From 603de5a42e928b2d4314278efec274c7cdcbff82 Mon Sep 17 00:00:00 2001 From: Przemyslaw Klys Date: Thu, 13 Aug 2020 22:02:48 +0200 Subject: [PATCH] Update --- Private/ConvertFrom-XMLRSOP.ps1 | 249 +++++++++++++++-------------- Private/New-GPOZaurrReportHTML.ps1 | 9 +- 2 files changed, 138 insertions(+), 120 deletions(-) diff --git a/Private/ConvertFrom-XMLRSOP.ps1 b/Private/ConvertFrom-XMLRSOP.ps1 index d680974..f4f0323 100644 --- a/Private/ConvertFrom-XMLRSOP.ps1 +++ b/Private/ConvertFrom-XMLRSOP.ps1 @@ -16,6 +16,7 @@ GroupPoliciesLinks = $null GroupPoliciesApplied = $null GroupPoliciesDenied = $null + Results = [ordered]@{} } $Object = [ordered] @{ @@ -39,7 +40,7 @@ [PSCustomObject] @{ Name = $GPO.Name #Path = $GPO.Path - Identifier = $GPO.Path.Identifier.'#text' + GUID = $GPO.Path.Identifier.'#text' DomainName = $GPO.Path.Domain.'#text' #VersionDirectory = $GPO.VersionDirectory #VersionSysvol = $GPO.VersionSysvol @@ -55,6 +56,21 @@ ExtensionName = $GPO.ExtensionName -join '; ' } } + [Array] $GPOPrimary['GroupPoliciesLinks'] = foreach ($GPO in $Content.$ResultsType.GPO) { + foreach ($Link in $GPO.Link) { + [PSCustomObject] @{ + DisplayName = $GPO.Name + DomainName = $GPO.Path.Domain.'#text' + GUID = $GPO.Path.Identifier.'#text' + SOMPath = $Link.SOMPath # : ad.evotec.xyz + SOMOrder = $Link.SOMOrder # : 2 + AppliedOrder = $Link.AppliedOrder # : 0 + LinkOrder = $Link.LinkOrder # : 4 + Enabled = if ($Link.Enabled -eq 'true') { $true } else { $false }; # : true + NoOverride = if ($Link.NoOverride -eq 'true') { $true } else { $false }; # : true + } + } + } [Array] $GPOPrimary['ScopeOfManagement'] = foreach ($SOM in $Content.$ResultsType.SearchedSOM) { [PSCustomObject] @{ @@ -66,29 +82,6 @@ Reason = if ($SOM.Reason -eq 'true') { $true } else { $false }; } } - - $GPOPrimary['SummaryDetails'] = [Ordered] @{ - ActivityId = $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.ActivityId # : {6400d0bf-ac88-4ee6-b2c2-ca2cbbab0695} - ProcessingTrigger = $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.ProcessingTrigger # : Periodic - ProcessingAppMode = $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.ProcessingAppMode # : Background - LinkSpeedInKbps = $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.LinkSpeedInKbps # : 0 - SlowLinkThresholdInKbps = $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.SlowLinkThresholdInKbps # : 500 - DomainControllerName = $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.DomainControllerName # : AD1.ad.evotec.xyz - DomainControllerIPAddress = $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.DomainControllerIPAddress # : 192.168.240.189 - PolicyProcessingMode = $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.PolicyProcessingMode # : None - PolicyElapsedTimeInMilliseconds = $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.PolicyElapsedTimeInMilliseconds # : 1202 - ErrorCount = $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.ErrorCount # : 0 - WarningCount = $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.WarningCount # : 0 - } - - [Array] $GPOPrimary['ProcessingTime'] = foreach ($Details in $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.ExtensionProcessingTime) { - [PSCustomObject] @{ - ExtensionName = $Details.ExtensionName - ExtensionGuid = $Details.ExtensionGuid - ElapsedTimeInMilliseconds = $Details.ElapsedTimeInMilliseconds - ProcessedTimeStamp = $Details.ProcessedTimeStamp - } - } [Array] $GPOPrimary['ExtensionStatus'] = foreach ($Details in $Content.