如何用PowerShell获取近期防火墙变更列表及详细信息
获取Windows防火墙变更详情并格式化输出
问题背景
需要获取近期由软件安装引发的防火墙变更列表及详情,已通过EventLogs在指定时间范围内拿到事件列表,message字段包含所需信息,但希望避免用冗长正则提取详情。
已执行以下命令获取事件列表:
Get-WinEvent -ErrorAction SilentlyContinue -FilterHashtable @{logname="Microsoft-Windows-Windows Firewall With Advanced Security/Firewall"; id=2097; StartTime=(Get-Date).AddHours(-2); EndTime=Get-Date}
输出结果:
ProviderName: Microsoft-Windows-Windows Firewall With Advanced Security TimeCreated Id LevelDisplayName Message ----------- -- ---------------- ------- 2024-11-22 18:18:24 2097 Information Windows Defender防火墙例外列表中已添加一条规则。… 2024-11-22 18:18:24 2097 Information Windows Defender防火墙例外列表中已添加一条规则。… 2024-11-22 18:18:21 2097 Information Windows Defender防火墙例外列表中已添加一条规则。… 2024-11-22 18:18:21 2097 Information Windows Defender防火墙例外列表中已添加一条规则。…
将命令通过管道传递给Format-List(fl)可查看完整详情:
TimeCreated : 2024-11-22 18:18:24 ProviderName : Microsoft-Windows-Windows Firewall With Advanced Security Id : 2097 Message : Windows Defender防火墙例外列表中已添加一条规则。 添加的规则: 规则ID: UDP Query User{D0EBCDC7-8C31-463A-ADB9-A72A2FE0EFA9}C:\bin\arduino\arduino ide.exe 规则名称: Arduino IDE 来源: 本地 已启用: 是 方向: 入站 配置文件: 公用 操作: 阻止 应用路径: C:\bin\arduino\arduino ide.exe 服务名称: 协议: UDP 安全选项: 无 边缘遍历: 无 修改用户: S-1-5-80-3088073201-1464728630-1879813800-1107566885-823218052 修改应用程序: C:\Windows\System32\svchost.exe PolicyAppId: 错误代码: 0
核心需求
如何筛选生成包含以下列的表格?TimeCreated, Protocol, Direction, '规则名称', '应用路径'
额外需求:添加端口号。
更新:最终实现函数
function get_firewall_changes { $nArgs = $($args.Count) if ( $nArgs -eq 0 ) { $tHours = -1 # 默认查询最近1小时的变更 } else { $tHours = -[int] $args[0] } $selector = [System.Diagnostics.Eventing.Reader.EventLogPropertySelector]::new( [string[]]@( "Event/EventData/Data[@Name='RuleName']" "Event/EventData/Data[@Name='ApplicationPath']")) $REX = '(?s)Direction:\s*(?<dir>[^\n]+).+Protocol:\s*(?<prot>[^\n]+)' Get-WinEvent -ErrorAction SilentlyContinue -FilterHashtable @{logname="Microsoft-Windows-Windows Firewall With Advanced Security/Firewall"; id=2097; StartTime=(Get-Date).AddHours($tHours); EndTime=Get-Date} | ForEach-Object { $RuleName, $ApplicationPath = $_.GetPropertyValues($selector) $Direction, $Protocol = [regex]::Match( $_.Message, $REX).Groups['dir', 'prot'].Value if ($RuleName.Length -gt 47 ) { $RuleName = ($RuleName[0..47] -join '') + '...'; } # 过长规则名截断为50字符 [pscustomobject]@{ TimeCreated = $_.TimeCreated Protocol = $Protocol Direction = $Direction RuleName = $RuleName ApplicationPath = $ApplicationPath } } | Format-Table -Autosize -Wrap }
内容的提问来源于stack exchange,提问作者not2qubit
相关产品推荐
相关产品推荐

