Private/Kinds/ProgramElevated.ps1

# The ProgramElevated Kind: the running processes, read with admin rights.
#
# The Program Kind runs in the Main Part, in the session of the person whose machine this
# is, and may not open the processes of another account: their GDI and USER objects, their
# file and whether they are 32 or 64 bit stay unread. On a terminal server that is every
# other user's programs. This Kind reads the same with admin rights and judges nothing:
# the Program Check is handed its reading as $Observed['ProgramElevated'] and fills in
# what it could not read itself.
#
# Its one Finding says that the reading was taken, so that the Check is accounted for in
# the Report like any other.

$script:ProgramElevatedNeedsAdmin = $true

function Get-ProgramElevatedData {
    <#
    .SYNOPSIS
        Every running process and what it holds, as an administrator may read it.
        Decides nothing.
    #>

    [CmdletBinding()]
    [OutputType([psobject])]
    param([hashtable]$Parameters = @{})

    [pscustomobject]@{
        PSTypeName = 'Gutcheck.Data.ProgramElevated'
        Processes  = @(Get-AppProcess -Pattern '.')
    }
}

function ConvertTo-ProgramElevatedFinding {
    <#
    .SYNOPSIS
        One Finding saying how many processes were read with admin rights. Pure.
    .DESCRIPTION
        No judgement: what a process holds is the Program Check's to judge, with the
        limits of its Definition.
    #>

    [CmdletBinding()]
    [OutputType([psobject])]
    param([AllowNull()]$Data, [hashtable]$Parameters = @{})

    $processes = @((Get-DataCollection $Data 'Processes') | ForEach-Object { $_ })
    if (-not $processes.Count) {
        return New-UnavailableFinding -Category Apps -Check (Get-Text 'Check.ProgramElevated.Reading') `
            -Hint (Get-Text 'Hint.Program.NothingRead')
    }

    $opened = @($processes | Where-Object { $null -ne (Get-DataProperty $_ 'Gdi') }).Count
    New-Finding -Category Apps -Check (Get-Text 'Check.ProgramElevated.Reading') -Severity OK `
        -Value ((Get-Text 'Value.ProgramElevated.Reading') -f $processes.Count, $opened)
}