$ResultsType.ExtensionStatus) { [PSCustomObject] @{ Name = $Details.Name # : Registry @@ -101,105 +94,127 @@ } [Array] $GPOPrimary['ExtensionData'] = $Content.$ResultsType.ExtensionData.Extension - $EventsLevel = @{ - '5' = 'Verbose' - '4' = 'Informational' - '3' = 'Warning' - '2' = 'Error' - '1' = 'Critical' - '0' = 'LogAlways' - } - $EventsReason = @{ - 'NOTAPPLIED-EMPTY' = 'Not Applied (Empty)' - 'DENIED-WMIFILTER' = 'Denied (WMI Filter)' - 'DENIED-SECURITY' = 'Denied (Security)' - } - [Array] $GPOPrimary['Events'] = foreach ($Event in $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.EventRecord) { - [xml] $EventDetails = $Event.EventXML - $EventInformation = [ordered] @{ - Description = $Event.EventDescription - Provider = $EventDetails.Event.System.Provider.Name # : Provider - ProviderGUID = $EventDetails.Event.System.Provider.Guid - EventID = $EventDetails.Event.System.EventID # : 4006 - Version = $EventDetails.Event.System.Version # : 1 - Level = $EventsLevel[$EventDetails.Event.System.Level] # : 4 - Task = $EventDetails.Event.System.Task # : 0 - Opcode = $EventDetails.Event.System.Opcode # : 1 - Keywords = $EventDetails.Event.System.Keywords # : 0x4000000000000000 - TimeCreated = [DateTime] $EventDetails.Event.System.TimeCreated.SystemTime # : TimeCreated, 2020-08-09T20:16:44.5668052Z - EventRecordID = $EventDetails.Event.System.EventRecordID # : 10641325 - Correlation = $EventDetails.Event.System.Correlation.ActivityID # : Correlation - Execution = -join ("ProcessID: ", $EventDetails.Event.System.Execution.ProcessID, " ThreadID: ", $EventDetails.Event.System.Execution.ThreadID) # : Execution - Channel = $EventDetails.Event.System.Channel # : Microsoft-Windows-GroupPolicy / Operational - Computer = $EventDetails.Event.System.Computer # : AD1.ad.evotec.xyz - Security = $EventDetails.Event.System.Security.UserID # : Security + foreach ($Single in $Content.$ResultsType.EventsDetails.SinglePassEventsDetails) { + $GPOPrimary['Results']["$($Single.ActivityId)"] = [ordered] @{} + $GPOPrimary['Results']["$($Single.ActivityId)"]['SummaryDetails'] = [Ordered] @{ + ActivityId = $Single.ActivityId # : {6400d0bf-ac88-4ee6-b2c2-ca2cbbab0695} + ProcessingTrigger = $Single.ProcessingTrigger # : Periodic + ProcessingAppMode = $Single.ProcessingAppMode # : Background + LinkSpeedInKbps = $Single.LinkSpeedInKbps # : 0 + SlowLinkThresholdInKbps = $Single.SlowLinkThresholdInKbps # : 500 + DomainControllerName = $Single.DomainControllerName # : AD1.ad.evotec.xyz + DomainControllerIPAddress = $Single.DomainControllerIPAddress # : 192.168.240.189 + PolicyProcessingMode = $Single.PolicyProcessingMode # : None + PolicyElapsedTimeInMilliseconds = $Single.PolicyElapsedTimeInMilliseconds # : 1202 + ErrorCount = $Single.ErrorCount # : 0 + WarningCount = $Single.WarningCount # : 0 } - foreach ($Entry in $EventDetails.Event.EventData.Data) { - $EventInformation["$($Entry.Name)"] = $Entry.'