You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PDQ Inventory:如何以登录用户身份执行BITS传输至文件共享

问题:PDQ Inventory本地管理员权限无法访问域共享传输文件

我需要用PDQ Inventory在部分终端上执行命令,把命令输出存储后传到文件共享。当前登录的域用户有该共享的访问权限,但PDQ是以本地管理员身份运行命令,导致无法访问共享。

已完成的操作代码

$csv  = 'C:\Temp\SecurityEvents.csv'
$zip  = 'C:\Temp\SecurityEvents.zip'
$dest = '\\Domain\Transfer\SecurityEvents.zip'

# export & compress
Get-WinEvent -FilterHashtable @{LogName='Security';Id=5140,5145} |
  Select-Object @{n='EventID';e={$_.Id}},
                @{n='Time';   e={$_.TimeCreated}},
                @{n='Source_IP';e={$_.Properties[5].Value}},
                @{n='User';   e={$_.Properties[1].Value}},
                @{n='Share';  e={$_.Properties[7].Value}},
                @{n='Target'; e={ if ($_.Id -eq 5140) { '' } else { $_.Properties[9].Value } }} |
  Export-Csv -Path $csv -NoTypeInformation

if (Test-Path $zip) { Remove-Item $zip -Force }
Compress-Archive -LiteralPath $csv -DestinationPath $zip

# Need help doing the transfer to the share

我试过以本地用户身份启动PowerShell进程、创建计划任务,但都没成功,求解决文件传输到共享的问题。


解决方案

方法1:使用PDQ内置的"Run As"功能(推荐)

PDQ Inventory/Deploy支持指定任务的运行身份,直接让整个脚本以拥有共享权限的域用户执行,无需修改脚本:

  • 打开PDQ任务的**Options(选项)**标签页
  • 找到Run As设置,选择Specific User(指定用户)
  • 输入格式为DOMAIN\Username的域账号及对应密码
  • 保存任务后重新执行,脚本里直接用Copy-Item $zip $dest即可完成传输

方法2:脚本内临时映射共享(无需修改PDQ配置)

如果无法调整PDQ运行身份,可在脚本中用域用户凭据临时映射共享,完成传输后取消映射:

$csv  = 'C:\Temp\SecurityEvents.csv'
$zip  = 'C:\Temp\SecurityEvents.zip'
$destShare = '\\Domain\Transfer'
$destFile = 'SecurityEvents.zip'

# 导出并压缩(保留原逻辑)
Get-WinEvent -FilterHashtable @{LogName='Security';Id=5140,5145} |
  Select-Object @{n='EventID';e={$_.Id}},
                @{n='Time';   e={$_.TimeCreated}},
                @{n='Source_IP';e={$_.Properties[5].Value}},
                @{n='User';   e={$_.Properties[1].Value}},
                @{n='Share';  e={$_.Properties[7].Value}},
                @{n='Target'; e={ if ($_.Id -eq 5140) { '' } else { $_.Properties[9].Value } }} |
  Export-Csv -Path $csv -NoTypeInformation

if (Test-Path $zip) { Remove-Item $zip -Force }
Compress-Archive -LiteralPath $csv -DestinationPath $zip

# 用域凭据临时映射共享
$domainUser = "DOMAIN\YourAuthorizedUser"
$domainPass = ConvertTo-SecureString "YourUserPassword" -AsPlainText -Force
$credential = New-Object System.Management.Automation.PSCredential($domainUser, $domainPass)

# 映射为未使用的盘符(比如Z:)
New-PSDrive -Name Z -PSProvider FileSystem -Root $destShare -Credential $credential -Persist:$false

# 复制文件到共享
Copy-Item -Path $zip -Destination "Z:\$destFile" -Force

# 清理映射
Remove-PSDrive -Name Z -Force

注意:硬编码密码不安全,建议用PDQ的加密变量存储凭据,避免明文泄露。

方法3:创建一次性计划任务(适配严格权限环境)

如果前两种方法受限,可在脚本中创建以域用户身份运行的一次性计划任务,执行文件复制:

$csv  = 'C:\Temp\SecurityEvents.csv'
$zip  = 'C:\Temp\SecurityEvents.zip'
$dest = '\\Domain\Transfer\SecurityEvents.zip'

# 导出并压缩(保留原逻辑)
Get-WinEvent -FilterHashtable @{LogName='Security';Id=5140,5145} |
  Select-Object @{n='EventID';e={$_.Id}},
                @{n='Time';   e={$_.TimeCreated}},
                @{n='Source_IP';e={$_.Properties[5].Value}},
                @{n='User';   e={$_.Properties[1].Value}},
                @{n='Share';  e={$_.Properties[7].Value}},
                @{n='Target'; e={ if ($_.Id -eq 5140) { '' } else { $_.Properties[9].Value } }} |
  Export-Csv -Path $csv -NoTypeInformation

if (Test-Path $zip) { Remove-Item $zip -Force }
Compress-Archive -LiteralPath $csv -DestinationPath $zip

# 创建一次性计划任务执行复制
$taskName = "Temp_CopySecurityZip_$(Get-Random)"
$domainUser = "DOMAIN\YourAuthorizedUser"
$domainPass = "YourUserPassword"

# 构建复制命令(含清理临时文件逻辑)
$action = New-ScheduledTaskAction -Execute "powershell.exe" -Argument "-Command `"Copy-Item -Path '$zip' -Destination '$dest' -Force; Remove-Item -Path '$zip','$csv' -Force`""

# 设置立即执行的触发器
$trigger = New-ScheduledTaskTrigger -Once -At (Get-Date).AddSeconds(5)

# 配置任务运行身份与自动清理
$settings = New-ScheduledTaskSettingsSet -DeleteExpiredTaskAfter 00:05:00
$principal = New-ScheduledTaskPrincipal -UserId $domainUser -LogonType Password -RunLevel Highest

# 注册并启动任务
Register-ScheduledTask -TaskName $taskName -Action $action -Trigger $trigger -Principal $principal -Settings $settings -Password $domainPass
Start-ScheduledTask -TaskName $taskName

内容的提问来源于stack exchange,提问作者gclark18

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 16:20:54