<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wikicyber.org/index.php?action=history&amp;feed=atom&amp;title=Draft%3APowerShell_for_Intermediate_Users</id>
	<title>Draft:PowerShell for Intermediate Users - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wikicyber.org/index.php?action=history&amp;feed=atom&amp;title=Draft%3APowerShell_for_Intermediate_Users"/>
	<link rel="alternate" type="text/html" href="https://wikicyber.org/index.php?title=Draft:PowerShell_for_Intermediate_Users&amp;action=history"/>
	<updated>2026-09-24T04:42:36Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.46.0</generator>
	<entry>
		<id>https://wikicyber.org/index.php?title=Draft:PowerShell_for_Intermediate_Users&amp;diff=186&amp;oldid=prev</id>
		<title>MigrationBot: Backfill (v3.0 review queue): added to the review queue</title>
		<link rel="alternate" type="text/html" href="https://wikicyber.org/index.php?title=Draft:PowerShell_for_Intermediate_Users&amp;diff=186&amp;oldid=prev"/>
		<updated>2026-09-22T05:42:50Z</updated>

		<summary type="html">&lt;p&gt;Backfill (v3.0 review queue): added to the review queue&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw-interface=&quot;&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 05:42, 22 September 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l220&quot;&gt;Line 220:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 220:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Windows PowerShell|010]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Windows PowerShell|010]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Migrated from cypat.guide]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Migrated from cypat.guide]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[Category:Pending review]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key wikicyber:diff:1.41:old-106:rev-186:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>MigrationBot</name></author>
	</entry>
	<entry>
		<id>https://wikicyber.org/index.php?title=Draft:PowerShell_for_Intermediate_Users&amp;diff=106&amp;oldid=prev</id>
		<title>MigrationBot: Import from cypat.guide: docs/windows/scripting/intermediate_powershell.md</title>
		<link rel="alternate" type="text/html" href="https://wikicyber.org/index.php?title=Draft:PowerShell_for_Intermediate_Users&amp;diff=106&amp;oldid=prev"/>
		<updated>2026-09-18T17:06:36Z</updated>

		<summary type="html">&lt;p&gt;Import from cypat.guide: docs/windows/scripting/intermediate_powershell.md&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Submit}}&lt;br /&gt;
&amp;lt;!-- Migrated from https://cypat.guide/docs/windows/scripting/intermediate_powershell (source: docs/windows/scripting/intermediate_powershell.md) --&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Author(s):&amp;#039;&amp;#039;&amp;#039; Byrch&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Last Updated:&amp;#039;&amp;#039;&amp;#039; 2025‑07‑30&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Recommended Prerequisites:&amp;#039;&amp;#039;&amp;#039; None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;blockquote&amp;gt;This content was written with the intermediate audience in mind. For the experienced Powershell users in the community its important to emphasize that all scripts should be tested in a safe environment before being run in production. Additionally, development of scripts should following best practices and modularity to ensure maintainability and reusability despite what environment might be thrown at it.&lt;br /&gt;
