October 2026 Tool Of The Month
In this issue:
- Overview
- Introduction
- FileInsight Views
- Folder Processing
- Archive Scanning
- Using the Library
- Summary
Overview
FileInspectorX is a PowerShell module for analyzing file and folder content types with a single command: Get-FileInsight. The project packages a built-in analysis engine and exposes a rich set of predefined output views, making it easy to inspect files from the command line without separate tools or manual scripting. After installation from the PowerShell Gallery, you will find a single cmdlet that can produce summary, analysis, assessment, permissions, signature, shell properties, and other structured views. FileInspectorX is particularly useful for anyone who needs fast, structured insight into files from the command line. Its combination of classification, policy context, and metadata extraction makes it a compelling tool for administrators managing uncertain or potentially malicious files at scale in enterprise Windows environments daily.
Introduction
Last month I introduced a new feature into the content line-up: a tool of the month. I want to continue today with a profile of a fascinating project that includes a PowerShell module. I'll focus on the module but if you have the interest and skill set you might want to explore the rest of the project.
FileInspectorX is a library designed to analyze file content type. The analysis engine is baked in to the library. You don't need to do anything. You can inspect a file or folder and retrieve a wealth information, all from a PowerShell prompt.
Install the module from the PowerShell Gallery.
Install-PSResource FileInspectorX
After you install the module, you'll see that it has a single command.
PS C:\> Get-Command -Module FileInspectorX
CommandType Name Version Source
----------- ---- ------- ------
Cmdlet Get-FileInsight 1.1.3 FileInspectorX
Yet there is a lot that this one command can accomplish.
PS C:\> Get-Command Get-FileInsight -Syntax
Get-FileInsight [-Path] <string[]> [-View <insightview>] [-DetectOnly] [-ComputeSha256] [-MagicHeaderBytes <int>] [-ExcludePermissions] [-ExcludeSignature] [-ExcludeReferences] [-ExcludeInstaller] [-EnableInstaller] [-ExcludeContainer] [-ExcludeAssessment] [-ExcludeShellProperties] [-EnableShellProperties] [-DisableMagika] [-MagikaPredictionMode <string>] [-LearnedClassificationMode <learnedclassificationmode>] [<commonparameters>]
Let's see what you can do with this command.
FileInsight Views
Because the command retrieves a lot information, you can simplify how it is presented by using one of the predefined views.
PS C:\> Get-FileInsight $profile -View Summary
Path : C:\Users\jeff\Documents\PowerShell\Microsoft.PowerShell_profile.ps1
Kind : Text
Extension : ps1
MimeType : text/x-powershell
Confidence : High
Reason : text:ps1
ValidationStatus :
Flags : IsScript, ScriptsPotentiallyDangerous
InstallerSummary :
Raw : FileInspectorX.FileAnalysis
This view takes values from some of the other possible views.
PS C:\> Get-FileInsight $profile -View Analysis
Path : C:\Users\jeff\Documents\PowerShell\Microsoft.PowerShell_profile.ps1
Extension : ps1
MimeType : text/x-powershell
Kind : Text
Flags : IsScript, ScriptsPotentiallyDangerous
GuessedExtension :
ContainerSubtype :
ContainerEntryCount :
ContainerTopExtensions :
TextSubtype : powershell
EstimatedLineCount : 223
ScriptLanguage : powershell
SecurityFindings : {script:dangerous-kind}
TopTokens :
PeMachine :
PeSubsystem :
Authenticode :
AuthChainValid :
AuthFileHashMatches :
AuthTrustedWindowsPolicy :
AuthTimestamp :
Raw : FileInspectorX.FileAnalysis
PS C:\> Get-FileInsight $profile -View Assessment
Path : C:\Users\jeff\Documents\PowerShell\Microsoft.PowerShell_profile.ps1
Score : 35
Decision : Allow
Codes : Name.DoubleExtension,Type.AmbiguousCandidates,Type.DangerousAlternative
Raw : FileInspectorX.FileAnalysis
I trust you can already see how useful this is. I especially appreciate information in the Permissions view.
PS C:\> Get-FileInsight $profile -View Permissions
Path : C:\Users\jeff\Documents\PowerShell\Microsoft.PowerShell_profile.ps1
IsSymlink : True
IsHidden : False
IsReadOnly : False
Owner : BUILTIN\Administrators
OwnerId : S-1-5-32-544
Group : Cadenza\None
GroupId : S-1-5-21-3998709781-1337716678-2240924477-513
ModeOctal :
ModeSymbolic :
IsExecutable :
IsWorldWritable :
EveryoneWriteAllowed : False
AuthenticatedUsersWriteAllowed : False
EveryoneReadAllowed : False
BuiltinUsersWriteAllowed : False
BuiltinUsersReadAllowed : False
AdministratorsWriteAllowed : True
AdministratorsReadAllowed : True
HasDenyEntries : False
TotalAllowCount : 3
TotalDenyCount : 0
ExplicitAllowCount : 0
ExplicitDenyCount : 0
Raw : FileInspectorX.FileAnalysis
Using Get-TypeMember from the PSScriptTools module, I can list the other available views.
PS C:\> Get-TypeMember FileInspectorX.InsightView -StaticOnly | Select Name
Name
----
Analysis
Assessment
Detection
Installer
Permissions
Policy
Raw
References
ShellProperties
Signature
Summary
You can use the Exclude parameters to fine-tune the command.
> I am using module version 1.1.3 and after reporting problems getting information from the Installer view, the module author submitted a PR to fix an apparent bug. Hopefully a new version of the module will be released soon with the update.