#BSidesCLEVO PowerShell Copyright (C) 2014 ClevelandBSides. PowerShell: Drink the Kool-Aid.

Slides:



Advertisements
Similar presentations
Presentation: 20 minutes
Advertisements

SharePoint 2007 Operations Module 1: Introduction.
02 | Managing Users, Groups, and Licenses Anthony Steven | Principal Technologist, Content Master Martin Coetzer | Portfolio Architect, Microsoft.
By Aaron Nelson I blog at SCVMM This!. Why Virtualize Four components make virtualization very compelling. * (to me) Live Migration – If you need to switch.
Daniel Petri MVP, Microsoft Infrastructure Manager John Bryce Training November 2007.
Welcome Course 20410B Module 0: Introduction Audience
Module 8 Implementing Backup and Recovery. Module Overview Planning Backup and Recovery Backing Up Exchange Server 2010 Restoring Exchange Server 2010.
PowerShell: Drink the Kool-Aid!. Who we are…..Who we are…..
#BSidesCMH PowerShell Copyright (C) 2014 ColumbusBSides. PowerShell: Drink the Kool-Aid.
Windows Server 2012 Certification and Training June 2012.
Ch 11 Managing System Reliability and Availability 1.
Module 1: Installing Internet Information Services 5.0.
Christopher Chapman | MCT Content PM, Microsoft Learning, PDG Planning, Microsoft.
Deploying and Managing Windows Server 2012
© 2007 Asynchrony Solutions, Inc. 1 10/29/07 Introduction to PowerShell Brian Button VP Engineering Asynchrony Solutions, Inc
Course 2072: Administering a Microsoft SQL Server 2000 Database.
9/10/20151 Hyperion Enterprise 6.5 New Features & Functionality Robert Cybulski, CPA Finit Solutions.
SharePoint 2010 Development Environment A Guide to Setup SharePoint 2010 Development Environment on Windows 7 Machine.
PowerShell Basics. o PowerShell is a great way to manipulate server and/or workstation components o It’s geared toward system administrators by creating.
Course 10135A Configuring, Managing, and Troubleshooting Microsoft® Exchange Server 2010.
20411B 8: Installing, Configuring, and Troubleshooting the Network Policy Server Role Presentation: 60 minutes Lab: 60 minutes After completing this module,
Module 11: Remote Access Fundamentals
Module 9: Preparing to Administer a Server. Overview Introduction to Administering a Server Configuring Remote Desktop to Administer a Server Managing.
20411B Administering Windows Server® B
December, 21, 2010 Bartek Bielawski Sr IT Site Services Specialist Warsaw, Poland.
Learningcomputer.com SQL Server 2008 – Administration, Maintenance and Job Automation.
Good Morning and Thank You!.  Have some Fun!  Learn at least one thing new!  Make myself available to you So please …  Ask questions and enjoy!
Module 3: Preparing for and Recovering from Non- Mailbox Server Failures.
Module 1: Configuring Windows Server Module Overview Describe Windows Server 2008 roles Describe Windows Server 2008 features Describe Windows Server.
A Networked Machine Management System 16, 1999.
Visit our Focus Rooms Evaluation of Implementation Proposals by Dynamics AX R&D Solution Architecture & Industry Experts Gain further insights on Dynamics.
Managing System Center 2012 Configuration Manager with Windows PowerShell MEMUG August 23 rd 2013.
PowerShell and SQL Server References. References - PowerShell  Windows PowerShell In Action Second Edition, Bruce Payette, Manning  Windows PowerShell.
Master Data Management & Microsoft Master Data Services Presented By: Jeff Prom Data Architect MCTS - Business Intelligence (2008), Admin (2008), Developer.
Course 6292A Installing and Configuring Windows® 7 Client.
Windows 7 Deployment Mark French
Configuring, Managing and Maintaining Windows Server® 2008 Servers Course 6419A.
Hyperion Artifact Life Cycle Management Agenda  Overview  Demo  Tips & Tricks  Takeaways  Queries.
POWERSHELL ABOVE AND BEYOND: GUIS, WORKFLOWS, AND MORE Dean Corcoran Partner Service Account Manager (Cloud) – MCT – MCITP:EA Microsoft Australia SESSION.
Microsoft Virtual Academy Module 12 Managing Services with VMM and App Controller.
Master Expert Associat e Microsoft Certified Solutions Master (MCSM) Microsoft Certified Solutions Expert (MCSE) Microsoft Certified Solutions Associate.
Windows Certification Paths OR MCSA Windows Server 2012 Installing and Configuring Windows Server 2012 Exam (20410) Administering Windows Server.
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. 1 Windows Server 2012.
Managing Office 365 Identities and Requirements.
C Copyright © 2006, Oracle. All rights reserved. Oracle Secure Backup Additional Installation Topics.
Windows Server 2012 Certification and Training
MCSA Windows Server 2012 Pass Upgrading Your Skills to MCSA Windows Server 2012 Exam By The Help Of Exams4Sure Get Complete File From
Exam : Upgrading Your Skills to MCSA: Windows Server 2016
Module 9: Preparing to Administer a Server
Exam In The First Attempt?
Supporting Windows 8.1 Krystle Portocarrero | Training Experts Inc.
Using Microsoft Identity Manger with SharePoint 2016 to fill the User Profile Sync Gap Max Fritz Senior Systems Consultant Now Micro.
How to pass Microsoft exam in first attempt?
MrCerts Practice Test
VCE Questions Dumps
Configuration Management with Azure Automation DSC
20341B Core Solutions of Microsoft® Exchange Server 2013.
Microsoft Dumps - Microsoft Question Answer - Realexamdumps.com
Prepare 1Y Question Answers - 1Y Exam Dumps - Dumps4Download
Pass Microsoft Exam in First Attempt | Dumps4download.us
Windows PowerShell Remoting: Definitely NOT Just for Servers
Configuring, Managing and Maintaining Windows Server® 2008 Servers Course 6419A.
Managing Services with VMM and App Controller
Overview of Client Configuration
Windows Active Directory Environment
Module 9: Preparing to Administer a Server
Automated Testing Strategies and Dynamics 365 Performance Management
Windows without windows...
Microsoft 365 Business Technical Fundamentals Series
Topics Today Capability Efficiency Troubleshooting
Presentation transcript:

#BSidesCLEVO PowerShell Copyright (C) 2014 ClevelandBSides. PowerShell: Drink the Kool-Aid

AGENDA SA Vs SA Why PowerShell PowerShell Overview Why you should care Brief description System Administration Incident Response Compliance Module #BSidesCLEVO PowerShell Copyright (C) 2014 ClevelandBSides.

PS C:\>Get-Content –ne Presentation Not intended to make you a programmer Not a deep-dive Will Not make you an expert We are not affiliated with any sweet rich vendors

PS C:\>Get-Content HardbitSolutions Wayne Pruitt 85%Mountaindew,15%Brain The Lead Geek of the Hardbit Solutions team MCAD, MCSD, MCDBA, C|EH, E|CSA, C|HFI, E|CSP, E|DRP, E|CIH and E|CEI. Over the past 12 years he has held many jobs supporting a variety of roles within the Federal Government ranks; ranging from system administrator, security administrator, developer and several IT manager roles. Zack Wojton 87%Beer,2%CrownRoyal,11%Hair CTO of the Hardbit Solutions team Masters of Science in Information Technology | Security, MCSA, ICND, G2700, C|EH, E|CSA, and C|HFI certifications A night owl, that believes in life-long learning. Has over a decade of IT security under his belt, held more IT related jobs than they have certifications for, and believes security is where it all comes together. Masters is so almost over. #BSidesCLEVO PowerShell Copyright (C) 2014 ClevelandBSides.

PS C:\>SA-Vs-SA Sure we have things wrong with our industry (but that is why it rocks!) Secure Administrator Mentoring Crossing the streams

PS C:\>Why-PowerShell Scripting powers for all Make reusable tools

PS C:\>Get-Caring PowerShell is native PowerShell can save you time PowerShell can save you $ PowerShell can do remote administration PowerShell can be controlled through policy Can be immediately effective

PS C:\>Get-Started No book necessary (there are some sweet ones) Verb-Noun Get-Help / Man Get-Command Get-Help About_*

PS C:\> Get-Process Handles NPM(K) PM(K) WS(K) VM(M) CPU(s) Id ProcessName AcroRd AcroRd32 _________________________________ PS C:\> Get-Process | sort-object –property VM -descending Handles NPM(K) PM(K) WS(K) VM(M) CPU(s) Id ProcessName OUTLOOK powershell _________________________________ PS C:\> Get-Process | sort-object –property VM –descending | select- object –first 10 –property company, Name, ID, Path | fl Company : Microsoft Corporation Name : OUTLOOK Id : 8920 Path : C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE DEMO

PS C:\>PowerShell Administrators Get-Hotfix Account Info / Management System Inventory / Management Log Review (Failed Logons)

PS C:\>PowerShell IR / Analysis Gather restore points Gather File Information Gather NIC Modes Gather File MRU List

PS C:\>PowerShell Compliance Is machine part of a domain? Gather Server Roles Gather Local Groups Gather Members of Local Admin Group Answer “are security updates installed on a regular basis?”

PS C:\>PowerShell Module Sweetness Get-MachineInfo Get-Uptime Get-RebootTime Get-PageFile Get-PendingReboot Get-InstalledSoftware Get-USBDevice

PS C:\>Get-Questions Any Questions?

CHEERS!

Resources: Hardbit Solutions: PowerShellCommunity.Org: Many excellent books: Manning Press book by PowerShell Dev Lead Bruce Payette: PowerShell in Action O’Reilly book by PowerShell Dev Lee Holmes – Windows PowerShell Cookbook