#text' - } - [PSCustomObject] $EventInformation - } - # Lets build events by ID, this will be useful for better/easier processing - $GPOPrimary['EventsByID'] = [ordered] @{} - $GroupedEvents = $GPOPrimary['Events'] | Group-Object -Property EventId - foreach ($Events in $GroupedEvents) { - $GPOPrimary['EventsByID'][$Events.Name] = $Events.Group - } - - - $GPOPrimary['News'] = foreach ($Event in $GPOPrimary['Events']) { - - #$Event - } - - $GPOPrimary['GroupPoliciesApplied'] = & { - if ($GPOPrimary['EventsByID']['5312']) { - [xml] $GPODetailsApplied = -join ('
', $GPOPrimary['EventsByID']['5312'].GPOinfoList, '
') - foreach ($GPO in $GPODetailsApplied.Details.GPO) { - $ReturnObject = [ordered] @{ - GUID = $GPO.ID # : { 4E1F9C70-1DDB-4AB6-BBA3-14A8E07F0B4B } - DisplayName = $GPO.Name # : DC | Event Log Settings - Version = $GPO.Version # : 851981 - Link = $GPO.SOM # : LDAP: / / OU = Domain Controllers, DC = ad, DC = evotec, DC = xyz - SysvolPath = $GPO.FSPath # : \\ad.evotec.xyz\SysVol\ad.evotec.xyz\Policies\ { 4E1F9C70-1DDB-4AB6-BBA3-14A8E07F0B4B }\Machine - #GPOTypes = $GPO.Extensions -join '; ' # : [ { 35378EAC-683F-11D2-A89A-00C04FBBCFA2 } { D02B1F72 - 3407 - 48AE-BA88-E8213C6761F1 }] - } - $TranslatedExtensions = foreach ($Extension in $GPO.Extensions) { - ConvertFrom-CSExtension -CSE $Extension -Limited - } - $ReturnObject['GPOTypes'] = $TranslatedExtensions -join '; ' - [PSCustomObject] $ReturnObject - } - } - } - $GPOPrimary['GroupPoliciesDenied'] = & { - if ($GPOPrimary['EventsByID']['5312']) { - [xml] $GPODetailsDenied = -join ('
', $GPOPrimary['EventsByID']['5313'].GPOinfoList, '
') - foreach ($GPO in $GPODetailsDenied.Details.GPO) { - [PSCustomObject] @{ - GUID = $GPO.ID #: { 6AC1786C-016F-11D2-945F-00C04fB984F9 } - DisplayName = $GPO.Name #: Default Domain Controllers Policy - Version = $GPO.Version #: 131074 - Link = $GPO.SOM #: LDAP: / / OU = Domain Controllers, DC = ad, DC = evotec, DC = xyz - SysvolPath = $GPO.FSPath #: \\ad.evotec.xyz\sysvol\ad.evotec.xyz\Policies\ { 6AC1786C-016F-11D2-945F-00C04fB984F9 }\Machine - Reason = $EventsReason["$($GPO.Reason)"] #: DENIED-WMIFILTER - } - } - } - } - - $GPOPrimary['SummaryDownload'] = & { - if ($GPOPrimary['EventsByID']['5126']) { + [Array] $GPOPrimary['Results']["$($Single.ActivityId)"]['ProcessingTime'] = foreach ($Details in $Single.ExtensionProcessingTime) { [PSCustomObject] @{ - IsBackgroundProcessing = if ($GPOPrimary['EventsByID']['5126'].IsBackgroundProcessing -eq 'true') { $true } else { $false }; # : true - IsAsyncProcessing = if ($GPOPrimary['EventsByID']['5126'].IsAsyncProcessing -eq 'true') { $true } else { $false }; # : false - Downloaded = $GPOPrimary['EventsByID']['5126'].NumberOfGPOsDownloaded # : 7 - Applicable = $GPOPrimary['EventsByID']['5126'].NumberOfGPOsApplicable # : 6 - DownloadTimeMiliseconds = $GPOPrimary['EventsByID']['5126'].GPODownloadTimeElapsedInMilliseconds # : 375 + ExtensionName = $Details.ExtensionName + ExtensionGuid = $Details.ExtensionGuid + ElapsedTimeInMilliseconds = $Details.ElapsedTimeInMilliseconds + ProcessedTimeStamp = $Details.ProcessedTimeStamp } + } + + $EventsLevel = @{ + '5' = 'Verbose' + '4' = 