MegaBites-AI/Windows-powershell
0372
1# Copyright (c) Microsoft Corporation.2# Licensed under the MIT License.3 4<#5.Synopsis6 Registers or unregisters the PowerShell ETW manifest7.Parameter Path8 The fully qualified path to the PowerShell.Core.Instrumentation.man manifest file.9 The default value is the location of this script.10 11.Parameter Unregister12 Specify to unregister the manifest.13.Notes14 The PowerShell.Core.Instrumentation.man and PowerShell.Core.Instrumentation.dll files are15 expected to be at the location specified by the Path parameter.16 When registered, PowerShell.Core.Instrumentation.dll is locked to prevent deleting or changing.17 To update the binary, first unregister the manifest using the -Unregister switch.18#>19[CmdletBinding()]20param21(22 [ValidateNotNullOrEmpty()]23 [string] $Path = $PSScriptRoot,24 25 [switch] $Unregister26)27Set-StrictMode -Version 3.028$ErrorActionPreference = 'Stop'29 30function Start-NativeExecution([scriptblock]$sb, [switch]$IgnoreExitcode)31{32 $backupEAP = $script:ErrorActionPreference33 $script:ErrorActionPreference = "Continue"34 try35 {36 & $sb37 # note, if $sb doesn't have a native invocation, $LASTEXITCODE will38 # point to the obsolete value39 if ($LASTEXITCODE -ne 0 -and -not $IgnoreExitcode)40 {41 throw "Execution of {$sb} failed with exit code $LASTEXITCODE"42 }43 }44 finally45 {46 $script:ErrorActionPreference = $backupEAP47 }48}49 50function Test-Elevated51{52 [CmdletBinding()]53 [OutputType([bool])]54 Param()55 56 # if the current Powershell session was called with administrator privileges,57 # the Administrator Group's well-known SID will show up in the Groups for the current identity.58 # Note that the SID won't show up unless the process is elevated.59 return (([Security.Principal.WindowsIdentity]::GetCurrent()).Groups -contains "S-1-5-32-544")60}61$IsWindowsOs = $PSHOME.EndsWith('\WindowsPowerShell\v1.0', [System.StringComparison]::OrdinalIgnoreCase) -or $IsWindows62 63if (-not $IsWindowsOs)64{65 throw 'This script must be run on Windows.'66}67 68if (-not (Test-Elevated))69{70 throw 'This script must be run from an elevated process.'71}72 73$manifest = Get-Item -Path (Join-Path -Path $Path -ChildPath 'PowerShell.Core.Instrumentation.man')74$binary = Get-Item -Path (Join-Path -Path $Path -ChildPath 'PowerShell.Core.Instrumentation.dll')75 76$files = @($manifest, $binary)77foreach ($file in $files)78{79 if (-not (Test-Path -Path $file))80 {81 throw "Could not find $($file.Name) at $Path"82 }83}84 85[string] $command = 'wevtutil um "{0}"' -f $manifest.FullName86 87# Unregister if present. Avoids warnings when registering the manifest88# and it is already registered.89Write-Verbose "unregister the manifest, if present: $command"90Start-NativeExecution {Invoke-Expression $command} $true91 92if (-not $Unregister)93{94 $command = 'wevtutil.exe im "{0}" /rf:"{1}" /mf:"{1}"' -f $manifest.FullName, $binary.FullName95 Write-Verbose -Message "Register the manifest: $command"96 Start-NativeExecution { Invoke-Expression $command }97}98 