You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用PowerShell获取近期防火墙变更列表及详细信息

获取Windows防火墙变更详情并格式化输出

问题背景

需要获取近期由软件安装引发的防火墙变更列表及详情,已通过EventLogs在指定时间范围内拿到事件列表,message字段包含所需信息,但希望避免用冗长正则提取详情。

已执行以下命令获取事件列表:

Get-WinEvent -ErrorAction SilentlyContinue -FilterHashtable @{logname="Microsoft-Windows-Windows Firewall With Advanced Security/Firewall"; id=2097; StartTime=(Get-Date).AddHours(-2); EndTime=Get-Date}

输出结果:

ProviderName: Microsoft-Windows-Windows Firewall With Advanced Security

TimeCreated                     Id LevelDisplayName Message
-----------                     -- ---------------- -------
2024-11-22 18:18:24           2097 Information      Windows Defender防火墙例外列表中已添加一条规则。…
2024-11-22 18:18:24           2097 Information      Windows Defender防火墙例外列表中已添加一条规则。…
2024-11-22 18:18:21           2097 Information      Windows Defender防火墙例外列表中已添加一条规则。…
2024-11-22 18:18:21           2097 Information      Windows Defender防火墙例外列表中已添加一条规则。…

将命令通过管道传递给Format-List(fl)可查看完整详情:

TimeCreated  : 2024-11-22 18:18:24
ProviderName : Microsoft-Windows-Windows Firewall With Advanced Security
Id           : 2097
Message      : Windows Defender防火墙例外列表中已添加一条规则。

               添加的规则:
                规则ID:        UDP Query User{D0EBCDC7-8C31-463A-ADB9-A72A2FE0EFA9}C:\bin\arduino\arduino ide.exe
                规则名称:      Arduino IDE
                来源: 本地
                已启用: 是
                方向:      入站
                配置文件:       公用
                操作: 阻止
                应用路径:       C:\bin\arduino\arduino ide.exe
                服务名称:
                协议:       UDP
                安全选项:       无
                边缘遍历: 无
                修改用户: S-1-5-80-3088073201-1464728630-1879813800-1107566885-823218052
                修改应用程序:  C:\Windows\System32\svchost.exe
                PolicyAppId:
                错误代码:     0

核心需求

如何筛选生成包含以下列的表格?
TimeCreated, Protocol, Direction, '规则名称', '应用路径'

额外需求:添加端口号。


更新:最终实现函数

function get_firewall_changes {
    $nArgs = $($args.Count)
    if ( $nArgs -eq 0 ) { 
        $tHours = -1        # 默认查询最近1小时的变更
    } else {
        $tHours = -[int] $args[0]
    }

    $selector = [System.Diagnostics.Eventing.Reader.EventLogPropertySelector]::new(
    [string[]]@(
        "Event/EventData/Data[@Name='RuleName']"
        "Event/EventData/Data[@Name='ApplicationPath']"))
    $REX = '(?s)Direction:\s*(?<dir>[^\n]+).+Protocol:\s*(?<prot>[^\n]+)'

    Get-WinEvent -ErrorAction SilentlyContinue -FilterHashtable @{logname="Microsoft-Windows-Windows Firewall With Advanced Security/Firewall"; id=2097; StartTime=(Get-Date).AddHours($tHours); EndTime=Get-Date} | ForEach-Object {
        $RuleName, $ApplicationPath = $_.GetPropertyValues($selector)
        $Direction, $Protocol = [regex]::Match( $_.Message, $REX).Groups['dir', 'prot'].Value
        if ($RuleName.Length -gt 47 ) { $RuleName = ($RuleName[0..47] -join '') + '...'; }      # 过长规则名截断为50字符
        [pscustomobject]@{
            TimeCreated     = $_.TimeCreated
            Protocol        = $Protocol
            Direction       = $Direction
            RuleName        = $RuleName
            ApplicationPath = $ApplicationPath
        }
    } | Format-Table -Autosize -Wrap
}

内容的提问来源于stack exchange,提问作者not2qubit

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 01:47:33