Add AMSI method invocation logging as experimental feature#16496
Add AMSI method invocation logging as experimental feature#16496PaulHigin merged 3 commits intoPowerShell:masterfrom PaulHigin:new-amsi-notify
Conversation
|
This pull request has been automatically marked as Review Needed because it has been there has not been any activity for 7 days. |
|
This PR has Quantification details
Why proper sizing of changes matters
Optimal pull request sizes drive a better predictable PR flow as they strike a
What can I do to optimize my changes
How to interpret the change counts in git diff output
Was this comment helpful? 👍 :ok_hand: :thumbsdown: (Email) |
|
@daxian-dbw Can you please review? |
|
/azp run |
|
Azure Pipelines successfully started running 6 pipeline(s). |
daxian-dbw
left a comment
There was a problem hiding this comment.
Would it be better that we special handle PowerShell class intances in LogMemberInvoaction? For example, if we found it's an instance of a PowerShell class, we just log its type name instead of calling its ToString method.
|
This pull request has been automatically marked as Review Needed because it has been there has not been any activity for 7 days. |
|
@anmenaga Can you please merge? |
|
This pull request has been automatically marked as Review Needed because it has been there has not been any activity for 7 days. |
|
@anmenaga gentle ping |
…l#16496) * Add AMSI method invocation logging as experimental feature * Add fix for value type errors in logging expression * Fix recursion error
|
🎉 Handy links: |
PR Summary
This PR adds a new experimental feature that adds new AMSI logging of .NET method invocations.
PR Context
This uses a new AMSI notification API to log .NET method invocations.
PR Checklist
.h,.cpp,.cs,.ps1and.psm1files have the correct copyright headerWIP:or[ WIP ]to the beginning of the title (theWIPbot will keep its status check atPendingwhile the prefix is present) and remove the prefix when the PR is ready.(which runs in a different PS Host).