Posts

Posts mit dem Label "powershell" werden angezeigt.

Microsoft Defender Antivirus

Get-MpComputerStatus Update-MpSignature Start-MpScan -ScanType QuickScan Start-MpScan -ScanType FullScan C:\Program Files\Windows Defender\MpCmdRun.exe" -Scan -Cancel C:\Program Files\Windows Defender\MpCmdRun.exe" -Scan -Cancel Remove-MpThreat Get-MpPreference Set-MpPreference -ScanScheduleQuickScanTime 03:00:00  Set-MpPreference -DisableRealtimeMonitoring $true Set-MpPreference -DisableRealtimeMonitoring $false

Powershell Install - RD Session Host on Windows Server

Add-WindowsFeature rds-rd-server -IncludeManagementTools -whatif

LastLogon

Get-Aduser - Filter * - SearchBase "OU=xx,OU=xx,DC=xx,DC=xx" - Properties * | Sort LastLogon | Select Name , Manager , LastLogonDate , @ { Name = 'LastLogon' ; Expression = {[ DateTime ]::FromFileTime( $_ .LastLogon )}} | Export-Csv C:\temp\adcomputers - last - logon - ou.csv - NoTypeInformation

Select String / Data from a txt File

$list = get-content "C:\Downloads\input.txt" $output = $list | Select-String interface , description , 'ip address' (((( $output -replace "interface" , "" ) -replace "description" , "" ) -replace "ip address" , "" ) -replace "\**>*" , "" ).trimstart()

Last Logon Date

Get-ADUser -Identity username -Properties "LastLogonDate"

WINRM Connect with Powershell

 Enter-PSSession **servername** -Credential (Get-Credential)

Anzahl Active Directory Benutzer ausgeben

 (get-aduser -filter "samaccountname -like 'max*'").count

Check Server Status

How To Check Server Status Windows PowerShell | VCP Blog (wordpress.com) # Declare Variables # $OutputFileName = "c:\temp\Server_Status.csv" # # Delete Output file # if ( Test-Path $OutputFileName ){     Clear-Host     Write-Host "Output File already Exists, deleting output file now - $OutputFileName . `n " -ForegroundColor Black -BackgroundColor Green     Remove-Item $OutputFileName     [ console ]::Beep( 500 , 700 ) } # # Validate to check Single or Muliple servers # $Check_Type = Read-Host "Do you want to Check status of (S)ingle or (M)ultiple Servers?" if ( $Check_Type -eq "S" -and $Check_Type -ne "" ) { $ServerName = Read-host "Enter Computer Name" if ( Test-Connection -ComputerName $ServerName -Count 1 -ErrorAction SilentlyContinue) {         # Write Column Heading delimited by Tab         #         echo "Host Name `t Node Status" > $OutputFileName     ...

Event Log mit Powershell auslesen

 Get-EventLog -LogName Security -InstanceId 4624  -Newest 10

GPO Search

Find String in Group Policy Settings # Get the string we want to search for $string = Read-Host -Prompt "What string do you want to search for?"   # Set the domain to search for GPOs $DomainName = $env:USERDNSDOMAIN   # Find all GPOs in the current domain write-host "Finding all the GPOs in $DomainName " Import-Module grouppolicy $allGposInDomain = Get-GPO -All -Domain $DomainName [ string []] $MatchedGPOList = @ () # Look through each GPO's XML for the string Write-Host "Starting search...." foreach ( $gpo in $allGposInDomain ) {     $report = Get-GPOReport -Guid $gpo .Id -ReportType Xml     if ( $report -match $string ) {         write-host "********** Match found in: $( $gpo .DisplayName ) **********" -foregroundcolor "Green"         $MatchedGPOList += " $( $gpo .DisplayName ) " ;     } # end if     else {         Write-Host "No match in: $( $gpo ....

Windows Firewall Logs überwachen

gc C:\Windows\System32\LogFiles\Firewall\pfirewall.log -Wait -Tail 1

Powershell History

%userprofile%\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadline\ConsoleHost_history.txt

LastLogonDate User

Get-ADUser „Username“ -Properties LastLogonDate | FT -Property Name, LastLogonDate -A

Shutdown / Lastlogon Analyse

Wer hat das System heruntergefahren: Get-EventLog - LogName system - Source user32 - Newest 1 | fl * Logons der letzten 7 Tage: $filter = @ {     LogName       = 'System'     ProviderName = 'Microsoft-Windows-Winlogon'     StartTime     = ( Get-Date ). AddDays ( -7 ) } $logs = Get-WinEvent - FilterHashtable $filter $res = @ () ForEach ( $log in $logs ) {     if ( $log . Id -eq 7001 ) { $type = "Logon" }     elseif ( $log . Id -eq 7002 ) { $type = "Logoff" }     else { Continue }     # Check if Properties[1] exists before accessing     if ( $log . Properties . Count -gt 1 ) {         try {             $user = ( New-Object System.Security.Principal.SecurityIdentifier $log . Properties [ 1 ]. Value ). Translate ([ System.Security.Principal.NTAccount ])         } catch { ...

Password Last Set

 Get-ADUser krbtgt -Properties PasswordLastSet

Convert Active Directory TimeStamp

 Local Time [DateTime]::FromFileTime(132902725142465784) UTC [DateTime]::FromFileTimeUtc(132902725142465784)

Hostname zu IP Adresse ausgeben

$ipaddress = Get-Content -Path C:\Temp\input.txt $results = @ () ForEach ( $i in $ipaddress )  {   $o = new-object psobject $o | Add-Member -MemberType NoteProperty -Name hostname -Value ([ System.Net.Dns ]:: GetHostByAddress ( $i ). HostName ) $results += $o } $results | Select-Object -Property hostname | Export-Csv C:\temp\output.csv

Port Test

Test-NetConnection -ComputerName server443 -port 443

IP Adressen zu Servernamen ausgeben

$servers = get-content "C:\TEMP\servers.txt" foreach ($server in $servers) {   $addresses = [System.Net.Dns]::GetHostAddresses($server)   foreach($a in $addresses) {     "{0},{1}" -f $server, $a.IPAddressToString   } }

DNS Server Adressen der Interfaces anzeigen

 Get-DnsClientServerAddress