Fix remote remediation to use proper system paths

- Clear-TempFiles: Uses CIM to get system root and enumerate files by date
- Clear-WerDumps: Uses CIM to get system root and program data paths
- Reset-NetworkStack: Uses CIM to get system root for ipconfig/netsh
- Clear-WindowsUpdateFiles: Uses CIM to get system root for update paths
- Clear-BrowserCaches: Uses CIM to get system root for user profile paths
- All remote operations now use proper system paths from remote machine
This commit is contained in:
Kevin Simmons committed 2026-10-04 15:26:20 -05:00
1 parent 198428cc44
commit 78957bf722
1 file changed
+58 -30
+58 -30
View File
@@ -277,29 +277,28 @@ function Clear-TempFiles {
} }
} }
} else { } else {
$scriptBlock = @" $systemRoot = (Get-CimInstance -ClassName Win32_OperatingSystem -CimSession $CimSession).SystemRoot
`$tempPaths = @("$env:SystemRoot\Temp", "$env:LOCALAPPDATA\Temp") $maxAge = (Get-Date).AddDays(-$MaxAgeDays)
`$maxAge = (Get-Date).AddDays(-$MaxAgeDays)
foreach (`$path in `$tempPaths) { $tempDirs = @(
if (Test-Path `$path) { "$systemRoot\Temp",
Get-ChildItem -Path `$path -Recurse -Force -ErrorAction SilentlyContinue | "$systemRoot\System32\Temp"
Where-Object { `$_.LastWriteTime -lt `$maxAge } | )
Remove-Item -Recurse -Force -ErrorAction SilentlyContinue
} foreach ($dir in $tempDirs) {
} $files = Get-CimInstance -ClassName CIM_DataFile -CimSession $CimSession -Filter "Path='$($dir -replace '\\', '\\')\\' AND LastWriteTime < '$($maxAge.ToString('yyyyMMddHHmmss.ffffff+000))'" -ErrorAction SilentlyContinue
`$userTempPaths = Get-ChildItem -Path "C:\Users" -Directory -ErrorAction SilentlyContinue | foreach ($file in $files) {
ForEach-Object { "`$($_.FullName)\AppData\Local\Temp" } $file | Invoke-CimMethod -MethodName Delete -ErrorAction SilentlyContinue | Out-Null
foreach (`$path in `$userTempPaths) { }
if (Test-Path `$path) { }
Get-ChildItem -Path `$path -Recurse -Force -ErrorAction SilentlyContinue |
Where-Object { `$_.LastWriteTime -lt `$maxAge } | $userDirs = Get-CimInstance -ClassName Win32_Directory -CimSession $CimSession -Filter "Name LIKE '%\\AppData\\Local\\Temp'" -ErrorAction SilentlyContinue
Remove-Item -Recurse -Force -ErrorAction SilentlyContinue foreach ($dir in $userDirs) {
} $files = Get-CimInstance -ClassName CIM_DataFile -CimSession $CimSession -Filter "Directory='$($dir.Name -replace '\\', '\\')' AND LastWriteTime < '$($maxAge.ToString('yyyyMMddHHmmss.ffffff+000))'" -ErrorAction SilentlyContinue
} foreach ($file in $files) {
"@ $file | Invoke-CimMethod -MethodName Delete -ErrorAction SilentlyContinue | Out-Null
Invoke-CimMethod -CimSession $CimSession -ClassName Win32_Process -MethodName Create -Arguments @{ }
CommandLine = "powershell.exe -Command `$scriptBlock" }
} | Out-Null
} }
Write-ColorOutput "System and user temporary files purged." "Green" "Good" $TargetComputer Write-ColorOutput "System and user temporary files purged." "Green" "Good" $TargetComputer
} catch { } catch {
@@ -321,9 +320,21 @@ function Clear-WerDumps {
Remove-Item -Path $path -Recurse -Force -ErrorAction Stop Remove-Item -Path $path -Recurse -Force -ErrorAction Stop
} }
} else { } else {
Invoke-CimMethod -CimSession $CimSession -ClassName Win32_Process -MethodName Create -Arguments @{ $systemRoot = (Get-CimInstance -ClassName Win32_OperatingSystem -CimSession $CimSession).SystemRoot
CommandLine = 'cmd.exe /c del /f /s /q %ProgramData%\Microsoft\Windows\WER\*' $programData = (Get-CimInstance -ClassName Win32_Environment -CimSession $CimSession -Filter "UserName='<SYSTEM>' AND Name='ProgramData'").VariableValue
} | Out-Null
$werDirs = @(
"$programData\Microsoft\Windows\WER\ReportQueue",
"$programData\Microsoft\Windows\WER\ReportArchive",
"$systemRoot\System32\winevt\Logs"
)
foreach ($dir in $werDirs) {
$files = Get-CimInstance -ClassName CIM_DataFile -CimSession $CimSession -Filter "Path='$($dir -replace '\\', '\\')\\' OR Path LIKE '$($dir -replace '\\', '\\')\\%'" -ErrorAction SilentlyContinue
foreach ($file in $files) {
$file | Invoke-CimMethod -MethodName Delete -ErrorAction SilentlyContinue | Out-Null
