Skip to content

Get‑ProcessSecurityDescriptor

raandree edited this page Sep 6, 2026 · 1 revision

SYNOPSIS

Gets selected security descriptor sections from pinned live processes.

SYNTAX

Process (Default)

Get-ProcessSecurityDescriptor [-InputObject] <Object[]> [-Sections <WindowsSecurityDescriptorSection>]
 [-ThrottleLimit <Int32>] [<CommonParameters>]

Handle

Get-ProcessSecurityDescriptor -Handle <IntPtr[]> [-Sections <WindowsSecurityDescriptorSection>]
 [-ThrottleLimit <Int32>] [<CommonParameters>]

DESCRIPTION

Resolves a PID, Process object, module output, or caller-owned handle, pins PID targets by creation FILETIME, and returns portable descriptor data.

EXAMPLES

EXAMPLE 1

Get-Process -Id $PID | Get-ProcessSecurityDescriptor -Sections Access

Gets the current process DACL through a pinned Process pipeline object.

PARAMETERS

-Handle

One or more caller-owned process handles that the module never closes.

Type: IntPtr[]
Parameter Sets: Handle
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-InputObject

One or more PIDs, Process objects, or process objects emitted by this module.

Type: Object[]
Parameter Sets: Process
Aliases: Process, Id, ProcessId

Required: True
Position: 1
Default value: None
Accept pipeline input: True (ByPropertyName, ByValue)
Accept wildcard characters: False

-Sections

Selects owner, group, access, audit, or any combination to retrieve.

Type: WindowsSecurityDescriptorSection
Parameter Sets: (All)
Aliases:
Accepted values: Owner, Group, Access, Audit, All

Required: False
Position: Named
Default value: All
Accept pipeline input: False
Accept wildcard characters: False

-ThrottleLimit

Limits concurrently processed pinned targets. One requests deterministic sequential execution.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: [Math]::Max(1, [Math]::Min(8, [Environment]::ProcessorCount))
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

System.Int32

System.Diagnostics.Process

WindowsAccessControl.ProcessSecurityDescriptor

OUTPUTS

WindowsAccessControl.ProcessSecurityDescriptor

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally