Cross-platform command-line interface and scripting language for system and network administration
POPULARITY
Categories
Microsoft tries to prove Windows on ARM is ready for prime time, but behind the PR push, unresolved questions about compatibility, branding, and a tepid market threaten to derail the company's ambitions. Also, PowerToys 0.101 is here with Windows Hopper and multiple improvements! Plus, Parallels Desktop 27 for Mac launches. Windows If a Week D falls in the woods and no one installs it, did a Week D really happen? Theory: This is the big one, with the three big changes Microsoft promised this year. Basically, this is Windows 11 version 26H2 Three new builds across Beta, Experimental, and Experimental (26H1) with a modernized AutoPlay experience and a new "Open apps maximized" accessibility feature Microsoft reminds business customers that Windows on Arm is terrific ahead of Nvidia RTX Spark launch Totally coincidental that this happened on the same day that Apple announced a new Mac Mini with M6 and M5 Pro and Mac Studio with M5 Ultra and M5 Max Microsoft 365 OneDrive for Mac gets native sync engine Proton Mail gets automatic and customizable category filtering AI/dev Bill Gates issues a strong warning on the dangers of AI. And you're not going to believe what number two is WSJ report echoes the complaints that Paul has been making for years. Again Adobe Firefly gets production-quality music, speech, and sound effect generation capabilities Apple Music will start labeling AI-generated music .NET Conf 2026 on track for November with .NET 11 XBOX and gaming XBOX testing long-awaited disc to digital entitlements The ASUS ROG XBOX Ally X20 is available now for $1299, or in a $2499 bundle Rumor: Microsoft prepping an Xbox Series X25 Limited Edition console for November Update: it's real. The XBOX 25th anniversary collection arrives November 13 Microsoft announces (third party) Designed for XBOX 25th Anniversary Collection of hardware peripherals IKEA has designed some XBOX-influenced furniture and it is amazing Rockstar Games weighs in on leaks as GTA VI reveal arrives (tomorrow) Commodore announces Alien Breed 35th Anniversary Collection for PC, consoles NVIDIA brings GeForce Now to Firefox Tips and picks Tip of the week: Expose yourself to other points of view App pick of the week: PowerToys RunAs Radio this week: Security Features of PowerShell 7 with Mike O'Neill Brown liquor pick of the week: SpiceBox Spiced Whisky Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell Download or subscribe to Windows Weekly at https://twit.tv/shows/windows-weekly Check out Paul's blog at thurrott.com The Windows Weekly theme music is courtesy of Carl Franklin. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsor: canary.tools/twit - use code: TWIT
Microsoft tries to prove Windows on ARM is ready for prime time, but behind the PR push, unresolved questions about compatibility, branding, and a tepid market threaten to derail the company's ambitions. Also, PowerToys 0.101 is here with Windows Hopper and multiple improvements! Plus, Parallels Desktop 27 for Mac launches. Windows If a Week D falls in the woods and no one installs it, did a Week D really happen? Theory: This is the big one, with the three big changes Microsoft promised this year. Basically, this is Windows 11 version 26H2 Three new builds across Beta, Experimental, and Experimental (26H1) with a modernized AutoPlay experience and a new "Open apps maximized" accessibility feature Microsoft reminds business customers that Windows on Arm is terrific ahead of Nvidia RTX Spark launch Totally coincidental that this happened on the same day that Apple announced a new Mac Mini with M6 and M5 Pro and Mac Studio with M5 Ultra and M5 Max Microsoft 365 OneDrive for Mac gets native sync engine Proton Mail gets automatic and customizable category filtering AI/dev Bill Gates issues a strong warning on the dangers of AI. And you're not going to believe what number two is WSJ report echoes the complaints that Paul has been making for years. Again Adobe Firefly gets production-quality music, speech, and sound effect generation capabilities Apple Music will start labeling AI-generated music .NET Conf 2026 on track for November with .NET 11 XBOX and gaming XBOX testing long-awaited disc to digital entitlements The ASUS ROG XBOX Ally X20 is available now for $1299, or in a $2499 bundle Rumor: Microsoft prepping an Xbox Series X25 Limited Edition console for November Update: it's real. The XBOX 25th anniversary collection arrives November 13 Microsoft announces (third party) Designed for XBOX 25th Anniversary Collection of hardware peripherals IKEA has designed some XBOX-influenced furniture and it is amazing Rockstar Games weighs in on leaks as GTA VI reveal arrives (tomorrow) Commodore announces Alien Breed 35th Anniversary Collection for PC, consoles NVIDIA brings GeForce Now to Firefox Tips and picks Tip of the week: Expose yourself to other points of view App pick of the week: PowerToys RunAs Radio this week: Security Features of PowerShell 7 with Mike O'Neill Brown liquor pick of the week: SpiceBox Spiced Whisky Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell Download or subscribe to Windows Weekly at https://twit.tv/shows/windows-weekly Check out Paul's blog at thurrott.com The Windows Weekly theme music is courtesy of Carl Franklin. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsor: canary.tools/twit - use code: TWIT
Microsoft tries to prove Windows on ARM is ready for prime time, but behind the PR push, unresolved questions about compatibility, branding, and a tepid market threaten to derail the company's ambitions. Also, PowerToys 0.101 is here with Windows Hopper and multiple improvements! Plus, Parallels Desktop 27 for Mac launches. Windows If a Week D falls in the woods and no one installs it, did a Week D really happen? Theory: This is the big one, with the three big changes Microsoft promised this year. Basically, this is Windows 11 version 26H2 Three new builds across Beta, Experimental, and Experimental (26H1) with a modernized AutoPlay experience and a new "Open apps maximized" accessibility feature Microsoft reminds business customers that Windows on Arm is terrific ahead of Nvidia RTX Spark launch Totally coincidental that this happened on the same day that Apple announced a new Mac Mini with M6 and M5 Pro and Mac Studio with M5 Ultra and M5 Max Microsoft 365 OneDrive for Mac gets native sync engine Proton Mail gets automatic and customizable category filtering AI/dev Bill Gates issues a strong warning on the dangers of AI. And you're not going to believe what number two is WSJ report echoes the complaints that Paul has been making for years. Again Adobe Firefly gets production-quality music, speech, and sound effect generation capabilities Apple Music will start labeling AI-generated music .NET Conf 2026 on track for November with .NET 11 XBOX and gaming XBOX testing long-awaited disc to digital entitlements The ASUS ROG XBOX Ally X20 is available now for $1299, or in a $2499 bundle Rumor: Microsoft prepping an Xbox Series X25 Limited Edition console for November Update: it's real. The XBOX 25th anniversary collection arrives November 13 Microsoft announces (third party) Designed for XBOX 25th Anniversary Collection of hardware peripherals IKEA has designed some XBOX-influenced furniture and it is amazing Rockstar Games weighs in on leaks as GTA VI reveal arrives (tomorrow) Commodore announces Alien Breed 35th Anniversary Collection for PC, consoles NVIDIA brings GeForce Now to Firefox Tips and picks Tip of the week: Expose yourself to other points of view App pick of the week: PowerToys RunAs Radio this week: Security Features of PowerShell 7 with Mike O'Neill Brown liquor pick of the week: SpiceBox Spiced Whisky Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell Download or subscribe to Windows Weekly at https://twit.tv/shows/windows-weekly Check out Paul's blog at thurrott.com The Windows Weekly theme music is courtesy of Carl Franklin. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsor: canary.tools/twit - use code: TWIT
Microsoft tries to prove Windows on ARM is ready for prime time, but behind the PR push, unresolved questions about compatibility, branding, and a tepid market threaten to derail the company's ambitions. Also, PowerToys 0.101 is here with Windows Hopper and multiple improvements! Plus, Parallels Desktop 27 for Mac launches. Windows If a Week D falls in the woods and no one installs it, did a Week D really happen? Theory: This is the big one, with the three big changes Microsoft promised this year. Basically, this is Windows 11 version 26H2 Three new builds across Beta, Experimental, and Experimental (26H1) with a modernized AutoPlay experience and a new "Open apps maximized" accessibility feature Microsoft reminds business customers that Windows on Arm is terrific ahead of Nvidia RTX Spark launch Totally coincidental that this happened on the same day that Apple announced a new Mac Mini with M6 and M5 Pro and Mac Studio with M5 Ultra and M5 Max Microsoft 365 OneDrive for Mac gets native sync engine Proton Mail gets automatic and customizable category filtering AI/dev Bill Gates issues a strong warning on the dangers of AI. And you're not going to believe what number two is WSJ report echoes the complaints that Paul has been making for years. Again Adobe Firefly gets production-quality music, speech, and sound effect generation capabilities Apple Music will start labeling AI-generated music .NET Conf 2026 on track for November with .NET 11 XBOX and gaming XBOX testing long-awaited disc to digital entitlements The ASUS ROG XBOX Ally X20 is available now for $1299, or in a $2499 bundle Rumor: Microsoft prepping an Xbox Series X25 Limited Edition console for November Update: it's real. The XBOX 25th anniversary collection arrives November 13 Microsoft announces (third party) Designed for XBOX 25th Anniversary Collection of hardware peripherals IKEA has designed some XBOX-influenced furniture and it is amazing Rockstar Games weighs in on leaks as GTA VI reveal arrives (tomorrow) Commodore announces Alien Breed 35th Anniversary Collection for PC, consoles NVIDIA brings GeForce Now to Firefox Tips and picks Tip of the week: Expose yourself to other points of view App pick of the week: PowerToys RunAs Radio this week: Security Features of PowerShell 7 with Mike O'Neill Brown liquor pick of the week: SpiceBox Spiced Whisky Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell Download or subscribe to Windows Weekly at https://twit.tv/shows/windows-weekly Check out Paul's blog at thurrott.com The Windows Weekly theme music is courtesy of Carl Franklin. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsor: canary.tools/twit - use code: TWIT
How secure are your PowerShell scripts? Richard talks to Mike O'Neill about the powerful security features introduced with PowerShell 7.3 and above, including session configuration files and clean blocks. Mike talks about how some organizations are strict about installing anything on servers, including the latest version of PowerShell - which is one of the reasons 5.1 has persisted so long. But that ends with 26H2 and opens the door to securing your PowerShell with strict controls over accounts, cmdlets, and more! The latest PowerShell makes it easier to have just enough administration - and makes it harder for the black hats to exploit! Links PowerShell 7 Just Enough Administration New-PSSessionConfiguration File PowerShell Clean Block Monthly PowerShell Team Call Mike's Exchange Add-In for PowerShell Recorded July 9, 2026
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting! https://isc.sans.edu/diary/Who%20Got%20Missed%20in%20the%20MFA%20Rollout%3F%20More%20Powershell%20%2B%20Graph%20%2B%20Entra%20scripting!/33272 Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays https://isc.sans.edu/diary/Even%20MOAR%20Powershell%2C%20looking%20at%20Entra%20logins%20-%20the%20good%2C%20the%20bad%20and%20the%20password%20sprays/33268 Microsoft Entra ID Remote Code Execution Vulnerability CVE-2026-69836 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836 GitLab Critical Patch Release CVE-2026-19478 CVE-2026-19650 https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/ GTA 6 Leak File with Malware https://x.com/Aidas29506493/status/2091194667073204624 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Mike Soule, Field CTO at Sentinel Technologies, returns to the PowerShell Podcast for the first time in three years to talk identity security, cloud configuration testing, and the evolving role of AI in the Microsoft ecosystem. Andrew and Mike dig into Maester, the open source PowerShell-based test automation framework that applies unit testing concepts to Microsoft 365 security configuration. Mike breaks down how Maester works, how Sentinel uses it with clients, and how the community has grown it into something that spans hundreds of built-in tests covering conditional access, CIS baselines, CISA standards, and more. They also cover EntraOps, the Enterprise Access Model, AI's impact on the MSP world, and why working in managed services is still one of the fastest ways to level up in IT. The episode closes with a strong Brandon Sanderson tangent. Key Takeaways: Maester brings the concept of unit testing to Microsoft 365 security configuration, letting admins continuously validate their cloud settings against known-good baselines with as few as three PowerShell commands. It's built on Pester, is fully open source, and now has over 100 community contributors. AI is changing the MSP landscape fast, but the fundamentals still matter. Mike and Andrew discuss how to think about Copilot licensing complexity, model routing in agent stacks, and why meeting users in their existing interface is often more important than deploying a shiny new tool. MSP experience accelerates learning in a way that internal IT often can't match. When you're working across multiple clients and environments, you accumulate reps quickly, and that breadth is hard to replicate elsewhere. Guest Bio: Mike Soule is the Field CTO at Sentinel Technologies, a large managed service provider focused on identity, cloud, and security strategy. Mike has been working hands-on with PowerShell, Entra ID, and Microsoft 365 security architecture for years and is a regular speaker at identity and security conferences. Resource Links: Maester (open source framework): https://maester.dev Maester on GitHub: https://github.com/maester365/maester Maester Cloud (hosted version by Merill Fernando): https://maester.cloud HIPConf (Hybrid Identity Protection Conference): https://www.hipconf.com EntraOps by Thomas Naunheim: https://github.com/Cloud-Architekt/EntraOps Mike Soule on LinkedIn: https://www.linkedin.com/in/mikesoule The PowerShell Podcast on YouTube: https://youtu.be/EQK693gGWoo
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses https://isc.sans.edu/diary/Using%20Microsoft%20Graph%20and%20Powershell%20to%20Mine%20for%20Information%20-%20Stale%20Accounts%20and%20Licenses/33264 Using Microsoft Graph and Powershell - Risk Detection Commands https://isc.sans.edu/diary/Using%20Microsoft%20Graph%20and%20Powershell%20-%20Risk%20Detection%20Commands/33266 Keycloak Vulnerability https://github.com/keycloak/keycloak/issues/51833 https://www.keycloak.org/2026/08/keycloak-2672-released CRYPTOGRAPHIC CONTEXT INJECTION ATTACK https://adversa.ai/blog/cryptographic-context-injection-grok-data-theft/ N-able password manager https://amibeingpwned.com/blog/solar-winds-part-2-avoided?_sp=75fd154a-e34f-41d0-8624-7c285776c13d.1787263544340 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Andrew Pla sits down with TJ Turner at Microsoft's TechMentor conference @ Microsoft HQ in Redmond, Washington, for a conversation about PowerShell, career growth, and the parts of working in IT that don't show up in the documentation. TJ traces his path from infrastructure through K-12, finance, and retail to his current role as a Cloud Evangelist at TD SYNNEX, along with his early days using PowerShell v2 and v3, competing in the Scripting Games, and helping start the Philadelphia PowerShell User Group. They also dig into real-world automation wins, including a PowerShell workflow that helped validate thousands of systems before a holiday weekend, plus burnout, community, asking for help, and what years of broken demos and IT mistakes can teach you about staying prepared and learning to adapt. Key Takeaways: · What got you here won't get you there. TJ's career moved from hands-on infrastructure into distribution, cloud, and technical evangelism, and none of those moves were necessarily part of the original plan. Staying open to new roles, skills, and opportunities has been a big part of that growth. · PowerShell changes how you think, not just how you work. TJ shares examples of using PowerShell to validate thousands of systems, automate VMware update workflows, and collect detailed system state information. Over time, that automation mindset became part of how he approaches problems, even as his career moved beyond day-to-day infrastructure work. · Community and communication are technical skills too. Whether it's recognizing burnout, asking for help, meeting someone at a conference, or admitting you don't know an answer during a presentation, the ability to connect with other people can have just as much impact on your career as knowing the technology. Guest Bio: TJ Turner is a Cloud Evangelist at TD SYNNEX, one of Microsoft's largest distributors in the CSP and partner channel. His background is in infrastructure, with experience spanning K-12, financial services, retail, and other enterprise environments. TJ got started with PowerShell during the v2 and v3 era, competed in the Scripting Games, and helped found the Philadelphia PowerShell User Group. Today, his work includes Azure, Microsoft 365, security, GitHub, DevOps, and helping partners grow their businesses. Resource Links: · TD SYNNEX Microsoft Partner Programs: https://www.tdsynnex.com/na/us/Microsoft/ · PDQ Connect PowerShell Scanner: https://www.pdq.com/powershell-scanner/ · PDQ PowerShell Scanner Blog Post: https://www.pdq.com/blog/the-powershell-scanner-has-arrived-in-pdq-connect/ · PDQ Community PowerShell Scanners Repository: https://github.com/pdqcom/PowerShell-Scanners · TJ Turner on LinkedIn: https://www.linkedin.com/search/results/people/?keywords=TJ+Turner+TD+SYNNEX The PowerShell Podcast on YouTube: https://youtu.be/ce9vxdkzDbo
Piotr talks about how he managed his 9.1 upgrade and the Powershell calling REST API's to avoid a subnet trap where traffic is blocked between subnets during install.
