310530e” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “f0411cd79ef1b71082f0817fe17fe1e6” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “25afe34ab1b36cc1ee118c9165f8619c” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “1bb7ba760f7f7cba0addd4a273b464f6” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “922af695fe14a7f70f8e068dcadc0584” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “729c12997f9639810666bb171ea9241d” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”) OR exists descendant whose (md5 of it as lowercase = “729c12997f9639810666bb171ea9241d” as lowercase) of root folders of drives whose (type of it =“DRIVE_FIXED”)