diff --git a/Private/Get-PrivGPOZaurrLInk.ps1 b/Private/Get-PrivGPOZaurrLInk.ps1 index 2032ac8..07cd47b 100644 --- a/Private/Get-PrivGPOZaurrLInk.ps1 +++ b/Private/Get-PrivGPOZaurrLInk.ps1 @@ -6,15 +6,37 @@ [System.Collections.IDictionary] $GPOCache ) if ($Object.GpLink -and $Object.GpLink.Trim() -ne '') { - #$Object.GpLink -split { $_ -eq '[' -or $_ -eq ']' } -replace ';0' -replace 'LDAP://' - $Object.GpLink -split '\[LDAP://' -split ';' | ForEach-Object -Process { - #Write-Verbose $_ - if ($_.Length -gt 10) { - $DomainCN = ConvertFrom-DistinguishedName -DistinguishedName $_ -ToDomainCN + $Object.GpLink -split '\]\[' | ForEach-Object -Process { + $Link = $_ -replace '\[LDAP://' -replace '\]' -replace '\[' + if ($Link.Length -gt 10) { + $SplitGPLink = $Link -split ';' + $DN = $SplitGPLink[0] + $Option = $SplitGPLink[1] + if ($Option -eq '0') { + $Enforced = $false + $Enabled = $true + } elseif ($Option -eq '1') { + $Enabled = $false + $Enforced = $false + } elseif ($Option -eq '2') { + $Enabled = $true + $Enforced = $true + } elseif ($Option -eq '3') { + $Enabled = $false + $Enforced = $true + } else { + Write-Warning "Get-PrivGPOZaurrLink - This should't happen. Please investigate - Option: $Option" + $Enabled = $null + $Enforced = $null + } + $DomainCN = ConvertFrom-DistinguishedName -DistinguishedName $DN -ToDomainCN $Output = [ordered] @{ DistinguishedName = $Object.DistinguishedName CanonicalName = if ($Object.CanonicalName) { $Object.CanonicalName.TrimEnd('/') } else { $Object.CanonicalName } - Guid = [Regex]::Match( $_, '(?={)(.*)(?<=})').Value -replace '{' -replace '}' + Guid = [Regex]::Match( $DN, '(?={)(.*)(?<=})').Value -replace '{' -replace '}' + Enforced = $Enforced + Enabled = $Enabled + ObjectClass = $Object.ObjectClass } $Search = -join ($DomainCN, $Output['Guid']) if ($GPOCache -and -not $Limited) { @@ -26,15 +48,15 @@ $Output['Description'] = $GPOCache[$Search].Description $Output['CreationTime'] = $GPOCache[$Search].CreationTime $Output['ModificationTime'] = $GPOCache[$Search].ModificationTime - $Output['GPODomainDistinguishedName'] = ConvertFrom-DistinguishedName -DistinguishedName $_ -ToDC - $Output['GPODistinguishedName'] = $_ + $Output['GPODomainDistinguishedName'] = ConvertFrom-DistinguishedName -DistinguishedName $DN -ToDC + $Output['GPODistinguishedName'] = $DN [PSCustomObject] $Output } else { Write-Warning "Get-PrivGPOZaurrLink - Couldn't find link $Search in a GPO Cache. Lack of permissions for given GPO? Are you running as admin? Skipping." } } else { - $Output['GPODomainDistinguishedName'] = ConvertFrom-DistinguishedName -DistinguishedName $_ -ToDC - $Output['GPODistinguishedName'] = $_ + $Output['GPODomainDistinguishedName'] = ConvertFrom-DistinguishedName -DistinguishedName $DN -ToDC + $Output['GPODistinguishedName'] = $DN [PSCustomObject] $Output } } diff --git a/Public/Get-GPOZaurrLink.ps1 b/Public/Get-GPOZaurrLink.ps1 index dc5cadd..008e8f1 100644 --- a/Public/Get-GPOZaurrLink.ps1 +++ b/Public/Get-GPOZaurrLink.ps1 @@ -1,13 +1,13 @@ function Get-GPOZaurrLink { - [cmdletbinding(DefaultParameterSetName = 'Filter')] + [cmdletbinding(DefaultParameterSetName = 'Linked')] param( [parameter(ParameterSetName = 'ADObject', ValueFromPipeline, ValueFromPipelineByPropertyName, Mandatory)][Microsoft.ActiveDirectory.Management.ADObject[]] $ADObject, # weirdly enough site doesn't really work this way unless you give it 'CN=Configuration,DC=ad,DC=evotec,DC=xyz' as SearchBase - [parameter(ParameterSetName = 'Filter')][string] $Filter = "(objectClass -eq 'organizationalUnit' -or objectClass -eq 'domainDNS' -or objectClass -eq 'site')", + [parameter(ParameterSetName = 'Filter')][string] $Filter, # "(objectClass -eq 'organizationalUnit' -or objectClass -eq 'domainDNS' -or objectClass -eq 'site')" [parameter(ParameterSetName = 'Filter')][string] $SearchBase, [parameter(ParameterSetName = 'Filter')][Microsoft.ActiveDirectory.Management.ADSearchScope] $SearchScope, - [parameter(ParameterSetName = 'Linked', Mandatory)][validateset('Root', 'DomainControllers', 'Site', 'Other')][string] $Linked, + [parameter(ParameterSetName = 'Linked')][validateset('All', 'Root', 'DomainControllers', 'Site', 'Other')][string[]] $Linked, [parameter(ParameterSetName = 'Filter')] [parameter(ParameterSetName = 'ADObject')] @@ -66,7 +66,11 @@ } Process { if (-not $ADObject) { - if ($Linked) { + if (-not $Filter) { + # if not linked, we force it to All + if (-not $Linked) { + $Linked = 'All' + } foreach ($Domain in $ForestInformation.Domains) { $Splat = @{ #Filter = $Filter @@ -74,40 +78,8 @@ # Filter = "(objectClass -eq 'organizationalUnit' -or objectClass -eq 'domainDNS' -or objectClass -eq 'site')" Server = $ForestInformation['QueryServers'][$Domain]['HostName'][0] } - if ($Linked -contains 'DomainControllers') { - $SearchBase = $ForestInformation['DomainsExtended'][$Domain]['DomainControllersContainer'] - #if ($SearchBase -notlike "*$DomainDistinguishedName") { - # we check if SearchBase is part of domain distinugishname. If it isn't we skip - # continue - #} - $Splat['Filter'] = "(objectClass -eq 'organizationalUnit')" - $Splat['SearchBase'] = $SearchBase - try { - $ADObjectGPO = Get-ADObject @Splat - } catch { - Write-Warning "Get-GPOZaurrLink - Get-ADObject error $($_.Exception.Message)" - } - foreach ($_ in $ADObjectGPO) { - $OutputGPOs = Get-PrivGPOZaurrLink -Object $_ -Limited:$Limited.IsPresent -GPOCache $GPOCache - foreach ($OutputGPO in $OutputGPOs) { - if (-not $SkipDuplicates) { - $OutputGPO - } else { - $UniqueGuid = $OutputGPO.GPODistinguishedName #-join ($OutputGPO.DomainName, $OutputGPO.Guid) - if (-not $CacheReturnedGPOs[$UniqueGuid]) { - $CacheReturnedGPOs[$UniqueGuid] = $OutputGPO - $OutputGPO - } - } - } - } - } - if ($Linked -contains 'Root') { + if ($Linked -contains 'Root' -or $Linked -contains 'All') { $SearchBase = $ForestInformation['DomainsExtended'][$Domain]['DistinguishedName'] - #if ($SearchBase -notlike "*$DomainDistinguishedName") { - # we check if SearchBase is part of domain distinugishname. If it isn't we skip - # continue - # } $Splat['Filter'] = "objectClass -eq 'domainDNS'" $Splat['SearchBase'] = $SearchBase try { @@ -115,29 +87,12 @@ } catch { Write-Warning "Get-GPOZaurrLink - Get-ADObject error $($_.Exception.Message)" } - foreach ($_ in $ADObjectGPO) { - $OutputGPOs = Get-PrivGPOZaurrLink -Object $_ -Limited:$Limited.IsPresent -GPOCache $GPOCache - foreach ($OutputGPO in $OutputGPOs) { - if (-not $SkipDuplicates) { - $OutputGPO - } else { - $UniqueGuid = $OutputGPO.GPODistinguishedName #-join ($OutputGPO.DomainName, $OutputGPO.Guid) - if (-not $CacheReturnedGPOs[$UniqueGuid]) { - $CacheReturnedGPOs[$UniqueGuid] = $OutputGPO - $OutputGPO - } - } - } - } + Get-GPOPrivLink -CacheReturnedGPOs $CacheReturnedGPOs -ADObject $ADObjectGPO -Domain $Domain -ForestInformation $ForestInformation -AsHashTable:$AsHashTable } - if ($Linked -contains 'Site') { + if ($Linked -contains 'Site' -or $Linked -contains 'All') { # Sites are defined only in primary domain if ($ForestInformation['DomainsExtended'][$Domain]['DNSRoot'] -eq $ForestInformation['DomainsExtended'][$Domain]['Forest']) { $SearchBase = -join ("CN=Configuration,", $ForestInformation['DomainsExtended'][$Domain]['DistinguishedName']) - # if ($SearchBase -notlike "*$DomainDistinguishedName") { - # we check if SearchBase is part of domain distinugishname. If it isn't we skip - #continue - #} $Splat['Filter'] = "(objectClass -eq 'site')" $Splat['SearchBase'] = $SearchBase try { @@ -145,28 +100,11 @@ } catch { Write-Warning "Get-GPOZaurrLink - Get-ADObject error $($_.Exception.Message)" } - foreach ($_ in $ADObjectGPO) { - $OutputGPOs = Get-PrivGPOZaurrLink -Object $_ -Limited:$Limited.IsPresent -GPOCache $GPOCache - foreach ($OutputGPO in $OutputGPOs) { - if (-not $SkipDuplicates) { - $OutputGPO - } else { - $UniqueGuid = $OutputGPO.GPODistinguishedName #-join ($OutputGPO.DomainName, $OutputGPO.Guid) - if (-not $CacheReturnedGPOs[$UniqueGuid]) { - $CacheReturnedGPOs[$UniqueGuid] = $OutputGPO - $OutputGPO - } - } - } - } + Get-GPOPrivLink -CacheReturnedGPOs $CacheReturnedGPOs -ADObject $ADObjectGPO -Domain $Domain -ForestInformation $ForestInformation -AsHashTable:$AsHashTable } } - if ($Linked -contains 'Other') { - $SearchBase = $ForestInformation['DomainsExtended'][$Domain]['DistinguishedName'] - #if ($SearchBase -notlike "*$DomainDistinguishedName") { - # we check if SearchBase is part of domain distinugishname. If it isn't we skip - # continue - #} + if ($Linked -contains 'DomainControllers' -or $Linked -contains 'All') { + $SearchBase = $ForestInformation['DomainsExtended'][$Domain]['DomainControllersContainer'] $Splat['Filter'] = "(objectClass -eq 'organizationalUnit')" $Splat['SearchBase'] = $SearchBase try { @@ -174,29 +112,21 @@ } catch { Write-Warning "Get-GPOZaurrLink - Get-ADObject error $($_.Exception.Message)" } - foreach ($_ in $ADObjectGPO) { - if ($_.DistinguishedName -eq $ForestInformation['DomainsExtended'][$Domain]['DistinguishedName']) { - # other skips Domain Root - } elseif ($_.DistinguishedName -eq $ForestInformation['DomainsExtended'][$Domain]['DomainControllersContainer']) { - # other skips Domain Controllers - } else { - $OutputGPOs = Get-PrivGPOZaurrLink -Object $_ -Limited:$Limited.IsPresent -GPOCache $GPOCache - foreach ($OutputGPO in $OutputGPOs) { - if (-not $SkipDuplicates) { - $OutputGPO - } else { - $UniqueGuid = $OutputGPO.GPODistinguishedName #-join ($OutputGPO.DomainName, $OutputGPO.Guid) - if (-not $CacheReturnedGPOs[$UniqueGuid]) { - $CacheReturnedGPOs[$UniqueGuid] = $OutputGPO - $OutputGPO - } - } - } - } + Get-GPOPrivLink -CacheReturnedGPOs $CacheReturnedGPOs -ADObject $ADObjectGPO -Domain $Domain -ForestInformation $ForestInformation -AsHashTable:$AsHashTable + } + if ($Linked -contains 'Other' -or $Linked -contains 'All') { + $SearchBase = $ForestInformation['DomainsExtended'][$Domain]['DistinguishedName'] + $Splat['Filter'] = "(objectClass -eq 'organizationalUnit')" + $Splat['SearchBase'] = $SearchBase + try { + $ADObjectGPO = Get-ADObject @Splat + } catch { + Write-Warning "Get-GPOZaurrLink - Get-ADObject error $($_.Exception.Message)" } + Get-GPOPrivLink -CacheReturnedGPOs $CacheReturnedGPOs -ADObject $ADObjectGPO -Domain $Domain -ForestInformation $ForestInformation -SkipDomainRoot -SkipDomainControllers -AsHashTable:$AsHashTable } } - } else { + } elseif ($Filter) { foreach ($Domain in $ForestInformation.Domains) { $Splat = @{ Filter = $Filter @@ -223,37 +153,11 @@ } catch { Write-Warning "Get-GPOZaurrLink - Get-ADObject error $($_.Exception.Message)" } - foreach ($_ in $ADObjectGPO) { - $OutputGPOs = Get-PrivGPOZaurrLink -Object $_ -Limited:$Limited.IsPresent -GPOCache $GPOCache - foreach ($OutputGPO in $OutputGPOs) { - if (-not $SkipDuplicates) { - $OutputGPO - } else { - $UniqueGuid = $OutputGPO.GPODistinguishedName #-join ($OutputGPO.DomainName, $OutputGPO.Guid) - if (-not $CacheReturnedGPOs[$UniqueGuid]) { - $CacheReturnedGPOs[$UniqueGuid] = $OutputGPO - $OutputGPO - } - } - } - } + Get-GPOPrivLink -CacheReturnedGPOs $CacheReturnedGPOs -ADObject $ADObjectGPO -Domain $Domain -ForestInformation $ForestInformation -AsHashTable:$AsHashTable } } } else { - foreach ($_ in $ADObject) { - $OutputGPOs = Get-PrivGPOZaurrLink -Object $_ -Limited:$Limited.IsPresent -GPOCache $GPOCache - foreach ($OutputGPO in $OutputGPOs) { - if (-not $SkipDuplicates) { - $OutputGPO - } else { - $UniqueGuid = $OutputGPO.GPODistinguishedName #-join ($OutputGPO.DomainName, $OutputGPO.Guid) - if (-not $CacheReturnedGPOs[$UniqueGuid]) { - $CacheReturnedGPOs[$UniqueGuid] = $OutputGPO - $OutputGPO - } - } - } - } + Get-GPOPrivLink -CacheReturnedGPOs $CacheReturnedGPOs -ADObject $ADObject -Domain '' -ForestInformation $ForestInformation -AsHashTable:$AsHashTable } } End {