PowerShell as an Acquisition Engine
PowerShell is described in Hosmer's book as a powerful acquisition engine for digital investigations. Its role is to gather raw information from live systems, servers, peripherals, mobile devices, and data-driven applications such as Active Directory.
Why PowerShell for Acquisition?
- Cross-platform: Since Microsoft open-sourced PowerShell, it can run on Windows, macOS, and Linux. With proper credentials, it can collect data from virtually any platform.
- CmdLet-based: PowerShell commands are built from small, reusable units called CmdLets (pronounced "command let"). These can be filtered, sorted, and piped together.
- Built-in and third-party support: Investigators can leverage both native CmdLets and community/third-party CmdLets.
- Piping and composition: Like Unix shells, PowerShell allows commands to be chained with the pipe operator (
|), making it easy to build complex acquisition workflows.
Integration with Python
The book integrates PowerShell with Python to form a complete investigative workbench:
- PowerShell handles acquisition of raw data.
- Python handles logical analysis, machine learning, and deep analysis of that data.
Together, they support innovative approaches to live investigations and incident response.