progrocker

Meltdown/Spectre Powershell Detection Script

Jan 9th, 2018
185
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. ## Credit to u/martinmcmanus for consolidation of the module and script as well as other various improvements.
  2. # https://www.reddit.com/r/SCCM/comments/7o6qe9/meltdownspectre_powershell_module/
  3.  
  4. function Get-SpeculationControlSettings {
  5.   <#
  6.  
  7.   .SYNOPSIS
  8.   This function queries the speculation control settings for the system.
  9.  
  10.   .DESCRIPTION
  11.   This function queries the speculation control settings for the system.
  12.  
  13.   Version 1.3.
  14.  
  15.   #>
  16.  
  17.   [CmdletBinding()]
  18.   param (
  19.  
  20.   )
  21.  
  22.   process {
  23.  
  24.     $NtQSIDefinition = @'
  25.    [DllImport("ntdll.dll")]
  26.    public static extern int NtQuerySystemInformation(uint systemInformationClass, IntPtr systemInformation, uint systemInformationLength, IntPtr returnLength);
  27. '@
  28.  
  29.     $ntdll = Add-Type -MemberDefinition $NtQSIDefinition -Name 'ntdll' -Namespace 'Win32' -PassThru
  30.  
  31.  
  32.     [System.IntPtr]$systemInformationPtr = [System.Runtime.InteropServices.Marshal]::AllocHGlobal(4)
  33.     [System.IntPtr]$returnLengthPtr = [System.Runtime.InteropServices.Marshal]::AllocHGlobal(4)
  34.  
  35.     $object = New-Object -TypeName PSObject
  36.  
  37.     try {
  38.  
  39.         #
  40.         # Query branch target injection information.
  41.         #
  42.         <# #Killed write host -MM
  43.         Write-Host "Speculation control settings for CVE-2017-5715 [branch target injection]" -ForegroundColor Cyan
  44.         Write-Host
  45.         #>
  46.  
  47.         $btiHardwarePresent = $false
  48.         $btiWindowsSupportPresent = $false
  49.         $btiWindowsSupportEnabled = $false
  50.         $btiDisabledBySystemPolicy = $false
  51.         $btiDisabledByNoHardwareSupport = $false
  52.  
  53.         [System.UInt32]$systemInformationClass = 201
  54.         [System.UInt32]$systemInformationLength = 4
  55.  
  56.         $retval = $ntdll::NtQuerySystemInformation($systemInformationClass, $systemInformationPtr, $systemInformationLength, $returnLengthPtr)
  57.  
  58.         if ($retval -eq 0xc0000003 -or $retval -eq 0xc0000002) {
  59.             # fallthrough
  60.         }
  61.         elseif ($retval -ne 0) {
  62.             #Killed throw, set complaince variable instead -MM
  63.             #throw (("Querying branch target injection information failed with error {0:X8}" -f $retval))
  64.             $Compliance = $false
  65.             Return $Compliance
  66.         }
  67.         else {
  68.  
  69.             [System.UInt32]$scfBpbEnabled = 0x01
  70.             [System.UInt32]$scfBpbDisabledSystemPolicy = 0x02
  71.             [System.UInt32]$scfBpbDisabledNoHardwareSupport = 0x04
  72.             [System.UInt32]$scfHwReg1Enumerated = 0x08
  73.             [System.UInt32]$scfHwReg2Enumerated = 0x10
  74.             [System.UInt32]$scfHwMode1Present = 0x20
  75.             [System.UInt32]$scfHwMode2Present = 0x40
  76.             [System.UInt32]$scfSmepPresent = 0x80
  77.  
  78.             [System.UInt32]$flags = [System.UInt32][System.Runtime.InteropServices.Marshal]::ReadInt32($systemInformationPtr)
  79.  
  80.             $btiHardwarePresent = ((($flags -band $scfHwReg1Enumerated) -ne 0) -or (($flags -band $scfHwReg2Enumerated)))
  81.             $btiWindowsSupportPresent = $true
  82.             $btiWindowsSupportEnabled = (($flags -band $scfBpbEnabled) -ne 0)
  83.  
