PowerShell for Security Analysts

The PowerShell a security analyst actually uses

Triage a Windows host, investigate processes, files, the registry and event logs, read the PowerShell attackers run, hunt across many hosts, and build tools other analysts can trust. Every command runs against real evidence, and nothing assumes you have written PowerShell before.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
Your subscription also includes the Practice Hub: graded scenarios, forensic cases, query drills and the response playbooks.
View Pricing Take End of Course Exam → 40 CPE Credits

What you'll be able to do

✓Choose between Windows PowerShell 5.1 and PowerShell 7, read what a command returns as objects, and find any command or property
✓Bring evidence in from CSV, JSON, XML, text and API responses without losing types, pages or rows
✓Triage a Windows host and its accounts, and follow processes to their parents, files and network connections
✓Read files, hashes, signatures, the mark of the web and the registry as evidence
✓Read Windows, Sysmon and PowerShell event logs, and decode the PowerShell attackers run
✓Find what is set to run again and check the state of Defender
✓Collect from one host or a fleet, seal the evidence, and hunt indicators across every host you can reach
✓Query Microsoft Graph and threat intelligence APIs with the keys kept out of your scripts
✓Build analyst tools others can trust: validated, documented, packaged, signed and reviewed, including code an AI wrote
SEC205 | Premium tier | 11 teaching modules, an orientation and a Project | 36–40 hours at your own pace | 40 CPE credits

Course Syllabus

Every module and every lesson. The first three modules are open; the rest open on a click.

Download the full syllabus (PDF)

Orientation

Module 0PowerShell in Security OperationsCourse Preview

Module 0 of PowerShell for Security Analysts: why defenders use PowerShell, Windows PowerShell 5.1 and PowerShell 7, how PowerShell is built, the console, Terminal and VS Code, cmdlets, functions, scripts and modules, finding your way around, an administrator's tool and an attacker's tool, and building an analyst workstation.

Show 8 lessonsHide lessons
  1. 0.10.1 Why Defenders Use PowerShellPreview
  2. 0.20.2 Windows PowerShell 5.1 and PowerShell 7Preview
  3. 0.30.3 How PowerShell Is BuiltPreview
  4. 0.40.4 Console, Terminal and VS CodePreview
  5. 0.50.5 Cmdlets, Functions, Scripts and ModulesPreview
  6. 0.60.6 Finding Your Way AroundPreview
  7. 0.70.7 An Administrator's Tool and an Attacker's ToolPreview
  8. 0.80.8 Building Your Analyst WorkstationPreview

Foundations

Module 1The Syntax Analysts Need

Module 1 of PowerShell for Security Analysts: objects and the pipeline, filtering and comparison, logic, wildcards and regular expressions, variables and collections, loops, functions and error handling, and reducing endpoint data to an answer.

Show 9 lessonsHide lessons
  1. 1.11.1 Objects, Properties and Methods
  2. 1.21.2 The Pipeline
  3. 1.31.3 Where-Object and Comparison Operators
  4. 1.41.4 Logical Operators, Wildcards and Regex
  5. 1.51.5 Variables, Arrays and Hashtables
  6. 1.61.6 Loops and Conditions
  7. 1.71.7 Functions and Error Handling
  8. 1.81.8 Reducing Endpoint Data to an Answer
  9. 1.9Module Summary and Knowledge Check
Module 2Working With Security Data

Module 2 of PowerShell for Security Analysts: CSV, JSON and REST responses, XML, plain text and Select-String, CliXml, sorting and grouping, calculated properties, and comparing datasets.

Show 9 lessonsHide lessons
  1. 2.12.1 CSV
  2. 2.22.2 JSON and REST Responses
  3. 2.32.3 XML
  4. 2.42.4 Text and Select-String
  5. 2.52.5 CliXml and PowerShell Objects
  6. 2.62.6 Sorting, Grouping and Unique Values
  7. 2.72.7 Calculated Properties
  8. 2.82.8 Comparing Datasets
  9. 2.9Module Summary and Knowledge Check

Endpoint Investigation

Module 3Host Triage and Accounts

Module 3 of PowerShell for Security Analysts: what the machine is, its patches, boot time and uptime, installed software, services and drivers, local users, groups and administrators, recently changed accounts, and Active Directory accounts.

Show 9 lessonsHide lessons
  1. 3.13.1 What Is This Machine
  2. 3.23.2 Patches, Boot Time and Uptime
  3. 3.33.3 Installed Software
  4. 3.43.4 Services and Drivers
  5. 3.53.5 Local Users and Groups
  6. 3.63.6 Local Administrators and Privileged Accounts
  7. 3.73.7 Recently Created and Re-enabled Accounts
  8. 3.83.8 Active Directory Accounts
  9. 3.9Module Summary and Knowledge Check
Module 4Process and Network Investigation

Module 4 of PowerShell for Security Analysts: Get-Process and Win32_Process, parent, path, command line and user, process trees, LOLBins and suspicious chains, connections and listeners, the DNS cache, and correlating processes with the addresses they reach.

Show 9 lessonsHide lessons
  1. 4.14.1 Get-Process and Win32_Process
  2. 4.24.2 Parent, Path, Command Line and User
  3. 4.34.3 Process Trees
  4. 4.44.4 LOLBins and Suspicious Chains
  5. 4.54.5 Connections and Listeners
  6. 4.64.6 DNS Cache and Resolution
  7. 4.74.7 From PID to Remote Address
  8. 4.84.8 A Process and Network Correlator
  9. 4.9Module Summary and Knowledge Check
Module 5Files and the Registry

Module 5 of PowerShell for Security Analysts: finding files, timestamps, hidden and recent files, hashing, signatures and PE files, alternate data streams and the mark of the web, the registry provider, persistence and configuration keys, and USB, RDP and recent-activity keys.

Show 9 lessonsHide lessons
  1. 5.15.1 Finding Files
  2. 5.25.2 Timestamps, Hidden and Recent Files
  3. 5.35.3 Hashing
  4. 5.45.4 Signatures and PE Files
  5. 5.55.5 Alternate Data Streams and the Mark of the Web
  6. 5.65.6 The Registry Provider
  7. 5.75.7 Persistence and Configuration Keys
  8. 5.85.8 USB, RDP and Recent-Activity Keys
  9. 5.9Module Summary and Knowledge Check

Logs and Detection

Module 6Windows Event Logs

Module 6 of PowerShell for Security Analysts: logs, providers and event IDs, Get-WinEvent and FilterHashtable, XPath and event XML, logon, process and privilege events, services, tasks and account changes, the Sysmon, Defender, RDP and WMI logs, and a security timeline tool.

Show 9 lessonsHide lessons
  1. 6.16.1 Logs, Providers and Event IDs
  2. 6.26.2 Get-WinEvent and FilterHashtable
  3. 6.36.3 XPath and Event XML
  4. 6.46.4 Logon Events
  5. 6.56.5 Process and Privilege Events
  6. 6.66.6 Services, Tasks and Account Changes
  7. 6.76.7 Sysmon, Defender, RDP and WMI Logs
  8. 6.86.8 A Security Timeline Tool
  9. 6.9Module Summary and Knowledge Check
Module 7PowerShell Logging and PowerShell Attacks

Module 7 of PowerShell for Security Analysts: script block, module and transcription logging, events 4103, 4104, 400 and 800, PSReadLine history, encoded commands, download cradles, obfuscation and safe deobfuscation, AMSI tampering as evidence, and execution policy and Constrained Language Mode.

Show 9 lessonsHide lessons
  1. 7.17.1 PowerShell's Own Logs
  2. 7.27.2 Reading Script Block Logs
  3. 7.37.3 PSReadLine History and Transcripts
  4. 7.47.4 Encoded Commands
  5. 7.57.5 Invoke-Expression and Download Cradles
  6. 7.67.6 Obfuscation and Safe Deobfuscation
  7. 7.77.7 AMSI and Its Bypasses, as Evidence
  8. 7.87.8 Execution Policy and Constrained Language Mode
  9. 7.9Module Summary and Knowledge Check
Module 8Persistence and Defender

Module 8 of PowerShell for Security Analysts: scheduled tasks, services and Run keys across a fleet, startup folders and PowerShell profiles, WMI event subscriptions, DLL search-order abuse, Defender status and signatures, threats, exclusions and tampering, and a persistence hunter.

Show 9 lessonsHide lessons
  1. 8.18.1 Scheduled Tasks
  2. 8.28.2 Services and Run Keys Across the Fleet
  3. 8.38.3 Startup Folders and PowerShell Profiles
  4. 8.48.4 WMI Event Subscriptions
  5. 8.58.5 DLL Search-Order Abuse
  6. 8.68.6 Defender Status and Signatures
  7. 8.78.7 Threats, Exclusions and Tampering
  8. 8.88.8 A Persistence Hunter
  9. 8.9Module Summary and Knowledge Check

Response, Hunting and Automation

Module 9Triage, Collection and IOC Hunting

Module 9 of PowerShell for Security Analysts: a repeatable triage method, the host triage collector, evidence integrity with hashing and case metadata, the incident evidence collector, hunting one indicator and many with an IOC scanner, and remote collection with WinRM, credentials and JEA.

Show 9 lessonsHide lessons
  1. 9.19.1 A Repeatable Triage Method
  2. 9.29.2 The Host Triage Collector
  3. 9.39.3 Evidence Integrity, Hashing and Case Metadata
  4. 9.49.4 The Incident Evidence Collector
  5. 9.59.5 Hunting One Indicator
  6. 9.69.6 Multi-Indicator Hunting and the IOC Scanner
  7. 9.79.7 Remoting, WinRM and Credentials
  8. 9.89.8 At Scale, with JEA
  9. 9.9Module Summary and Knowledge Check
Module 10APIs and Threat Intelligence

Module 10 of PowerShell for Security Analysts: REST calls with headers and authentication, JSON paging and rate limits, reputation lookups, API keys as secrets, Microsoft Graph PowerShell, Entra ID sign-in data, the Defender XDR and Sentinel APIs, and an enriched report from an alert.

Show 9 lessonsHide lessons
  1. 10.110.1 REST, Headers and Authentication
  2. 10.210.2 JSON, Paging and Rate Limits
  3. 10.310.3 Reputation Lookups
  4. 10.410.4 Secrets for API Keys
  5. 10.510.5 Microsoft Graph PowerShell
  6. 10.610.6 Entra ID and Sign-in Data
  7. 10.710.7 Defender XDR and Sentinel APIs
  8. 10.810.8 From Alert to Enriched Report
  9. 10.9Module Summary and Knowledge Check
Module 11Building Analyst Tools

Module 11 of PowerShell for Security Analysts: from one-liners to functions, parameters and validation, logging and help, configuration and credentials, risk scoring, modules and the analyst toolkit, signing, JEA, WDAC and AppLocker, and checking a script you did not write.

Show 9 lessonsHide lessons
  1. 11.111.1 From One-liners to Functions
  2. 11.211.2 Parameters, Validation and Pipeline Input
  3. 11.311.3 Logging, Verbose Output and Help
  4. 11.411.4 Configuration and Credentials
  5. 11.511.5 Risk Scoring
  6. 11.611.6 Modules and the Analyst Toolkit
  7. 11.711.7 Signing, JEA, WDAC and AppLocker
  8. 11.811.8 Checking a Script You Did Not Write
  9. 11.9Module Summary and Knowledge Check

Resources

ResourcesAnalyst Cheatsheets

One sheet per module of PowerShell for Security Analysts, each entry a question, a command that answers it against the course evidence with its real output, what to read and what the answer does not prove.

Show 12 lessonsHide lessons
  1. 1PowerShell in Security Operations
  2. 2Syntax Analysts Need
  3. 3Working with Security Data
  4. 4Host Triage and Accounts
  5. 5Process and Network
  6. 6Files and Registry
  7. 7Windows Event Logs
  8. 8PowerShell Logging and Attacks
  9. 9Persistence and Defender
  10. 10Triage, Collection and Hunting
  11. 11APIs and Threat Intelligence
  12. 12Building Analyst Tools
ResourcesInvestigation Cookbooks

Procedures for the three problems every PowerShell analyst meets: a command that returns nothing, a collection that is incomplete, and an evidence file nobody has read before.

Show 3 lessonsHide lessons
  1. 1A Command Returns Nothing
  2. 2A Collection Is Incomplete
  3. 3Reading an Unfamiliar Evidence File
ResourcesWindows Lab Setup

The course evidence, which runs every lesson on any machine with PowerShell 7, and a Windows virtual machine of your own for the live commands, with the logging and remoting the course relies on.

Show 2 lessonsHide lessons
  1. 1The Course Evidence
  2. 2A Windows Lab of Your Own
ResourcesCase Walkthroughs

Six worked investigations on the course evidence, each from the question handed to you to the finding written honestly, with every command run and every wrong turn shown.

Show 6 lessonsHide lessons
  1. 1From Word to the DLL
  2. 2The Count That Missed Two Hosts
  3. 3The Filter That Found Microsoft
  4. 4The Toolkit That Answered Differently
  5. 5The Account Nobody Created
  6. 6One Timeline from Two Logs
ResourcesHunting Playbooks

Six hunting patterns in PowerShell, each run on the course evidence: rare across the fleet, rare configuration, new since the baseline, Office starting a shell, paired events in sequence, and start then connect.

Show 6 lessonsHide lessons
  1. 1Rare Across the Fleet
  2. 2Rare Configuration
  3. 3New Since the Baseline
  4. 4Office Starting a Shell
  5. 5Paired Events in Sequence
  6. 6Start Then Connect
ResourcesEvidence Playground

Places to practice PowerShell for security work and things to keep open while you do: the course evidence, the detection library, the SOC simulator, the playbook suite, an open-source DFIR toolkit, and reference pages.

ResourcesOperational Reference

Every command, check and trap from PowerShell for Security Analysts in one place, organized by the task in front of you and linked back to the lesson that explains it.

