Private/Rules/Find-IslExecutionPolicyCall.ps1

function Find-IslExecutionPolicyCall {
    <#
    .SYNOPSIS
        Flags Set-ExecutionPolicy calls, which the agent's own launch makes redundant or harmful.
 
    .DESCRIPTION
        Every script the agent runs is launched as
        powershell.exe -NoProfile -ExecutionPolicy Bypass -File <script> (AgentExecutor.log, all
        rounds), so the process already runs with Bypass and a Set-ExecutionPolicy -Scope Process
        changes nothing. Any other scope is a change to the machine or the user policy made as
        SYSTEM on every run: a side effect that outlives the script and does nothing for it.
 
    .PARAMETER Context
        The IntuneScriptLab.ScriptContext from Get-IslScriptContext: AST, tokens, bytes and the
        effective ScriptType, Context and Architecture.
 
    .EXAMPLE
        Find-IslExecutionPolicyCall -Context (Get-IslScriptContext -Path .\Detect.ps1)
 
        The findings this rule produces for one script, as IntuneScriptLab.Finding objects.
    #>

    [CmdletBinding()]
    param(
        [Parameter(Mandatory)]
        [pscustomobject]$Context
    )

    $rule = 'IslExecutionPolicyCall'
    $evidence = ('AgentExecutor launches every script with -NoProfile -ExecutionPolicy Bypass -File ' +
        '(AgentExecutor.log); Get-ExecutionPolicy -List inside a remediation reported the process scope as ' +
        'Bypass with the machine scopes untouched (REM-EXECPOLICY)')

    foreach ($command in (Find-IslCommand -Ast $Context.Ast -Name 'Set-ExecutionPolicy')) {
        $elements = $command.CommandElements
        $scope = 'LocalMachine'
        for ($i = 1; $i -lt $elements.Count; $i++) {
            $element = $elements[$i]
            $next = if ($i + 1 -lt $elements.Count) { $elements[$i + 1] } else { $null }
            if ($element.GetType().Name -eq 'CommandParameterAst' -and
                'Scope'.StartsWith($element.ParameterName, 'OrdinalIgnoreCase') -and $next) {
                $scope = $next.Extent.Text.Trim("'", '"')
            }
        }
        if ($scope -eq 'Process') {
            $findingSplat = @{
                RuleName = $rule
                Severity = 'Information'
                Context  = $Context
                Extent   = $command.Extent
                Message  = ('Set-ExecutionPolicy -Scope Process does nothing here: the agent already launches ' +
                    'the script with -ExecutionPolicy Bypass')
                Evidence = $evidence
            }
        }
        else {
            $findingSplat = @{
                RuleName = $rule
                Severity = 'Warning'
                Context  = $Context
                Extent   = $command.Extent
                Message  = ("Set-ExecutionPolicy with scope $scope changes the device's policy on every run and " +
                    'does nothing for this script, which the agent launches with -ExecutionPolicy Bypass. ' +
                    'Remove it')
                Evidence = $evidence
            }
        }
        New-IslFinding @findingSplat
    }
}