diff --git a/Private/ConvertFrom-XMLRSOP.ps1 b/Private/ConvertFrom-XMLRSOP.ps1
index d680974..f4f0323 100644
--- a/Private/ConvertFrom-XMLRSOP.ps1
+++ b/Private/ConvertFrom-XMLRSOP.ps1
@@ -16,6 +16,7 @@
GroupPoliciesLinks = $null
GroupPoliciesApplied = $null
GroupPoliciesDenied = $null
+ Results = [ordered]@{}
}
$Object = [ordered] @{
@@ -39,7 +40,7 @@
[PSCustomObject] @{
Name = $GPO.Name
#Path = $GPO.Path
- Identifier = $GPO.Path.Identifier.'#text'
+ GUID = $GPO.Path.Identifier.'#text'
DomainName = $GPO.Path.Domain.'#text'
#VersionDirectory = $GPO.VersionDirectory
#VersionSysvol = $GPO.VersionSysvol
@@ -55,6 +56,21 @@
ExtensionName = $GPO.ExtensionName -join '; '
}
}
+ [Array] $GPOPrimary['GroupPoliciesLinks'] = foreach ($GPO in $Content.$ResultsType.GPO) {
+ foreach ($Link in $GPO.Link) {
+ [PSCustomObject] @{
+ DisplayName = $GPO.Name
+ DomainName = $GPO.Path.Domain.'#text'
+ GUID = $GPO.Path.Identifier.'#text'
+ SOMPath = $Link.SOMPath # : ad.evotec.xyz
+ SOMOrder = $Link.SOMOrder # : 2
+ AppliedOrder = $Link.AppliedOrder # : 0
+ LinkOrder = $Link.LinkOrder # : 4
+ Enabled = if ($Link.Enabled -eq 'true') { $true } else { $false }; # : true
+ NoOverride = if ($Link.NoOverride -eq 'true') { $true } else { $false }; # : true
+ }
+ }
+ }
[Array] $GPOPrimary['ScopeOfManagement'] = foreach ($SOM in $Content.$ResultsType.SearchedSOM) {
[PSCustomObject] @{
@@ -66,29 +82,6 @@
Reason = if ($SOM.Reason -eq 'true') { $true } else { $false };
}
}
-
- $GPOPrimary['SummaryDetails'] = [Ordered] @{
- ActivityId = $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.ActivityId # : {6400d0bf-ac88-4ee6-b2c2-ca2cbbab0695}
- ProcessingTrigger = $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.ProcessingTrigger # : Periodic
- ProcessingAppMode = $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.ProcessingAppMode # : Background
- LinkSpeedInKbps = $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.LinkSpeedInKbps # : 0
- SlowLinkThresholdInKbps = $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.SlowLinkThresholdInKbps # : 500
- DomainControllerName = $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.DomainControllerName # : AD1.ad.evotec.xyz
- DomainControllerIPAddress = $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.DomainControllerIPAddress # : 192.168.240.189
- PolicyProcessingMode = $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.PolicyProcessingMode # : None
- PolicyElapsedTimeInMilliseconds = $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.PolicyElapsedTimeInMilliseconds # : 1202
- ErrorCount = $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.ErrorCount # : 0
- WarningCount = $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.WarningCount # : 0
- }
-
- [Array] $GPOPrimary['ProcessingTime'] = foreach ($Details in $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.ExtensionProcessingTime) {
- [PSCustomObject] @{
- ExtensionName = $Details.ExtensionName
- ExtensionGuid = $Details.ExtensionGuid
- ElapsedTimeInMilliseconds = $Details.ElapsedTimeInMilliseconds
- ProcessedTimeStamp = $Details.ProcessedTimeStamp
- }
- }
[Array] $GPOPrimary['ExtensionStatus'] = foreach ($Details in $Content.$ResultsType.ExtensionStatus) {
[PSCustomObject] @{
Name = $Details.Name # : Registry
@@ -101,105 +94,127 @@
}
[Array] $GPOPrimary['ExtensionData'] = $Content.$ResultsType.ExtensionData.Extension
- $EventsLevel = @{
- '5' = 'Verbose'
- '4' = 'Informational'
- '3' = 'Warning'
- '2' = 'Error'
- '1' = 'Critical'
- '0' = 'LogAlways'
- }
- $EventsReason = @{
- 'NOTAPPLIED-EMPTY' = 'Not Applied (Empty)'
- 'DENIED-WMIFILTER' = 'Denied (WMI Filter)'
- 'DENIED-SECURITY' = 'Denied (Security)'
- }
- [Array] $GPOPrimary['Events'] = foreach ($Event in $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.EventRecord) {
- [xml] $EventDetails = $Event.EventXML
- $EventInformation = [ordered] @{
- Description = $Event.EventDescription
- Provider = $EventDetails.Event.System.Provider.Name # : Provider
- ProviderGUID = $EventDetails.Event.System.Provider.Guid
- EventID = $EventDetails.Event.System.EventID # : 4006
- Version = $EventDetails.Event.System.Version # : 1
- Level = $EventsLevel[$EventDetails.Event.System.Level] # : 4
- Task = $EventDetails.Event.System.Task # : 0
- Opcode = $EventDetails.Event.System.Opcode # : 1
- Keywords = $EventDetails.Event.System.Keywords # : 0x4000000000000000
- TimeCreated = [DateTime] $EventDetails.Event.System.TimeCreated.SystemTime # : TimeCreated, 2020-08-09T20:16:44.5668052Z
- EventRecordID = $EventDetails.Event.System.EventRecordID # : 10641325
- Correlation = $EventDetails.Event.System.Correlation.ActivityID # : Correlation
- Execution = -join ("ProcessID: ", $EventDetails.Event.System.Execution.ProcessID, " ThreadID: ", $EventDetails.Event.System.Execution.ThreadID) # : Execution
- Channel = $EventDetails.Event.System.Channel # : Microsoft-Windows-GroupPolicy / Operational
- Computer = $EventDetails.Event.System.Computer # : AD1.ad.evotec.xyz
- Security = $EventDetails.Event.System.Security.UserID # : Security
+ foreach ($Single in $Content.$ResultsType.EventsDetails.SinglePassEventsDetails) {
+ $GPOPrimary['Results']["$($Single.ActivityId)"] = [ordered] @{}
+ $GPOPrimary['Results']["$($Single.ActivityId)"]['SummaryDetails'] = [Ordered] @{
+ ActivityId = $Single.ActivityId # : {6400d0bf-ac88-4ee6-b2c2-ca2cbbab0695}
+ ProcessingTrigger = $Single.ProcessingTrigger # : Periodic
+ ProcessingAppMode = $Single.ProcessingAppMode # : Background
+ LinkSpeedInKbps = $Single.LinkSpeedInKbps # : 0
+ SlowLinkThresholdInKbps = $Single.SlowLinkThresholdInKbps # : 500
+ DomainControllerName = $Single.DomainControllerName # : AD1.ad.evotec.xyz
+ DomainControllerIPAddress = $Single.DomainControllerIPAddress # : 192.168.240.189
+ PolicyProcessingMode = $Single.PolicyProcessingMode # : None
+ PolicyElapsedTimeInMilliseconds = $Single.PolicyElapsedTimeInMilliseconds # : 1202
+ ErrorCount = $Single.ErrorCount # : 0
+ WarningCount = $Single.WarningCount # : 0
}
- foreach ($Entry in $EventDetails.Event.EventData.Data) {
- $EventInformation["$($Entry.Name)"] = $Entry.'#text'
- }
- [PSCustomObject] $EventInformation
- }
- # Lets build events by ID, this will be useful for better/easier processing
- $GPOPrimary['EventsByID'] = [ordered] @{}
