This section introduces three PowerShell CmdLets used to examine network settings on a Windows system. Unlike the legacy Windows Command Line, PowerShell exposes network configuration as rich objects that can be filtered, piped, and analyzed programmatically.
CmdLets Covered
Get-NetIPAddress
Shows IP address information. Useful for listing all IP addresses assigned to interfaces, including IPv4 and IPv6 addresses, prefix lengths, and address states (e.g., Preferred, Deprecated).
Get-NetIPAddress
Get-Help Get-NetIPAddress -Examples
Interpreting Address Origin
The PrefixOrigin and SuffixOrigin properties reveal whether an address is static or dynamically assigned:
- Manual — statically configured by a user or administrator.
- Dhcp — assigned by a DHCP server.
- WellKnown / Other — special cases such as APIPA, multicast, or loopback addresses.
A static IPv4 address typically reports both values as Manual, and its ValidLifetime and PreferredLifetime are Infinite because there is no DHCP lease to expire.
Get-NetIPAddress | Where-Object { $_.PrefixOrigin -eq "Manual" }
Get-NetIPConfiguration
Provides a more consolidated view of network configuration, similar to what ipconfig displays but as structured objects. It typically returns IP address, default gateway, DNS servers, and interface aliases in one view.
Get-NetIPConfiguration
Get-Help Get-NetIPConfiguration -Examples
Get-NetIPInterface
Displays IP interface properties such as MTU, DHCP status, connection state, and IPv4/IPv6 forwarding settings. This is useful for understanding how the interface is configured at the protocol level.
Get-NetIPInterface
Get-Help Get-NetIPInterface -Examples
Discovery
These CmdLets can be found by querying the help system with a keyword:
Get-Help ip
This returns all CmdLets related to the word "ip", demonstrating that PowerShell's help system is a discovery tool, not just a reference.
Relevance to Investigations
Network configuration artifacts can reveal:
- Whether a system uses static or dynamic IP addressing.
- The presence of multiple network interfaces or virtual adapters.
- IPv6 configuration that may be overlooked in traditional command-line output.
- Interface state at the time of collection.