You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何读取凭据/UAC提示框文本并识别触发该提示的应用?

读取UAC提示框文本并识别触发应用的方法

方法一:通过Windows API捕获窗口文本(PowerShell实现)

UAC提示框属于系统级窗口,必须以管理员权限运行脚本才能读取其内容。可以借助Windows API枚举窗口并提取文本中的应用名称:

  • 核心思路:调用user32.dll的API函数枚举所有顶层窗口,筛选出含UAC标识的窗口,再提取窗口文本中的应用名称。

示例脚本:

Add-Type @"
using System;
using System.Runtime.InteropServices;
public class Win32 {
    [DllImport("user32.dll")]
    public static extern bool EnumWindows(EnumWindowsProc enumProc, IntPtr lParam);
    
    public delegate bool EnumWindowsProc(IntPtr hWnd, IntPtr lParam);
    
    [DllImport("user32.dll", CharSet = CharSet.Unicode)]
    public static extern int GetWindowText(IntPtr hWnd, StringBuilder lpString, int nMaxCount);
    
    [DllImport("user32.dll")]
    public static extern int GetWindowTextLength(IntPtr hWnd);
}
"@

$uacWindowList = @()
$enumCallback = {
    param($hWnd, $lParam)
    $textLength = [Win32]::GetWindowTextLength($hWnd)
    if ($textLength -gt 0) {
        $textBuilder = New-Object System.Text.StringBuilder ($textLength + 1)
        [Win32]::GetWindowText($hWnd, $textBuilder, $textBuilder.Capacity)
        $windowText = $textBuilder.ToString()
        # 筛选UAC提示窗口,匹配中英文关键词
        if ($windowText -match "用户账户控制|User Account Control") {
            $uacWindowList += @{
                WindowHandle = $hWnd
                FullText = $windowText
            }
        }
    }
    return $true
}

[Win32]::EnumWindows($enumCallback, [IntPtr]::Zero)

foreach ($window in $uacWindowList) {
    Write-Host "UAC提示内容:`n$($window.FullText)`n"
    # 从文本中提取应用名称,适配常见UAC提示格式
    if ($window.FullText -match "应用名称:\s*(.*?)\s*(?=\||\n|$)") {
        Write-Host "触发UAC的应用:$($matches[1])"
    }
}

方法二:优化事件日志筛选,精准定位触发源

事件4688结合关联事件可以更精准定位UAC触发进程:

  • 事件ID 4688:记录进程创建,其中New Process Name为UAC提示进程(consent.exe),Creator Process Name就是触发UAC的源应用
  • 可以通过筛选consent.exe的父进程来直接获取应用路径

PowerShell筛选示例:

Get-WinEvent -FilterHashtable @{
    LogName = 'Security'
    Id = 4688
} | Where-Object { $_.Properties[5].Value -like "*consent.exe" } | Select-Object TimeCreated,
    @{Name='UAC提示进程'; Expression={$_.Properties[5].Value}},
    @{Name='触发源应用'; Expression={$_.Properties[10].Value}}

注意事项

  • 读取UAC窗口文本必须以管理员权限运行脚本,否则会被系统权限拦截
  • 不同版本Windows的UAC窗口类名、文本格式可能有差异,需根据实际情况调整脚本中的匹配规则
  • 若启用UAC虚拟化,部分进程路径会被重定向,需结合虚拟化路径分析

内容的提问来源于stack exchange,提问作者Azure_CloudServices

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 07:38:22