- $GroupedEvents = $GPOPrimary['Events'] | Group-Object -Property EventId
- foreach ($Events in $GroupedEvents) {
- $GPOPrimary['EventsByID'][$Events.Name] = $Events.Group
- }
-
-
- $GPOPrimary['News'] = foreach ($Event in $GPOPrimary['Events']) {
-
- #$Event
- }
-
- $GPOPrimary['GroupPoliciesApplied'] = & {
- if ($GPOPrimary['EventsByID']['5312']) {
- [xml] $GPODetailsApplied = -join ('', $GPOPrimary['EventsByID']['5312'].GPOinfoList, ' ')
- foreach ($GPO in $GPODetailsApplied.Details.GPO) {
- $ReturnObject = [ordered] @{
- GUID = $GPO.ID # : { 4E1F9C70-1DDB-4AB6-BBA3-14A8E07F0B4B }
- DisplayName = $GPO.Name # : DC | Event Log Settings
- Version = $GPO.Version # : 851981
- Link = $GPO.SOM # : LDAP: / / OU = Domain Controllers, DC = ad, DC = evotec, DC = xyz
- SysvolPath = $GPO.FSPath # : \\ad.evotec.xyz\SysVol\ad.evotec.xyz\Policies\ { 4E1F9C70-1DDB-4AB6-BBA3-14A8E07F0B4B }\Machine
- #GPOTypes = $GPO.Extensions -join '; ' # : [ { 35378EAC-683F-11D2-A89A-00C04FBBCFA2 } { D02B1F72 - 3407 - 48AE-BA88-E8213C6761F1 }]
- }
- $TranslatedExtensions = foreach ($Extension in $GPO.Extensions) {
- ConvertFrom-CSExtension -CSE $Extension -Limited
- }
- $ReturnObject['GPOTypes'] = $TranslatedExtensions -join '; '
- [PSCustomObject] $ReturnObject
- }
- }
- }
- $GPOPrimary['GroupPoliciesDenied'] = & {
- if ($GPOPrimary['EventsByID']['5312']) {
- [xml] $GPODetailsDenied = -join ('', $GPOPrimary['EventsByID']['5313'].GPOinfoList, ' ')
- foreach ($GPO in $GPODetailsDenied.Details.GPO) {
- [PSCustomObject] @{
- GUID = $GPO.ID #: { 6AC1786C-016F-11D2-945F-00C04fB984F9 }
- DisplayName = $GPO.Name #: Default Domain Controllers Policy
- Version = $GPO.Version #: 131074
- Link = $GPO.SOM #: LDAP: / / OU = Domain Controllers, DC = ad, DC = evotec, DC = xyz
- SysvolPath = $GPO.FSPath #: \\ad.evotec.xyz\sysvol\ad.evotec.xyz\Policies\ { 6AC1786C-016F-11D2-945F-00C04fB984F9 }\Machine
- Reason = $EventsReason["$($GPO.Reason)"] #: DENIED-WMIFILTER
- }
- }
- }
- }
-
- $GPOPrimary['SummaryDownload'] = & {
- if ($GPOPrimary['EventsByID']['5126']) {
+ [Array] $GPOPrimary['Results']["$($Single.ActivityId)"]['ProcessingTime'] = foreach ($Details in $Single.ExtensionProcessingTime) {
[PSCustomObject] @{
- IsBackgroundProcessing = if ($GPOPrimary['EventsByID']['5126'].IsBackgroundProcessing -eq 'true') { $true } else { $false }; # : true
- IsAsyncProcessing = if ($GPOPrimary['EventsByID']['5126'].IsAsyncProcessing -eq 'true') { $true } else { $false }; # : false
- Downloaded = $GPOPrimary['EventsByID']['5126'].NumberOfGPOsDownloaded # : 7
- Applicable = $GPOPrimary['EventsByID']['5126'].NumberOfGPOsApplicable # : 6
- DownloadTimeMiliseconds = $GPOPrimary['EventsByID']['5126'].GPODownloadTimeElapsedInMilliseconds # : 375
+ ExtensionName = $Details.ExtensionName
+ ExtensionGuid = $Details.ExtensionGuid
+ ElapsedTimeInMilliseconds = $Details.ElapsedTimeInMilliseconds
+ ProcessedTimeStamp = $Details.ProcessedTimeStamp
}
+ }
+
+ $EventsLevel = @{
+ '5' = 'Verbose'
+ '4' = 'Informational'
+ '3' = 'Warning'
+ '2' = 'Error'
+ '1' = 'Critical'
+ '0' = 'LogAlways'
+ }
+ $EventsReason = @{
+ 'NOTAPPLIED-EMPTY' = 'Not Applied (Empty)'
