PowerShell for Security Analysts
The PowerShell a security analyst actually uses
Triage a Windows host, investigate processes, files, the registry and event logs, read the PowerShell attackers run, hunt across many hosts, and build tools other analysts can trust. Every command runs against real evidence, and nothing assumes you have written PowerShell before.
What you'll be able to do
Course Syllabus
Every module and every lesson. The first three modules are open; the rest open on a click.
Download the full syllabus (PDF)
Orientation
Module 0 of PowerShell for Security Analysts: why defenders use PowerShell, Windows PowerShell 5.1 and PowerShell 7, how PowerShell is built, the console, Terminal and VS Code, cmdlets, functions, scripts and modules, finding your way around, an administrator's tool and an attacker's tool, and building an analyst workstation.
Show 8 lessonsHide lessons
- 0.10.1 Why Defenders Use PowerShellPreview
- 0.20.2 Windows PowerShell 5.1 and PowerShell 7Preview
- 0.30.3 How PowerShell Is BuiltPreview
- 0.40.4 Console, Terminal and VS CodePreview
- 0.50.5 Cmdlets, Functions, Scripts and ModulesPreview
- 0.60.6 Finding Your Way AroundPreview
- 0.70.7 An Administrator's Tool and an Attacker's ToolPreview
- 0.80.8 Building Your Analyst WorkstationPreview
Foundations
Module 1 of PowerShell for Security Analysts: objects and the pipeline, filtering and comparison, logic, wildcards and regular expressions, variables and collections, loops, functions and error handling, and reducing endpoint data to an answer.
Show 9 lessonsHide lessons
- 1.11.1 Objects, Properties and Methods
- 1.21.2 The Pipeline
- 1.31.3 Where-Object and Comparison Operators
- 1.41.4 Logical Operators, Wildcards and Regex
- 1.51.5 Variables, Arrays and Hashtables
- 1.61.6 Loops and Conditions
- 1.71.7 Functions and Error Handling
- 1.81.8 Reducing Endpoint Data to an Answer
- 1.9Module Summary and Knowledge Check
Module 2 of PowerShell for Security Analysts: CSV, JSON and REST responses, XML, plain text and Select-String, CliXml, sorting and grouping, calculated properties, and comparing datasets.
Endpoint Investigation
Module 3 of PowerShell for Security Analysts: what the machine is, its patches, boot time and uptime, installed software, services and drivers, local users, groups and administrators, recently changed accounts, and Active Directory accounts.
Show 9 lessonsHide lessons
- 3.13.1 What Is This Machine
- 3.23.2 Patches, Boot Time and Uptime
- 3.33.3 Installed Software
- 3.43.4 Services and Drivers
- 3.53.5 Local Users and Groups
- 3.63.6 Local Administrators and Privileged Accounts
- 3.73.7 Recently Created and Re-enabled Accounts
- 3.83.8 Active Directory Accounts
- 3.9Module Summary and Knowledge Check
Module 4 of PowerShell for Security Analysts: Get-Process and Win32_Process, parent, path, command line and user, process trees, LOLBins and suspicious chains, connections and listeners, the DNS cache, and correlating processes with the addresses they reach.
Show 9 lessonsHide lessons
- 4.14.1 Get-Process and Win32_Process
- 4.24.2 Parent, Path, Command Line and User
- 4.34.3 Process Trees
- 4.44.4 LOLBins and Suspicious Chains
- 4.54.5 Connections and Listeners
- 4.64.6 DNS Cache and Resolution
- 4.74.7 From PID to Remote Address
- 4.84.8 A Process and Network Correlator
- 4.9Module Summary and Knowledge Check
Module 5 of PowerShell for Security Analysts: finding files, timestamps, hidden and recent files, hashing, signatures and PE files, alternate data streams and the mark of the web, the registry provider, persistence and configuration keys, and USB, RDP and recent-activity keys.
Show 9 lessonsHide lessons
- 5.15.1 Finding Files
- 5.25.2 Timestamps, Hidden and Recent Files
- 5.35.3 Hashing
- 5.45.4 Signatures and PE Files
- 5.55.5 Alternate Data Streams and the Mark of the Web
- 5.65.6 The Registry Provider
- 5.75.7 Persistence and Configuration Keys
- 5.85.8 USB, RDP and Recent-Activity Keys
- 5.9Module Summary and Knowledge Check
Logs and Detection
Module 6 of PowerShell for Security Analysts: logs, providers and event IDs, Get-WinEvent and FilterHashtable, XPath and event XML, logon, process and privilege events, services, tasks and account changes, the Sysmon, Defender, RDP and WMI logs, and a security timeline tool.
