PowerShell for Security Operations

The PowerShell you reach for mid-incident.

An alert fires and the clock starts: processes end, connections close, and volatile state is lost while you decide what to run. This course teaches the specific PowerShell that answers the first half hour, taught from the object model up so you understand why each command works. You build from the pipeline through remoting and evidence collection to event log analysis, persistence hunting, M365 containment, and the automation that keeps a posture honest, and you finish able to take an alert from the first command to a documented handoff.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
Your subscription also includes the Practice Hub: graded scenarios, forensic cases, query drills and the response playbooks.
View Pricing Take End of Course Exam → 10 CPE Credits

What you'll be able to do

Work with PowerShell as an object pipeline rather than as text: filter, select, calculate, group, and export endpoint state into evidence you can reopen
Reach every machine an incident touches with remoting, run a tested script across the fleet in one command, and bring the evidence back attributable per host
Capture the volatile layer in the order it decays, from network state to persistence, with a chain-of-custody log and output that never touches the volume under investigation
Query millions of event log records in seconds, parse them into named fields, and merge several logs and hosts into one chronological timeline
Hunt persistence where audits stop looking: fixed-value registry keys, pattern-searched hives, service libraries, WMI event subscriptions, and dropped files
Investigate and contain a compromised M365 account in the order that holds, including the consent grant that survives a password reset, then scale it to a campaign
Turn any of it into a scheduled check that authenticates unattended, reports only what changed, and tells you when it has stopped working
SEC205 | Essentials tier | 7 modules across 4 phases | 10–12 hours at your own pace | 10 CPE credits | Updated July 2026
Course Agenda View Course ModulesHide Course Modules

Course overview

PowerShell for Security Operations teaches the commands a professional actually runs during an incident, and teaches them from the model underneath so they compose instead of breaking. You start from the pipeline and the object model, the reason a command filters on a real field rather than scraped text. From there you fan collection out across endpoints with remoting, build the script that captures volatile evidence in the first thirty minutes, reconstruct authentication timelines from the Windows event log, hunt persistence across the registry and services, contain a compromised M365 account, and automate the standing checks that catch drift before it becomes an incident. Learn how to:

Filter, sort, and export security-relevant endpoint state through the object pipeline rather than scraping text
Run investigation commands across many endpoints at once with remoting, and handle credentials and the double-hop problem
Build a timestamped first-response script that captures volatile evidence in order of volatility before it disappears
Query the Windows event log with precision and reconstruct logon timelines and lateral movement from 4624 and 4625 events
Hunt persistence across the registry, services, and scheduled tasks, and contain a compromised M365 account through Graph and Exchange Online

By the end you can take an alert from the first command to a contained account and a handoff another responder can act on, with a script kit you wrote and understand.

Who this course is for

You are a SOC analyst, incident responder, Windows administrator, or security engineer who runs PowerShell under pressure and wants commands you can trust rather than snippets you paste and hope. Anyone who investigates Windows and M365 endpoints and wants to own the console during an incident belongs here. The course is self-contained, every concept explained at first use, so an experienced reader can move fast and a newer one is never left behind. It is for you if you want to:

Understand the commands you run instead of copying them from blog posts and hoping the output means what you think
Collect volatile evidence off any Windows host, and off many at once, before a reboot destroys it
Reconstruct what happened on a host from its event log and registry rather than guessing
Contain a live M365 account compromise without missing the sessions and rules that survive a password reset

What you'll learn

By the end of PowerShell for Security Operations you will be able to:

Use the pipeline and object model to filter and shape endpoint data on real properties, not on formatting
Collect from many endpoints at once with Invoke-Command and PSSession, and diagnose why a remote command fails
Build and run a first-response collection script that captures processes, connections, tasks, and autoruns to timestamped files
Query the event log with FilterHashtable and XPath and build a logon timeline that shows lateral movement
Investigate persistence across the registry, services, and scheduled tasks, and read a service binary path for what does not belong
Query sign-ins and inbox rules and contain an account through Microsoft Graph and Exchange Online, then automate a daily posture check

Key course takeaways

The object model that makes every investigation command a variation on the same move, so commands compose instead of breaking
A first-response method built on order of volatility: what to capture, in what sequence, and how to preserve it
The event log and persistence knowledge to reconstruct an intrusion from a host rather than from an alert summary
A reusable script kit for collection, event log querying, and M365 containment that turns ad hoc commands into a repeatable practice

Things you need to know

What are the prerequisites for this course?

Familiarity with Windows administration helps, and if you have opened a PowerShell prompt and run Get-Process you have enough. No prior scripting experience is required. Every concept, from the object model to the Graph and Exchange modules, is taught at first use, and an experienced reader can skip past what they already know.

Do I need a lab to take this course?

No. Every command and its output is shown in full, so you can follow the reasoning without a machine in front of you. You will get more from it with a Windows machine and a test M365 tenant to run commands against, and all demonstrations use representative output from the fictional Northgate Engineering environment, never production or personal data.

How does this relate to FOR401 (Incident Response) and SEC202 (Security Automation and Orchestration)?

This course teaches the PowerShell craft itself: the commands and scripts you run during an investigation. FOR401 teaches the incident response methodology those commands serve. SEC202 takes automation further into Logic Apps, Azure Functions, and Sentinel. Each stands alone, and together they cover the tool, the method, and the orchestration. Neither is a prerequisite for this course.

How will the course benefit your career?

PowerShell is the connective tissue of Windows and M365 security work, and the professionals who can compose it, rather than paste it, move faster and make fewer mistakes when it matters. The collection, event log, and containment skills here apply directly in a SOC or IR role, and the automation habit turns recurring manual checks into monitored, repeatable ones.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may not redistribute course content or share account credentials.

Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.

Version and changelog

Current version: 1.0  |  Last updated: July 2026

July 2026, v1.0: Full course launch, rebuilt from the original PowerShell for Security Operations skill into seven teaching modules across four phases, framed by a course orientation and two reference modules. Covers the pipeline and object model, remoting for fan-out collection, volatile evidence collection, event log analysis, persistence hunting across the registry and services, M365 and Entra containment, and automation, closing with a first-response capstone. The student finishes able to take an alert from the first command to a contained account and a documented handoff.

This course is actively maintained.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
1scenario
Take End of Course Exam

Requires 80% course completion. One random scenario per attempt. Certificate issued on pass.