PowerShell Function Basics and Recursion

## Defining a Function ```powershell function Get-Factorial { param([int]$n) if ($n -le 1) { return 1 } return $n * (Get-Factorial -n ($n - 1)) } Get-Factorial -n 5 …

PowerShell as an Acquisition Engine

# PowerShell as an Acquisition Engine PowerShell is described in Hosmer's book as a powerful **acquisition engine** for digital investigations. Its role is to gather raw informat…

PowerShell Cross-Platform

# PowerShell Cross-Platform PowerShell was originally **Windows-only** because it was built on the .NET Framework. In 2016, Microsoft open-sourced PowerShell and rebuilt it on .N…

Experimenting with PowerShell

PowerShell is typically preinstalled on modern Windows desktop and server platforms. If it is not present, you can download and install it by searching for **Windows Management Fr…

PowerShell ISE Panels

PowerShell ISE (Integrated Scripting Environment) is a free Windows application that provides a workspace for experimenting with and writing [[PowerShell CmdLets]] and scripts. It…

Investigative Event Log Discovery Strategy

# Investigative Event Log Discovery Strategy When you need to find events in Windows but do not yet know the exact log, event ID, or provider, follow a repeatable discovery proce…

PowerShell Get-Help Parameter Discovery

# PowerShell Get-Help Parameter Discovery Use `Get-Help` with the `-Parameter` switch to learn about a specific parameter of a CmdLet. ```powershell Get-Help Get-ChildItem -Para…

PowerShell Custom Objects

PowerShell is built around **objects** rather than plain text. CmdLets like `Get-Process` return objects with **properties** (data) and **methods** (actions). Objects make it easy…

Select-Object

`Select-Object` is a PowerShell CmdLet that selects or shapes the properties of objects coming through the pipeline. It is commonly used to limit output, pick specific properties,…

PowerShell ForEach-Object CmdLet

`ForEach-Object` is a PowerShell CmdLet that processes each object coming through the pipeline one at a time. It is the standard way to run a script block against every item in a …

PowerShell EventLog CmdLets

PowerShell provides built-in **EventLog cmdlets** for collecting and inspecting Windows event logs. The most commonly used cmdlet is **Get-EventLog**, which retrieves events from …

Inspecting .NET Classes from PowerShell

PowerShell can instantiate and inspect .NET objects directly. The [[Get-Member CmdLet]] is central to this, as covered in [[Experimenting with PowerShell]]. A practical discovery …

PowerShell Network Configuration CmdLets

This section introduces three PowerShell CmdLets used to examine network settings on a Windows system. Unlike the legacy Windows Command Line, PowerShell exposes network configura…

Baseline in Digital Forensics

# Baseline in Digital Forensics A **baseline** is a captured snapshot of a system's normal state under known-good conditions. It records what processes, services, network connect…

Firewall Service Filter

A **Service Filter** in Windows Firewall with Advanced Security is a rule property that limits a firewall rule to traffic associated with a specific Windows service. Instead of ap…

Get-Member CmdLet

# Get-Member CmdLet `Get-Member` is a PowerShell discovery CmdLet that reveals the **members** (properties, methods, events, and other object attributes) of any object piped into…

PowerShell + Python Acquisition Pipeline

# PowerShell + Python Acquisition Pipeline A practical exercise pattern from the book's philosophy: use **PowerShell** for acquiring raw data from Windows systems and **Python** …

PowerShell Replace String in File

PowerShell provides several ways to replace strings inside files using the standard **verb-noun** [[CmdLet]] pairs `Get-Content` and `Set-Content`, plus the `-replace` operator. …