+ 'DENIED-WMIFILTER' = 'Denied (WMI Filter)'
+ 'DENIED-SECURITY' = 'Denied (Security)'
+ }
+
+ [Array] $GPOPrimary['Results']["$($Single.ActivityId)"]['Events'] = foreach ($Event in $Single.EventRecord) {
+ [xml] $EventDetails = $Event.EventXML
+ $EventInformation = [ordered] @{
+ Description = $Event.EventDescription
+ Provider = $EventDetails.Event.System.Provider.Name # : Provider
+ ProviderGUID = $EventDetails.Event.System.Provider.Guid
+ EventID = $EventDetails.Event.System.EventID # : 4006
+ Version = $EventDetails.Event.System.Version # : 1
+ Level = $EventsLevel[$EventDetails.Event.System.Level] # : 4
+ Task = $EventDetails.Event.System.Task # : 0
+ Opcode = $EventDetails.Event.System.Opcode # : 1
+ Keywords = $EventDetails.Event.System.Keywords # : 0x4000000000000000
+ TimeCreated = [DateTime] $EventDetails.Event.System.TimeCreated.SystemTime # : TimeCreated, 2020-08-09T20:16:44.5668052Z
+ EventRecordID = $EventDetails.Event.System.EventRecordID # : 10641325
+ Correlation = $EventDetails.Event.System.Correlation.ActivityID # : Correlation
+ Execution = -join ("ProcessID: ", $EventDetails.Event.System.Execution.ProcessID, " ThreadID: ", $EventDetails.Event.System.Execution.ThreadID) # : Execution
+ Channel = $EventDetails.Event.System.Channel # : Microsoft-Windows-GroupPolicy / Operational
+ Computer = $EventDetails.Event.System.Computer # : AD1.ad.evotec.xyz
+ Security = $EventDetails.Event.System.Security.UserID # : Security
+ }
+ foreach ($Entry in $EventDetails.Event.EventData.Data) {
+ $EventInformation["$($Entry.Name)"] = $Entry.'#text'
+ }
+ [PSCustomObject] $EventInformation
+ }
+
+ # Lets build events by ID, this will be useful for better/easier processing
+ $GPOPrimary['Results']["$($Single.ActivityId)"]['EventsByID'] = [ordered] @{}
+ $GroupedEvents = $GPOPrimary['Results']["$($Single.ActivityId)"]['Events'] | Group-Object -Property EventId
+ foreach ($Events in $GroupedEvents) {
+ $GPOPrimary['Results']["$($Single.ActivityId)"]['EventsByID'][$Events.Name] = $Events.Group
+ }
+
+ $GPOPrimary['Results']["$($Single.ActivityId)"]['GroupPoliciesApplied'] = & {
+ if ($GPOPrimary['Results']["$($Single.ActivityId)"]['EventsByID']['5312']) {
+ [xml] $GPODetailsApplied = -join ('', $GPOPrimary['Results']["$($Single.ActivityId)"]['EventsByID']['5312'].GPOinfoList, ' ')
+ foreach ($GPO in $GPODetailsApplied.Details.GPO) {
+ $ReturnObject = [ordered] @{
+ GUID = $GPO.ID # : { 4E1F9C70-1DDB-4AB6-BBA3-14A8E07F0B4B }
+ DisplayName = $GPO.Name # : DC | Event Log Settings
+ Version = $GPO.Version # : 851981
+ Link = $GPO.SOM # : LDAP: / / OU = Domain Controllers, DC = ad, DC = evotec, DC = xyz
+ SysvolPath = $GPO.FSPath # : \\ad.evotec.xyz\SysVol\ad.evotec.xyz\Policies\ { 4E1F9C70-1DDB-4AB6-BBA3-14A8E07F0B4B }\Machine
+ #GPOTypes = $GPO.Extensions -join '; ' # : [ { 35378EAC-683F-11D2-A89A-00C04FBBCFA2 } { D02B1F72 - 3407 - 48AE-BA88-E8213C6761F1 }]
+ }
+ $TranslatedExtensions = foreach ($Extension in $GPO.Extensions) {
+ ConvertFrom-CSExtension -CSE $Extension -Limited
+ }
+ $ReturnObject['GPOTypes'] = $TranslatedExtensions -join '; '
+ [PSCustomObject] $ReturnObject