Show 9 lessonsHide lessons
- 6.16.1 Logs, Providers and Event IDs
- 6.26.2 Get-WinEvent and FilterHashtable
- 6.36.3 XPath and Event XML
- 6.46.4 Logon Events
- 6.56.5 Process and Privilege Events
- 6.66.6 Services, Tasks and Account Changes
- 6.76.7 Sysmon, Defender, RDP and WMI Logs
- 6.86.8 A Security Timeline Tool
- 6.9Module Summary and Knowledge Check
Module 7 of PowerShell for Security Analysts: script block, module and transcription logging, events 4103, 4104, 400 and 800, PSReadLine history, encoded commands, download cradles, obfuscation and safe deobfuscation, AMSI tampering as evidence, and execution policy and Constrained Language Mode.
Show 9 lessonsHide lessons
- 7.17.1 PowerShell's Own Logs
- 7.27.2 Reading Script Block Logs
- 7.37.3 PSReadLine History and Transcripts
- 7.47.4 Encoded Commands
- 7.57.5 Invoke-Expression and Download Cradles
- 7.67.6 Obfuscation and Safe Deobfuscation
- 7.77.7 AMSI and Its Bypasses, as Evidence
- 7.87.8 Execution Policy and Constrained Language Mode
- 7.9Module Summary and Knowledge Check
Module 8 of PowerShell for Security Analysts: scheduled tasks, services and Run keys across a fleet, startup folders and PowerShell profiles, WMI event subscriptions, DLL search-order abuse, Defender status and signatures, threats, exclusions and tampering, and a persistence hunter.
Show 9 lessonsHide lessons
- 8.18.1 Scheduled Tasks
- 8.28.2 Services and Run Keys Across the Fleet
- 8.38.3 Startup Folders and PowerShell Profiles
- 8.48.4 WMI Event Subscriptions
- 8.58.5 DLL Search-Order Abuse
- 8.68.6 Defender Status and Signatures
- 8.78.7 Threats, Exclusions and Tampering
- 8.88.8 A Persistence Hunter
- 8.9Module Summary and Knowledge Check
Response, Hunting and Automation
Module 9 of PowerShell for Security Analysts: a repeatable triage method, the host triage collector, evidence integrity with hashing and case metadata, the incident evidence collector, hunting one indicator and many with an IOC scanner, and remote collection with WinRM, credentials and JEA.
Show 9 lessonsHide lessons
- 9.19.1 A Repeatable Triage Method
- 9.29.2 The Host Triage Collector
- 9.39.3 Evidence Integrity, Hashing and Case Metadata
- 9.49.4 The Incident Evidence Collector
- 9.59.5 Hunting One Indicator
- 9.69.6 Multi-Indicator Hunting and the IOC Scanner
- 9.79.7 Remoting, WinRM and Credentials
- 9.89.8 At Scale, with JEA
- 9.9Module Summary and Knowledge Check
Module 10 of PowerShell for Security Analysts: REST calls with headers and authentication, JSON paging and rate limits, reputation lookups, API keys as secrets, Microsoft Graph PowerShell, Entra ID sign-in data, the Defender XDR and Sentinel APIs, and an enriched report from an alert.
Show 9 lessonsHide lessons
- 10.110.1 REST, Headers and Authentication
- 10.210.2 JSON, Paging and Rate Limits
- 10.310.3 Reputation Lookups
- 10.410.4 Secrets for API Keys
- 10.510.5 Microsoft Graph PowerShell
- 10.610.6 Entra ID and Sign-in Data
- 10.710.7 Defender XDR and Sentinel APIs
- 10.810.8 From Alert to Enriched Report
- 10.9Module Summary and Knowledge Check
Module 11 of PowerShell for Security Analysts: from one-liners to functions, parameters and validation, logging and help, configuration and credentials, risk scoring, modules and the analyst toolkit, signing, JEA, WDAC and AppLocker, and checking a script you did not write.
Show 9 lessonsHide lessons
- 11.111.1 From One-liners to Functions
- 11.211.2 Parameters, Validation and Pipeline Input
- 11.311.3 Logging, Verbose Output and Help
- 11.411.4 Configuration and Credentials
- 11.511.5 Risk Scoring
- 11.611.6 Modules and the Analyst Toolkit
- 11.711.7 Signing, JEA, WDAC and AppLocker
- 11.811.8 Checking a Script You Did Not Write
- 11.9Module Summary and Knowledge Check
Resources
One sheet per module of PowerShell for Security Analysts, each entry a question, a command that answers it against the course evidence with its real output, what to read and what the answer does not prove.
