Private/Kinds/ProgramElevated.ps1
|
# The ProgramElevated Kind: the running processes, read with admin rights. # # The Program Kind runs in the Main Part, in the session of the person whose machine this # is, and may not open the processes of another account: their GDI and USER objects, their # file and whether they are 32 or 64 bit stay unread. On a terminal server that is every # other user's programs. This Kind reads the same with admin rights and judges nothing: # the Program Check is handed its reading as $Observed['ProgramElevated'] and fills in # what it could not read itself. # # Its one Finding says that the reading was taken, so that the Check is accounted for in # the Report like any other. $script:ProgramElevatedNeedsAdmin = $true function Get-ProgramElevatedData { <# .SYNOPSIS Every running process and what it holds, as an administrator may read it. Decides nothing. #> [CmdletBinding()] [OutputType([psobject])] param([hashtable]$Parameters = @{}) [pscustomobject]@{ PSTypeName = 'Gutcheck.Data.ProgramElevated' Processes = @(Get-AppProcess -Pattern '.') } } function ConvertTo-ProgramElevatedFinding { <# .SYNOPSIS One Finding saying how many processes were read with admin rights. Pure. .DESCRIPTION No judgement: what a process holds is the Program Check's to judge, with the limits of its Definition. #> [CmdletBinding()] [OutputType([psobject])] param([AllowNull()]$Data, [hashtable]$Parameters = @{}) $processes = @((Get-DataCollection $Data 'Processes') | ForEach-Object { $_ }) if (-not $processes.Count) { return New-UnavailableFinding -Category Apps -Check (Get-Text 'Check.ProgramElevated.Reading') ` -Hint (Get-Text 'Hint.Program.NothingRead') } $opened = @($processes | Where-Object { $null -ne (Get-DataProperty $_ 'Gdi') }).Count New-Finding -Category Apps -Check (Get-Text 'Check.ProgramElevated.Reading') -Severity OK ` -Value ((Get-Text 'Value.ProgramElevated.Reading') -f $processes.Count, $opened) } |