PowerShell Cross-Platform
PowerShell was originally Windows-only because it was built on the .NET Framework. In 2016, Microsoft open-sourced PowerShell and rebuilt it on .NET Core, making it run on Windows, macOS, and Linux.
Two main versions
| Version | Platform | Notes |
|---|---|---|
| Windows PowerShell | Windows only | Built into Windows; based on .NET Framework |
| PowerShell Core / PowerShell 7 | Windows, macOS, Linux | Based on .NET Core / modern .NET |
Why it matters for investigations
- Mixed environments are common: Windows servers, Linux web servers, macOS endpoints.
- Investigators can use a single command language to acquire data across platforms.
- PowerShell pipelines and common CmdLet patterns transfer between systems.
Caveat
Some Windows-specific CmdLets still only work on Windows. Cross-platform support applies to the core engine and many common commands, but not every Windows-only feature.