You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows11 22H2下阻止PowerShell执行未签名脚本时联网

问题描述

我配置了一个每日定时运行的任务计划,用于执行一段未签名的PowerShell脚本。升级Windows 11到22H2版本后,防火墙多次弹出提示,显示PowerShell尝试连接互联网,目标地址为sv.symcb.com或Digicert相关站点,推测是应用签名的证书校验操作,但无法确认。

脚本能正常运行并完成任务,我仅希望阻止它发起联网请求,请问有没有办法阻止该脚本运行时PowerShell的联网行为?

定时任务参数

-WindowStyle Hidden -NonInteractive -ExecutionPolicy Bypass -File "C:\path-to\script.ps1"

脚本内容

Param (
    # vCenter server & credintials
    [string]$VIServer = "192.168.224.123",
    [string]$User = 'administrator@vsphere.loc',
    [string]$Password = 'xxxxxxx',
    
    [string]$ConfigPath = "C:\path-to\backups\",
    [int]$Days = 21
)
Import-Module VMware.PowerCLI
$Time = Get-Date -Format "MM-dd-yy-hhmm"
If (-not (Test-Path $ConfigPath\Old))
{   New-Item $ConfigPath\Old -ItemType Directory
}
# Add date/time to the configuration file name and move to archive
ForEach ($File in (Get-ChildItem $ConfigPath\*.tgz))
{   $NewName = "$($File.Basename)-$Time.tgz"
    Copy-Item $File.FullName "$ConfigPath\Old\$NewName"
    Remove-Item $File.FullName
}
# Download latest configuration files
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
Connect-VIServer $VIServer -User $User -Password $Password -Force
Get-VMHost | Get-VMHostFirmware -BackupConfiguration -DestinationPath $ConfigPath
# Remove older files in archive
ForEach ($File in (Get-ChildItem $ConfigPath\Old\*.tgz | Where LastWriteTime -LE (Get-Date).AddDays(-$Days)))
{   Remove-Item $File.FullName
}

# Disconnect from vCenter
Disconnect-VIServer -Server $VIServer -Confirm:$false
解决方法

1. 配置Windows防火墙出站规则

直接针对PowerShell或脚本创建出站阻止规则,精准限制联网行为:

  • 打开「Windows Defender防火墙」→「高级设置」→「出站规则」→「新建规则」
  • 选择「程序」→ 下一步 → 指定C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe(或对应PowerShell版本路径)
  • 选择「阻止连接」→ 下一步 → 根据需求勾选网络类型(建议全选)
  • 命名规则(如「阻止PowerShell联网」)并完成
  • 若需更精准,可在规则的「条件」选项卡添加「远程IP地址」或「域名」,指定sv.symcb.com和Digicert相关站点

2. 临时禁用证书链验证(谨慎使用)

如果确认联网请求来自证书校验,可在脚本开头添加以下命令跳过验证:

[System.Net.ServicePointManager]::ServerCertificateValidationCallback = { $true }

⚠️ 此方法会降低系统安全性,仅在完全信任的内网环境中使用。

3. 用受限账户运行定时任务

创建仅拥有本地必要权限的标准用户,以此账户运行定时任务,并通过组策略限制该账户的网络访问权限。这种方式更安全,但配置相对复杂。

4. 离线加载VMware PowerCLI模块

由于脚本仅访问内网vCenter,可提前将PowerCLI模块下载到本地,避免联网验证:

  • 在联网机器上执行Save-Module -Name VMware.PowerCLI -Path C:\local-modules
  • 将模块复制到目标机器的C:\Program Files\WindowsPowerShell\Modules或自定义路径
  • 修改脚本中的Import-Module命令,指向本地模块路径:Import-Module C:\local-modules\VMware.PowerCLI

内容的提问来源于stack exchange,提问作者Jeff

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 11:50:50