Get-Member CmdLet
Get-Member is a PowerShell discovery CmdLet that reveals the members (properties, methods, events, and other object attributes) of any object piped into it. Because PowerShell cmdlets return structured .NET objects rather than plain text, Get-Member lets an analyst see exactly what data and actions are available without memorizing every object type.
Why It Matters for Investigators
- Avoid memorization: No need to remember every property of every cmdlet.
- Discover evidence: Cmdlets often return far more data than their default display shows (e.g.,
Get-ServiceexposesStartType,CanPauseAndContinue,ServiceHandle, etc.). - Chain pipeline operations: Once you know a property name, you can pipe it to
Select-Object,Where-Object,Export-Csv, and more.
Basic Usage
Get-Service | Get-Member
This lists each member of the objects returned by Get-Service, including member type (Property, Method, Alias, etc.), name, and definition.
Common Member Types
| Type | Meaning | Example for services |
|---|---|---|
| Property | Data attribute | Name, Status, StartType |
| Method | Action the object can perform | Start, Stop, WaitForStatus |
| AliasProperty | Shorthand for another property | Name may alias ServiceName |
| ScriptProperty | Calculated property | depends on object |
| Event | Event hooks | less common in daily use |
Filtering by Member Type
Get-Service | Get-Member -MemberType Property
Get-Service | Get-Member -MemberType Method
Real-World Example from the Book
The book shows that Get-Service default output only shows Status, Name, and DisplayName. To find whether a service starts automatically or manually, an analyst can inspect the object:
Get-Service | Get-Member
and discover the StartType property:
Property System.ServiceProcess.ServiceStartMode StartType {get;}
Then display only the relevant properties:
Get-Service | Select-Object -Property Name, Status, StartType
Key Insight
In PowerShell, the pipe (|) passes objects, not text. Get-Member interrogates the type and structure of those objects, making it the primary tool for understanding what a cmdlet can actually tell you about a target system.
Related Concepts
- PowerShell as an Acquisition Engine — how PowerShell collects system evidence as objects
- PowerShell Network Configuration CmdLets — another example of object-based investigation in PowerShell
Get-Help— use it to learn aboutGet-Memberitself:Get-Help Get-MemberSelect-Object— used after discovering property names to build custom output