Fred Weinmann is back, and this time he's walking us through the PowerShell Framework Collective – his personal answer to the age-old problem of building the tools that build the tools. The core idea is simple but powerful: if you invest in the scaffolding around your code, the actual code you write gets faster, cleaner, and more consistent every time. Fred breaks down four key wins from his framework stack, including PSModuleDevelopment for templating new projects, PSUtil for leveling up your console experience, PSReadLine for predictive history, and PSFramework itself for things like logging, configuration, parameter handling, and protected command execution. If you've ever spent more time wiring up logging and retry logic than solving the actual problem, this episode is going to feel very familiar – and very useful. Key Takeaways: PSModuleDevelopment makes spinning up a new, fully scaffolded PowerShell module a one-liner – complete with tests, GitHub release pipelines, and PowerShell Gallery publishing – so you can focus entirely on the actual functions you need to write. PSFramework handles the infrastructure layer of your code (logging, configuration, tab completion, parameter validation, retry logic) so you stop reinventing the wheel and your projects stay consistent across years and teammates. The real payoff of a shared framework is long-term maintainability: Fred opened a module he hadn't touched in six years and had a bug fixed and released in five minutes because everything was exactly where he expected it to be. Guest Bio: Friedrich "Fred" Weinmann is a Cloud Solution Architect at Microsoft and one of the most recognized PowerShell community contributors working today. He is the creator of PSFramework, which underpins many other modules in the ecosystem, as well as tools like PSModuleDevelopment, PSUtil, and the Active Directory Management Framework. Fred is a frequent conference speaker, a longtime community collaborator, and someone Andrew credits with helping shape his own PowerShell journey. Resource Links: PSFramework Project Home: https://psframework.org/ PSFramework on GitHub: https://github.com/PowershellFrameworkCollective/psframework PSModuleDevelopment on GitHub: https://github.com/PowershellFrameworkCollective/PSModuleDevelopment PSUtil on GitHub: https://github.com/PowershellFrameworkCollective/PSUtil PowerShell Framework Collective on GitHub: https://github.com/PowershellFrameworkCollective/ PDQ Discord – PowerShell Scripting Channel: https://discord.gg/pdq The PowerShell Podcast on YouTube:https://youtu.be/sZQdgBZM75Y
Today we are joined by Brian Hussey, SVP of Howler Cell Threat Services at Cyderes, discussing their work on "Bad Ads, Worse Binaries: Fake Claude Code Installer Drops Infostealer." Howler Cell identified an SEO poisoning campaign targeting people searching for Claude Code installation guides, using a fake Anthropic page and a ClickFix lure to trick victims into running a malicious MSHTA command. The attack uses a six-stage, largely fileless chain that employs an MP3/HTA polyglot, PowerShell obfuscation, AMSI bypasses, per-victim infrastructure, and in-memory execution to evade detection. The final payload is a .NET infostealer that steals credentials, while Anthropic and the legitimate Claude Code installation process were not compromised. The research and executive brief can be found here: Bad Ads, Worse Binaries: Fake Claude Code Installer Drops Infostealer
Today we are joined by Brian Hussey, SVP of Howler Cell Threat Services at Cyderes, discussing their work on "Bad Ads, Worse Binaries: Fake Claude Code Installer Drops Infostealer." Howler Cell identified an SEO poisoning campaign targeting people searching for Claude Code installation guides, using a fake Anthropic page and a ClickFix lure to trick victims into running a malicious MSHTA command. The attack uses a six-stage, largely fileless chain that employs an MP3/HTA polyglot, PowerShell obfuscation, AMSI bypasses, per-victim infrastructure, and in-memory execution to evade detection. The final payload is a .NET infostealer that steals credentials, while Anthropic and the legitimate Claude Code installation process were not compromised. The research and executive brief can be found here: Bad Ads, Worse Binaries: Fake Claude Code Installer Drops Infostealer
Two pen testers have spent thousands of hours inside client networks, and the most common failure they see isn't a missing security product — it's an EDR nobody ever tuned.In this episode, Spencer and Tyler open up the CrowdStrike Falcon console and walk through the specific settings that decide whether your team catches an attack or never sees it. They start with the story that kicked the whole thing off: Tyler running a pen test where every AMSI bypass gets blocked and detections fire left and right, while Spencer runs nearly identical tooling against the same product at another client and the SOC sees nothing all week. Same CrowdStrike. Same version. Different checkboxes.From there it's a tactical walkthrough of Endpoint Security → Prevention Policies and the settings worth your attention: Enhanced Exploitation Visibility, which unlocks command-line and PowerShell telemetry that Microsoft disables by default; Enhanced DLL Load Visibility for side-loading attacks; WSL2 Visibility, which closes a sandbox threat actors have been using to run Kali tooling under the radar; memory scanning for in-memory C# tradecraft; Office malicious macro removal; file system containment for ransomware over SMB; vulnerable driver protection, the direct mitigation for BYOVD attacks and EDR killers; and cloud-based anomalous process execution for living-off-the-land binaries.They also cover custom IOA rule groups for blocking unauthorized RMM tools, centralized firewall policy management, device policies for USB control, and a warning on exclusions — especially wildcard paths, which Tyler calls a threat actor's best dream.The takeaway is simple: you're paying real money for EDR, and default configurations aren't giving you what you paid for. Open your console, work through the settings, test them against an IT pilot group, and enable what fits your environment.TOPICS COVERED- Why EDR vendors ship deficient defaults on purpose- Enhanced Exploitation Visibility and the telemetry gap in PowerShell attacks- DLL side-loading, WSL2 abuse, and vulnerable driver attacks- Memory scanning and in-memory tooling detection- Blocking RMM tools with custom IOA rule groups- Exclusion hygiene and the wildcard path problem- Device policies, USB blocking, and insider threatSentinel One and Defender for Endpoint are next — let us know what else you want covered.Blog: https://offsec.blogWork with us on an internal pen test: https://securit360.comBlog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.comWork with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
This show has been flagged as Clean by the host. I recently had an experience where UNIX tools proved very useful. A relative had an old mobile phone running Android that stopped connecting to the carrier's network and bought a new one to replace it. I took on the job of trying to copy their files (consisting of just photos and videos) off of the old phone. Google's software was desperate to convince me to upload everything to the cloud, but I wasn't interested. It offered the option of copying the files over to an SD card, but failed on repeated attempts to do that. The option I tried next was to transfer them to another device via Bluetooth—that one did actually work, although it was slow and would only handle sending about 100 files at a time. They came over to my laptop OK, but the problem with that method was that all of the file times were set to the time when they were transferred. I'm not super familiar with how mobile apps manage metadata, but would presume that they look to file times for organizing photos by date. Fortunately, the names of each of the files included the date and time they were created. I recognized that I could write a bit of shell script to parse the filenames and set the file times accordingly. While there were over 800 files, the good news is that there were only three different categories of filenames, so the logic to extract the information needed was relatively simple. Each file had eight numerical digits representing the date and six digits representing the time. It would definitely be an option to come up with a more sophisticated parser that could handle a wide variety of filenames, but I went the lazy way and just handled those three cases. Another nice aspect was that none of the filenames contained spaces, which allowed me to be a bit less careful when using them in command lines. I didn't need to worry about time zones because my laptop was set to the same time zone as the phone—also, if a time was off a by a few hours it wouldn't make a practical difference. Examples of the three different types of filenames I had to deal with, labeled with the relevant values: YYYY=year, MM=month, DD=day, hh=hour, mm=minute, and SS=second. 00001IMG_00001_BURST20250525140124.jpg YYYYMMDDhhmmSS IMG_20220223_124023.jpg VID_20221017_095024.mp4 YYYYMMDD hhmmSS 20191224_195939.jpg 20161021_122620-1.jpg 20191130_134317_Burst01.jpg 20200129_223612_010.jpg YYYYMMDD hhmmSS I considered awk as an option (see Whiskeyjack's comment on HPR episode 4657 ), but realized it has no built-in way to change file times, so I set it aside. Don't worry, I will come back to that later. My approach was to use an if-then shell construct to choose how to treat the three categories of filenames. For the if condition, I fed the filename into the grep -q command with an appropriate regular expression to test whether it matches. The -q option to grep causes it not to output anything—it returns a zero exit status if there's a match and a status greater than zero if there isn't. Then, there is an elif statement with another grep -q test for the second category of filenames. Finally, an else statement is followed by the command to run for all other filenames. The whole thing is wrapped in a for loop that runs over all the files in the current directory. The touch command , when used with the -t option, can be given a string consisting of the year, month, day, hour, minute, and second. These are all numerals that are run together, except that a period sits between the minute and second. So we need a way to extract these numbers and to insert the period. That's where the cut utility comes in. It can be given a set of characters to select, and I specified a different set representing the appropriate ones depending on which category a filename fit into. To insert the period, I used sed to replace the last two characters with a period followed by those characters. The first script was to test out that I was getting the correct results. for fn in * do if echo "$fn" | grep -q BURST then printf "$fn " echo $fn | cut -c '21-34' | sed 's/..$/.&/' elif echo "$fn" | grep -q -E '^(IMG_|VID_)' then printf "$fn " echo $fn | cut -c '5-12,14-19' | sed 's/..$/.&/' else printf "$fn " echo $fn | cut -c '1-8,10-15' | sed 's/..$/.&/' fi done This one actually sets the file times. The -c option to touch prevents it from creating a file if one with that name doesn't already exist. for fn in * do if echo "$fn" | grep -q BURST then touch -c -t "$(echo $fn | cut -c '21-34' | sed 's/..$/.&/')" "$fn" elif echo "$fn" | grep -q -E '^(IMG_|VID_)' then touch -c -t "$(echo $fn | cut -c '5-12,14-19' | sed 's/..$/.&/')" "$fn" else touch -c -t "$(echo $fn | cut -c '1-8,10-15' | sed 's/..$/.&/')" "$fn" fi done The script ran over all the files in less than 15 seconds and correctly set the file time on each. Job done, right? Well, after I did this, it struck me that there was room for improvement. The script would probably run more quickly if I used a case construct instead of an if construct that called grep multiple times. While the pattern-matching notation used with case is not as flexible and can handle fewer situations than the regular expression syntax available with grep , in this case (see what I did there?) it is sufficient. Testing it out, using case reduced the running time by 45%. Replacing if with case —the commands to be executed for each category of filename can remain exactly the same. for fn in * do case "$fn" in *BURST*) printf "$fn " echo $fn | cut -c '21-34' | sed 's/..