$lsa=Get-ADDomainController -Filter * | %{Invoke-Command -ComputerName $_.Hostname {ls HKLM:\SYS
TEM\CurrentControlSet\Control\Lsa}}
Now check the $lsa object for "Notification Packages"
For example, you can pipe it to Out-GridView and use the search field.
More info on registering password filters registration :
https://msdn.microsoft.com/en-us/library/windows/desktop/ms721766(v=vs.85).aspx
Showing posts with label powershell. Show all posts
Showing posts with label powershell. Show all posts
Thursday, September 29, 2016
Checking for Active Directory password filters
As Microsoft puts it, "Password filters provide a way for you to implement password policy and change notification."
The other day , I read hackers were registering password filters to catch user passwords, following the revelation of the Project Sauron APT .
Therefore, I had to check if any malicious password filters were installed on my domain controllers.
One line of Powershell is enough :-)
Monday, August 11, 2014
Powershell - check if members of a group are members of another group
import-module activedirectory
foreach ($u in Get-ADGroupMember -Identity "Users")
{
if(-not (Get-ADPrincipalGroupMembership $u| ?{$_.Name -eq "Domain Users"})){write-host $u " is missing from Domain Users"}
}
Thursday, July 31, 2014
Poor man's IP to to Username, using Powershell & Domain Controller logs
This customer had many offices and needed to get rid of Windows XP machines.
Due to the lack of inventory and computer management, we were unable to know who were the people behind them!
Ping and remote access were shut off from the host so we couldn't gather information via WMI.
But the LastLogonTimeStamp was being updated for these computers which led us to believe they were still in use.
The solution I came up with : if someone was still using these XP machines, they were authenticating against the domain controllers, and a "logon event" was created with the source ip and the username.
Once you load the quick and dirty function called "Get-UserName-for_PC-by-DC-events (silly name sorry), run these 2 commands to get some results
Import-module ActiveDirectory
Get-ADComputer -Filter {Enabled -eq $true -and operatingsystem -like '*xp*'} -Properties IPv4Address | %{Get-UserName-for-PC-by-DC-events -DCname "DC01" -Ip $_.IPv4Address}
7/31/2014 1:18:33 PM -- john.doe at this address --> 10.26.1.15 using Kerberos
A nice enhancement would be to query all domain controllers.
Finally, your mileage may vary depending on how big your security logs are, how often they rotate and how often these XP users log on (you could run a scheduled task)
Function Get-UserName-for-PC-by-DC-events
{
param(
[Parameter(Mandatory=$True)]
[string]$DCname,
[Parameter(Mandatory=$True)]
[string]$Ip
)
$xpathfilter = 'Event[System[EventID=4624] and EventData[Data[@Name="IpAddress"]="'+$ip+'"]]'
Foreach ($event in get-winevent -ComputerName $DCname -LogName Security -FilterXPath $xpathfilter -MaxEvents 1)
{
Write-host $event.TimeCreated " -- " $event.Properties[5].Value "at this address --> " $event.Properties[18].Value " using " $event.Properties[9].Value
}
}
Wednesday, July 16, 2014
DCHP server migration from Debian to Windows Server 2008
My customer wanted to migrate DHCP server function from
Debian Wheezy 7.50 running ISC-DHCP to Windows Server 2008.
The task can broken in 6 parts
get this great AWK parser onto the Debian box https://gist.github.com/mattpascoe/4039747
make it executable
Import the parsed file to your Windows Server
have a look at it to remove errors.
Setup DHCP role on Windows Server
skipping this part as it's pretty self explanatory
Run script
You will need this Powershell module , referred to as "Microsoft.DHCP.Powershell.Admin.psm1" in the script. If Window Server is version 2012 R2 , I guess you can use the DHCP server cmdlets from Microsoft instead.
You will also need to make a Powershell module -which is a combination of this function and this function. Just add one function under the other and put the line "export-modulemember IsIpAddressInRange,Get-IPrange". This module is referred as "IPutil.psm1"
The task can broken in 6 parts
- parse dhcpd.conf on the DHCP server (Linux)
- import the parsed file to your *new* DHCP server
- setup DHCP role on *new*server
- run a script on the *new* DHCP server which creates scopes,pools and reservations (Windows) according to the parsed file.
- manually rename the scopes to "friendly" names
- manually set the server,scope and/or reservation options and scope lease times
get this great AWK parser onto the Debian box https://gist.github.com/mattpascoe/4039747
make it executable
chmod +x dhcpparse.awk
parse the file
cat /etc/dhcp/dhcpd.conf | dhcpparse.awk > dhcp-config.txt
Import the parsed file to your Windows Server
have a look at it to remove errors.
Setup DHCP role on Windows Server
skipping this part as it's pretty self explanatory
Run script
You will need this Powershell module , referred to as "Microsoft.DHCP.Powershell.Admin.psm1" in the script. If Window Server is version 2012 R2 , I guess you can use the DHCP server cmdlets from Microsoft instead.
