PowerShell Cross-Platform

PowerShell was originally Windows-only because it was built on the .NET Framework. In 2016, Microsoft open-sourced PowerShell and rebuilt it on .NET Core, making it run on Windows, macOS, and Linux.

Two main versions

Version Platform Notes
Windows PowerShell Windows only Built into Windows; based on .NET Framework
PowerShell Core / PowerShell 7 Windows, macOS, Linux Based on .NET Core / modern .NET

Why it matters for investigations

  • Mixed environments are common: Windows servers, Linux web servers, macOS endpoints.
  • Investigators can use a single command language to acquire data across platforms.
  • PowerShell pipelines and common CmdLet patterns transfer between systems.

Caveat

Some Windows-specific CmdLets still only work on Windows. Cross-platform support applies to the core engine and many common commands, but not every Windows-only feature.