$/.&/' ;; IMG_*|VID_*) printf "$fn " echo $fn | cut -c '5-12,14-19' | sed 's/..$/.&/' ;; *) printf "$fn " echo $fn | cut -c '1-8,10-15' | sed 's/..$/.&/' esac done for fn in * do case "$fn" in *BURST*) touch -c -t "$(echo $fn | cut -c '21-34' | sed 's/..$/.&/')" "$fn" ;; IMG_*|VID_*) touch -c -t "$(echo $fn | cut -c '5-12,14-19' | sed 's/..$/.&/')" "$fn" ;; *) touch -c -t "$(echo $fn | cut -c '1-8,10-15' | sed 's/..$/.&/')" "$fn" esac done I couldn't completely put awk out of my mind, though, and I eventually came up with an awk script for the same purpose. This is far faster, probably because everything can be done within awk except actually modifying the file times, which is possible using the system() function to call touch . I was able to knock 90% off the running time, which for 800 files isn't a big deal but might make a difference if you have hundreds of thousands of files. The awk counterparts to both scripts above. Unlike those, ls is used to feed it with the list of filenames. We have the full power of extended regular expressions available to use for matching against the filenames. The next statement causes awk to skip any remaining pattern-action pairs and go to the next line of input. ls | awk '/BURST/ { print $0, substr($0, 21, 12) "." substr($0, 33, 2) next } /^(IMG_|VID_)/ { print $0, substr($0, 5, 8) substr($0, 14, 4) "." substr($0, 18, 2) next } { print $0, substr($0, 1, 8) substr($0, 10, 4) "." substr($0, 14, 2) }' ls | awk '/BURST/ { system("touch -c -t " substr($0, 21, 12) "." substr($0, 33, 2) " " $0) next } /^(IMG_|VID_)/ { system("touch -c -t " substr($0, 5, 8) substr($0, 14, 4) "." substr($0, 18, 2) " " $0) next } { system("touch -c -t " substr($0, 1, 8) substr($0, 10, 4) "." substr($0, 14, 2) " " $0) }' A further optimization that came to me later was to not call system() from within awk , but to instead just have awk print out a set of command lines. These can then be piped to sh to actually be executed. This cut the running time down by 95% compared to my original script. The fastest version I was able to come up with. If you run it without the | sh on the end, you can check that it's outputting the right information before actually modifying anything. The backslash on the end of a couple lines causes the subsequent line to be treated as a continuation of the existing line. Normally I would just keep everything on one line even if it runs longer than 80 columns, but for display purposes this looks nicer. ls | awk '/BURST/ { print "touch -c -t " substr($0, 21, 12) "." substr($0, 33, 2) " " $0 next } /^(IMG_|VID_)/ { print "touch -c -t " substr($0, 5, 8) substr($0, 14, 4) "." substr($0, 18, 2) " " $0 next } { print "touch -c -t " substr($0, 1, 8) substr($0, 10, 4) "." substr($0, 14, 2) " " $0 }' | sh It is probably true that this could have been carried out just as easily on Windows using Microsoft's PowerShell. I'm not very familiar with it, but would imagine (or hope) that it includes commands for managing these basic things like text manipulation and modifying file times. If you are stuck in an environment where you don't have a UNIX-like system available, investigate how to accomplish a task with the tools you do have. While I had the necessary information in the filenames to use, that might not be the case in all situations. You could look for other sources of dates—most digital cameras will add EXIF tags to a JPEG file giving the date and time it was created. (Hopefully, the clock in the camera will be set accurately.) While there is no standard UNIX utility to read those tags, free and open source software tools are widely available for that purpose. I found one called exiftags that included the utility exiftime , which specifically outputs EXIF data relating to time. The output format was a little trickier to handle, but awk was able to manage it with a little coaxing. Example of output produced by exiftime . Note that the first line with the filename is only printed if more than one filename is given as an argument. Also, for amusing-sign.jpg , apparently I edited that photo after taking it and the editing software updated the "created" tag but left the others intact. Not all images will necessarily have created, generated, and digitized tags; we will just take whichever ones exist. I redirected standard error to /dev/null to get rid of error messages for files that don't have EXIF tags; we'll handle those below. $ exiftime *.jpg 2>/dev/null 20260508_154743.jpg: Image Created: 2026:05:08 15:47:43 Image Generated: 2026:05:08 15:47:43 Image Digitized: 2026:05:08 15:47:43 20260508_155044.jpg: Image Created: 2026:05:08 15:50:44 Image Generated: 2026:05:08 15:50:44 Image Digitized: 2026:05:08 15:50:44 3704a78e771c2a25a894ef2f0b5a2a629f1eba80.jpg: amusing-sign.jpg: Image Created: 2017:01:24 23:14:04 Image Generated: 2017:01:24 21:18:07 Image Digitized: 2017:01:24 21:18:07 dscf3011.jpg: Image Created: 2015:01:01 00:02:19 Image Generated: 2015:01:01 00:02:19 Image Digitized: 2015:01:01 00:02:19 window-view.jpg: $ We can take advantage of the fact that different records are separated by a blank line. In awk , when RS is set to a null string and FS is set to a newline character, each set of non-blank lines is treated as a record and each line within those sets is treated as a field. One or more blank lines separate each record. For the output of exiftime , this means that $1 will contain the filename and $2 will contain the first line after the filename. For those files without an EXIF date tag, $2 will be a null string, which is treated by awk as FALSE, so the pattern will not match, the action will not be taken, and nothing will be printed. If a file has multiple tags, I will just use the first one reported by exiftime (contained in $2 ). The sub() function call removes the colon that exiftime prints after the filename, and the gsub() function call removes all non-numeric characters from the date and time in the tag. (After a comma within a print statement, a backslash is not necessary to continue a line.) Also, this time I bothered to print quotation marks around the filename in case it contains spaces. $ exiftime *.jpg 2>/dev/null | awk 'BEGIN { FS = "n" ; RS = "" } $2 { sub(":$", "", $1) gsub("[^0-9]", "", $2) print "touch -c -t", substr($2, 1, 12) "." substr($2, 13, 2), """ $1 """ }' touch -c -t 202605081547.43 "20260508_154743.jpg" touch -c -t 202605081550.44 "20260508_155044.jpg" touch -c -t 201701242314.04 "amusing-sign.jpg" touch -c -t 201501010002.19 "dscf3011.jpg" $ I would imagine that there's some photo management program out there that I could have used to accomplish this. But then I would have had to locate it, verify that it wasn't some malware-loaded garbage, download, and install it. And chances are it would want to take over all the photos on my laptop. Instead, with standard UNIX tools and shell capabilities like if , case , process substitution, and pipelines, I was able to complete the task without having to install anything. The techniques I described can be used in different circumstances and with the output of different utilities. My intention was not just to explain how to solve this specific problem, but to hopefully teach you some things that you can apply in many situations. Perhaps if you use them to tackle a challenge of your own, you'll record an episode for HPR to share what you know. Provide feedback on this episode.
Andrew sits down with Evgenij Smirnov, a Berlin-based IT veteran with 30 years of experience in Active Directory and security consulting, to dig into what actually gets organizations popped. Evgenij walks through the most common escalation paths he sees in real-world AD environments, including over-permissioned accounts, exposed certificate authorities, and unencrypted domain controller backups, and explains how attackers chain these together to produce golden tickets and gain god-mode access. The conversation covers why these misconfigurations keep happening (bad defaults, lazy vendors, and a long history of "just click next"), how PowerShell fits into both hardening and attack scenarios, and what proper tier isolation actually looks like when you implement it with both authentication policies and user rights assignments. Evgenij also introduces his book, Building Modern Active Directory, and makes the case for treating security not as a chapter you can skip, but as something baked into the design from day one. Key Takeaways: The most common Active Directory escalation paths are not sophisticated. Over-permissioned accounts with ACL chains to DC sync, exposed certificate authorities, and unencrypted backup tapes are consistently the entry points attackers exploit. If you can find these first, you are already ahead of most threat actors. Tier isolation done right requires both authentication policies and user rights assignment policies working together. Either technique alone leaves a blind spot that a determined attacker can walk through. Cybersecurity is a team sport, and bad cybersecurity is too. Microsoft ships AD with questionable defaults, vendors demand domain admin for service accounts, and administrators make shortcuts under pressure. The fix is not one heroic hardening sprint; it is a culture of least privilege built into every decision from the start. Guest Bio: Evgenij Smirnov is a Principal Solutions Architect at Semperis and a Microsoft MVP in both Security and PowerShell since 2020. Based in Berlin, Germany, he has spent more than 30 years in IT and security consulting, with deep expertise in Active Directory, identity security, and hybrid infrastructure. He is a longtime community leader, running the PowerShell User Group Berlin and the Windows Server User Group Berlin, and a regular speaker at conferences including PSConfEU. He is the author of Building Modern Active Directory, published by Apress in 2024. Resource Links: Building Modern Active Directory (book site): ad2049.com Evgenij's personal blog): it-pro-berlin.de Evgenij on LinkedIn: linkedin.com/in/evgenijsmirnov ADMF (Active Directory Management Framework) on GitHub: github.com/ActiveDirectoryManagementFramework/ADMF ADMF documentation and project site: admf.one Attack Scenario To Go: https://github.com/HerrHoZi/AS2Go The PowerShell Podcast on YouTube: https://youtu.be/EQb7H6vBOtg
