Opleiding: Masterclass: PowerShell for Digital Investigation & Threat Hunting [PST]

OVERVIEW

This advanced course equips cybersecurity professionals with the skills to detect, investigate, and respond to modern threats using native Windows tools and PowerShell. With a strong focus on real-world attacker behaviors, participants will learn to identify Advanced Persistent Threats (APTs), analyze attack timelines, and uncover hidden or deleted artifacts using forensic techniques.

PowerShell is used throughout the course as both a defensive and investigative tool, supporting artifact collection, process and network analysis, registry inspection, and script-based detection. Participants will explore common attacker techniques such as living-off-the-land binaries (LOLBins), scheduled tasks, and encoded payloads, and learn how to detect and counter them through logging, event analysis, and behavioral detection rules.

Virtual Learning

This interactive training can be taken from any location, your office or home and is delivered by a trainer. This training does not have any delegates in the class with the instructor, since all delegates are virtually connected. Virtual delegates do not travel to this course, Global Knowledge will send you all the information needed before the start of the course and you can test the logins.

OBJECTIVES

  • Investigate advanced persistent threats (APTs) using PowerShell and native Windows tools.
  • Perform digital forensics and artifact collection for incident investigations.
  • Analyze process, network, and registry artifacts to identify malicious activity.
  • Implement PowerShell logging, detection, and threat hunting techniques.
  • Conduct Active Directory enumeration and investigate fileless attacks.
  • Apply real-world threat hunting and incident response techniques through hands-on exercises.

AUDIENCE

This course is designed for security professionals across offensive, defensive, and hybrid roles. Analysts, hunters, SOC teams, and incident responders will learn to enhance investigations with AI-driven workflows. Red and purple teamers will strengthen adversary emulation and detection validation, while engineers and developers gain hands-on experience building AI-powered tools, pipelines, and multi-agent systems. Security leaders and architects will benefit from practical insights into securing AI systems and addressing emerging vulnerabilities.

CERTIFICATION

  • After completing the course, participants will receive a CQURE Certificate of Completion and will also be eligible for CPE points.

CONTENT

Module 1: APT Attacks & Investigation
Module 2: PowerShell 101 for Blue Teams
Module 3: Understanding Information Gathering and Timelining
Module 4: PowerShell for Digital Forensics & Artifact Collection
Module 5: Process & Network Artifact Collection
Module 6: PowerShell Logging & Detection
Module 7: Threat Hunting with WMI & Scheduled Tasks
Module 8: PowerShell for Enterprise
Module 9: Hands-On Threat Hunting Case Study
Module 10: Active Directory Enumeration with PowerShell
Module 11: Red Teaming Tactics with PowerShell
Module 12: Complete Fileless Attack Analysis Walkthrough

Meer...
€3.000
ex. BTW
Aangeboden door
Global Knowledge Network Netherlands B.V.
Onderwerp
Threat intelligence
Microsoft Windows PowerShell
Niveau
Looptijd
4 dagen
Taal
nl
Type product
cursus
Lesvorm
Klassikaal
Aantal deelnemers
Max: 16
Tijdstip
Overdag
Tijden en locaties
CQure Virtual English
di 13 okt. 2026
CQure Virtual English
di 8 dec. 2026
Keurmerken aanbieder
Cedeo
CRKBO en BTW-vrijstelling
VOI
EXIN
ISO register
Microsoft Learning Partner
VMWare Partner
Oracle Education Partner
AgilePM - Agile Project Management (APMG)
ASL