&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-----&lt;br /&gt;
&lt;br /&gt;
== Learning objectives ==&lt;br /&gt;
&lt;br /&gt;
By the end, learners should be able to:&lt;br /&gt;
&lt;br /&gt;
* Write reusable &amp;#039;&amp;#039;&amp;#039;functions&amp;#039;&amp;#039;&amp;#039; and bundle them into &amp;#039;&amp;#039;&amp;#039;modules&amp;#039;&amp;#039;&amp;#039; with help/validation.&lt;br /&gt;
* Inspect and control &amp;#039;&amp;#039;&amp;#039;Windows services&amp;#039;&amp;#039;&amp;#039; and &amp;#039;&amp;#039;&amp;#039;processes&amp;#039;&amp;#039;&amp;#039; safely.&lt;br /&gt;
* Make targeted, reversible &amp;#039;&amp;#039;&amp;#039;registry&amp;#039;&amp;#039;&amp;#039; changes.&lt;br /&gt;
* Manage &amp;#039;&amp;#039;&amp;#039;local users, groups, and permissions&amp;#039;&amp;#039;&amp;#039; with audit trails.&lt;br /&gt;
* Build &amp;amp;quot;&amp;#039;&amp;#039;&amp;#039;automation&amp;#039;&amp;#039;&amp;#039;&amp;amp;quot; that logs actions and supports Powershell best practices.&lt;br /&gt;
&lt;br /&gt;
-----&lt;br /&gt;
&lt;br /&gt;
== 1) Functions &amp;amp;amp; modules ==&lt;br /&gt;
&lt;br /&gt;
=== Minimal, production‑ish function ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;powershell&amp;quot;&amp;gt;&lt;br /&gt;
# Powershell functions follow a verb-noun naming convention, with only a few verbs approved for use.&lt;br /&gt;
&lt;br /&gt;
function Set-StartupType {&lt;br /&gt;
&lt;br /&gt;
    # Parameter validation and support for -WhatIf and -Confirm&lt;br /&gt;
    # CmdletBinding attribute enables advanced function features (and pipeline support)&lt;br /&gt;
    [CmdletBinding(SupportsShouldProcess, ConfirmImpact=&amp;#039;Medium&amp;#039;)]&lt;br /&gt;
    param(&lt;br /&gt;
        [Parameter(Mandatory, ValueFromPipelineByPropertyName)]&lt;br /&gt;
        [ValidateSet(&amp;#039;Automatic&amp;#039;,&amp;#039;Manual&amp;#039;,&amp;#039;Disabled&amp;#039;)]&lt;br /&gt;
        [string]$StartupType,&lt;br /&gt;
&lt;br /&gt;
        [Parameter(Mandatory, ValueFromPipeline, ValueFromPipelineByPropertyName)]&lt;br /&gt;
        [Alias(&amp;#039;Name&amp;#039;)]&lt;br /&gt;
        [string[]]$ServiceName&lt;br /&gt;
    )&lt;br /&gt;
&lt;br /&gt;
    # Function body should follow a begin, process, end pattern for structure and organization.&lt;br /&gt;
    begin { }&lt;br /&gt;
    process {&lt;br /&gt;
        foreach ($svc in $ServiceName) {&lt;br /&gt;
            if ($PSCmdlet.ShouldProcess(&amp;quot;service &amp;#039;$svc&amp;#039;&amp;quot;, &amp;quot;set startup to $StartupType&amp;quot;)) {&lt;br /&gt;
                try {&lt;br /&gt;
                    Set-Service -Name $svc -StartupType $StartupType -ErrorAction Stop&lt;br /&gt;
                }&lt;br /&gt;
                catch { Write-Error &amp;quot;Failed to set $svc: $_&amp;quot; }&lt;br /&gt;
            }&lt;br /&gt;
        }&lt;br /&gt;
    }&lt;br /&gt;
}&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
=== Turning functions into a module ===&lt;br /&gt;
&lt;br /&gt;
* Create a folder named for your module or script. Below is a simple structure for a module named &amp;lt;code&amp;gt;MyTeam.SecurityTools&amp;lt;/code&amp;gt;. Such structure is the gold standard for modular and reusable Powershell code. (It also makes readability and maintenance easier :)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;MyTeam.SecurityTools\&lt;br /&gt;
  MyTeam.SecurityTools.psd1   # module manifest (version, author, tags)&lt;br /&gt;
  MyTeam.SecurityTools.psm1   # exported functions&lt;br /&gt;