Hey friends! Today's episode comes to you from a parking lot in the rain, with a mint hot cocoa in hand and your host absolutely dragging his butt (D-R-A-G-G-I-N-G, not D-R-A-G-O-N – I've never seen a dragon's butt and can't speak to how mine compares). I've had a bunch of internals back to back lately and I'm basically a drooling dog who found a frisbee and refuses to put it down. Sleep be darned. So instead of walking through one test start to finish, I want to share a few things that have helped me claw out a foothold in environments that are otherwise really locked down: The "good problem" of a mature client – several of these engagements are third- or fourth-year tests, and the clients actually clear findings off the board. Which is great for them and rough for me, because this year's test shouldn't look anything like last year's. All my favorite go-tos came up empty – machine account quota set to zero, no broadcast traffic tomfoolery (Responder and mitm6 got me nothing), SMB signing on everywhere, ADCS either absent or buttoned up, and a low-priv account that BloodHound says has zero interesting permissions and zero local admin anywhere. Cool cool cool. When the network's clean, go file-hunting – which means firing up Snaffler and letting it comb the shares. Normally that wraps up in about an hour. On these engagements it was running three and four hours. Then Windows told me I was out of disk – I like having Snaffler pull down copies of interesting files so I can review them locally instead of authenticating to each share. Turns out it had grabbed 50-60 gigs and left me with about eight gigs of breathing room. Tip #1: put a 1 TB drive in your drop boxes – I ran with tiny drives for years early in the 7MS days and it was always a pinch. Beyond situations like this one, sometimes you find a giant backup file or VMDK on a share and you need somewhere to put it so you can crack it open and go shopping. Tip #2: you can grow a VM disk on the fly – in Proxmox you can resize the disk on a running VM, then hop into Disk Management inside Windows and extend the C drive. Instant elbow room, no downtime. Death by a million tiny files – the real culprit was one file extension I should have excluded, and the client had hundreds of thousands of them. Rather than restart a run I was already hours into, I had AI whip up a little PowerShell loop that swept the Snaffler dump folder every 10 minutes and deleted the extensions I didn't care about. Woke up the next morning to a finished run and plenty of free space. Making a gig-sized log file readable – I fed the log into Chimas, a slick web interface for Snaffler output that lets you filter down to just the red stuff or just the likely-credential files, and sort by modified date. Watch those timestamps – I kept finding AD creds in documents, then comparing the doc's date against the account's last password reset in BloodHound and discovering the file was a year stale. Son of a biscuit. The tool that actually cracked it open: Copernic Desktop Search – my pal Jeff McJunkin recommended this to me years ago, I talked about it on the show once, and then inexplicably forgot about it. Not a sponsor, no kickbacks, just a paid tool that's earned its keep. It's basically Google for your hard drive. How I use it – install it on the Windows VM, clear out the default indexing scope entirely, and point it only at the Snaffler dump folder. The top tier (about a hundred bucks a year) will chew through PSTs, DWGs, Office docs, PDFs and more, and it OCRs images too. Indexing took the better part of a day on these engagements, but then search is instant, and it previews basically every file type without Office installed. Years ago this same tool surfaced a photo on a file share of a piece of printer paper where a sysadmin had handwritten a 40-character admin password in Bic pen. OCR for the win. What I search for – the obvious stuff like "password," plus the domain name, "plain text," and things like "=sa" to sniff out SQL admin creds. Nuggets and threads to pull – sometimes a hit is the gold. Other times it just tells you where to go dumpster-diving like a raccoon on the live share. That's how I found upgrade project plans with multiple teams and contractors involved, half-cleaned-up temp work, and high-privilege system, database and local admin creds just sitting there. Worth the hours – these didn't all end in domain admin, but they were rich, real findings, and a great teaching opportunity about what's sitting wide open to Domain Users. (Bonus: Copernic can also point straight at a UNC path with your AD creds and index it live.) Know a free alternative? – one of my favorite parts of doing this podcast is when someone writes in with "hey, there's an open source thing that does that." If that's you, I'd love to hear it! Also, on this week's TuesdayTOOLSday I walked through getting a self-hosted Bitwarden password vault (and file sender) up and running on Linux, and there's now a cheat sheet over at 7MinSec.wiki that'll get you there in about seven minutes – all the commands from the official install guide in one place, with a couple of gotchas flagged. Last thing: subscriptions to 7MinSec.club are free, but paid subs help cover hosting and the time this takes each week, and they're getting some exclusive content soon. No guilt trip here, Mom – I'm going to keep barfing up everything I learn either way. But if you've got the means, I'd sure appreciate it.
Martin Boam, Architect - Centre of Excellence at Microsoft, walks through Microsoft Places, the AI-powered workplace solution for coordinating hybrid work, booking rooms and desks, and optimising space management.• The licensing shake-up: key Places user features now included in Microsoft Teams Enterprise licences from April 2025, plus a new Shared Spaces licence for desk and room booking at four desks per licence• Room reservations with Places Finder and Places Explorer, featuring enriched search with room images, occupancy details, and Microsoft Teams Rooms device information• Desk booking with map-based reservation, multi-day booking, desk pools, finding desks near colleagues, and ad hoc check-in via USB-C peripherals• Automatic work location updates using corporate Wi-Fi, now generally available with admin and user opt-in• Microsoft 365 Copilot integration for natural language scheduling, room finding, and conflict rescheduling via Work IQ• The new Places admin portal replacing PowerShell for managing buildings, floors, desks, auto-release policies, and space analytics• Upcoming investments including deeper Copilot alignment, enhanced location intelligence, and expanded extensibilityThanks to AudioCodes, this episode's sponsor, for their continued support of Empowering.Cloud
Andrew sits down with Fred Weinmann, one of the most prolific PowerShell module authors in the community, for part one of a multi-episode series covering his projects. This episode focuses on the Active Directory Management Framework, or ADMF, a configuration-driven system Fred originally built while working as a field engineer at Microsoft for a large enterprise customer managing hundreds of Active Directory forests. Fred walks through the problem ADMF was designed to solve: Active Directory is notoriously hard to manage consistently across environments, and most organizations just accept the chaos as the cost of doing business. The old approach at this particular customer involved zipping up scripts, RDPing into domain controllers, and running them manually. ADMF changed that by borrowing the test/apply concept from Desired State Configuration, but making it flexible enough to handle the messiness of real-world AD environments. The conversation covers how ADMF is structured around components (like organizational units) and contexts, why generating a reference configuration from an existing environment is harder than it sounds, the protocol juggling required to handle Group Policy and schema updates, and why Fred would use raw LDAP instead of the built-in AD commands if he were starting from scratch today. Fred also touches on the credential provider plugin system, which lets teams plug in their own password management workflows for things like break-glass accounts. Key Takeaways: ADMF follows a test-before-apply model borrowed from DSC, but trades DSC's all-or-nothing enforcement for a more selective, component-by-component approach that better fits the fluid reality of Active Directory management. Generating a configuration from an existing AD environment is tempting but potentially counterproductive. If you auto-generate your desired state from a domain that's accumulated years of cruft, you're not capturing what you want, you're just freezing what already exists. Performance at scale is a real consideration. The built-in Active Directory PowerShell module uses the AD Web Services protocol, which sends XML over the wire. Raw LDAP is significantly faster, and Fred says switching to it is the one architectural change he'd make if building ADMF over again. Guest Bio: Friedrich "Fred" Weinmann is a Cloud Solution Architect at Microsoft and one of the most recognized PowerShell community contributors working today. He is the creator of PSFramework, which underpins many other modules in the ecosystem, as well as tools like PSModuleDevelopment, PSUtil, and the Active Directory Management Framework. Fred is a frequent conference speaker, a longtime community collaborator, and someone Andrew credits with helping shape his own PowerShell journey. Resource Links: ADMF documentation and getting started guide: admf.one ADMF on GitHub: github.com/ActiveDirectoryManagementFramework/ADMF ADMF on PowerShell Gallery: powershellgallery.com/packages/ADMF PSFramework (Fred's logging, configuration, and scripting infrastructure module): psframework.org Fred Weinmann on GitHub: github.com/FriedrichWeinmann Fred Weinmann on X: x.com/FredWeinmann PDQ Community Discord: discord.gg/pdq The PowerShell Podcast on YouTube: https://youtu.be/8SlIqUKP3hY
Jake Hildreth, Principal Security Consultant at Semperis and Microsoft MVP, is back on the podcast fresh off a trip to PowerShell Conference Europe, where he and Andrew co-presented a session on securing PowerShell. Jake also gave his own talk on Stepper, his open-source module for building resumable, step-by-step scripts — a tool that's grown considerably since his last appearance on the show. The two dig into what makes PSConf EU such a standout event, the refreshing lack of elitism in the PowerShell community, and the updates Jake's been shipping, including named steps, built-in logging, and secret suppression. The conversation winds into burnout, the importance of actually taking your vacation days, and how the same mindset that drives good automation — knowing when to stop and reset — applies to taking care of yourself. Key Takeaways: Stepper has gotten some meaningful quality-of-life updates since Jake last appeared on the show, including named steps, automatic logging, and the ability to suppress secrets from logs — making it more practical for real-world production scripts. PSConf EU punches above its weight as a conference experience: technically deep but genuinely welcoming at every skill level, with none of the elitism that can creep into security-adjacent events. Your vacation time is a benefit, not a backlog item. Jake makes the case that getting good at separating your work time from your off time isn't a soft skill — it's a sustainability practice. Guest Bio: Jake Hildreth is a Principal Security Consultant at Semperis, a Microsoft MVP in both PowerShell and Identity/Access, and a recovering sysadmin with 25 years of IT under his belt. He's probably best known for building Locksmith, the open-source AD CS auditing and remediation tool, but he's also the creator of Stepper, Deck, BlueTuxedo, and PowerPUG! — a suite of tools designed to make identity security a little less painful for the admins who live in it. When he's not untangling Kerberos or chasing down ADCS misconfigurations, he goes by "horse" in the PowerShell Discords. Resource Links: Jake Hildreth's Website: jakehildreth.com Jake's GitHub: github.com/jakehildreth Stepper (Resumable PowerShell Scripts): github.com/jakehildreth/Stepper Locksmith (AD CS Auditing & Remediation): github.com/jakehildreth/Locksmith Locksmith 2 (Next-Gen AD CS Toolkit): github.com/jakehildreth/… PowerShell Conference Europe: psconf.eu PDQ Discord: discord.gg/PDQ The PowerShell Podcast on YouTube: https://youtu.be/Rqkuaeps_jM
