PowerShell as an Acquisition Engine

PowerShell is described in Hosmer's book as a powerful acquisition engine for digital investigations. Its role is to gather raw information from live systems, servers, peripherals, mobile devices, and data-driven applications such as Active Directory.

Why PowerShell for Acquisition?

  • Cross-platform: Since Microsoft open-sourced PowerShell, it can run on Windows, macOS, and Linux. With proper credentials, it can collect data from virtually any platform.
  • CmdLet-based: PowerShell commands are built from small, reusable units called CmdLets (pronounced "command let"). These can be filtered, sorted, and piped together.
  • Built-in and third-party support: Investigators can leverage both native CmdLets and community/third-party CmdLets.
  • Piping and composition: Like Unix shells, PowerShell allows commands to be chained with the pipe operator (|), making it easy to build complex acquisition workflows.

Integration with Python

The book integrates PowerShell with Python to form a complete investigative workbench:

  • PowerShell handles acquisition of raw data.
  • Python handles logical analysis, machine learning, and deep analysis of that data.

Together, they support innovative approaches to live investigations and incident response.