Show 12 lessonsHide lessons
- 1PowerShell in Security Operations
- 2Syntax Analysts Need
- 3Working with Security Data
- 4Host Triage and Accounts
- 5Process and Network
- 6Files and Registry
- 7Windows Event Logs
- 8PowerShell Logging and Attacks
- 9Persistence and Defender
- 10Triage, Collection and Hunting
- 11APIs and Threat Intelligence
- 12Building Analyst Tools
Procedures for the three problems every PowerShell analyst meets: a command that returns nothing, a collection that is incomplete, and an evidence file nobody has read before.
Show 3 lessonsHide lessons
The course evidence, which runs every lesson on any machine with PowerShell 7, and a Windows virtual machine of your own for the live commands, with the logging and remoting the course relies on.
Show 2 lessonsHide lessons
Six worked investigations on the course evidence, each from the question handed to you to the finding written honestly, with every command run and every wrong turn shown.
Six hunting patterns in PowerShell, each run on the course evidence: rare across the fleet, rare configuration, new since the baseline, Office starting a shell, paired events in sequence, and start then connect.
Places to practice PowerShell for security work and things to keep open while you do: the course evidence, the detection library, the SOC simulator, the playbook suite, an open-source DFIR toolkit, and reference pages.
Every command, check and trap from PowerShell for Security Analysts in one place, organized by the task in front of you and linked back to the lesson that explains it.
Show 1 lessonHide lessons
The documentation behind PowerShell for Security Analysts, arranged by the question it answers: the language and its editions, logs and evidence, PowerShell's own security, remoting and APIs, tools and review, and incident response practice.
Project
The PowerShell for Security Analysts project: a brief for investigating one compromised laptop from its incident package alone, with the course's PowerShell, from first alert to a PowerShell-generated investigation report. No submission, no grading.
Show 1 lessonHide lessons
Course Completion
PowerShell for Security Analysts end-of-course exam: twenty-two tasks, two per teaching module, each answered by writing PowerShell against an evidence set the course did not investigate, and checked on the server.
Show 1 lessonHide lessons
Course overview
Most of what an analyst needs from a Windows host, and much of what they need from Microsoft 365, is one PowerShell command away, if they know which command, which property and which trap. This course teaches that PowerShell: not the language for its own sake, but the commands and habits that answer an investigation's questions and survive being checked.
It is taught against one intrusion at Northgate Engineering, followed across laptops, a file server and the cloud tenant: a macro document, an encoded PowerShell command, a DLL in a Temp folder, a scheduled task, a new administrator account and a cloud sign-in nobody blocked. Every module adds a way of asking the evidence a question, and the Project hands you an endpoint nobody has investigated.
How this course works
Every result is real. Each lesson runs its commands against evidence files from Northgate's hosts and tenant, and every output in the course came from running that command. Download a module's evidence and the same commands give the same answers on any machine with PowerShell 7.4 or later.
Windows PowerShell and PowerShell 7. The course is written for PowerShell 7.6 and teaches Windows PowerShell 5.1 wherever it behaves differently, because it is on every Windows machine you will investigate.
Check every answer. An empty result, a total, an unsigned file and an AI-written script are all things the course teaches you to verify before anyone relies on them.
What you will learn
Who this course is for
Anyone who investigates Windows hosts or Microsoft 365: SOC analysts, incident responders, threat hunters and administrators moving into security, and people preparing for those roles. No PowerShell experience is assumed; every idea is explained at first use.
Readers who already write PowerShell will find the later modules, on fleet collection, APIs and building trustworthy tools, go well past the basics, and the Course Fit Check in the free Module 0 shows where you sit.
What you will build
What this course does not cover
PowerShell as a software product, such as binary modules, Gallery publishing and desktop tools, and offensive PowerShell for its own sake. Deeper Windows forensics and detection engineering each have their own courses on the platform.
Things you need to know
What are the prerequisites?
None. The free Module 0 explains what PowerShell is, which version to use and how to set up an analyst workstation before the first command.
What do I need to run the commands?
PowerShell 7.4 or later on Windows, macOS or Linux runs every lesson against its evidence files. A Windows virtual machine of your own lets you run the live commands too; the lab setup pages explain how to build one and turn on the logging the course reads.
How is the course assessed?
By a practical exam: twenty-two tasks, two per teaching module, each answered by running PowerShell against evidence the course did not investigate, and checked on the server. A score of 70 or more earns the PowerShell for Security Analysts certificate with CPE credit.
Usage rights and disclaimer
Course materials: Licensed for individual professional development. You may use the scripts and tools you build in your own environment. You may not redistribute course content or share account credentials.
Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.
End of Course Exam
Complete the course, then work the evidence: twenty-two tasks answered by running PowerShell on evidence the course did not investigate, no time limit. Pass mark: 70. Earn your certificate with CPE credits.
Answers are checked on the server. Certificate issued on pass.