Private/Rules/Find-IslSignatureIssue.ps1
|
function Find-IslSignatureIssue { <# .SYNOPSIS Flags a Win32 detection script that the agent will refuse to run under a signature check. .DESCRIPTION With "Enforce script signature check" on a Win32 PowerShell detection rule, the agent hands the script to AgentExecutor, which returns exit 1 without running it when the script is not signed (no probe record, log "EnforceSignatureCheck: 1 ... applicationDetected: False", W32-DET-SIGCHECK). The app is then "not detected", the install runs, and the app ends in 0x87D1041C, not detected after installation. The rule applies when the context says the check is on: -EnforceSignatureCheck on Test-IntuneScript, or the directive # IntuneScriptLab: EnforceSignatureCheck=true in the script. .PARAMETER Context The IntuneScriptLab.ScriptContext from Get-IslScriptContext: AST, tokens, bytes and the effective ScriptType, Context, Architecture and EnforceSignatureCheck. .EXAMPLE Find-IslSignatureIssue -Context (Get-IslScriptContext -Path .\Detect-App.ps1 -EnforceSignatureCheck) The findings this rule produces for one script, as IntuneScriptLab.Finding objects. #> [CmdletBinding()] param( [Parameter(Mandatory)] [pscustomobject]$Context ) $rule = 'IslSignatureIssue' if (-not $Context.EnforceSignatureCheck) { return } if ($Context.ScriptType -notin 'Win32Detection', 'Win32Requirement') { return } $signature = Get-AuthenticodeSignature -FilePath $Context.Path if ($signature.Status -eq 'Valid') { return } $phrase = if ($Context.ScriptType -eq 'Win32Detection') { 'detection' } else { 'requirement' } $outcome = if ($Context.ScriptType -eq 'Win32Detection') { 'the app is "not detected", the install runs and the app ends in 0x87D1041C' } else { 'the requirement is not met (observed for detection rules; assumed for requirement rules)' } $findingSplat = @{ RuleName = $rule Severity = 'Error' Context = $Context Extent = $Context.Ast.Extent Message = ("Signature status $($signature.Status): with the signature check enforced the agent " + "does not run an unsigned $phrase script at all, and $outcome. Sign the script or turn the " + 'check off on the rule') Evidence = ('Unsigned detection script with enforceSignatureCheck: no probe record, AgentExecutor ' + 'exit 1, "EnforceSignatureCheck: 1 ... applicationDetected: False", install ran, 0x87D1041C ' + '(W32-DET-SIGCHECK)') } New-IslFinding @findingSplat } |