PowerShell Function Basics and Recursion
## Defining a Function ```powershell function Get-Factorial { param([int]$n) if ($n -le 1) { return 1 } return $n * (Get-Factorial -n ($n - 1)) } Get-Factorial -n 5 …
19 published notes
## Defining a Function ```powershell function Get-Factorial { param([int]$n) if ($n -le 1) { return 1 } return $n * (Get-Factorial -n ($n - 1)) } Get-Factorial -n 5 …
# PowerShell as an Acquisition Engine PowerShell is described in Hosmer's book as a powerful **acquisition engine** for digital investigations. Its role is to gather raw informat…
# PowerShell Cross-Platform PowerShell was originally **Windows-only** because it was built on the .NET Framework. In 2016, Microsoft open-sourced PowerShell and rebuilt it on .N…
PowerShell is typically preinstalled on modern Windows desktop and server platforms. If it is not present, you can download and install it by searching for **Windows Management Fr…
PowerShell ISE (Integrated Scripting Environment) is a free Windows application that provides a workspace for experimenting with and writing [[PowerShell CmdLets]] and scripts. It…
# Investigative Event Log Discovery Strategy When you need to find events in Windows but do not yet know the exact log, event ID, or provider, follow a repeatable discovery proce…
# PowerShell Get-Help Parameter Discovery Use `Get-Help` with the `-Parameter` switch to learn about a specific parameter of a CmdLet. ```powershell Get-Help Get-ChildItem -Para…
PowerShell is built around **objects** rather than plain text. CmdLets like `Get-Process` return objects with **properties** (data) and **methods** (actions). Objects make it easy…
`Select-Object` is a PowerShell CmdLet that selects or shapes the properties of objects coming through the pipeline. It is commonly used to limit output, pick specific properties,…
`ForEach-Object` is a PowerShell CmdLet that processes each object coming through the pipeline one at a time. It is the standard way to run a script block against every item in a …
PowerShell provides built-in **EventLog cmdlets** for collecting and inspecting Windows event logs. The most commonly used cmdlet is **Get-EventLog**, which retrieves events from …
PowerShell can instantiate and inspect .NET objects directly. The [[Get-Member CmdLet]] is central to this, as covered in [[Experimenting with PowerShell]]. A practical discovery …
This section introduces three PowerShell CmdLets used to examine network settings on a Windows system. Unlike the legacy Windows Command Line, PowerShell exposes network configura…
# Baseline in Digital Forensics A **baseline** is a captured snapshot of a system's normal state under known-good conditions. It records what processes, services, network connect…
A **Service Filter** in Windows Firewall with Advanced Security is a rule property that limits a firewall rule to traffic associated with a specific Windows service. Instead of ap…
# Get-Member CmdLet `Get-Member` is a PowerShell discovery CmdLet that reveals the **members** (properties, methods, events, and other object attributes) of any object piped into…
# Designing Python Scripts for Automation and Pipelines A script is rarely the final destination. In pentest, forensics, and reverse engineering work, Python tools usually feed o…
# PowerShell + Python Acquisition Pipeline A practical exercise pattern from the book's philosophy: use **PowerShell** for acquiring raw data from Windows systems and **Python** …
PowerShell provides several ways to replace strings inside files using the standard **verb-noun** [[CmdLet]] pairs `Get-Content` and `Set-Content`, plus the `-replace` operator. …