To access material, start machines and answer questions login.
In this room, we'll break down how attackers weaponize and how defenders catch them. You'll see the real campaigns behind the techniques and learn how to find that abuse through event logs and forensic artifacts, even when attackers clear their tracks.
Learning Objectives
- Explain how attackers use PowerShell
- Detect PowerShell execution using logs and artifacts
- Investigate artifacts of remote PowerShell execution (PS Remoting)
- Implement controls that make PowerShell abuse harder and more detectable
Prerequisites
- Know common forensic artifacts on Windows (e.g., )
- Know how to read and interpret simple PowerShell scripts
- Preferably, complete the Script room
Answer the questions below
Let's start!
Ready to learn Cyber Security?
The Investigating PowerShell Execution room is only available for Premium or Max subscribers. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.
Already have an account? Log in