'Informational' + '3' = 'Warning' + '2' = 'Error' + '1' = 'Critical' + '0' = 'LogAlways' + } + $EventsReason = @{ + 'NOTAPPLIED-EMPTY' = 'Not Applied (Empty)' + 'DENIED-WMIFILTER' = 'Denied (WMI Filter)' + 'DENIED-SECURITY' = 'Denied (Security)' + } + + [Array] $GPOPrimary['Results']["$($Single.ActivityId)"]['Events'] = foreach ($Event in $Single.EventRecord) { + [xml] $EventDetails = $Event.EventXML + $EventInformation = [ordered] @{ + Description = $Event.EventDescription + Provider = $EventDetails.Event.System.Provider.Name # : Provider + ProviderGUID = $EventDetails.Event.System.Provider.Guid + EventID = $EventDetails.Event.System.EventID # : 4006 + Version = $EventDetails.Event.System.Version # : 1 + Level = $EventsLevel[$EventDetails.Event.System.Level] # : 4 + Task = $EventDetails.Event.System.Task # : 0 + Opcode = $EventDetails.Event.System.Opcode # : 1 + Keywords = $EventDetails.Event.System.Keywords # : 0x4000000000000000 + TimeCreated = [DateTime] $EventDetails.Event.System.TimeCreated.SystemTime # : TimeCreated, 2020-08-09T20:16:44.5668052Z + EventRecordID = $EventDetails.Event.System.EventRecordID # : 10641325 + Correlation = $EventDetails.Event.System.Correlation.ActivityID # : Correlation + Execution = -join ("ProcessID: ", $EventDetails.Event.System.Execution.ProcessID, " ThreadID: ", $EventDetails.Event.System.Execution.ThreadID) # : Execution + Channel = $EventDetails.Event.System.Channel # : Microsoft-Windows-GroupPolicy / Operational + Computer = $EventDetails.Event.System.Computer # : AD1.ad.evotec.xyz + Security = $EventDetails.Event.System.Security.UserID # : Security + } + foreach ($Entry in $EventDetails.Event.EventData.Data) { + $EventInformation["$($Entry.Name)"] = $Entry.'#text' + } + [PSCustomObject] $EventInformation + } + + # Lets build events by ID, this will be useful for better/easier processing + $GPOPrimary['Results']["$($Single.ActivityId)"]['EventsByID'] = [ordered] @{} + $GroupedEvents = $GPOPrimary['Results']["$($Single.ActivityId)"]['Events'] | Group-Object -Property EventId + foreach ($Events in $GroupedEvents) { + $GPOPrimary['Results']["$($Single.ActivityId)"]['EventsByID'][$Events.Name] = $Events.Group + } + + $GPOPrimary['Results']["$($Single.ActivityId)"]['GroupPoliciesApplied'] = & { + if ($GPOPrimary['Results']["$($Single.ActivityId)"]['EventsByID']['5312']) { + [xml] $GPODetailsApplied = -join ('
', $GPOPrimary['Results']["$($Single.ActivityId)"]['EventsByID']['5312'].GPOinfoList, '
') + foreach ($GPO in $GPODetailsApplied.Details.GPO) { + $ReturnObject = [ordered] @{ + GUID = $GPO.ID # : { 4E1F9C70-1DDB-4AB6-BBA3-14A8E07F0B4B } + DisplayName = $GPO.Name # : DC | Event Log Settings + Version = $GPO.Version # : 851981 + Link = $GPO.SOM # : LDAP: / / OU = Domain Controllers, DC = ad, DC = evotec, DC = xyz + SysvolPath = $GPO.FSPath # : \\ad.evotec.xyz\SysVol\ad.evotec.xyz\Policies\ { 4E1F9C70-1DDB-4AB6-BBA3-14A8E07F0B4B }\Machine + #GPOTypes = $GPO.Extensions -join '; ' # : [ { 35378EAC-683F-11D2-A89A-00C04FBBCFA2 } { D02B1F72 - 3407 - 48AE-BA88-E8213C6761F1 }] + } + $TranslatedExtensions = foreach ($Extension in $GPO.Extensions) { + ConvertFrom-CSExtension -CSE $Extension -Limited + } + $ReturnObject['GPOTypes'] = $TranslatedExtensions -join '; ' + [PSCustomObject] $ReturnObject + } + } + } + $GPOPrimary['Results']["$($Single.ActivityId)"]['GroupPoliciesDenied'] = & { + if ($GPOPrimary['Results']["$($Single.ActivityId)"]['EventsByID']['5312']) { + [xml] $GPODetailsDenied = -join ('