Show 1 lessonHide lessons
  1. 1Operational Reference
ResourcesReferences & Further Reading

The documentation behind PowerShell for Security Analysts, arranged by the question it answers: the language and its editions, logs and evidence, PowerShell's own security, remoting and APIs, tools and review, and incident response practice.

Project

ResourcesProject: One Compromised Endpoint

The PowerShell for Security Analysts project: a brief for investigating one compromised laptop from its incident package alone, with the course's PowerShell, from first alert to a PowerShell-generated investigation report. No submission, no grading.

Show 1 lessonHide lessons
  1. 1The Brief

Course Completion

CompletionCourse Exam

PowerShell for Security Analysts end-of-course exam: twenty-two tasks, two per teaching module, each answered by writing PowerShell against an evidence set the course did not investigate, and checked on the server.

Show 1 lessonHide lessons
  1. 1Course Completion. PowerShell for Security Analysts

Course overview

Most of what an analyst needs from a Windows host, and much of what they need from Microsoft 365, is one PowerShell command away, if they know which command, which property and which trap. This course teaches that PowerShell: not the language for its own sake, but the commands and habits that answer an investigation's questions and survive being checked.

It is taught against one intrusion at Northgate Engineering, followed across laptops, a file server and the cloud tenant: a macro document, an encoded PowerShell command, a DLL in a Temp folder, a scheduled task, a new administrator account and a cloud sign-in nobody blocked. Every module adds a way of asking the evidence a question, and the Project hands you an endpoint nobody has investigated.

How this course works

Every result is real. Each lesson runs its commands against evidence files from Northgate's hosts and tenant, and every output in the course came from running that command. Download a module's evidence and the same commands give the same answers on any machine with PowerShell 7.4 or later.

Windows PowerShell and PowerShell 7. The course is written for PowerShell 7.6 and teaches Windows PowerShell 5.1 wherever it behaves differently, because it is on every Windows machine you will investigate.

Check every answer. An empty result, a total, an unsigned file and an AI-written script are all things the course teaches you to verify before anyone relies on them.

What you will learn

✓ Choose the right PowerShell for the job, read what a command returns as objects, and find your way to any command and property
✓ Bring evidence in from CSV, JSON, XML, plain text and API responses without losing types, pages or rows
✓ Triage a Windows host and its accounts, and follow processes to their parents, their files and their network connections
✓ Read files, hashes, signatures, the mark of the web and the registry as evidence
✓ Read Windows event logs and Sysmon, and PowerShell's own logs, decoding the commands attackers hoped nobody would read
✓ Find what will run again, from scheduled tasks to WMI subscriptions, and check the state of Defender
✓ Collect from one host or a fleet, seal the evidence, and hunt indicators across every host you can reach
✓ Query Microsoft Graph, Defender and threat intelligence APIs, and keep the keys out of your scripts
✓ Turn scripts into tools other analysts can trust: validated, documented, configured, packaged, signed and reviewed, including code an AI wrote

Who this course is for

Anyone who investigates Windows hosts or Microsoft 365: SOC analysts, incident responders, threat hunters and administrators moving into security, and people preparing for those roles. No PowerShell experience is assumed; every idea is explained at first use.

Readers who already write PowerShell will find the later modules, on fleet collection, APIs and building trustworthy tools, go well past the basics, and the Course Fit Check in the free Module 0 shows where you sit.

What you will build

✓ An investigation of a compromised endpoint the course never investigates, from its evidence package to a report your own script generates
✓ An analyst toolkit module of tested functions, signed and ready to share
✓ Collectors that package evidence with hashes and a record of what they could not collect

What this course does not cover

PowerShell as a software product, such as binary modules, Gallery publishing and desktop tools, and offensive PowerShell for its own sake. Deeper Windows forensics and detection engineering each have their own courses on the platform.

Things you need to know

What are the prerequisites?

None. The free Module 0 explains what PowerShell is, which version to use and how to set up an analyst workstation before the first command.

What do I need to run the commands?

PowerShell 7.4 or later on Windows, macOS or Linux runs every lesson against its evidence files. A Windows virtual machine of your own lets you run the live commands too; the lab setup pages explain how to build one and turn on the logging the course reads.

How is the course assessed?

By a practical exam: twenty-two tasks, two per teaching module, each answered by running PowerShell against evidence the course did not investigate, and checked on the server. A score of 70 or more earns the PowerShell for Security Analysts certificate with CPE credit.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may use the scripts and tools you build in your own environment. You may not redistribute course content or share account credentials.

Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then work the evidence: twenty-two tasks answered by running PowerShell on evidence the course did not investigate, no time limit. Pass mark: 70. Earn your certificate with CPE credits.

22tasks
11modules
100points
Take End of Course Exam

Answers are checked on the server. Certificate issued on pass.