PowerShell ISE (Integrated Scripting Environment) is a free Windows application that provides a workspace for experimenting with and writing PowerShell CmdLets and scripts. It is typically preinstalled on modern Windows systems or available via the Windows Management Framework 5.
Key Workflow
Investigators should experiment interactively in the Direct Command Entry Panel first, refine their approach, and only then move commands into the Scripting Panel.
Three Main Panels
1. Scripting Panel
- A code editor for writing multi-command PowerShell scripts.
- Not the starting point for learning or discovery.
- Used after commands have been tested interactively.
2. Direct Command Entry Panel
- The interactive console for executing individual CmdLets.
- More powerful than the Windows Command Prompt / DOS.
- Commands follow the verb-noun format.
- This is the experimentation sandbox.
3. Command Help Panel
- Built-in browser showing help for every CmdLet.
- The author prefers using the
Get-HelpCmdLet directly in the command entry panel instead.
Running as Administrator
Many acquisition CmdLets require Administrator privileges. Launch ISE as Administrator by right-clicking the icon → right-clicking Windows PowerShell ISE → Run as administrator.
⚠️ Caution: CmdLets can damage systems or delete files even when run as a standard user. Always proceed carefully, especially on live systems.
Source
Chet Hosmer, PowerShell and Python Together: Targeting Digital Investigations (Apress, 2019), Chapter 1, "Navigating PowerShell ISE."