Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Filters seem to be Ignored in Mode HailMary #60

Open
PauleTR opened this issue Oct 27, 2024 · 1 comment
Open

Filters seem to be Ignored in Mode HailMary #60

PauleTR opened this issue Oct 27, 2024 · 1 comment
Assignees

Comments

@PauleTR
Copy link

PauleTR commented Oct 27, 2024

Hi team, thank you so much for this great software and all the work put into the lists!

I have been trying to use the tool to set some individual configurations without editing the csv lists. Instead, I've tried setting filters on the IDs I'm interested in,
This works well for audit and backup:
Invoke-HardeningKitty -Filter { 1900,1911 -contains $_.ID } -FileFindingList ..\ASR.csv -Mode Audit
Invoke-HardeningKitty -Filter { 1900,1911 -contains $_.ID } -FileFindingList ..\ASR.csv -Mode Config -Backup -BackupFile ..\ASR_Backup_2.csv

When using the same filter with HailMary, the filter was ignored and every single line of the file was configured with the recommended value. I did this on a test system with just the asr rules in my list file, so no great harm was done. But I was surprised and the csv backup list was incomplete because the filters worked fine there ...
Is this a bug or did I do something wrong?

Version used: 0.9.2-1690255284

Many thanks and best regards,

PauleTR

@PauleTR PauleTR changed the title Filters seem tpbe Ignored in Mode Filters seem to be Ignored in Mode HailMary Oct 27, 2024
@0x6d69636b 0x6d69636b self-assigned this Oct 28, 2024
@0x6d69636b
Copy link
Member

Hi PauleTR,

For now, the filter function is only supported in Audit and Config mode. As the HailMary mode is a delicate matter, I suggest you create your own file and remove all the lines you want to filter.

I updated the documentation in the dev repo: 0x6d69636b/windows_hardening@ead6933

All the best

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

2 participants