You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于PowerShell从域控制器批量查询20台主机Winlogon注册表键并导出CSV的脚本开发需求

实现跨20台计算机的注册表键验证并导出CSV方案

我来帮你完善这个PowerShell脚本,完全覆盖你提到的所有需求:批量检查远程计算机注册表键、处理未找到的情况、简化变量、导出干净的CSV结果。下面是完整的实现方案:

完整脚本代码

# --------------------------
# 配置参数(根据你的需求修改)
# --------------------------
# 要验证的3个注册表键名称
$targetRegKeys = @("Key1", "Key2", "Key3")
# 目标计算机列表(可替换为从文件读取:Get-Content .\computers.txt)
$targetComputers = @("PC01", "PC02", "PC03", "PC04") # 补充你的20台计算机名
# 注册表路径(注意HKLM:是本地路径,远程执行时会自动对应目标机的HKLM)
$regPath = "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"
# 输出CSV文件路径
$outputCsvPath = "C:\Temp\RegistryCheckResults.csv"

# --------------------------
# 初始化结果存储数组
# --------------------------
$allResults = @()

# --------------------------
# 循环遍历每台计算机
# --------------------------
foreach ($computer in $targetComputers) {
    Write-Host "正在处理计算机: *$computer*" -ForegroundColor Cyan

    # 先检查计算机是否在线(可选但推荐)
    if (-not (Test-Connection -ComputerName $computer -Count 1 -Quiet -ErrorAction SilentlyContinue)) {
        $allResults += [PSCustomObject]@{
            ComputerName = $computer
            RegistryKey  = "N/A"
            KeyValue     = "N/A"
            Status       = "计算机离线/无法连接"
        }
        continue
    }

    # 循环遍历每个要验证的注册表键
    foreach ($keyName in $targetRegKeys) {
        try {
            # 远程执行注册表查询,强制终止错误触发catch
            $regResult = Invoke-Command -ComputerName $computer -ScriptBlock {
                param($path, $key)
                Get-ItemProperty -Path $path -Name $key -ErrorAction Stop
            } -ArgumentList $regPath, $keyName

            # 提取有效数据,排除PS开头的系统属性
            $allResults += [PSCustomObject]@{
                ComputerName = $computer
                RegistryKey  = $keyName
                KeyValue     = $regResult.$keyName
                Status       = "键存在"
            }
        }
        catch {
            # 区分错误类型:键不存在 vs 其他错误
            $errorStatus = if ($_.Exception.Message -match "属性.*不存在") {
                "键未找到"
            } else {
                "查询失败: $($_.Exception.Message)"
            }

            $allResults += [PSCustomObject]@{
                ComputerName = $computer
                RegistryKey  = $keyName
                KeyValue     = "N/A"
                Status       = $errorStatus
            }
        }
    }
}

# --------------------------
# 导出结果到CSV
# --------------------------
$allResults | Export-Csv -Path $outputCsvPath -NoTypeInformation -Encoding UTF8
Write-Host "所有结果已导出至: *$outputCsvPath*" -ForegroundColor Green

关键功能说明

  • 远程执行支持:使用Invoke-Command实现跨域远程注册表查询,依赖WinRM服务(域环境下默认开启,若未开启可在目标机执行Enable-PSRemoting -Force)。
  • 错误处理:通过try/catch捕获两种核心错误:计算机无法连接、注册表键未找到,并在结果中明确标记状态。
  • 干净的CSV输出:用[PSCustomObject]统一结果结构,导出时自动排除PS开头的系统属性,同时添加-NoTypeInformation避免CSV头部的冗余类型注释。
  • 可扩展性:所有配置参数集中在脚本顶部,修改计算机列表、注册表键或输出路径只需调整变量即可。

使用提示

  1. 计算机列表批量导入:如果20台计算机名已存放在文本文件(每行一个名称),可替换$targetComputers的定义为:
    $targetComputers = Get-Content .\YourComputerList.txt
    
  2. 权限要求:运行脚本的账号需要具备域内远程计算机的注册表读取权限(域管理员账号默认满足)。
  3. 编码设置:添加-Encoding UTF8确保CSV中的中文或特殊字符显示正常。

内容的提问来源于stack exchange,提问作者manuman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 15:17:31