Hey friends! Fair warning: today's episode is a bit of an emotional rollercoaster — we've got a big security win, some honest lab feedback, and a very personal share about my dad's funeral. Buckle up. CARTP certified, baby! — I'm officially a Certified Azure Red Team Professional (CARTP), courtesy of the folks at Altered Security. It's been a long time coming (I originally signed up for the live version and fell off after missing a couple Saturdays), but I came back for the self-paced 30-day version and finally finished the job. The lab experience — the good: — ~25 objectives, a solid lab guide, and a really fun variety of attack paths. Highlights include stealing tokens, enumerating Azure tenants, attacking apps and VMs and key vaults, simulated phishing against real tenant email addresses, popping reverse shells, and some clever OneDrive-based follow-on attacks via session hijacking. There's even some web app pen testing (hello, server-side template injection!) sprinkled in. The lab experience — the not-so-good: — The included videos are… not my favorite format. Think notepad-on-screen copy-paste tutorials with zero context. To fill in the gaps, I leaned heavily on Claude — pasting blobs of the lab guide and asking things like "why did stealing this token give me X but not Y?" — and it did a great job standing in where a live instructor would normally add color and context. Exam tips (spoiler-free, I promise): — A few things that helped me: I had Claude build me a CliffsNotes study guide from all our study-session chats — token context, command flags, the works. Before hitting start on the 24-hour clock, I fed Claude a list of all the tools I'd been using in the lab and had it build a one-shot PowerShell script to pull them all down from GitHub onto a fresh Windows VM. If your exam lab environment fails to spin up (as mine did in the US region), just try a different region — UK worked great for me. Enumerate. Enumerate. Enumerate. Know your tools, know which ones cover which areas of an Azure tenancy, and know how to get more verbose/tabular output when you need it. Take screenshots and notes as you go — the lab closes after 24 hours and you've got 48 hours to submit your report, so if you forgot to grab a screenshot of a flag… you are SOL, my friend. The exam itself: — I started around 5:30 p.m., wrapped up around 11 p.m., and had the final flag captured, a full Word report drafted, and was in bed at a reasonable hour. Submitted the report the next morning after the gym and a mint hot cocoa, and had my pass confirmation back well within their 7-business-day window. Private pen test training is happening: — I'm currently running a private 3-day session of our Active Directory pen testing class (version 2.0 — it got a big facelift!). It's built on the Game of Active Directory platform and we fully pwn three separate domains over the course of three days. If you can send 3–7 people, reach out at 7MinSec.com/training to line up a private session. I'm also building an interest list for a public version later this fall (reach out if interested)! Also: check out 7MinSec.club — I dropped a little show-and-tell video over on 7MinSec.club this week giving you a peek at what the training looks like in action. Dad's funeral: — I shared some words at my dad's service this past Saturday and wanted to capture them here while they're fresh, since this podcast is basically my journal at this point. The service was perfect — very "him." He'd actually written funeral instructions (yes, they literally sat in a safety deposit box for years) specifying things like: max 10-minute message from the pastor, specific Bible verses, specific songs, and — my favorite — if the service runs over 45 minutes, someone needs to pull the fire alarm. He came up with that final instruction at his brother's funeral, which ran nearly two hours. He leaned over, squeezed my knee and said, "If my service goes over 45 minutes, pull the fire alarm." The song: — I played and sang at the service. The song was "Jesus Savior Pilot Me" — not a personal favorite of my dad's exactly, but he called it "the one about Jesus flying airplanes" after seeing me perform it years ago at the Minnesota State Fair chapel. I practiced it in the car on the way to Caribou every morning until I could get through it without crying. My guitar teacher's advice: close your eyes, focus on your fingers, and pretend you're just playing a tune in a room. It worked. Mostly. Thank you: — Seriously, so many of you have sent kind messages and I just want you to know it means the world. He taught me a lot about being a good dad, a good husband, and how to live with passion, a good attitude about your work, and a heart for serving others.
This show has been flagged as Explicit by the host. SUMMARY The presenter outlines a practical cybersecurity workflow, covering ergonomic setups, browser isolation, virtual machine troubleshooting, AI-assisted scripting, and network tunneling methods utilized during active security assessments. ONE-SENTENCE TAKEAWAY Isolate browser environments, utilize automation scripts, and verify network paths before starting security tests to avoid workflow interruptions. TOOLS Talon Voice – Open-source voice recognition software enabling hands-free computer control and command execution. Obsidian – Local-first markdown note-taking application supporting secure, AI-friendly knowledge management. AutoHotkey – Windows scripting utility for creating custom macros and remapping keyboard inputs. Chrome Debug Commands – Browser developer tools allowing direct inspection of extensions, cookies, and storage. Whisper Diarization – Audio processing script that separates speaker tracks and converts recordings to searchable text. Hyper-V / WSL – Microsoft virtualization platforms enabling isolated guest environments and Linux subsystem integration. OpenConnect / OpenVPN – Command-line tunneling clients used for establishing secure, split-tunnel network connections. Jamboree Framework – Portable PowerShell environment that dynamically provisions development tools without altering system paths. MOBA Portable – Feature-rich terminal emulator supporting static/dynamic tunnels, auto-reconnect, and embedded X-server capabilities. Nmap – Network discovery and security auditing tool utilized for comprehensive port scanning and service detection. 00:00:00 Ergonomic Workspace Configuration Configures physical workstation elements to reduce strain during extended testing sessions. Proper alignment prevents repetitive stress injuries while maintaining focus on technical tasks. Monitor Positioning – Displays should align with eye level to maintain neutral neck posture; the speaker notes their curved 49-inch screen sits slightly high due to chair adjustments. Split Keyboard Layout – Utilizes a Freestyle 2 mechanical keyboard, allowing natural shoulder-width arm placement and reducing wrist deviation during prolonged typing. Postural Adaptation – Acknowledges that ergonomic equipment requires matching body alignment; elbow rests should sit between hip and shoulder height for optimal leverage. 01:45:00 Voice Control & Note Synchronization Utilizes auditory input methods and localized knowledge bases to streamline documentation workflows. Separating secure work notes from casual observations prevents data contamination. Talon Voice Integration – Runs continuously to handle navigation, text entry, and application switching without manual keyboard interaction. Obsidian Migration – Transitions from cloud-based keep apps to local markdown files, enabling direct querying by local AI models while maintaining offline accessibility. Note Categorization – Divides information into secure work records and insecure personal logs, ensuring clean data pipelines for future retrieval and analysis. 03:50:00 Browser Extension Management & Security Isolation Separates web browsing activities from primary work processes to minimize attack surfaces. Running dedicated user profiles prevents plugin conflicts and credential leakage. Jailed User Accounts – Creates restricted system profiles that only launch the browser, isolating extensions from core workstation operations. Shared Folder Synchronization – Establishes a single directory path bridging work and browsing users, allowing seamless file transfers without cross-contamination. Extension Audit Process – Leverages Chrome debug commands to enumerate installed plugins, verifying functionality before deployment on target networks. 06:15:00 Training Optimization & Audio Processing Accelerates mandatory compliance viewing through speed manipulation and automated transcription. Converting video content into searchable text enables rapid information retrieval. Global Speed Control – Increases playback rates up to sixteen times normal speed, drastically reducing time spent on repetitive corporate training modules. Whisper Diarization Pipeline – Downloads video tracks, separates speaker voices, and generates timestamped transcripts for quick reference during assessments. Download Management – Employs multi-threaded swarm downloaders and classic turbo managers to handle bulk media retrieval without interrupting active workflows. 10:40:00 Virtualization & Network Tunneling Protocols Establishes isolated testing environments using Windows virtual machines while managing connectivity constraints. Proper session handling prevents unexpected disconnections during remote engagements. Enhanced Session Mode – A Hyper-V feature providing higher resolution and shared clipboard functionality; disabling it is required before initiating certain VPN clients to avoid routing conflicts. Split Tunneling Mechanics – Routes specific traffic through the virtual network while keeping local resources accessible, preventing complete internet loss during connection tests. Certificate Verification – Identifies self-signed SSL mismatches early in the process, documenting them as preliminary findings before proceeding with authentication steps. 15:30:00 Macro Automation & Input Remapping Remaps frequently used keyboard shortcuts to reduce physical strain and accelerate command execution. Running scripts with elevated privileges ensures reliable input registration across virtual environments. Caps Lock Repurposing – Converts the caps lock key into a primary modifier, assigning copy/paste functions to adjacent letters for faster workflow navigation. Physical Typing Macros – Simulates keystrokes with deliberate delays, allowing seamless data entry into restricted VM consoles that block standard clipboard operations. Administrator Execution Requirement – Highlights that macro scripts must run with elevated privileges to successfully inject inputs across different desktop sessions. 20:15:00 Portable Development Environments & Python Management Deploys lightweight scripting frameworks that dynamically provision necessary tools without modifying host configurations. Verifying package contents prevents dependency conflicts during testing. Jamboree Framework – A PowerShell-driven utility that downloads and configures development stacks on demand, resetting environment variables to maintain system cleanliness. NuGet Package Filtering – Queries Microsoft's repository API to retrieve specific Python versions, ensuring compatibility with legacy tunneling scripts. Binary Verification Process – Checks extracted archives for bundled pip.exe or pip3.exe executables, eliminating manual module installation steps during rapid deployments. 28:40:00 AI-Assisted Scripting & Debugging Workflows Generates and refines PowerShell functions through iterative conversational prompts. Validating AI output against actual system behavior prevents silent configuration errors. Vibe Coding Approach – Relies on continuous feedback loops with language models to draft, minimize, and debug automation scripts in real-time. Parameter Standardization – Enforces strict formatting rules for PowerShell commands, avoiding hardcoded paths and ensuring cross-environment compatibility. Temporary Storage Management – Monitors extraction directories to prevent disk saturation, redirecting large package downloads away from constrained system partitions. 35:10:00 Terminal Emulation & Advanced Tunneling Strategies Facilitates complex network routing through dedicated terminal applications. Configuring dynamic and static tunnels enables reliable reverse connections for remote assessments. MOBA Portable Configuration – Utilizes an INI-based tunnel manager that automatically maintains connections across changing IP addresses or Wi-Fi networks. Reverse Shell Routing – Establishes outbound channels back to the tester, then proxies all subsequent traffic through those connections for consistent monitoring. Proxy Chain Integration – Forces non-proxy-aware applications to route through Burp Suite or custom interceptors using Windows utility wrappers like Priboxy. 42:30:00 Final Connectivity Testing & Engagement Wrap-Up Executes comprehensive port scans to verify target accessibility before documenting findings. Acknowledging workflow detours ensures realistic time management during active engagements. Nmap Verification – Runs full-port scans with verbose output to confirm host responsiveness and identify open services prior to credential testing. Connection Refusal Documentation – Captures screenshot evidence of failed routing attempts, providing clear proof of network restrictions for client reporting. Workflow Reflection – Recognizes that exploratory debugging adds value but requires time boundaries; balancing thoroughness with engagement scope maintains professional efficiency. Provide feedback on this episode.
