Advertisement
Guest User

Untitled

a guest
Sep 4th, 2015
109
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.21 KB | None | 0 0
  1. $s1 = (gwmi -List Win32_ShadowCopy).Create("C:\", "ClientAccessible")
  2. $s2 = gwmi Win32_ShadowCopy | ? { $_.ID -eq $s1.ShadowID }
  3. $d = $s2.DeviceObject + "\"
  4. cmd /c mklink /d C:\scpy "$d"
  5. New-CIPolicy -Level RootCertificate -FilePath C:\BasePolicy.xml -ScanPath C:\scpy -UserPEs
  6. $s2.Delete()
  7. Remove-Item -Path C:\scpy -Force
  8. Set-RuleOption –option 3 –FilePath C:\BasePolicy.xml
  9. ConvertFrom-CIPolicy C:\BasePolicy.xml C:\BasePolicy.bin
  10. Move-Item C:\BasePolicy.bin c:\Windows\System32\CodeIntegrity\SIPolicy.p7b -force
  11. # Reboot
  12.  
  13. # Update after use
  14. New-CIPolicy -Level PcaCertificate -f C:\AuditPolicy.xml -Audit -UserPEs -Fallback Hash
  15. Merge-CIPolicy –OutputFilePath C:\MergedPolicy.xml –PolicyPaths C:\AuditPolicy.xml,C:\BasePolicy.xml
  16. Set-RuleOption –option 3 –FilePath C:\MergedPolicy.xml
  17. ConvertFrom-CIPolicy C:\MergedPolicy.xml C:\MergedPolicy.bin
  18. Move-Item C:\MergedPolicy.bin c:\Windows\System32\CodeIntegrity\SIPolicy.p7b -force
  19. #reboot
  20.  
  21. # Check for missing apps, libraries and drivers if none, enforce
  22. Set-RuleOption –option 3 –FilePath C:\MergedPolicy.xml -Delete
  23. ConvertFrom-CIPolicy C:\MergedPolicy.xml C:\MergedPolicy.bin
  24. Move-Item C:\MergedPolicy.bin c:\Windows\System32\CodeIntegrity\SIPolicy.p7b -Force
  25. # reboot
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement