
PowerShell security course opens with the instructor introducing the program, outlines its structure, and highlights cyber security operations center experience, cloud and on-premises security, and key Microsoft certifications.
Understand PowerShell security across architecture, operational security, and mitigations with hands-on labs, final exams, and reviews, enabling you to deploy and support Microsoft security services.
Prepare the PowerShell security lab by installing VirtualBox, importing three preconfigured virtual machines, including a 2016 domain controller, a domain member server, and a Windows 10 Pro client with RSAT.
Explore the Windows PowerShell architecture, from the runtime engine and hosting applications to run spaces, session state, and how commands, modules, and providers interact with .NET data objects.
Learn two ways to run Windows PowerShell and master key parameters like -Command, -EncodedCommand, -ExecutionPolicy, -File, and -NoExit, plus profile and obfuscation-aware session behaviors.
Learn how Windows PowerShell execution policies control local script execution, including restricted, all signed, remote signed, and bypass, with scope considerations, group policy configuration, and digital signing of scripts.
Learn how to manage remote execution in Windows PowerShell using wsman, endpoints, and session configurations. Implement remoting with certificates, mutual authentication, and multi-hop delegation using CredSSP or Kerberos constrained delegation.
Learn how constrained endpoints create constrained run spaces and session configurations to limit PowerShell commands, including startup scripts, security descriptors, and language mode for stronger defense in depth.
Explore PowerShell language modes from full to constrained and restricted, plus a new mode; learn how AppLocker and Windows Defender Device Guard enforce constrained language mode for secure scripting.
Discover the anti-malware scan interface (AMSI), a vendor-agnostic PowerShell security feature that enables file, memory, or stream scanning with IP reputation checks and session-based correlation.
Explore Windows PowerShell desired state configuration (DSC) architecture, including resources and MOF files, and learn to enforce security with push and pull modes, the LCM, and auditing.
Discover how just enough administration (jea) enables delegated, constrained management of Windows servers via session configurations and role capabilities, deployable with Windows PowerShell desired state configuration.
Explore Windows PowerShell auditing and logging, including system-wide transcription, script block logging, protected event logging, and module logging, with group policy and PowerShell methods.
Learn how Windows PowerShell based attacks unfold, from obfuscated in-memory scripts and base64 commands to code injection, reflective loading, and cross-process injection, with defender strategies in red and blue teams.
Explore Windows PowerShell-based security tools, focusing on PowerSplit and Nishank for red teaming and security testing, with features like code execution, persistence, exfiltration, and reconnaissance.
Explore defense in depth for Windows PowerShell security, comparing scripting languages and detailing logging, execution policy, remote administration, and security controls like IP filters and SSL.
In this course, we will examine the concepts of PowerShell from a security stand point. We will cover topics like PowerShell architecture, PowerShell Remoting capabilities, Desired State Configuration, Just Enough Administration and much more.
Later in the course we will examine some common Powershell-based attacks, sample payload and their mitigation/remediation.
After completing this course, you will be able to:
Understand the architecture of Powershell
Deploy Powershell operational security
Analyze PowerShell Auditing and Logging
Enhance server management with Desired State Configuration and Just Enough Administration
Analyze and debug scripts
Understand Powershell based exploits and their remediation
This course is designed to get you started as quickly as possible. There are a variety of self-paced learning activities. You will get:
Video lectures on each topic explaining each concept thoroughly with examples (and Demonstrations where applicable)
Hands-on Lab at the end of the course in which you will practice at your own pace. You will have a step by step instruction file available to complete the Lab tasks like: implementing Powershell DSC, JEA, performing PowerShell attacks and much more.
Final Exam at the end of the course - 20 questions to test your knowledge on the topics and concepts learned in the course
Links to official Microsoft resources/blogs/videos for further documentation
This course is the 3rd course from a series of 9 courses which address all aspects to become a Microsoft Cyber Security Professional . This cyber security track is designed to teach you, or fill in the knowledge gaps, all the aspects and technologies to become a successful cyber security professional. The entire track addresses mostly Microsoft security technologies, including the latest cloud services made available by Microsoft like: Microsoft Defender Suite, Office 365 security features and services, Microsoft Graph, Azure Active Directory Security and many more.
Microsoft, Windows, Microsoft 365 and Microsoft Azure are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries. This course is not certified, accredited, affiliated with, nor endorsed by Microsoft Corporation.