  84.             if ($btiWindowsSupportEnabled -eq $false) {
  85.                 $btiDisabledBySystemPolicy = (($flags -band $scfBpbDisabledSystemPolicy) -ne 0)
  86.                 $btiDisabledByNoHardwareSupport = (($flags -band $scfBpbDisabledNoHardwareSupport) -ne 0)
  87.             }
  88.  
  89.             if ($PSBoundParameters['Verbose']) {
  90.                 Write-Host "BpbEnabled                   :" (($flags -band $scfBpbEnabled) -ne 0)
  91.                 Write-Host "BpbDisabledSystemPolicy      :" (($flags -band $scfBpbDisabledSystemPolicy) -ne 0)
  92.                 Write-Host "BpbDisabledNoHardwareSupport :" (($flags -band $scfBpbDisabledNoHardwareSupport) -ne 0)
  93.                 Write-Host "HwReg1Enumerated             :" (($flags -band $scfHwReg1Enumerated) -ne 0)
  94.                 Write-Host "HwReg2Enumerated             :" (($flags -band $scfHwReg2Enumerated) -ne 0)
  95.                 Write-Host "HwMode1Present               :" (($flags -band $scfHwMode1Present) -ne 0)
  96.                 Write-Host "HwMode2Present               :" (($flags -band $scfHwMode2Present) -ne 0)
  97.                 Write-Host "SmepPresent                  :" (($flags -band $scfSmepPresent) -ne 0)
  98.             }
  99.         }
  100.         <# #Killed write host -MM
  101.         Write-Host "Hardware support for branch target injection mitigation is present:"($btiHardwarePresent) -ForegroundColor $(If ($btiHardwarePresent) { [System.ConsoleColor]::Green } Else { [System.ConsoleColor]::Red })
  102.         Write-Host "Windows OS support for branch target injection mitigation is present:"($btiWindowsSupportPresent) -ForegroundColor $(If ($btiWindowsSupportPresent) { [System.ConsoleColor]::Green } Else { [System.ConsoleColor]::Red })
  103.         Write-Host "Windows OS support for branch target injection mitigation is enabled:"($btiWindowsSupportEnabled) -ForegroundColor $(If ($btiWindowsSupportEnabled) { [System.ConsoleColor]::Green } Else { [System.ConsoleColor]::Red })
  104.  
  105.         if ($btiWindowsSupportPresent -eq $true -and $btiWindowsSupportEnabled -eq $false) {
  106.             Write-Host -ForegroundColor Red "Windows OS support for branch target injection mitigation is disabled by system policy:"($btiDisabledBySystemPolicy)
  107.             Write-Host -ForegroundColor Red "Windows OS support for branch target injection mitigation is disabled by absence of hardware support:"($btiDisabledByNoHardwareSupport)
  108.         }
  109.         #>
  110.         $object | Add-Member -MemberType NoteProperty -Name BTIHardwarePresent -Value $btiHardwarePresent
  111.         $object | Add-Member -MemberType NoteProperty -Name BTIWindowsSupportPresent -Value $btiWindowsSupportPresent
  112.         $object | Add-Member -MemberType NoteProperty -Name BTIWindowsSupportEnabled -Value $btiWindowsSupportEnabled
  113.         $object | Add-Member -MemberType NoteProperty -Name BTIDisabledBySystemPolicy -Value $btiDisabledBySystemPolicy
  114.         $object | Add-Member -MemberType NoteProperty -Name BTIDisabledByNoHardwareSupport -Value $btiDisabledByNoHardwareSupport
  115.  
  116.         #
  117.         # Query kernel VA shadow information.
  118.         #
  119.         <# #Killed write host -MM
  120.         Write-Host
  121.         Write-Host "Speculation control settings for CVE-2017-5754 [rogue data cache load]" -ForegroundColor Cyan
  122.         Write-Host    
  123.         #>
  124.  
  125.         $kvaShadowRequired = $true
  126.         $kvaShadowPresent = $false
  127.         $kvaShadowEnabled = $false
  128.         $kvaShadowPcidEnabled = $false
  129.  
  130.         $cpu = Get-WmiObject Win32_Processor
  131.  
  132.         if ($cpu.Manufacturer -eq "AuthenticAMD") {
  133.             $kvaShadowRequired = $false
  134.         }
  135.         elseif ($cpu.Manufacturer -eq "GenuineIntel") {
  136.             $regex = [regex]'Family (\d+) Model (\d+) Stepping (\d+)'
  137.             $result = $regex.Match($cpu.Description)
  138.             if ($result.Success) {
  139.                 $family = [System.UInt32]$result.Groups[1].Value
  140.                 $model = [System.UInt32]$result.Groups[2].Value
  141.                 $stepping = [System.UInt32]$result.Groups[3].Value
  142.  
  143.                 if (($family -eq 0x6) -and
  144.                     (($model -eq 0x1c) -or
  145.                      ($model -eq 0x26) -or
  146.                      ($model -eq 0x27) -or
  147.                      ($model -eq 0x36) -or
  148.                      ($model -eq 0x35))) {
  149.  
  150.                     $kvaShadowRequired = $false
  151.                 }
  152.             }
  153.         }
  154.         else {
  155.             #Killed throw, set complaince variable instead -MM
  156.             #throw ("Unsupported processor manufacturer: {0}" -f $cpu.Manufacturer)
  157.             $Compliance = $False
  158.             Return $Compliance
  159.         }
  160.  
  161.         [System.UInt32]$systemInformationClass = 196
  162.         [System.UInt32]$systemInformationLength = 4
  163.  
  164.         $retval = $ntdll::NtQuerySystemInformation($systemInformationClass, $systemInformationPtr, $systemInformationLength, $returnLengthPtr)
  165.  
  166.         if ($retval -eq 0xc0000003 -or $retval -eq 0xc0000002) {
  167.         }
  168.         elseif ($retval -ne 0) {
  169.             #Killed throw, set complaince variable instead -MM
  170.             #throw (("Querying kernel VA shadow information failed with error {0:X8}" -f $retval))
  171.             $Compliance = $False
  172.             Return $Compliance
  173.         }
  174.         else {
  175.  
  176.             [System.UInt32]$kvaShadowEnabledFlag = 0x01
  177.             [System.UInt32]$kvaShadowUserGlobalFlag = 0x02
  178.             [System.UInt32]$kvaShadowPcidFlag = 0x04
  179.             [System.UInt32]$kvaShadowInvpcidFlag = 0x08
  180.  
  181.             [System.UInt32]$flags = [System.UInt32][System.Runtime.InteropServices.Marshal]::ReadInt32($systemInformationPtr)
  182.  
  183.             $kvaShadowPresent = $true
  184.             $kvaShadowEnabled = (($flags -band $kvaShadowEnabledFlag) -ne 0)
  185.             $kvaShadowPcidEnabled = ((($flags -band $kvaShadowPcidFlag) -ne 0) -and (($flags -band $kvaShadowInvpcidFlag) -ne 0))
  186.  
  187.             if ($PSBoundParameters['Verbose']) {
  188.                 Write-Host "KvaShadowEnabled             :" (($flags -band $kvaShadowEnabledFlag) -ne 0)
  189.                 Write-Host "KvaShadowUserGlobal          :" (($flags -band $kvaShadowUserGlobalFlag) -ne 0)
  190.                 Write-Host "KvaShadowPcid                :" (($flags -band $kvaShadowPcidFlag) -ne 0)
  191.                 Write-Host "KvaShadowInvpcid             :" (($flags -band $kvaShadowInvpcidFlag) -ne 0)
  192.             }
  193.         }
  194.         <# #Killed write host -MM
  195.         Write-Host "Hardware requires kernel VA shadowing:"$kvaShadowRequired
  196.  
  197.         if ($kvaShadowRequired) {
  198.  
  199.             Write-Host "Windows OS support for kernel VA shadow is present:"$kvaShadowPresent -ForegroundColor $(If ($kvaShadowPresent) { [System.ConsoleColor]::Green } Else { [System.ConsoleColor]::Red })
  200.             Write-Host "Windows OS support for kernel VA shadow is enabled:"$kvaShadowEnabled -ForegroundColor $(If ($kvaShadowEnabled) { [System.ConsoleColor]::Green } Else { [System.ConsoleColor]::Red })
  201.  