  Private\*.ps1               # helpers&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
* Export with &amp;lt;code&amp;gt;Export-ModuleMember&amp;lt;/code&amp;gt;.&lt;br /&gt;
* Version your manifest; keep functions idempotent and &amp;lt;code&amp;gt;-WhatIf&amp;lt;/code&amp;gt; friendly.&lt;br /&gt;
&lt;br /&gt;
-----&lt;br /&gt;
&lt;br /&gt;
== 2) Working with services &amp;amp;amp; processes ==&lt;br /&gt;
&lt;br /&gt;
=== Example of an auditing of services ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;powershell&amp;quot;&amp;gt;$knownGood = &amp;#039;wuauserv&amp;#039;,&amp;#039;BITS&amp;#039;,&amp;#039;WinDefend&amp;#039;,&amp;#039;LanmanWorkstation&amp;#039;,&amp;#039;LanmanServer&amp;#039;,&amp;#039;Dhcp&amp;#039;,&amp;#039;Dnscache&amp;#039;&lt;br /&gt;
Get-Service | Select-Object Name, Status, StartType | Sort-Object Name |&lt;br /&gt;
    Tee-Object -FilePath &amp;quot;$env:USERPROFILE\Desktop\services-audit.csv&amp;quot; | Out-Host&lt;br /&gt;
# Keeping a CSV of current services is a great way to baseline and track changes over time. Additionally, it can be useful for troubleshooting unexpected errors or behaviors.&lt;br /&gt;
&lt;br /&gt;
# Highlight non-standard auto services&lt;br /&gt;
Get-Service | Where-Object { $_.StartType -eq &amp;#039;Automatic&amp;#039; -and $_.Name -notin $knownGood } |&lt;br /&gt;
    Select Name,DisplayName,Status | Format-Table -AutoSize&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
=== Safe scripting tips ===&lt;br /&gt;
&lt;br /&gt;
* Prefer &amp;lt;code&amp;gt;Set-Service -StartupType Manual&amp;lt;/code&amp;gt; over disabling until you confirm necessity.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;powershell&amp;quot;&amp;gt;$baseline = @{ &amp;#039;Workstation&amp;#039; = @(&amp;#039;WinDefend&amp;#039;,&amp;#039;wuauserv&amp;#039;,&amp;#039;BITS&amp;#039;); }&lt;br /&gt;
$expected = $baseline.Workstation&lt;br /&gt;
Get-Service | Where-Object Name -notin $expected | Export-Csv baseline-delta.csv -NoTypeInformation&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-----&lt;br /&gt;
&lt;br /&gt;
== 3) Registry edits (reversible and targeted) ==&lt;br /&gt;
&lt;br /&gt;
=== Always: export before you change ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;powershell&amp;quot;&amp;gt;$stamp = Get-Date -Format &amp;#039;yyyyMMdd-HHmmss&amp;#039;&lt;br /&gt;
reg.exe export HKLM\SOFTWARE &amp;quot;HKLM_SOFTWARE_$stamp.reg&amp;quot; /y | Out-Null&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
=== Common, defensible tweaks ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;powershell&amp;quot;&amp;gt;# Show file extensions (reduces double-extension tricks)&lt;br /&gt;
Set-ItemProperty -Path &amp;#039;HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced&amp;#039; -Name HideFileExt -Value 0&lt;br /&gt;
&lt;br /&gt;
# Disable Guest if present&lt;br /&gt;
Get-LocalUser -Name &amp;#039;Guest&amp;#039; -ErrorAction SilentlyContinue | ForEach-Object {&lt;br /&gt;
    Disable-LocalUser -Name $_.Name&lt;br /&gt;
}&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&amp;lt;blockquote&amp;gt;Keep a small revert script (or robust change log) alongside your changes.&lt;br /&gt;
&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-----&lt;br /&gt;
&lt;br /&gt;
== 4) Permissions &amp;amp;amp; Users ==&lt;br /&gt;
&lt;br /&gt;
=== Local accounts &amp;amp;amp; groups ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;powershell&amp;quot;&amp;gt;# Create a standard user&lt;br /&gt;
$u = &amp;#039;ExampleTestUser&amp;#039;&lt;br /&gt;
