PowerShell + Python Acquisition Pipeline

A practical exercise pattern from the book's philosophy: use PowerShell for acquiring raw data from Windows systems and Python for formatting, processing, and analysis of that data.

Why Combine Them?

  • PowerShell has deep, native access to Windows artifacts: processes, services, event logs, registry, and Active Directory.
  • Python has rich libraries for parsing, analysis, visualization, and machine learning.

Common Workflow

PowerShell acquires → export to CSV/JSON → Python reads → analyzes → outputs/report

Example

PowerShell: acquire and export

Get-Process |
    Select-Object Name, Id, CPU, WorkingSet |
    Export-Csv -Path "processes.csv" -NoTypeInformation

Python: read and analyze

import csv

with open("processes.csv", newline="") as f:
    reader = csv.DictReader(f)
    high_cpu = [row for row in reader if float(row["CPU"] or 0) > 10]

for proc in high_cpu:
    print(proc["Name"], proc["CPU"])

Data Exchange Formats

Format Best for
CSV Simple tabular data
JSON Nested or structured objects
XML PowerShell-native output, though less common in Python