  202.             if ($kvaShadowEnabled) {
  203.                 Write-Host "Windows OS support for PCID optimization is enabled:"$kvaShadowPcidEnabled -ForegroundColor $(If ($kvaShadowPcidEnabled) { [System.ConsoleColor]::Green } Else { [System.ConsoleColor]::Red })
  204.             }
  205.         }
  206.  
  207.         #>
  208.         $object | Add-Member -MemberType NoteProperty -Name KVAShadowRequired -Value $kvaShadowRequired
  209.         $object | Add-Member -MemberType NoteProperty -Name KVAShadowWindowsSupportPresent -Value $kvaShadowPresent
  210.         $object | Add-Member -MemberType NoteProperty -Name KVAShadowWindowsSupportEnabled -Value $kvaShadowEnabled
  211.         $object | Add-Member -MemberType NoteProperty -Name KVAShadowPcidEnabled -Value $kvaShadowPcidEnabled
  212.  
  213.         #
  214.         # Provide guidance as appropriate.
  215.         #
  216.  
  217.         $actions = @()
  218.  
  219.         if ($btiHardwarePresent -eq $false) {
  220.             $actions += "Install BIOS/firmware update provided by your device OEM that enables hardware support for the branch target injection mitigation."
  221.         }
  222.  
  223.         if ($btiWindowsSupportPresent -eq $false -or $kvaShadowPresent -eq $false) {
  224.             $actions += "Install the latest available updates for Windows with support for speculation control mitigations."
  225.         }
  226.  
  227.         if ($btiWindowsSupportEnabled -eq $false -or ($kvaShadowRequired -eq $true -and $kvaShadowEnabled -eq $false)) {
  228.             $actions += "Follow the guidance for enabling Windows support for speculation control mitigations are described in https://support.microsoft.com/help/4072698"
  229.         }
  230.  
  231.         <# #Killed write host -MM
  232.         if ($actions.Length -gt 0) {
  233.  
  234.             Write-Host
  235.             Write-Host "Suggested actions" -ForegroundColor Cyan
  236.             Write-Host
  237.  
  238.             foreach ($action in $actions) {
  239.                 Write-Host " *" $action
  240.             }
  241.         }
  242.         #>
  243.  
  244.         #Killed Object Return, returning compliance variable later -MM
  245.         #return $object
  246.  
  247.     }
  248.     finally
  249.     {
  250.         if ($systemInformationPtr -ne [System.IntPtr]::Zero) {
  251.             [System.Runtime.InteropServices.Marshal]::FreeHGlobal($systemInformationPtr)
  252.         }
  253.  
  254.         if ($returnLengthPtr -ne [System.IntPtr]::Zero) {
  255.             [System.Runtime.InteropServices.Marshal]::FreeHGlobal($returnLengthPtr)
  256.         }
  257.     }
  258.         #Custom Lines for using script as a compliance baseline -MM
  259.         #First check for CVE-2017-5715
  260.     IF ($btiHardwarePresent -and $btiWindowsSupportPresent -and $btiWindowsSupportEnabled) {
  261.         #Second check for CVE-2017-5754
  262.         IF (($kvaShadowRequired -and $kvaShadowPresent -and $kvaShadowEnabled -and $kvaShadowPcidEnabled) -or !$kvaShadowRequired){
  263.             $Compliance = $True
  264.             Return $Compliance
  265.         }
  266.     }
  267.     IF (!$btiHardwarePresent -or !$btiWindowsSupportPresent -or !$btiWindowsSupportEnabled -or ($kvaShadowRequired -and (!$kvaShadowPresent -or !$kvaShadowEnabled -or !$kvaShadowPcidEnabled)) ) {
  268.         $Compliance = $False
  269.         Return $Compliance
  270.     }  
  271.   }
  272.  
  273. }
  274.  
  275. $compliance = Get-SpeculationControlSettings
  276. Return $compliance
Add Comment
Please, Sign In to add comment