> For the complete documentation index, see [llms.txt](https://dhaneshsivasamy07.gitbook.io/oscp-2022/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://dhaneshsivasamy07.gitbook.io/oscp-2022/windows-post-exploitation/notes/powershell.md).

# Powershell

> Basic notes for powershell and its explanations

{% hint style="info" %}
In Powershell, ***`Get-Help, Get-Command, Get-Alias`*** are the most handful commands to ever exist
{% endhint %}

{% tabs %}
{% tab title="Get-Alias" %}
Aliases are the shorthand notes for the commandlets, it lets to identify the correct commandlet of the specified alias&#x20;

```bash
Get-Alias iwr
```

{% endtab %}

{% tab title="Get-Help" %}
Provides help of the specified commandlet, if `-Examples` is specified the usage examples are also provided

```bash
Get-Help Get-ChildItem
Get-Help Get-ChildItem -Examples
```

{% endtab %}

{% tab title="Get-Command" %}
Lists the available commandlets with the sepecified noun and verb

```bash
Get-Command "Get-*"
Get-Command "*-Service"
```

{% endtab %}
{% endtabs %}

* Know the propeties of a command

```bash
Get-NetTCPConnection | Get-Member
```

* Reference

```bash
$_ --> refers to the element which is piped
```

* Referncing with conditions

```bash
# ? --> alias to where 
# $_ --> refers to the ouptut of the Get-NetTCPConenction
# LocalAddress --> an members of the Get-NetTCPConnection cmdlet
Get-NetTCPConnection | ? {$_.LocalAddress -eq "127.0.0.1"}
Get-NetTCPConnection | Where-Object {$_.LocalAddress -eq "127.0.0.1"}
```

* Only select contents whose contents are not empty

```bash
# $null --> value of the emptry string in powershell
Get-Process | ? {$_.Path -ne $null } | Select-Object path
```

* Head / tail in powershell

```bash
# head
Get-Process | Get-Member | Select-Object -First 10
# tail
Get-Process | Get-Member | Select-Object -last 10
```

* The `gettype()` is used to identify the output type from a command
* Based on the type of output, we can query it accordingly

```bash
(whoami).gettype()
(ls).gettype()
```

* Once the type is identified, the parameters that support the ouptut of the commandlet can be identified with `Get-Member`

```bash
whoami | Get-Member
```

* The methods and properties of the specified commandlet can be accessed with `().` operator

```bash
# accessing property
(whoami).length

# accessing mehtod
(whoami).ToUpper()
```

* The commands can be nested or can be used as a subset with the ()
* The `Format-Table, Format-List, Format-Custom` are common ways to show an output

```bash
(New-Object -com "Microsoft.Update.AutoUpdate").Results | Format-List
```

* The `2>/dev/null` equivalent of powershell is `-ErrorAction`

```bash
Get-ChildItem -ErrorAction 'SilentlyContinue'
```

* `ls -la` of powershell `Get-ChildItem -Force`