if (-not (Get-LocalUser -Name $u -ErrorAction SilentlyContinue)) {&lt;br /&gt;
    $pw = Read-Host -AsSecureString &amp;quot;Enter password for $u&amp;quot;&lt;br /&gt;
    New-LocalUser -Name $u -Password $pw -AccountNeverExpires:$true -FullName &amp;#039;Student Standard&amp;#039;&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
# Add new user to group&lt;br /&gt;
Add-LocalGroupMember -Group &amp;#039;Users&amp;#039; -Member $u -ErrorAction SilentlyContinue&lt;br /&gt;
&lt;br /&gt;
# Review admins&lt;br /&gt;
$approvedAdmins = @(&amp;#039;Administrator&amp;#039;,&amp;#039;SusAdmin&amp;#039;)&lt;br /&gt;
(Get-LocalGroupMember &amp;#039;Administrators&amp;#039;).Name |&lt;br /&gt;
  Where-Object { $_ -notin $approvedAdmins } |&lt;br /&gt;
  ForEach-Object { Write-Output &amp;quot;Review admin member: $_&amp;quot; }&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
=== NTFS ACLs ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;powershell&amp;quot;&amp;gt;$path = &amp;#039;C:\Shared&amp;#039;&lt;br /&gt;
if (-not (Test-Path $path)) { New-Item -ItemType Directory -Path $path | Out-Null }&lt;br /&gt;
$acl = Get-Acl $path&lt;br /&gt;
$rule = New-Object System.Security.AccessControl.FileSystemAccessRule(&amp;#039;Users&amp;#039;,&amp;#039;Modify&amp;#039;,&amp;#039;ContainerInherit,ObjectInherit&amp;#039;,&amp;#039;None&amp;#039;,&amp;#039;Allow&amp;#039;)&lt;br /&gt;
$acl.SetAccessRule($rule)&lt;br /&gt;
Set-Acl -Path $path -AclObject $acl&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
==== - It is important to note that some cmdlets used in this section may require recent versions of Windows Powershell (or Powershell Core). ====&lt;br /&gt;
&lt;br /&gt;
==== - Please ensure the support of these commandlets in your environment before using them. (i.e. Get-LocalUser, Get-LocalGroupMember, Add-LocalGroupMember will not work in Microsoft Windows 7 Powershell) ====&lt;br /&gt;
&lt;br /&gt;
-----&lt;br /&gt;
&lt;br /&gt;
== 5) Now that we have the scripting basics down, let&amp;#039;s look at what more we can do with Powershell. Take a look at all these cmdlets! ==&lt;br /&gt;
&lt;br /&gt;
= Management Module =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;powershell&amp;quot;&amp;gt;Get-Command -Module Microsoft.PowerShell.Management | Out-GridView&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
= Users =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;powershell&amp;quot;&amp;gt;Get-Command -Noun *User | Out-GridView&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
= Services =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;powershell&amp;quot;&amp;gt;Get-Command -Noun *Service | Out-GridView&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
= Processes =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;powershell&amp;quot;&amp;gt;Get-Command -Noun *Process | Out-GridView&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
= Registry =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;powershell&amp;quot;&amp;gt;Get-Command -Noun *ItemProperty | Out-GridView&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
= Firewall =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;powershell&amp;quot;&amp;gt;Get-Command -Noun *Firewall* | Out-GridView&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
= Scheduled Tasks =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;powershell&amp;quot;&amp;gt;Get-Command -Noun *ScheduledTask* | Out-GridView&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
