Private/Resolve-IslRulePath.ps1

function Resolve-IslRulePath {
    <#
    .SYNOPSIS
        Expands a file rule's path the way the agent does, in the 64-bit or the 32-bit context.
 
    .DESCRIPTION
        A file rule's path may hold %VARIABLE% references. The agent expands them in the 64-bit
        context by default, so %ProgramFiles% is C:\Program Files even though the agent itself is a
        32-bit process; with check32BitOn64System it expands them in the 32-bit context, where
        %ProgramFiles% and %CommonProgramFiles% are the (x86) folders (W32-FILE-PF-32 found a file
        that only existed under Program Files (x86); W32-FILE-PF-64 did not). On a 32-bit device
        there is only one context.
 
    .PARAMETER Path
        The folder part of the rule, with or without %VARIABLE% references.
 
    .PARAMETER Check32BitOn64System
        Expand in the 32-bit context on a 64-bit device.
 
    .EXAMPLE
        Resolve-IslRulePath -Path '%ProgramFiles%\Vendor' -Check32BitOn64System $true
 
        C:\Program Files (x86)\Vendor on a 64-bit device.
    #>

    [CmdletBinding()]
    [OutputType([string])]
    param(
        [Parameter(Mandatory)]
        [string]$Path,

        [bool]$Check32BitOn64System
    )

    $expanded = $Path
    if ($Check32BitOn64System -and [Environment]::Is64BitOperatingSystem) {
        # The variables whose value differs between the two contexts, substituted before the general
        # expansion so the rest of the string still expands normally
        $x86ProgramFiles = ${env:ProgramFiles(x86)}
        $x86Common = ${env:CommonProgramFiles(x86)}
        if ($x86ProgramFiles) { $expanded = $expanded -replace '(?i)%ProgramFiles%', $x86ProgramFiles }
        if ($x86Common) { $expanded = $expanded -replace '(?i)%CommonProgramFiles%', $x86Common }
    }
    [Environment]::ExpandEnvironmentVariables($expanded)
}