none
WinPE10 - Detection Bitlocker avec powershell RRS feed

  • Discussion générale

  • Bonjour ,

    Je realise actuellement un script powershell qui sera executé sous Winpe10.

    Celui ci devra detecté si le disque a été crypté ou non avant de continuer.

    J'utilise la ressources WMI suivante :

    $Drives = Get-WmiObject -Namespace root/cimv2/Security/MicrosoftVolumeEncryption -Class Win32_EncryptableVolume | Select-Object DriveLetter, ProtectionStatus

    Cette commande passe tres bien sur un Win7 et sur un Win10 classique. En revanche sous WinPE10 $Drives n'a jamais de valeur.

    Par la meme occasion  j'ai constater que le cmdlet get-bitlockervolume n'existait pas non plus.

    en passant par wbemtest on vois que toutes les valeurs contenue dans cette classe sont NULL.

    Dans le PE j'ai ajouté les packages suivants :

    Deployment Image Servicing and Management tool
    Version: 10.0.15063.0

    Image Version: 10.0.15063.0

    Packages listing:

    Package Identity : Microsoft-Windows-WinPE-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~10.0.15063.0
    State : Installed
    Release Type : Language Pack
    Install Time : 18/03/2017 21:40

    Package Identity : Microsoft-Windows-WinPE-LanguagePack-Package~31bf3856ad364e35~amd64~fr-FR~10.0.15063.0
    State : Installed
    Release Type : Language Pack
    Install Time : 11/07/2017 10:01

    Package Identity : Microsoft-Windows-WinPE-Package~31bf3856ad364e35~amd64~~10.0.15063.0
    State : Installed
    Release Type : Foundation
    Install Time : 18/03/2017 21:39

    Package Identity : WinPE-DismCmdlets-Package~31bf3856ad364e35~amd64~en-US~10.0.15063.0
    State : Installed
    Release Type : Language Pack
    Install Time : 12/07/2017 10:38

    Package Identity : WinPE-DismCmdlets-Package~31bf3856ad364e35~amd64~fr-FR~10.0.15063.0
    State : Installed
    Release Type : Language Pack
    Install Time : 12/07/2017 10:39

    Package Identity : WinPE-DismCmdlets-Package~31bf3856ad364e35~amd64~~10.0.15063.0
    State : Installed
    Release Type : Feature Pack
    Install Time : 12/07/2017 10:38

    Package Identity : WinPE-EnhancedStorage-Package~31bf3856ad364e35~amd64~en-US~10.0.15063.0
    State : Installed
    Release Type : Language Pack
    Install Time : 03/08/2017 09:14

    Package Identity : WinPE-EnhancedStorage-Package~31bf3856ad364e35~amd64~fr-FR~10.0.15063.0
    State : Installed
    Release Type : Language Pack
    Install Time : 03/08/2017 09:15

    Package Identity : WinPE-EnhancedStorage-Package~31bf3856ad364e35~amd64~~10.0.15063.0
    State : Installed
    Release Type : Feature Pack
    Install Time : 03/08/2017 08:57

    Package Identity : WinPE-FMAPI-Package~31bf3856ad364e35~amd64~~10.0.15063.0
    State : Installed
    Release Type : Feature Pack
    Install Time : 03/08/2017 08:56

    Package Identity : WinPE-NetFx-Package~31bf3856ad364e35~amd64~en-US~10.0.15063.0
    State : Installed
    Release Type : Language Pack
    Install Time : 12/07/2017 10:34

    Package Identity : WinPE-NetFx-Package~31bf3856ad364e35~amd64~fr-FR~10.0.15063.0
    State : Installed
    Release Type : Language Pack
    Install Time : 12/07/2017 10:36

    Package Identity : WinPE-NetFx-Package~31bf3856ad364e35~amd64~~10.0.15063.0
    State : Installed
    Release Type : Feature Pack
    Install Time : 12/07/2017 10:33

    Package Identity : WinPE-PowerShell-Package~31bf3856ad364e35~amd64~en-US~10.0.15063.0
    State : Installed
    Release Type : Language Pack
    Install Time : 12/07/2017 10:37

    Package Identity : WinPE-PowerShell-Package~31bf3856ad364e35~amd64~fr-FR~10.0.15063.0
    State : Installed
    Release Type : Language Pack
    Install Time : 12/07/2017 10:38

    Package Identity : WinPE-PowerShell-Package~31bf3856ad364e35~amd64~~10.0.15063.0
    State : Installed
    Release Type : Feature Pack
    Install Time : 12/07/2017 10:37

    Package Identity : WinPE-Scripting-Package~31bf3856ad364e35~amd64~en-US~10.0.15063.0
    State : Installed
    Release Type : Language Pack
    Install Time : 12/07/2017 10:36

    Package Identity : WinPE-Scripting-Package~31bf3856ad364e35~amd64~fr-FR~10.0.15063.0
    State : Installed
    Release Type : Language Pack
    Install Time : 12/07/2017 10:37

