Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 19 additions & 0 deletions Engine.Tests/Analyze/BuiltInConditionCatalogTests.cs
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
using Engine;
using System.Linq;
using Xunit;

namespace Engine.Tests.Analyze
{
public class BuiltInConditionCatalogTests
{
[Fact]
public void ShouldEnumerateAllBuiltInRules()
{
var rules = BuiltInConditionCatalog.GetRules().ToList();

Assert.Equal(12, rules.Count);
Assert.Contains(rules, rule => rule.Name == "amsiBypass");
Assert.All(rules, rule => Assert.False(string.IsNullOrWhiteSpace(rule.Description)));
}
}
}
16 changes: 1 addition & 15 deletions PowerShellProtect/Analyze/Analyzer.cs
Original file line number Diff line number Diff line change
Expand Up @@ -50,21 +50,7 @@ public Analyzer()
new ScriptStringCondition(),
}.ToDictionary(m => m.Name.ToLower(), m => m);

_builtInConditions = new List<ICondition>
{
new AmsiBypass(),
new LoggingBypass(),
new DisableDefender(),
new PowerSploit(),
new AssemblyLoad(),
new ReflectionEmit(),
new MarshalClass(),
new PersistentWmi(),
new BloudHound(),
new Kerberoasting(),
new InvokeExpression(),
new Log4J()
};
_builtInConditions = BuiltInConditionCatalog.Create().ToList();

foreach (var builtInCondition in _builtInConditions)
{
Expand Down
38 changes: 38 additions & 0 deletions PowerShellProtect/Analyze/BuiltInConditionCatalog.cs
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
using System.Collections.Generic;
using System.Linq;
using Engine.Configuration;
using PowerShellProtect.Analyze.Conditions;

namespace Engine
{
internal static class BuiltInConditionCatalog
{
internal static IEnumerable<ICondition> Create()
{
return new ICondition[]
{
new AmsiBypass(),
new LoggingBypass(),
new DisableDefender(),
new PowerSploit(),
new AssemblyLoad(),
new ReflectionEmit(),
new MarshalClass(),
new PersistentWmi(),
new BloudHound(),
new Kerberoasting(),
new InvokeExpression(),
new Log4J()
};
}

internal static IEnumerable<BuiltInRule> GetRules()
{
return Create().Select(condition => new BuiltInRule
{
Name = condition.Name,
Description = condition.Description
});
}
}
}
9 changes: 7 additions & 2 deletions PowerShellProtect/Cmdlets/GetConfigurationCommand.cs
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
using Engine.Configuration;
using Engine;
using Engine.Configuration;
using System.Management.Automation;
using System.Linq;

namespace PowerShellProtect.Cmdlets
{
Expand All @@ -9,8 +11,11 @@ public class GetConfigurationCommand : PSCmdlet
protected override void BeginProcessing()
{
var config = new Config();
var configuration = config.GetConfiguration();

WriteObject(config.GetConfiguration());
configuration.BuiltInRules = BuiltInConditionCatalog.GetRules().ToList();

WriteObject(configuration);
}
}
}
10 changes: 10 additions & 0 deletions PowerShellProtect/Configuration/Configuration.cs
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
using System.Collections.Generic;
using System.Linq;
using System.Xml.Serialization;

namespace Engine.Configuration
{
Expand All @@ -9,6 +10,15 @@ public class Configuration
public List<Action> Actions { get; set; } = new List<Action>();
public BuiltIn BuiltIn { get; set; } = new BuiltIn();
public AiConfiguration AI { get; set; } = new AiConfiguration();

[XmlIgnore]
public List<BuiltInRule> BuiltInRules { get; set; } = new List<BuiltInRule>();
}

public class BuiltInRule
{
public string Name { get; set; }
public string Description { get; set; }
}

public class AiConfiguration
Expand Down
10 changes: 10 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,16 @@ Install-Module PowerShellProtect
Install-PowerShellProtect
```

## Inspect built-in rules

`Get-PSPConfiguration` includes the built-in rules that ship with the module. The
`BuiltInRules` property lists each rule's name and description; it is informational
only and is not written into exported configuration XML.

```powershell
(Get-PSPConfiguration).BuiltInRules | Format-Table Name, Description -Wrap
```

## Resources

- [License](./LICENSE)
Expand Down