+ }
+ }
+ }
+ $GPOPrimary['Results']["$($Single.ActivityId)"]['GroupPoliciesDenied'] = & {
+ if ($GPOPrimary['Results']["$($Single.ActivityId)"]['EventsByID']['5312']) {
+ [xml] $GPODetailsDenied = -join ('', $GPOPrimary['Results']["$($Single.ActivityId)"]['EventsByID']['5313'].GPOinfoList, ' ')
+ foreach ($GPO in $GPODetailsDenied.Details.GPO) {
+ [PSCustomObject] @{
+ GUID = $GPO.ID #: { 6AC1786C-016F-11D2-945F-00C04fB984F9 }
+ DisplayName = $GPO.Name #: Default Domain Controllers Policy
+ Version = $GPO.Version #: 131074
+ Link = $GPO.SOM #: LDAP: / / OU = Domain Controllers, DC = ad, DC = evotec, DC = xyz
+ SysvolPath = $GPO.FSPath #: \\ad.evotec.xyz\sysvol\ad.evotec.xyz\Policies\ { 6AC1786C-016F-11D2-945F-00C04fB984F9 }\Machine
+ Reason = $EventsReason["$($GPO.Reason)"] #: DENIED-WMIFILTER
+ }
+ }
+ }
+ }
+
+ $GPOPrimary['Results']["$($Single.ActivityId)"]['SummaryDownload'] = & {
+ if ($GPOPrimary['Results']["$($Single.ActivityId)"]['EventsByID']['5126']) {
+ [PSCustomObject] @{
+ IsBackgroundProcessing = if ($GPOPrimary['Results']["$($Single.ActivityId)"]['EventsByID']['5126'].IsBackgroundProcessing -eq 'true') { $true } else { $false }; # : true
+ IsAsyncProcessing = if ($GPOPrimary['Results']["$($Single.ActivityId)"]['EventsByID']['5126'].IsAsyncProcessing -eq 'true') { $true } else { $false }; # : false
+ Downloaded = $GPOPrimary['Results']["$($Single.ActivityId)"]['EventsByID']['5126'].NumberOfGPOsDownloaded # : 7
+ Applicable = $GPOPrimary['Results']["$($Single.ActivityId)"]['EventsByID']['5126'].NumberOfGPOsApplicable # : 6
+ DownloadTimeMiliseconds = $GPOPrimary['Results']["$($Single.ActivityId)"]['EventsByID']['5126'].GPODownloadTimeElapsedInMilliseconds # : 375
+ }
+
+ }
}
}
$GPOPrimary
diff --git a/Private/New-GPOZaurrReportHTML.ps1 b/Private/New-GPOZaurrReportHTML.ps1
index 69ba08b..84db051 100644
--- a/Private/New-GPOZaurrReportHTML.ps1
+++ b/Private/New-GPOZaurrReportHTML.ps1
@@ -13,9 +13,9 @@ function New-GPOZaurrReportHTML {
$Path = [io.path]::GetTempFileName().Replace('.tmp', ".html")
}
$ComputerName = $($Support.ResultantSetPolicy.LoggingComputer)
- $UserName = $($Support.ResultantSetPolicy.UserName)
- $LoggingMode = $($Support.ResultantSetPolicy.LoggingMode)
- New-HTML -TitleText "Group Policy Report - $ComputerName / $UserName / $LoggingMode" {
+ #$UserName = $($Support.ResultantSetPolicy.UserName)
+ #$LoggingMode = $($Support.ResultantSetPolicy.LoggingMode)
+ New-HTML -TitleText "Group Policy Report - $ComputerName" {
#New-HTMLTabOptions -SlimTabs -Transition -LinearGradient -SelectorColor Akaroa
New-HTMLTabOptions -SlimTabs `
-BorderBottomStyleActive solid -BorderBottomColorActive LightSkyBlue -BackgroundColorActive none `
@@ -57,6 +57,9 @@ function New-GPOZaurrReportHTML {
New-HTMLSection -HeaderText 'Group Policies' {
New-HTMLTable -DataTable $Support.$Key.GroupPolicies -Filtering
}
+ New-HTMLSection -HeaderText 'Group Policies Links' {
+ New-HTMLTable -DataTable $Support.$Key.GroupPoliciesLinks -Filtering
+ }
New-HTMLSection -HeaderText 'Group Policies Applied' {
New-HTMLTable -DataTable $Support.$Key.GroupPoliciesApplied -Filtering
}