    Package Identity : WinPE-Scripting-Package~31bf3856ad364e35~amd64~~10.0.15063.0
    State : Installed
    Release Type : Feature Pack
    Install Time : 12/07/2017 10:36

    Package Identity : WinPE-SecureStartup-Package~31bf3856ad364e35~amd64~en-US~10.0.15063.0
    State : Installed
    Release Type : Language Pack
    Install Time : 13/07/2017 08:21

    Package Identity : WinPE-SecureStartup-Package~31bf3856ad364e35~amd64~fr-FR~10.0.15063.0
    State : Installed
    Release Type : Language Pack
    Install Time : 13/07/2017 08:23

    Package Identity : WinPE-SecureStartup-Package~31bf3856ad364e35~amd64~~10.0.15063.0
    State : Installed
    Release Type : Feature Pack
    Install Time : 13/07/2017 08:21

    Package Identity : WinPE-StorageWMI-Package~31bf3856ad364e35~amd64~en-US~10.0.15063.0
    State : Installed
    Release Type : Language Pack
    Install Time : 21/07/2017 15:04

    Package Identity : WinPE-StorageWMI-Package~31bf3856ad364e35~amd64~fr-FR~10.0.15063.0
    State : Installed
    Release Type : Language Pack
    Install Time : 21/07/2017 15:04

    Package Identity : WinPE-StorageWMI-Package~31bf3856ad364e35~amd64~~10.0.15063.0
    State : Installed
    Release Type : Feature Pack
    Install Time : 21/07/2017 15:03

    Package Identity : WinPE-WMI-Package~31bf3856ad364e35~amd64~en-US~10.0.15063.0
    State : Installed
    Release Type : Language Pack
    Install Time : 12/07/2017 10:33

    Package Identity : WinPE-WMI-Package~31bf3856ad364e35~amd64~fr-FR~10.0.15063.0
    State : Installed
    Release Type : Language Pack
    Install Time : 12/07/2017 10:28

    Package Identity : WinPE-WMI-Package~31bf3856ad364e35~amd64~~10.0.15063.0
    State : Installed
    Release Type : Feature Pack
    Install Time : 12/07/2017 10:27

    The operation completed successfully.

    il y a donc les features suivantes :

    Deployment Image Servicing and Management tool
    Version: 10.0.15063.0

    Image Version: 10.0.15063.0

    Features listing for package : Microsoft-Windows-WinPE-Package~31bf3856ad364e35~amd64~~10.0.15063.0

    Feature Name : SMB1Protocol
    State : Enabled

    Feature Name : WinPE-WMI
    State : Enabled

    Feature Name : WinPE-NetFx
    State : Enabled

    Feature Name : Microsoft-Windows-NetFx-Shared-Package-WinPE
    State : Enabled

    Feature Name : WinPE-PowerShell
    State : Enabled

    Feature Name : WinPE-DismCmdlets
    State : Enabled

    Feature Name : WinPE-SecureStartup
    State : Enabled

    Feature Name : WinPE-TPM
    State : Enabled

    Feature Name : WinPE-StorageWMI
    State : Enabled

    Feature Name : WinPE-Scripting
    State : Enabled

    Feature Name : WinPE-FMAPI-Package
    State : Enabled

    Feature Name : WinPE-EnhancedStorage
    State : Enabled

    The operation completed successfully.

    il y a egalement les drivers suivants :

    Deployment Image Servicing and Management tool
    Version: 10.0.15063.0

    Image Version: 10.0.15063.0

    Obtaining list of 3rd party drivers from the driver store...

    Driver packages listing:

    Published Name : oem0.inf
    Original File Name : iaahcic.inf
    Inbox : No
    Class Name : HDC
    Provider Name : Intel Corporation
    Date : 13/09/2016
    Version : 15.2.0.1020

    Published Name : oem1.inf
    Original File Name : iastorac.inf
    Inbox : No
    Class Name : SCSIAdapter
    Provider Name : Intel Corporation
    Date : 13/09/2016
    Version : 15.2.0.1020

    The operation completed successfully.

    Version Powershell :

    Name                           Value                                                                                  
    ----                           -----                                                                                  
    PSVersion                      5.1.15063.0                                                                            
    PSEdition                      Desktop                                                                                
    PSCompatibleVersions           {1.0, 2.0, 3.0, 4.0...}                                                                
    BuildVersion                   10.0.15063.0                                                                           
    CLRVersion                     4.0.30319.42000                                                                        
    WSManStackVersion              3.0                                                                                    
    PSRemotingProtocolVersion      2.3                                                                                    
    SerializationVersion           1.1.0.1                                                                    

    Auriez vous une idée, un debut de piste pour ce probleme. il y aurait il un package manquant ? un driver ? je seche completement la.

    Merci d'avance.            

    jeudi 3 août 2017 14:27

Toutes les réponses