Fix native collector subscription inventory and Unicode readback

This commit is contained in:
Shirofune-Security committed 2026-09-22 09:46:28 +09:00
1 parent 03039cb1c6
commit af88b87e01
16 files changed
+327 -8

No files matched your search

+3 -2
View File
@@ -30,13 +30,14 @@ function Get-WelaWefControlState {
'SubscriptionManager' { return Get-WelaRegistryState -Path $Target.Path -Name $Target.Name }
'ForwardedEvents' { return Get-WelaNativeChannel -Name 'ForwardedEvents' }
'Subscription' {
$ids = @((Invoke-WelaNative -FilePath 'wecutil.exe' -Arguments @('es')).Output | ForEach-Object { $_.ToString().Trim() } | Where-Object { $_ })
$ids = @(Get-WelaWecSubscriptionIds)
if ($ids -notcontains $Target.Id) { return [pscustomobject]@{ Exists=$false; Xml=$null; Key=$null; Definition=$null } }
# Keep evidence as a plain string. Windows PowerShell 5.1's JSON
# serializer expands ETS properties on strings (for example a test
# reader's PSDrive/PSProvider graph), unlike modern PowerShell.
$xml = [string]::Concat((Invoke-WelaNative -FilePath 'wecutil.exe' -Arguments @('gs',$Target.Id,'/f:xml')).Diagnostic)
$xml = [string]::Concat((Read-WelaWecSubscriptionXml -Id $Target.Id))
$model = ConvertFrom-WelaWefSubscription -Xml $xml -SourceSids $Target.SourceSids -Observed
if($model.Id -cne $Target.Id){throw 'Native subscription identity differs from the selected ID.'}
return [pscustomobject]@{ Exists=$true; Xml=$xml; Key=$model.Key; Definition=$model.Definition }
}
default { throw "Unsupported WEF control kind: $Kind" }