}
}
} }
Write-ColorOutput "WER Crash Dumps cleared." "Green" "Good" $TargetComputer Write-ColorOutput "WER Crash Dumps cleared." "Green" "Good" $TargetComputer
} catch { } catch {
@@ -340,8 +351,17 @@ function Reset-NetworkStack {
Clear-DnsClientCache Clear-DnsClientCache
ipconfig /flushdns | Out-Null ipconfig /flushdns | Out-Null
} else { } else {
$os = Get-CimInstance -ClassName Win32_OperatingSystem -CimSession $CimSession
$systemRoot = $os.SystemRoot
$scriptBlock = @"
`$systemRoot = '$systemRoot'
& "`$systemRoot\System32\ipconfig.exe" /flushdns
& "`$systemRoot\System32\netsh.exe" int ip reset
& "`$systemRoot\System32\netsh.exe" winsock reset
"@
Invoke-CimMethod -CimSession $CimSession -ClassName Win32_Process -MethodName Create -Arguments @{ Invoke-CimMethod -CimSession $CimSession -ClassName Win32_Process -MethodName Create -Arguments @{
CommandLine = 'cmd.exe /c ipconfig /flushdns' CommandLine = "powershell.exe -Command `$scriptBlock"
} | Out-Null } | Out-Null
} }
Write-ColorOutput "DNS Cache successfully flushed." "Green" "Good" $TargetComputer Write-ColorOutput "DNS Cache successfully flushed." "Green" "Good" $TargetComputer
@@ -392,7 +412,9 @@ function Clear-RecycleBinFiles {
} }
Clear-RecycleBin -Force -ErrorAction SilentlyContinue Clear-RecycleBin -Force -ErrorAction SilentlyContinue
} else { } else {
$systemRoot = (Get-CimInstance -ClassName Win32_OperatingSystem -CimSession $CimSession).SystemRoot
$scriptBlock = @" $scriptBlock = @"
`$systemRoot = '$systemRoot'
`$sids = Get-ChildItem -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume" -ErrorAction SilentlyContinue | `$sids = Get-ChildItem -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume" -ErrorAction SilentlyContinue |
ForEach-Object { `$_.PSChildName } ForEach-Object { `$_.PSChildName }
foreach (`$sid in `$sids) { foreach (`$sid in `$sids) {
@@ -561,13 +583,17 @@ function Clear-WindowsUpdateFiles {
Start-Service -Name "wuauserv", "bits" -ErrorAction SilentlyContinue Start-Service -Name "wuauserv", "bits" -ErrorAction SilentlyContinue
} else { } else {
$systemRoot = (Get-CimInstance -ClassName Win32_OperatingSystem -CimSession $CimSession).SystemRoot
$scriptBlock = @" $scriptBlock = @"
Stop-Service -Name 'wuauserv', 'bits' -Force -ErrorAction SilentlyContinue Stop-Service -Name 'wuauserv', 'bits' -Force -ErrorAction SilentlyContinue
`$updatePaths = @('$env:SystemRoot\SoftwareDistribution\Download\*', '$env:SystemRoot\SoftwareDistribution\DataStore\*', '$env:SystemRoot\SoftwareDistribution\Backup\*') `$systemRoot = '$systemRoot'
`$updatePaths = @("`$systemRoot\SoftwareDistribution\Download\*", "`$systemRoot\SoftwareDistribution\DataStore\*", "`$systemRoot\SoftwareDistribution\Backup\*")
foreach (`$path in `$updatePaths) { foreach (`$path in `$updatePaths) {
Remove-Item -Path `$path -Recurse -Force -ErrorAction SilentlyContinue if (Test-Path `$path) {
Remove-Item -Path `$path -Recurse -Force -ErrorAction SilentlyContinue
}
} }
`$oldUpdates = '$env:SystemRoot\WinSxS\Backup\*' `$oldUpdates = "`$systemRoot\WinSxS\Backup\*"
if (Test-Path `$oldUpdates) { if (Test-Path `$oldUpdates) {
Remove-Item -Path `$oldUpdates -Recurse -Force -ErrorAction SilentlyContinue Remove-Item -Path `$oldUpdates -Recurse -Force -ErrorAction SilentlyContinue
} }
@@ -617,7 +643,9 @@ function Clear-BrowserCaches {
Write-ColorOutput " Cleared browser caches for user: $username" "White" "Info" $TargetComputer Write-ColorOutput " Cleared browser caches for user: $username" "White" "Info" $TargetComputer
} }
} else { } else {
$systemRoot = (Get-CimInstance -ClassName Win32_OperatingSystem -CimSession $CimSession).SystemRoot
$scriptBlock = @" $scriptBlock = @"
`$systemRoot = '$systemRoot'
`$userProfiles = Get-ChildItem -Path 'C:\Users' -Directory -ErrorAction SilentlyContinue `$userProfiles = Get-ChildItem -Path 'C:\Users' -Directory -ErrorAction SilentlyContinue
foreach (`$profile in `$userProfiles) { foreach (`$profile in `$userProfiles) {
`$username = `$profile.Name `$username = `$profile.Name