Get-Member CmdLet

Get-Member is a PowerShell discovery CmdLet that reveals the members (properties, methods, events, and other object attributes) of any object piped into it. Because PowerShell cmdlets return structured .NET objects rather than plain text, Get-Member lets an analyst see exactly what data and actions are available without memorizing every object type.

Why It Matters for Investigators

  • Avoid memorization: No need to remember every property of every cmdlet.
  • Discover evidence: Cmdlets often return far more data than their default display shows (e.g., Get-Service exposes StartType, CanPauseAndContinue, ServiceHandle, etc.).
  • Chain pipeline operations: Once you know a property name, you can pipe it to Select-Object, Where-Object, Export-Csv, and more.

Basic Usage

Get-Service | Get-Member

This lists each member of the objects returned by Get-Service, including member type (Property, Method, Alias, etc.), name, and definition.

Common Member Types

Type Meaning Example for services
Property Data attribute Name, Status, StartType
Method Action the object can perform Start, Stop, WaitForStatus
AliasProperty Shorthand for another property Name may alias ServiceName
ScriptProperty Calculated property depends on object
Event Event hooks less common in daily use

Filtering by Member Type

Get-Service | Get-Member -MemberType Property
Get-Service | Get-Member -MemberType Method

Real-World Example from the Book

The book shows that Get-Service default output only shows Status, Name, and DisplayName. To find whether a service starts automatically or manually, an analyst can inspect the object:

Get-Service | Get-Member

and discover the StartType property:

Property System.ServiceProcess.ServiceStartMode StartType {get;}

Then display only the relevant properties:

Get-Service | Select-Object -Property Name, Status, StartType

Key Insight

In PowerShell, the pipe (|) passes objects, not text. Get-Member interrogates the type and structure of those objects, making it the primary tool for understanding what a cmdlet can actually tell you about a target system.