Windows11 22H2下阻止PowerShell执行未签名脚本时联网
问题描述
我配置了一个每日定时运行的任务计划,用于执行一段未签名的PowerShell脚本。升级Windows 11到22H2版本后,防火墙多次弹出提示,显示PowerShell尝试连接互联网,目标地址为sv.symcb.com或Digicert相关站点,推测是应用签名的证书校验操作,但无法确认。
脚本能正常运行并完成任务,我仅希望阻止它发起联网请求,请问有没有办法阻止该脚本运行时PowerShell的联网行为?
定时任务参数
-WindowStyle Hidden -NonInteractive -ExecutionPolicy Bypass -File "C:\path-to\script.ps1"
脚本内容
Param ( # vCenter server & credintials [string]$VIServer = "192.168.224.123", [string]$User = 'administrator@vsphere.loc', [string]$Password = 'xxxxxxx', [string]$ConfigPath = "C:\path-to\backups\", [int]$Days = 21 ) Import-Module VMware.PowerCLI $Time = Get-Date -Format "MM-dd-yy-hhmm" If (-not (Test-Path $ConfigPath\Old)) { New-Item $ConfigPath\Old -ItemType Directory } # Add date/time to the configuration file name and move to archive ForEach ($File in (Get-ChildItem $ConfigPath\*.tgz)) { $NewName = "$($File.Basename)-$Time.tgz" Copy-Item $File.FullName "$ConfigPath\Old\$NewName" Remove-Item $File.FullName } # Download latest configuration files [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12 Connect-VIServer $VIServer -User $User -Password $Password -Force Get-VMHost | Get-VMHostFirmware -BackupConfiguration -DestinationPath $ConfigPath # Remove older files in archive ForEach ($File in (Get-ChildItem $ConfigPath\Old\*.tgz | Where LastWriteTime -LE (Get-Date).AddDays(-$Days))) { Remove-Item $File.FullName } # Disconnect from vCenter Disconnect-VIServer -Server $VIServer -Confirm:$false
解决方法
1. 配置Windows防火墙出站规则
直接针对PowerShell或脚本创建出站阻止规则,精准限制联网行为:
- 打开「Windows Defender防火墙」→「高级设置」→「出站规则」→「新建规则」
- 选择「程序」→ 下一步 → 指定
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe(或对应PowerShell版本路径) - 选择「阻止连接」→ 下一步 → 根据需求勾选网络类型(建议全选)
- 命名规则(如「阻止PowerShell联网」)并完成
- 若需更精准,可在规则的「条件」选项卡添加「远程IP地址」或「域名」,指定
sv.symcb.com和Digicert相关站点
2. 临时禁用证书链验证(谨慎使用)
如果确认联网请求来自证书校验,可在脚本开头添加以下命令跳过验证:
[System.Net.ServicePointManager]::ServerCertificateValidationCallback = { $true }
⚠️ 此方法会降低系统安全性,仅在完全信任的内网环境中使用。
3. 用受限账户运行定时任务
创建仅拥有本地必要权限的标准用户,以此账户运行定时任务,并通过组策略限制该账户的网络访问权限。这种方式更安全,但配置相对复杂。
4. 离线加载VMware PowerCLI模块
由于脚本仅访问内网vCenter,可提前将PowerCLI模块下载到本地,避免联网验证:
- 在联网机器上执行
Save-Module -Name VMware.PowerCLI -Path C:\local-modules - 将模块复制到目标机器的
C:\Program Files\WindowsPowerShell\Modules或自定义路径 - 修改脚本中的
Import-Module命令,指向本地模块路径:Import-Module C:\local-modules\VMware.PowerCLI
内容的提问来源于stack exchange,提问作者Jeff
相关产品推荐
相关产品推荐