You will also need to make a Powershell module -which is a combination of this function and this function. Just add one function under the other and put the line "export-modulemember IsIpAddressInRange,Get-IPrange". This module is referred as "IPutil.psm1"
Import-Module .\Microsoft.DHCP.Powershell.Admin.psm1
Import-Module .\IPutil.psm1
#Group by line types
$subnets = Select-String -Pattern 'subnet' -Path .\dhcp-config.txt |%{$_.Line}
$pools = Select-String -Pattern 'pool' -Path .\dhcp-config.txt | %{$_.Line}
$hosts = Select-string -Pattern ‘host’ -path .\dhcp-config.txt |%{$_.Line}
#Create scopes
$scopes = $subnets |%{$l=$_.Split(','); New-DHCPScope -Server $env:COMPUTERNAME -Address $l[1] -SubnetMask $l[2] -Name $l[3]}
foreach ($scope in $scopes)
{
# generate all the IP addresses in this scope
$ips=Get-IPrange -ip $scope.Address -mask $scope.SubnetMask
# Create pools
Write-host "Creating pool(s) for " $scope.Address
foreach ($line in $pools)
{
if($ips -contains $line.split(',')[1])
{
Add-DhcpIPRange -scope $scope -startaddress $line.split(',')[1] -endaddress $line.split(',')[2]
}
}
# Create reservations
Write-host "Creating reservation(s) for " $scope.Address
foreach ($line in $hosts)
{
if($ips -contains $line.split(',')[1])
{
New-DHCPReservation -scope $scope -IPAddress $line.split(',')[1] -MACAddress $line.split(',')[2] -Description $line.split(',')[4]
}
}
}
Write-host “You should now rename the scopes to friendly names”
Write-host “You should manually set options and lease times"
Thursday, December 1, 2011
PowerShell - count folders in folders
Counting the number of files in a directory is easy
The problem
An invoice scanning system uploads files to a file server. The directory structure is the following.
\\server\files\<country_code-invoices>\<date>\<invoice_id></invoice_id></date></country_code-invoices>
Here's an German invoice folder scanned on December 1st 2011
\\server\files\DE-invoices\2011-12-01\2ad52000-32d5-4d72-925a-98ac442d2381
The question is : "How many invoices have been created every day by country ?" . The output has to be a table to be analyzed with Excel.
The proposed solution
Get all the country folders
Now it's getting a bit tricky.We'll put a pipeline inside a pipeline!
Because we need to process each date folder in each country folder.
Display the country name and the date folder
DE-invoices 2011-12-01
DE-invoices 2011-11-30
etc..
Display the folder count
outputs
DE-invoices 2011-12-01 5
DE-invoices 2011-11-30 18
etc..
The result can now be imported as CSV file ,using the space character as the separator.
(dir).CountHere's a more complex example that I will break down, like a tutorial. Unlike the previous example, this is taking advantage of the object oriented nature of PowerShell. You should understand about_pipelines before you continue reading
The problem
An invoice scanning system uploads files to a file server. The directory structure is the following.
\\server\files\<country_code-invoices>\<date>\<invoice_id></invoice_id></date></country_code-invoices>
Here's an German invoice folder scanned on December 1st 2011
\\server\files\DE-invoices\2011-12-01\2ad52000-32d5-4d72-925a-98ac442d2381
The question is : "How many invoices have been created every day by country ?" . The output has to be a table to be analyzed with Excel.
The proposed solution
Get all the country folders
dir \\server\files\*-invoicesFor each (% is the operator) country folder ($_ is the pipeline object), display only its name
dir \\server\files\*-invoices | %{$_.Name}
#
Display the date folders for each countrydir \\server\files\*-invoices | %{dir $_}
#
We'll store the country name in $country, to use it later as we bring it up the pipeline.dir \\server\files\*-invoices | %{$country=$_.Name}
#
Now it's getting a bit tricky.We'll put a pipeline inside a pipeline!
Because we need to process each date folder in each country folder.
- For Each country folder display its name
- For Each date folder in a country folder display its name
- For Each date folder, count the number of folders it contains
Display the country name and the date folder
dir \\server\files\*-invoices | %{$country=$_.Name;dir $_ |%{Write-Host $country $_.Name}}
#
outputsDE-invoices 2011-12-01
DE-invoices 2011-11-30
etc..
Display the folder count
dir \\server\files\*-invoices | %{$country=$_.Name;dir $_ |%{Write-Host $country $_.Name (dir $_).count}}
#
outputs
DE-invoices 2011-12-01 5
DE-invoices 2011-11-30 18
etc..
The result can now be imported as CSV file ,using the space character as the separator.
Wednesday, November 16, 2011
Windows PowerShell : consolidate log files
I'm using Windows PowerShell more and more every day, here's a simple example.
The task is to consolidate several csv files.
With command prompt
With Powershell, use Get-Content and Add-Content
Now we have used a "text-based" approach in both cases.
In case you have headers in the .csv file, and you just want to filter out some fields of the CSV file, it will get very complicated with the command prompt.
That's when you have to take a more "object-oriented" approach with PowerShell : check out this article from Microsoft's Scripting Guy, which addresses this particular issue.
Since you can use COM and .Net objects in PowerShell, the possibilities are endless! So instead of developing a VBScript for a task we'll run one time only (not a batch), I use PowerShell interactively.
The task is to consolidate several csv files.
With command prompt
copy/b SoftDistribution*.csv Consolidated_logs.csv
With Powershell, use Get-Content and Add-Content
Get-Content SoftDistribution*.csv | Add-Content Consolidated_logs.csv
Now we have used a "text-based" approach in both cases.
In case you have headers in the .csv file, and you just want to filter out some fields of the CSV file, it will get very complicated with the command prompt.
That's when you have to take a more "object-oriented" approach with PowerShell : check out this article from Microsoft's Scripting Guy, which addresses this particular issue.
Since you can use COM and .Net objects in PowerShell, the possibilities are endless! So instead of developing a VBScript for a task we'll run one time only (not a batch), I use PowerShell interactively.
Subscribe to:
Posts (Atom)