keepwatch
As of PR #41, McAfee Endpoint Security detects `sbPSReflect.ps1` as `HTool-PoshSec` and deletes it from the analyst machine. The module continues to return results, but without the SYSTEM capabilities and with the three error messages included below. The errors interfere with any wrapper scripts as well by triggering try/catch blocks. Would obfuscating this .ps1 on disk be an option? (human) readability suffers but compatible functionality would improve. ``` get-content : Cannot find path 'C:\Users\<username>\Documents\WindowsPowerShell\Modules\Invoke-LiveResponse\Content \Scriptblock\base\sbPSReflect.ps1' because it does not exist. At C:\Users\<username>\Documents\WindowsPowerShell\Modules\Invoke-LiveResponse\Invoke-LiveResponse.psm1:354 char:72 + ... k]::Create((get-content "$PSScriptRoot\Content\Scriptblock\base\sbPSR ... + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : ObjectNotFound: (C:\Users\<username>...sbPSReflect.ps1:String) [Get-Content], ItemNotFoundEx ception + FullyQualifiedErrorId : PathNotFound,Microsoft.PowerShell.Commands.GetContentCommand Exception calling "Create" with "1" argument(s): "Object reference not set to an instance of an object." At C:\Users\<username>\Documents\WindowsPowerShell\Modules\Invoke-LiveResponse\Invoke-LiveResponse.psm1:354 char:5 + $sbPSReflect = [System.Management.Automation.ScriptBlock]::Create ... + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : NotSpecified: (:) [], MethodInvocationException + FullyQualifiedErrorId : NullReferenceException You cannot call a method on a null-valued expression. At C:\Users\<username>\Documents\WindowsPowerShell\Modules\Invoke-LiveResponse\Invoke-LiveResponse.psm1:356 char:5 + $Scriptblock = [ScriptBlock]::Create($Scriptblock.ToString() + $s ... + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : InvalidOperation: (:) [], RuntimeException + FullyQualifiedErrorId : InvokeMethodOnNull ```