Andrew sits down with Robert Prüst, a Netherlands-based Microsoft MVP, to geek out about Pester, AI-assisted coding, and the power of showing your work in the PowerShell community. Robert breaks down how Pester works as a testing framework (unit testing, integration testing, and mocking) and explains why testing is the key to trusting AI-generated code. They also dig into a Visual Studio Code extension Robert built for Azure DevOps, the conference culture around PSConf EU, and why community involvement matters as much as technical skill. The conversation wraps with some honest takes on imposter syndrome, learning in public, and the value of just getting started. Key Takeaways: Pester isn't just for unit testing your functions -- it scales all the way up to testing live infrastructure, validating Azure environments, and serving as the backbone of security tools like Maester. The more you invest in it, the more useful it gets. AI-generated code needs a safety net, and Pester is exactly that. Testing gives sysadmins a way to verify what the code is actually doing, which is especially critical when you didn't write it yourself. Imposter syndrome is almost universal in this community, and the people who feel it most are often the ones learning the most. Getting into community spaces -- online or in person -- is one of the fastest ways to grow. Guest Bio: Robert Prüst is a Microsoft MVP and MCT based in the Netherlands, focused on PowerShell, Azure automation, and DevOps. He has around 24 years of professional IT experience and has been working with PowerShell since roughly 2012. Robert is a regular speaker at PSConf EU, blogs at powershellpr0mpt.com, and is active on GitHub under the handle powershellpr0mpt. He runs a custom Azure Engineer bootcamp course and contributes to open source projects including the AMBA and EPAC frameworks. Resource Links: Pester documentation: https://pester.dev Maester: https://maester.dev PSKoans: https://github.com/vexx32/PSKoans PSConfEU: https://psconf.eu PDQ Discord: https://discord.gg/pdq Connect with Andrew: https://andrewpla.tech/links Robert's blog: https://powershellpr0mpt.com Robert on GitHub: https://github.com/powershellpr0mpt Robert on LinkedIn: https://www.linkedin.com/in/rprust/ The PowerShell Podcast on YouTube: https://youtu.be/7Z2Pk0y2Xss
Dan Adams is a 13-year Microsoft 365 and SharePoint veteran who joined Andrew to talk about the often misunderstood world of SharePoint, the shift to Microsoft Graph, and his custom PowerShell module built which can assess and benchmark M365 environments. Dan breaks down why SharePoint gets such a bad reputation (spoiler: it's usually about who built it, not the platform), explains why "everything in M365 is SharePoint" isn't just a meme, and digs into how the Microsoft Graph API is changing the way admins interact with the platform. He also shares his experience going from longtime podcast listener to first-time guest, and closes with some honest advice about reaching out to people in the community. Key Takeaways: SharePoint's bad reputation often comes from poor initial architecture, not the platform itself. Getting the information structure right at the start has downstream effects on everything from Copilot to Purview to legal compliance, and PowerShell automation is only as useful as the metadata you've set up to work with. The Microsoft Graph API is consolidating how everything in M365 is accessed. Where older APIs like the SharePoint client-side object model might count a batch of 100 items as 100 separate API calls, Graph treats that same batch as a single call, which is a meaningful difference for performance and rate limiting. Dan's custom PowerShell module (SP'r Smash Bros Automation) automates M365 permission extraction to produce security assessments against CIS benchmarks and Microsoft Secure Score. Built as a practical tool for consultants and admins, it delivers a fast, standardized baseline of a tenant's security posture, featuring an optional AI sidecar to instantly generate personalized remediation plans. Guest Bio: Dan Adams is a Microsoft 365 and SharePoint Architect with 13 years of M365 consulting experience. Leveraging deep SharePoint and strategic information architecture expertise, he has led teams to deliver over 40 Fortune 500 intranets across industries ranging from healthcare to the NFL. He is the architect behind multiple award-winning portals, including two Ragan "Best Overall Intranet" winners. Dan is also an AI enthusiast, an advanced PowerShell expert, and the creator of the custom "SP'r Smash Bros Automation" module for Microsoft 365. Resource Links: Dan Adams on LinkedIn: https://www.linkedin.com/in/dan-adams-10887650/ Dan Adams on Github: https://github.com/sprsmashbrosautomation Connect with Andrew: https://andrewpla.tech/links PnP PowerShell: https://pnp.github.io/powershell/ PDQ Discord Community: https://discord.gg/pdq The PowerShell Podcast on YouTube: https://youtu.be/OLsTaKC9GmM PowerShell Wednesday Playlist: https://www.youtube.com/watch?v=XQT8lrn8hhU&list=PL1mL90yFExsix-L0havb8SbZXoYRPol0B
Intel Chat with Matt Bromiley and Chris Luft.Matt and Chris break down four stories from the week in threat intel:• Cisco CUCM (CVE-2026-20230) — a web-dialer SSRF that chains to root-level RCE, exploited in the wild less than 24 hours after the PoC and full exploit chain were published.• The latest Ransomware Tool Matrix (RTM) / Ransomware Vulnerability Matrix (RVM) update, profiling three active groups — The Gentlemen, DragonForce and Warlock — and the BYOVD and legit-admin-tool tradecraft they increasingly share.• Gamaredon's upgraded toolkit against Ukraine (per ESET): new PowerShell downloaders like PteroPaste, Cloudflare tunneling and Workers for C2, and exfiltration to trusted cloud storage such as Amazon S3 and Dropbox.• Varonis Threat Labs phishing an AI email agent ("Pinchy") — why agents spot technical phishing better than humans yet hand over credentials to a convincing social request, and why you should treat them as privileged junior employees.Chapters:0:00 Intro & catching up2:25 Cisco CUCM exploited within 24h of the PoC9:57 Ransomware Tool Matrix: The Gentlemen, DragonForce & Warlock15:44 Gamaredon's upgraded TTPs against Ukraine22:18 Can AI email agents be phished?28:08 Wrap-up: Black Hat plans & the LimaCharlie suiteThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Subscribe wherever you listen:• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740• YouTube: https://www.youtube.com/@limacharlieioLearn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #threatintel #ransomware #DFIR
US Puts $10M Bounty on Russian Hackers, Supreme Court Limits Geofence Warrants, New phishing campaign targets hotels, AI Coding Agents Tricked into Malware and Canada's Electronic Spies Go After Ransomware Gangs. The episode covers the US State Department's up to $10 million reward for information on Russia-linked hacker groups UNC 5792 and UNC 4221 tied to phishing campaigns that compromise Signal and WhatsApp accounts by stealing Signal backup recovery keys. It also explains a US Supreme Court 6–3 ruling limiting geofence warrants by recognizing Fourth Amendment privacy protections for phone location data and requiring probable cause and narrower requests. Mozilla ODIN researchers demonstrate a proof of concept where a clean GitHub repo can cause AI coding agents to run an init command that executes attacker-controlled code via DNS and opens a reverse shell. A hotel-focused phishing campaign using Calendly and Google redirects delivers ZIP files that install the Tonrat implant through PowerShell and a user-space Node.js runtime. Finally, Canada's CSE says it disrupted infrastructure used by 10 major ransomware groups and reports incident volumes rising nearly 26% year over year. 00:24 Top Headlines Rundown 00:54 10 Million Bounty Russian Hackers 02:42 Supreme Court Limits Geofence Warrants 03:56 AI Coding Agent Repo Trap 05:31 Listener Thanks And Reviews 05:51 Hotel Front Desk Phishing Attack 08:01 Canada Disrupts Ransomware Gangs 09:45 Closing And Sign Off