= Transcription (Logging) =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;powershell&amp;quot;&amp;gt;Get-Command -Noun *Transcript* | Out-GridView&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-----&lt;br /&gt;
&lt;br /&gt;
== 9) Comment‑based help template ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;powershell&amp;quot;&amp;gt;&amp;lt;#!&lt;br /&gt;
.SYNOPSIS&lt;br /&gt;
  Sets a service startup type with WhatIf/Confirm support.&lt;br /&gt;
.DESCRIPTION&lt;br /&gt;
  Safe wrapper around Set-Service for baseline enforcement.&lt;br /&gt;
.PARAMETER ServiceName&lt;br /&gt;
  One or more service names.&lt;br /&gt;
.PARAMETER StartupType&lt;br /&gt;
  Automatic, Manual, or Disabled.&lt;br /&gt;
.EXAMPLE&lt;br /&gt;
  &amp;#039;WinDefend&amp;#039; | Set-StartupType -StartupType Automatic -WhatIf&lt;br /&gt;
#&amp;gt;&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-----&lt;br /&gt;
&lt;br /&gt;
== 10) Quick reference (cheat sheet) (more cmdlets to take a look at) ==&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;List services:&amp;#039;&amp;#039;&amp;#039; &amp;lt;code&amp;gt;Get-Service | Sort Name&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Change startup:&amp;#039;&amp;#039;&amp;#039; &amp;lt;code&amp;gt;Set-Service -Name &amp;amp;lt;svc&amp;amp;gt; -StartupType Manual&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Running processes:&amp;#039;&amp;#039;&amp;#039; &amp;lt;code&amp;gt;Get-Process | Sort CPU -Desc | Select -First 10&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Local users:&amp;#039;&amp;#039;&amp;#039; &amp;lt;code&amp;gt;Get-LocalUser&amp;lt;/code&amp;gt; / &amp;lt;code&amp;gt;Enable-LocalUser&amp;lt;/code&amp;gt; / &amp;lt;code&amp;gt;Disable-LocalUser&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Local groups:&amp;#039;&amp;#039;&amp;#039; &amp;lt;code&amp;gt;Get-LocalGroupMember Administrators&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Registry provider:&amp;#039;&amp;#039;&amp;#039; &amp;lt;code&amp;gt;Get-Item &amp;#039;HKLM:\...&amp;#039;&amp;lt;/code&amp;gt; / &amp;lt;code&amp;gt;Set-ItemProperty&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Firewall:&amp;#039;&amp;#039;&amp;#039; &amp;lt;code&amp;gt;Set-NetFirewallProfile -Profile Domain,Private,Public -Enabled True&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Logging:&amp;#039;&amp;#039;&amp;#039; &amp;lt;code&amp;gt;Start-Transcript&amp;lt;/code&amp;gt; / &amp;lt;code&amp;gt;Stop-Transcript&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Scheduled task:&amp;#039;&amp;#039;&amp;#039; &amp;lt;code&amp;gt;Register-ScheduledTask&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-----&lt;br /&gt;
&lt;br /&gt;
== 12) Notes &amp;amp;amp; guardrails ==&lt;br /&gt;
&lt;br /&gt;
* Use &amp;lt;code&amp;gt;-WhatIf&amp;lt;/code&amp;gt; first; only remove or disable after documenting a reason.&lt;br /&gt;
* Create a restore point if available: &amp;lt;code&amp;gt;Checkpoint-Computer -Description &amp;#039;BeforeHygiene&amp;#039;&amp;lt;/code&amp;gt; (requires System Protection).&lt;br /&gt;
* Avoid blanket disabling of services; prefer Manual unless you’ve confirmed.&lt;br /&gt;
* Keep all changes reversible and logged to a dated folder on the Desktop.&lt;br /&gt;
&lt;br /&gt;
-----&lt;br /&gt;
&lt;br /&gt;
=== Attribution ===&lt;br /&gt;
&lt;br /&gt;
You may copy/adapt with attribution.&lt;br /&gt;
&lt;br /&gt;
[[Category:Windows PowerShell|010]]&lt;br /&gt;
[[Category:Migrated from cypat.guide]]&lt;/div&gt;</summary>
		<author><name>MigrationBot</name></author>
	</entry>
</feed>