mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-03 21:14:42 +02:00
Fix native collector subscription inventory and Unicode readback
This commit is contained in:
1 parent
03039cb1c6
commit
af88b87e01
16 files changed
+327
-8
No files matched your search
@@ -30,13 +30,14 @@ function Get-WelaWefControlState {
|
||||
'SubscriptionManager' { return Get-WelaRegistryState -Path $Target.Path -Name $Target.Name }
|
||||
'ForwardedEvents' { return Get-WelaNativeChannel -Name 'ForwardedEvents' }
|
||||
'Subscription' {
|
||||
$ids = @((Invoke-WelaNative -FilePath 'wecutil.exe' -Arguments @('es')).Output | ForEach-Object { $_.ToString().Trim() } | Where-Object { $_ })
|
||||
$ids = @(Get-WelaWecSubscriptionIds)
|
||||
if ($ids -notcontains $Target.Id) { return [pscustomobject]@{ Exists=$false; Xml=$null; Key=$null; Definition=$null } }
|
||||
# Keep evidence as a plain string. Windows PowerShell 5.1's JSON
|
||||
# serializer expands ETS properties on strings (for example a test
|
||||
# reader's PSDrive/PSProvider graph), unlike modern PowerShell.
|
||||
$xml = [string]::Concat((Invoke-WelaNative -FilePath 'wecutil.exe' -Arguments @('gs',$Target.Id,'/f:xml')).Diagnostic)
|
||||
$xml = [string]::Concat((Read-WelaWecSubscriptionXml -Id $Target.Id))
|
||||
$model = ConvertFrom-WelaWefSubscription -Xml $xml -SourceSids $Target.SourceSids -Observed
|
||||
if($model.Id -cne $Target.Id){throw 'Native subscription identity differs from the selected ID.'}
|
||||
return [pscustomobject]@{ Exists=$true; Xml=$xml; Key=$model.Key; Definition=$model.Definition }
|
||||
}
|
||||
default { throw "Unsupported WEF control kind: $Kind" }
|
||||
|
||||
Reference in new issue
Block a user