Defensive PowerShell - Log Parsing

No ratings

Presented at Texas Cyber Summit 2023 by

NEEDED: A virtualized Windows 10 on your host machine. It is recommended that your host machine be a Windows machine. If you show up with a Mac or Linux, we will set up PowerShell Remoting over SSH instead of PowerShell v7 Remoting. That will be the only difference; everything else will be the same. This is a portion of my all-day immersive Defensive PowerShell workshop. This portion has more hands-on learning activities. We will use PowerShell Remoting techniques to "Reach out" and parse Windows Event logs. I will cover how to use a custom PowerShell Remoting configuration to make sure you are logging in with PowerShell v7 instead of v5. We cover multiple ways to query the logs, like filterhashtable and xml. We also talk about various ways to query on text in the message block of the log.