Behind the PowerShell Pipeline logo

Behind the PowerShell Pipeline

Archives
Log in
Subscribe
October 9, 2026

October 2026 Tool Of The Month

In this issue:

  • Overview
  • Introduction
  • FileInsight Views
    • ShellProperties
  • Folder Processing
  • Archive Scanning
  • Using the Library
  • Summary

Overview

FileInspectorX is a PowerShell module for analyzing file and folder content types with a single command: Get-FileInsight. The project packages a built-in analysis engine and exposes a rich set of predefined output views, making it easy to inspect files from the command line without separate tools or manual scripting. After installation from the PowerShell Gallery, you will find a single cmdlet that can produce summary, analysis, assessment, permissions, signature, shell properties, and other structured views. FileInspectorX is particularly useful for anyone who needs fast, structured insight into files from the command line. Its combination of classification, policy context, and metadata extraction makes it a compelling tool for administrators managing uncertain or potentially malicious files at scale in enterprise Windows environments daily.

Introduction

Last month I introduced a new feature into the content line-up: a tool of the month. I want to continue today with a profile of a fascinating project that includes a PowerShell module. I'll focus on the module but if you have the interest and skill set you might want to explore the rest of the project.

FileInspectorX is a library designed to analyze file content type. The analysis engine is baked in to the library. You don't need to do anything. You can inspect a file or folder and retrieve a wealth information, all from a PowerShell prompt.

Install the module from the PowerShell Gallery.

Install-PSResource FileInspectorX

After you install the module, you'll see that it has a single command.

PS C:\> Get-Command -Module FileInspectorX

CommandType Name            Version Source
----------- ----            ------- ------
Cmdlet      Get-FileInsight 1.1.3   FileInspectorX

Yet there is a lot that this one command can accomplish.

PS C:\> Get-Command Get-FileInsight -Syntax

Get-FileInsight [-Path] <string[]> [-View <insightview>] [-DetectOnly] [-ComputeSha256] [-MagicHeaderBytes <int>] [-ExcludePermissions] [-ExcludeSignature] [-ExcludeReferences] [-ExcludeInstaller] [-EnableInstaller] [-ExcludeContainer] [-ExcludeAssessment] [-ExcludeShellProperties] [-EnableShellProperties] [-DisableMagika] [-MagikaPredictionMode <string>] [-LearnedClassificationMode <learnedclassificationmode>] [<commonparameters>]

Let's see what you can do with this command.

FileInsight Views

Because the command retrieves a lot information, you can simplify how it is presented by using one of the predefined views.

PS C:\&gt; Get-FileInsight $profile -View Summary

Path             : C:\Users\jeff\Documents\PowerShell\Microsoft.PowerShell_profile.ps1
Kind             : Text
Extension        : ps1
MimeType         : text/x-powershell
Confidence       : High
Reason           : text:ps1
ValidationStatus :
Flags            : IsScript, ScriptsPotentiallyDangerous
InstallerSummary :
Raw              : FileInspectorX.FileAnalysis

This view takes values from some of the other possible views.

PS C:\&gt; Get-FileInsight $profile -View Analysis

Path                     : C:\Users\jeff\Documents\PowerShell\Microsoft.PowerShell_profile.ps1
Extension                : ps1
MimeType                 : text/x-powershell
Kind                     : Text
Flags                    : IsScript, ScriptsPotentiallyDangerous
GuessedExtension         :
ContainerSubtype         :
ContainerEntryCount      :
ContainerTopExtensions   :
TextSubtype              : powershell
EstimatedLineCount       : 223
ScriptLanguage           : powershell
SecurityFindings         : {script:dangerous-kind}
TopTokens                :
PeMachine                :
PeSubsystem              :
Authenticode             :
AuthChainValid           :
AuthFileHashMatches      :
AuthTrustedWindowsPolicy :
AuthTimestamp            :
Raw                      : FileInspectorX.FileAnalysis

PS C:\&gt; Get-FileInsight $profile -View Assessment

Path     : C:\Users\jeff\Documents\PowerShell\Microsoft.PowerShell_profile.ps1
Score    : 35
Decision : Allow
Codes    : Name.DoubleExtension,Type.AmbiguousCandidates,Type.DangerousAlternative
Raw      : FileInspectorX.FileAnalysis

I trust you can already see how useful this is. I especially appreciate information in the Permissions view.

PS C:\&gt; Get-FileInsight $profile -View Permissions

Path                           : C:\Users\jeff\Documents\PowerShell\Microsoft.PowerShell_profile.ps1
IsSymlink                      : True
IsHidden                       : False
IsReadOnly                     : False
Owner                          : BUILTIN\Administrators
OwnerId                        : S-1-5-32-544
Group                          : Cadenza\None
GroupId                        : S-1-5-21-3998709781-1337716678-2240924477-513
ModeOctal                      :
ModeSymbolic                   :
IsExecutable                   :
IsWorldWritable                :
EveryoneWriteAllowed           : False
AuthenticatedUsersWriteAllowed : False
EveryoneReadAllowed            : False
BuiltinUsersWriteAllowed       : False
BuiltinUsersReadAllowed        : False
AdministratorsWriteAllowed     : True
AdministratorsReadAllowed      : True
HasDenyEntries                 : False
TotalAllowCount                : 3
TotalDenyCount                 : 0
ExplicitAllowCount             : 0
ExplicitDenyCount              : 0
Raw                            : FileInspectorX.FileAnalysis

Using Get-TypeMember from the PSScriptTools module, I can list the other available views.

PS C:\&gt; Get-TypeMember FileInspectorX.InsightView -StaticOnly | Select Name

Name
----
Analysis
Assessment
Detection
Installer
Permissions
Policy
Raw
References
ShellProperties
Signature
Summary

You can use the Exclude parameters to fine-tune the command.

> I am using module version 1.1.3 and after reporting problems getting information from the Installer view, the module author submitted a PR to fix an apparent bug. Hopefully a new version of the module will be released soon with the update.

Want to read the full issue?
Already a paid subscriber? Click here to log in.
GitHub
Bluesky
LinkedIn
Mastodon
jdhitsolutions.github.io
Powered by Buttondown, the easiest way to start and grow your newsletter.