如何将PowerView的Convert-SidToName函数应用于SecurityIdentifier列表?
如何将PowerView的Convert-SidToName函数应用于SecurityIdentifier列表?
嗨,我来帮你搞定这个问题!你遇到的报错原因很清晰——当你用select SecurityIdentifier的时候,输出的是包含SecurityIdentifier属性的对象,而不是纯SID字符串,Convert-SidToName(或者你错误提示里的ConvertFrom-SID,这俩其实是PowerView里同一个函数的别名)需要的是直接的SID值,不是带属性包装的对象。
给你几个可行的解决方法:
方法一:用-ExpandProperty提取纯SID值
这个方法最简洁,直接把属性值从对象里提取出来变成纯字符串列表:
Get-ObjectAcl -Identity "DnsAdmins" | Where-Object {$_.ActiveDirectoryRights -eq "GenericAll"} | Select-Object -ExpandProperty SecurityIdentifier | Convert-SidToName
方法二:用ForEach-Object逐个处理对象
如果你更习惯遍历对象的写法,也可以这样做,逐个把每个对象的SID属性传给转换函数:
Get-ObjectAcl -Identity "DnsAdmins" | Where-Object {$_.ActiveDirectoryRights -eq "GenericAll"} | ForEach-Object { Convert-SidToName $_.SecurityIdentifier }
额外技巧:保留原始属性同时添加解析后的名称
如果你想同时看到原始SID和对应的可读名称,方便对照,可以用计算属性的方式:
Get-ObjectAcl -Identity "DnsAdmins" | Where-Object {$_.ActiveDirectoryRights -eq "GenericAll"} | Select-Object SecurityIdentifier, @{Name='AccountName'; Expression={Convert-SidToName $_.SecurityIdentifier}}
这样输出结果会包含两列:SecurityIdentifier(原始SID)和AccountName(解析后的可读名称)。
备注:内容来源于stack exchange,提问作者TMOTTM
相关产品推荐
相关产品推荐

