Skip to main content

Investigating PowerShell Execution

Learn which forensic artifacts PowerShell leaves on a compromised system.

Back to all walkthroughs
Room Icon

Investigating PowerShell Execution

Max room.

Learn which forensic artifacts PowerShell leaves on a compromised system.

medium

60 min

80

User profile photo.
User profile photo.
User profile photo.

To access material, start machines and answer questions login.

In this room, we'll break down how attackers weaponize and how defenders catch them. You'll see the real campaigns behind the techniques and learn how to find that abuse through event logs and forensic artifacts, even when attackers clear their tracks.

Learning Objectives

  • Explain how attackers use PowerShell
  • Detect PowerShell execution using logs and artifacts
  • Investigate artifacts of remote PowerShell execution (PS Remoting)
  • Implement controls that make PowerShell abuse harder and more detectable

Prerequisites

  • Know common forensic artifacts on Windows (e.g., )
  • Know how to read and interpret simple PowerShell scripts
  • Preferably, complete the Script room
Answer the questions below

Let's start!