
This course covers PowerShell fundamentals, execution logging options, and security features for both offensive and defensive applications in IT environments.
Course Length: 16 Hours
Includes a Certificate of Completion
Next scheduled date:
Notify me when available
Description
This course covers PowerShell fundamentals, execution logging options, and security features for both offensive and defensive applications in IT environments.
PowerShell is an excellent cross-platform shell for executing commands and scripts on both local and remote machines. It is installed on Windows by default and is widely used by both network defenders and attackers. This course will cover key PowerShell concepts that both blue and red teamers should understand including logging, credential management, remote administration, security bypass techniques and popular PowerShell attack tools.
-
System Requirements
- A computer with VMware Player/Workstation/Fusion installed
- Note: Administrative Access required for install
- You can use other virtualization platforms if you prefer but specific instructions won’t be provided
- At least 8GB RAM and 50 GB free disk space
- Lab VMs Installed as described here
- Solid internet access
Syllabus
- PowerShell Usage Fundamentals
- Profiles
- Environment Variables
- Aliases
- PowerShell Gallery
- History Files
- Encoded commands
- Help System
- Objects and Piping
- Modules and Module Load Hijacking
- Logging: Script Block, Module and Transcription
- PS Remoting
- Secure Administration Options:
- Just Enough Admin (JEA)
- Constrained Language Mode
- Antimalware Scan Interface (AMSI) Bypass
- Execution Policy Bypass
- Credential Management
- PowerShell without PowerShell
- Download Cradles
- PowerShell Core
- Popular PS Attack Tools
- Obfuscation
FAQ
Anyone interested in learning more about PowerShell and its use as both an offensive and defensive tool
About the Instructor
Carrie Roberts
"Teacher and Mentor"Bio
Carrie Roberts is a programmer, turned pentester, turned red teamer, turned blueish purple. She is currently on the Red Team at Walmart. She loves to learn and give back to the community. She is one of the primary Atomic Red Team project maintainers and developers and has developed many of her own open-source tools. She holds master’s Degrees in both Computer Science and Information Security Engineering.
Register for Upcoming
PowerShell for InfoSec: What You Need to Know
On-Demand Carrie Roberts
Attention: This is not a phish!
Antisyphon Training accounts have moved to learning.antisyphontraining.com. Training purchases will now be directed to that site. You can trust us.
Related products
-
Joff ThyerLive16 Hrs
Enterprise Attacker Emulation and C2 Implant Development
View Course -
Wade WellsLiveOD8 Hrs
Cyber Threat Intelligence 101
View Course -
Markus SchoberLive16 Hrs
Ransomware Attack Simulation and Investigation for Blue Teamers
View Course -
Multiple InstructorsLiveOD8 Hrs
Attacking and Defending AI
View Course

