param( [switch]$Strict, [switch]$Help ) $ErrorActionPreference = 'Continue' $ScriptName = Split-Path -Leaf $PSCommandPath if ($Help) { @' Usage: privacy-audit.ps1 [-Strict] [-Help] Read-only audit of common history, profile, and log locations. This script does not delete or modify evidence. '@ exit 0 } function Write-Section { param([string]$Name) Write-Host "" Write-Host "== $Name ==" } function Show-PathState { param([string]$Label, [string]$Path) if ([string]::IsNullOrWhiteSpace($Path)) { Write-Host "UNKNOWN $Label" return $false } try { $exists = Test-Path -LiteralPath $Path -ErrorAction Stop } catch { Write-Host "UNKNOWN $Label`: $Path ($($_.Exception.Message))" return $false } $state = if ($exists) { 'FOUND ' } else { 'MISSING' } Write-Host "$state $Label`: $Path" return $exists } Write-Host "[$ScriptName] Read-only privacy audit. No history or logs are deleted." $found = 0 Write-Section 'PowerShell history and profiles' try { $historyPath = (Get-PSReadLineOption).HistorySavePath if (Show-PathState 'PSReadLine history' $historyPath) { $found++ } } catch { Write-Host "UNKNOWN PSReadLine history: $($_.Exception.Message)" } foreach ($path in @($PROFILE.CurrentUserCurrentHost, $PROFILE.CurrentUserAllHosts) | Select-Object -Unique) { if (Show-PathState 'PowerShell profile' $path) { $found++ } } Write-Section 'Windows event logs' try { foreach ($name in @('PowerShellCore/Operational', 'Windows PowerShell', 'Microsoft-Windows-PowerShell/Operational', 'Security', 'System')) { $log = Get-WinEvent -ListLog $name -ErrorAction SilentlyContinue if ($log) { Write-Host ("FOUND {0}: records={1} enabled={2}" -f $name, $log.RecordCount, $log.IsEnabled) $found++ } else { Write-Host "MISSING $name" } } } catch { Write-Host "UNKNOWN event logs: $($_.Exception.Message)" } Write-Section 'Shell and tool traces' $candidatePaths = @( @('OpenSSH user config', "$HOME\.ssh\config"), @('OpenSSH known_hosts', "$HOME\.ssh\known_hosts"), @('Git user config', "$HOME\.gitconfig"), @('PowerShell transcript dir', "$HOME\Documents\PowerShell_transcript"), @('Recent items', "$env:APPDATA\Microsoft\Windows\Recent"), @('ConsoleHost history dir', "$env:APPDATA\Microsoft\Windows\PowerShell\PSReadLine"), @('Windows Terminal settings', "$env:LOCALAPPDATA\Packages\Microsoft.WindowsTerminal_8wekyb3d8bbwe\LocalState\settings.json") ) foreach ($item in $candidatePaths) { if (Show-PathState $item[0] $item[1]) { $found++ } } Write-Section 'Browser profile hints' foreach ($item in @( @('Edge user data', "$env:LOCALAPPDATA\Microsoft\Edge\User Data"), @('Chrome user data', "$env:LOCALAPPDATA\Google\Chrome\User Data"), @('Firefox profiles', "$env:APPDATA\Mozilla\Firefox\Profiles") )) { if (Show-PathState $item[0] $item[1]) { $found++ } } Write-Host "" Write-Host "[$ScriptName] Audit complete. Review paths before screenshots, demos, or publishing logs." if ($Strict -and $found -eq 0) { exit 1 }