public/Get-VPASActiveSessionProperties.ps1
<#
.Synopsis GET ACTIVE SESSION PROPERTIES CREATED BY: Vadim Melamed, EMAIL: vmelamed5@gmail.com .DESCRIPTION USE THIS FUNCTION TO GET ACTIVE PSM SESSION PROPERTIES .PARAMETER token HashTable of data containing various pieces of login information (PVWA, LoginToken, HeaderType, etc). If -token is not passed, function will use last known hashtable generated by New-VPASToken .PARAMETER SearchQuery Search string to find target resource via username, address, safe, platform, etc. Comma separated for multiple fields, or to search all pass a blank value like so: " " .PARAMETER ActiveSessionID Unique ID that maps to the target ActiveSession Supply the ActiveSessionID to skip any querying to find the target ActiveSession .EXAMPLE $GetActiveSessionPropertiesJSON = Get-VPASActiveSessionProperties -SearchQuery {SEARCHQUERY VALUE} .EXAMPLE $GetActiveSessionPropertiesJSON = Get-VPASActiveSessionProperties -ActiveSessionID {ACTIVE SESSION ID VALUE} .OUTPUTS If successful: { "CanTerminate": false, "CanMonitor": true, "CanSuspend": false, "SessionID": "31_24", "SessionGuid": "737160df-bba6-494f-875d-8bcf0f5ef9db", "SafeName": "PSMRecordings", "FolderName": "Root", "IsLive": true, "FileName": "737160df-bba6-494f-875d-8bcf0f5ef9db.session", "Start": 1724215310, "End": 0, "Duration": 260, "User": "administrator", "RemoteMachine": "192.168.20.126", "ProtectionDate": 0, "ProtectedBy": "", "ProtectionEnabled": false, "AccountUsername": "PSMTestUser", "AccountPlatformID": "WinServerLocal", "AccountAddress": "192.168.20.126", "PIMSuCommand": "", "PIMSuCWD": "", "ConnectionComponentID": "PSM-RDP", "PSMRecordingEntity": "SessionRecording", "TicketID": "", "FromIP": "192.168.20.1", "Protocol": "RDP", "Client": "RDP", "RiskScore": -1, "Severity": "", "IncidentDetails": null, "RawProperties": { "Address": "192.168.20.126", "ConnectionComponentID": "PSM-RDP", "DeviceType": "Operating System", "EntityVersion": "1.0", "ExpectedRecordingsList": "737160df-bba6-494f-875d-8bcf0f5ef9db.WIN.txt,737160df-bba6-494f-875d-8bcf0f5ef9db.VID.avi", "PSMClientApp": "mstsc.exe", "PSMPasswordID": "5", "PSMProtocol": "RDP", "PSMRecordingEntity": "SessionRecording", "PSMRemoteMachine": "192.168.20.126", "PSMSafeID": "28", "PSMSourceAddress": "192.168.20.1", "PSMStartTime": "1724215310", "PSMStatus": "Placeholder", "PSMVaultUserName": "administrator", "PolicyID": "WinServerLocal", "ProviderID": "PSMApp_COMPONENTS", "UserName": "PSMTestUser", "Safe": "PSMRecordings", "Folder": "Root", "Name": "737160df-bba6-494f-875d-8bcf0f5ef9db.session" }, "RecordingFiles": [ ], "RecordedActivities": null, "VideoSize": null, "TextSize": null, "DetailsUrl": null } --- $false if failed #> function Get-VPASActiveSessionProperties{ [OutputType('System.Object',[bool])] [CmdletBinding()] Param( [Parameter(Mandatory=$false,ValueFromPipelineByPropertyName=$true,Position=0)] [String]$SearchQuery, [Parameter(Mandatory=$false,ValueFromPipelineByPropertyName=$true,Position=1)] [String]$ActiveSessionID, [Parameter(Mandatory=$false,ValueFromPipelineByPropertyName=$true,Position=2)] [hashtable]$token ) Begin{ $tokenval,$sessionval,$PVWA,$Header,$ISPSS,$IdentityURL,$EnableTextRecorder,$AuditTimeStamp,$NoSSL,$VaultVersion,$HideWarnings,$AuthenticatedAs,$SubDomain = Get-VPASSession -token $token $CommandName = $MyInvocation.MyCommand.Name $log = Write-VPASTextRecorder -inputval $CommandName -token $token -LogType COMMAND } Process{ Write-Verbose "SUCCESSFULLY PARSED PVWA VALUE" Write-Verbose "SUCCESSFULLY PARSED TOKEN VALUE" try{ if([String]::IsNullOrEmpty($ActiveSessionID)){ Write-Verbose "NO ACTIVESESSIONID PROVIDED...INVOKING HELPER FUNCTION TO RETRIEVE UNIQUE ACTIVE SESSION ID BASED ON SPECIFIED PARAMETERS" $ActiveSessionID = Get-VPASActiveSessionIDHelper -token $token -SearchQuery $SearchQuery Write-Verbose "RETURNING ACTIVE SESSION ID" } else{ Write-Verbose "ACTIVE SESSION ID SUPPLIED, SKIPPING HELPER FUNCTION" } if($NoSSL){ Write-Verbose "NO SSL ENABLED, USING HTTP INSTEAD OF HTTPS" $uri = "http://$PVWA/PasswordVault/API/livesessions/$ActiveSessionID/properties/" } else{ Write-Verbose "SSL ENABLED BY DEFAULT, USING HTTPS" $uri = "https://$PVWA/PasswordVault/API/livesessions/$ActiveSessionID/properties/" } $log = Write-VPASTextRecorder -inputval $uri -token $token -LogType URI $log = Write-VPASTextRecorder -inputval "GET" -token $token -LogType METHOD write-verbose "MAKING API CALL TO CYBERARK" if($sessionval){ $response = Invoke-RestMethod -Headers @{"Authorization"=$Header} -Uri $uri -Method GET -ContentType "application/json" -WebSession $sessionval } else{ $response = Invoke-RestMethod -Headers @{"Authorization"=$Header} -Uri $uri -Method GET -ContentType "application/json" } $outputlog = $response $log = Write-VPASTextRecorder -inputval $outputlog -token $token -LogType RETURN Write-Verbose "RETURNING JSON OBJECT" return $response }catch{ $log = Write-VPASTextRecorder -inputval $_ -token $token -LogType ERROR $log = Write-VPASTextRecorder -inputval "REST API COMMAND RETURNED: FALSE" -token $token -LogType MISC Write-Verbose "UNABLE TO GET ACTIVE SESSION PROPERTIES" Write-VPASOutput -str $_ -type E return $false } } End{ $log = Write-VPASTextRecorder -inputval $CommandName -token $token -LogType DIVIDER } } |