mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-09 07:45:34 +02:00
Retain partial WMI tree observations after a parent write
This commit is contained in:
1 parent
488d179f09
commit
d5de556f74
3 files changed
+18
-5
No files matched your search
@@ -278,11 +278,11 @@ function Set-WelaWmiAuditControls {
|
||||
param($Context, [array]$Plan)
|
||||
foreach ($entry in $Plan) {
|
||||
$inherit=@($entry.Definitions|Where-Object {($_.AceFlags -band 2) -ne 0}).Count -gt 0
|
||||
$callback = @{ Namespace = $entry.Namespace; Definitions = $entry.Definitions; Original = $null; ExpectedJson = $null; Applied = $false; VerifiedJson = $null; Inherit=$inherit; PlannedTree=$entry.Descendants; OriginalTree=$null; VerifiedTree=$null; DescendantVerification=[pscustomobject]@{Observation=$null} }
|
||||
$callback = @{ Namespace = $entry.Namespace; Definitions = $entry.Definitions; Original = $null; ExpectedJson = $null; Applied = $false; VerifiedJson = $null; Inherit=$inherit; PlannedTree=$entry.Descendants; OriginalTree=$null; VerifiedTree=$null; DescendantVerification=[pscustomobject]@{ParentSetterAttempted=$false;ParentSetterAccepted=$false;Observation=$null;LastTree=$null} }
|
||||
$read = {
|
||||
param($state)
|
||||
if($state.Inherit){
|
||||
$tree=Get-WelaWmiStableDescendants $state.Namespace
|
||||
$tree=Get-WelaWmiStableDescendants $state.Namespace $state.DescendantVerification
|
||||
if($null -eq $state.OriginalTree){
|
||||
if((Get-WelaWmiDescendantKey $tree) -cne (Get-WelaWmiDescendantKey $state.PlannedTree)){throw 'WMI descendant tree changed after planning; no SACL was written.'}
|
||||
$state.OriginalTree=$tree
|
||||
@@ -318,10 +318,13 @@ function Set-WelaWmiAuditControls {
|
||||
$apply = {
|
||||
param($state)
|
||||
if($state.Inherit){
|
||||
$fresh=Get-WelaWmiStableDescendants $state.Namespace
|
||||
$fresh=Get-WelaWmiStableDescendants $state.Namespace $state.DescendantVerification
|
||||
if((Get-WelaWmiDescendantKey $fresh) -cne (Get-WelaWmiDescendantKey $state.OriginalTree)){throw 'WMI descendant topology or descriptor changed before the parent setter; no SACL was written.'}
|
||||
$state.DescendantVerification.ParentSetterAttempted=$true
|
||||
$state.DescendantVerification.Observation=$null
|
||||
}
|
||||
Set-WelaWmiNamespaceDescriptor -Namespace $state.Namespace -ExpectedJson $state.ExpectedJson -Definitions $state.Definitions
|
||||
if($state.Inherit){$state.DescendantVerification.ParentSetterAccepted=$true}
|
||||
$state.Applied = $true
|
||||
}
|
||||
Invoke-WelaConfigurationControl -Context $Context -Id "WmiNamespace/$($entry.Namespace)/SACL" -Kind WmiNamespaceSacl `
|
||||
|
||||
@@ -82,12 +82,14 @@ function Get-WelaWmiDescendants {
|
||||
[pscustomobject]@{Status=$(if($diagnostics.Count){'Incomplete'}else{'Complete'});Maximum=64;MaximumDepth=8;StartedUtc=$started.ToString('o');CompletedUtc=[DateTime]::UtcNow.ToString('o');Root=$root;Entries=@($entries.ToArray());Diagnostics=@($diagnostics.ToArray())}
|
||||
}
|
||||
function Get-WelaWmiStableDescendants {
|
||||
param([string]$Namespace)
|
||||
param([string]$Namespace,$Observation)
|
||||
$context=Get-WelaWmiDescendantContext
|
||||
try {
|
||||
$first=Get-WelaWmiDescendants $Namespace
|
||||
if($Observation){$Observation.LastTree=$first}
|
||||
if($first.Status -cne 'Complete'){throw ('Incomplete WMI descendant inventory: '+($first.Diagnostics -join '; '))}
|
||||
$second=Get-WelaWmiDescendants $Namespace
|
||||
if($Observation){$Observation.LastTree=$second}
|
||||
if((Get-WelaWmiDescendantKey $first) -cne (Get-WelaWmiDescendantKey $second)){throw 'WMI descendant topology or full descriptor changed between observations.'}
|
||||
$second|Add-Member NoteProperty Context $context
|
||||
$second
|
||||
|
||||
Reference in new issue
Block a user