Common Commands
Execution policy - UAC
Variables
Variables in PowerShell are prefixed with a dollar ($) symbol and assigned by stating the variable name that is followed by an equals sign (=) and the desired value.
File Manipulation
Using the 'Get-Content' cmdlet, it is possible to read in the contents of a file, the result of which can be stored in a variable for later use or displayed on screen.
When reading in a file with Get-Content, it is possible to specify how much of the file is read. This is similar to the head and tail commands in Linux.
With the -TotalCount parameter you can specify how many lines you would like PowerShell to read (from the top, e.g. Get-Content <PATH> -TotalCount 5).
The -Tail parameter will do the same but from the bottom of the file.
In addition to reading files it is possible to write data to them, either by using Set-Content to create and overwrite files or Add-Content which can append content to an existing file.
Syntax: Set-Content -Value "This is a test" -Path ./test.txt.
Remember you can use Get-Content to read the file at any time.
File Transfer
I Module Manipulation ◇ https://docs.microsoft.com/en-gb/powershell/module/Microsoft.PowerShell.Core/Import-Module?view=powershell-6 ◇ https://docs.microsoft.com/en-gb/powershell/module/microsoft.powershell.core/get-module?view=powershell-6 ◇ https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.core/remove-module?view=powershell-6
Download files and inject them directly into memory
Antivirus will scan the disk of your target regularly and block any files that you download on to it, if they are flagged as a virus. You can Bypass this by invoking a powershell command call to pull a remote file directly into memory
IEX - pull directly into memory
Net.WebClient - Needed to run the DownloadString function
EventLog
PowerShell comes with a cmdlet that allows you to query event logs from the command line. By default, it will query the local machine; however, it can also be used to query logs from remote connections. It has several options that can be used to filter the query and, similar to most PowerShell, the output can be piped to other filters like search and output.
Last updated