', $GPOPrimary['Results']["$($Single.ActivityId)"]['EventsByID']['5313'].GPOinfoList, '
') + foreach ($GPO in $GPODetailsDenied.Details.GPO) { + [PSCustomObject] @{ + GUID = $GPO.ID #: { 6AC1786C-016F-11D2-945F-00C04fB984F9 } + DisplayName = $GPO.Name #: Default Domain Controllers Policy + Version = $GPO.Version #: 131074 + Link = $GPO.SOM #: LDAP: / / OU = Domain Controllers, DC = ad, DC = evotec, DC = xyz + SysvolPath = $GPO.FSPath #: \\ad.evotec.xyz\sysvol\ad.evotec.xyz\Policies\ { 6AC1786C-016F-11D2-945F-00C04fB984F9 }\Machine + Reason = $EventsReason["$($GPO.Reason)"] #: DENIED-WMIFILTER + } + } + } + } + + $GPOPrimary['Results']["$($Single.ActivityId)"]['SummaryDownload'] = & { + if ($GPOPrimary['Results']["$($Single.ActivityId)"]['EventsByID']['5126']) { + [PSCustomObject] @{ + IsBackgroundProcessing = if ($GPOPrimary['Results']["$($Single.ActivityId)"]['EventsByID']['5126'].IsBackgroundProcessing -eq 'true') { $true } else { $false }; # : true + IsAsyncProcessing = if ($GPOPrimary['Results']["$($Single.ActivityId)"]['EventsByID']['5126'].IsAsyncProcessing -eq 'true') { $true } else { $false }; # : false + Downloaded = $GPOPrimary['Results']["$($Single.ActivityId)"]['EventsByID']['5126'].NumberOfGPOsDownloaded # : 7 + Applicable = $GPOPrimary['Results']["$($Single.ActivityId)"]['EventsByID']['5126'].NumberOfGPOsApplicable # : 6 + DownloadTimeMiliseconds = $GPOPrimary['Results']["$($Single.ActivityId)"]['EventsByID']['5126'].GPODownloadTimeElapsedInMilliseconds # : 375 + } + + } } } $GPOPrimary diff --git a/Private/New-GPOZaurrReportHTML.ps1 b/Private/New-GPOZaurrReportHTML.ps1 index 69ba08b..84db051 100644 --- a/Private/New-GPOZaurrReportHTML.ps1 +++ b/Private/New-GPOZaurrReportHTML.ps1 @@ -13,9 +13,9 @@ function New-GPOZaurrReportHTML { $Path = [io.path]::GetTempFileName().Replace('.tmp', ".html") } $ComputerName = $($Support.ResultantSetPolicy.LoggingComputer) - $UserName = $($Support.ResultantSetPolicy.UserName) - $LoggingMode = $($Support.ResultantSetPolicy.LoggingMode) - New-HTML -TitleText "Group Policy Report - $ComputerName / $UserName / $LoggingMode" { + #$UserName = $($Support.ResultantSetPolicy.UserName) + #$LoggingMode = $($Support.ResultantSetPolicy.LoggingMode) + New-HTML -TitleText "Group Policy Report - $ComputerName" { #New-HTMLTabOptions -SlimTabs -Transition -LinearGradient -SelectorColor Akaroa New-HTMLTabOptions -SlimTabs ` -BorderBottomStyleActive solid -BorderBottomColorActive LightSkyBlue -BackgroundColorActive none ` @@ -57,6 +57,9 @@ function New-GPOZaurrReportHTML { New-HTMLSection -HeaderText 'Group Policies' { New-HTMLTable -DataTable $Support.$Key.GroupPolicies -Filtering } + New-HTMLSection -HeaderText 'Group Policies Links' { + New-HTMLTable -DataTable $Support.$Key.GroupPoliciesLinks -Filtering + } New-HTMLSection -HeaderText 'Group Policies Applied' { New-HTMLTable -DataTable $Support.$Key.GroupPoliciesApplied -Filtering }