Encore presentation: Lessons in Leadership from PowerShell Pioneers Jeffrey Snover and Don Jones In this encore presentation of the PowerShell Podcast from April 28, 2025, we sit down with two legends of the PowerShell world: Jeffrey Snover, the inventor of PowerShell, and Don Jones, bestselling author, teacher, and longtime PowerShell community builder. Recorded live at the PowerShell + DevOps Global Summit, this conversation is packed with personal insights, impactful moments, and the kind of storytelling that only Snover and Jones can deliver. Key topics in this episode include: The origin stories of PowerShell and how Jeffrey and Don's paths crossed at a pivotal moment. The evolution of PowerShell as a scripting language, community, and ecosystem. The importance of storytelling in tech, from teaching to team-building to leadership. The shift from individual contributor to leader and how both hosts navigated that path with intention. The power of community: real stories from users whose lives were changed by learning PowerShell. Career advice for the next generation of IT professionals and community contributors. Along the way, we hear hilarious stories from the early days of PowerShell development, honest reflections on growth and failure, and powerful reminders that vulnerability, repetition, and kindness are core to success in any career. Whether you're new to PowerShell or a long-time community member, this episode is a true masterclass in leadership, learning, and legacy. Bio and links: Jeffrey Snover is the inventor of PowerShell, Microsoft Technical Fellow, and a legendary figure in the IT and DevOps communities. With a background in distributed systems, Jeffrey led the development of PowerShell to revolutionize system management and automation on Windows. Known for his visionary leadership and storytelling, Jeffrey has played a pivotal role in shaping modern IT practices. His work continues to inspire technologists around the world to build, share, and lead with intention and clarity. Don Jones is a bestselling author, speaker, educator, and one of the most influential figures in the PowerShell community. With decades of experience in IT, Don has written numerous foundational books on PowerShell, including Learn Windows PowerShell in a Month of Lunches. He co-founded the PowerShell + DevOps Global Summit and has mentored countless professionals through his teaching, writing, and leadership. Don is a passionate advocate for storytelling in tech, career development, and building inclusive communities that empower the next generation. Resource links: https://www.linkedin.com/in/jeffreysnover/ https://www.linkedin.com/in/concentrateddon/ https://www.linkedin.com/in/andrewplatech/ https://www.powershellsummit.org/ The PowerShell Podcast: https://pdq.com/the-powershell-podcast The PowerShell Podcast on YouTube: https://youtu.be/51w_lWFIfqU
Andrew sits down with Leo D'Arcy, cloud solutions architect and PSConfEU speaker, to talk certificates, PKI infrastructure, and why so many organizations get it so spectacularly wrong. Leo shares how a decade of consulting work in remote access solutions pulled him into the world of Active Directory Certificate Services whether he liked it or not, and how that hands-on experience turned into conference talks and a genuine specialty. The conversation covers the difference between self-signed certs and proper CA infrastructure, why code signing deserves more attention than it gets, and how integrating signing into a CI/CD pipeline is less painful than it sounds. They also get into the "developer-ization" of IT, the underrated value of consulting experience for career growth, and why communicating across teams is just as important as knowing your PowerShell. Key Takeaways: Code signing through a CI/CD pipeline is a practical, scalable alternative to constrained language mode. By adding a signing step to your build process, you get cryptographic proof that scripts haven't been tampered with, without giving up flexibility in what you can run. Self-signed certificates are essentially the same as having no certificate at all. A proper PKI means having a chain of trust, a policy behind how certs are issued, and infrastructure that your organization actually manages and maintains. Technical depth only gets you so far. The people who advance in IT are the ones who can talk networking with network engineers, infrastructure with server teams, and business outcomes with leadership. Soft skills aren't a bonus, they're a multiplier. Guest Bio: Leo D'Arcy is a UK-based cloud solutions architect with nearly a decade of consulting background in Microsoft technologies, including Azure, remote access solutions, PKI, and Active Directory Certificate Services. He's a repeat speaker at PSConfEU and runs the Remote Access User Group community on Discord. He's currently focused on Azure landing zone architecture and large-scale PowerShell automation at a stakeholder advisory firm. Resource Links: Leo on GitHub: github.com/ld0614 PSConfEU: psconf.eu Leo on Bluesky: https://bsky.app/profile/leodarcy.bsky.social Leo on LinkedIn: https://www.linkedin.com/in/leodarcy/ Connect with Andrew: https://andrewpla.tech/links Microsoft Remote Access User Group Discord: https://discord.aovpndpc.com/ The PowerShell Podcast on YouTube: https://youtu.be/BidUaXtwUNM
This week, we are joined by Tom Kellermann, Trend Micro's VP of AI Security and Threat Research, discussing their work on "Inside SHADOW-WATER-063's Banana RAT: From Build Server to Banking Fraud." Researchers from Trend Micro's MDR team uncovered the full operation behind Banana RAT, a sophisticated banking trojan they track as SHADOW-WATER-063, by analyzing both attacker infrastructure and infected victim systems. The malware uses fileless PowerShell execution, layered obfuscation, and remote-control capabilities to steal credentials, manipulate banking sessions, intercept Pix QR code payments, and facilitate financial fraud targeting Brazilian banks. The campaign appears to be operated by a Brazilian Portuguese-speaking cybercriminal group with ties to the broader Tetrade banking malware ecosystem and may be evolving toward a malware-as-a-service model. The research and executive brief can be found here: Inside SHADOW-WATER-063's Banana RAT: From Build Server to Banking Fraud Learn more about your ad choices. Visit megaphone.fm/adchoices
This week, we are joined by Tom Kellermann, Trend Micro's VP of AI Security and Threat Research, discussing their work on "Inside SHADOW-WATER-063's Banana RAT: From Build Server to Banking Fraud." Researchers from Trend Micro's MDR team uncovered the full operation behind Banana RAT, a sophisticated banking trojan they track as SHADOW-WATER-063, by analyzing both attacker infrastructure and infected victim systems. The malware uses fileless PowerShell execution, layered obfuscation, and remote-control capabilities to steal credentials, manipulate banking sessions, intercept Pix QR code payments, and facilitate financial fraud targeting Brazilian banks. The campaign appears to be operated by a Brazilian Portuguese-speaking cybercriminal group with ties to the broader Tetrade banking malware ecosystem and may be evolving toward a malware-as-a-service model. The research and executive brief can be found here: Inside SHADOW-WATER-063's Banana RAT: From Build Server to Banking Fraud Learn more about your ad choices. Visit megaphone.fm/adchoices
In this episode of Command Control Power, the hosts discuss practical IT uses of AI, including improving client communications, speeding email migration due diligence via AI-generated PowerShell reporting (mailbox size, forwarding rules, aliases, naming pitfalls, licensing limits), and reducing billing friction by summarizing recorded RingCentral calls in Claude to log hours and generate detailed invoices, including for Ubiquiti camera projects. They debate risks such as blindly running AI-suggested commands, clients acting on AI advice, and data leakage when employees paste company information into public AI tools, emphasizing guardrails, policies, and potential local/private AI setups (e.g., Mac mini with Ollama). The conversation broadens to AI's impact on IT business models, automation in ticketing, and Apple's lackluster AI progress, delayed Siri features, privacy positioning, and reliance on partners like Google/Gemini. 00:00 Show Kickoff 00:02 New Studio Tour 00:31 Flag Outage Story 01:35 AI Migration Prep 03:26 PowerShell Due Diligence 05:36 Call Summaries Invoicing 07:31 Automating Call Logs 09:35 AI As Expert Helper 11:51 Safety With Commands 12:58 Clients Using AI 13:54 Data Privacy Guardrails 17:17 Industry Shift Fears 20:07 Auto Reply Ticketing 24:18 Local AI Knowledge Base 26:02 AI Eats Software 27:35 Future Of IT Services 29:04 AI Automation Ethics 30:06 Market Pressure On IT 31:03 Apple Intelligence Doubts 33:10 Privacy And Gemini 35:06 Apple Strategy And Mindshare 37:43 MDM Guardrails Needed 39:39 First Mover Myth 43:32 Ubiquity And AirPods AI 47:21 Beta Plans And Rollout 48:06 AI Policy And Profiles 51:32 Wrap Up And Outro
In this episode, Andrew chats with Adriano Carollo at PSConfEU about community, PowerShell Universal, AI, and what happens when you stop lurking and start talking to people. Adriano shares how PowerShell helped him grow from sysadmin into web apps, automation, and open source-style contribution, while Andrew reflects on learning, AI, and why enthusiasm still matters. Key Takeaways: · Community accelerates growth. Adriano came to PSConfEU after hearing Andrew encourage listeners to engage, and the payoff was immediate. · PowerShell Universal can open unexpected doors. Adriano describes using it daily to learn web development concepts like JavaScript, HTML, and React through PowerShell. · AI is most useful when it supports learning instead of replacing it. Both Andrew and Adriano talk about using AI for research, syntax help, documentation, and personal workflows while still valuing hands-on problem solving. Guest Bio: Adriano Carollo is a Berlin-based system administrator and PowerShell enthusiast who uses PowerShell Universal daily. He is active in the PowerShell Universal Discord community and is exploring automation, web apps, self-hosting, and entrepreneurship. Resource Links: PDQ Connect:https://www.pdq.com/pdq-connect/ PowerShell Scanner for PDQ Connect:https://www.pdq.com/blog/the-powershell-scanner-has-arrived-in-pdq-connect/ PowerShell Universal:https://powershelluniversal.com/ PSConfEU:https://psconf.eu/ PDQ Community Discord:https://discord.gg/pdq Adriano C. https://linkedin.com/in/adriano-c-501203213 The PowerShell Podcast on YouTube: https://youtu.be/qLYqUF9gD9s
Automation as Core Strategy: Aarin Bailey on RPA, AI, and Scaling MSP OperationsOn the Evolved Radio podcast, Todd interviews Aarin Bailey, COO at Webit Services and former COO at MSP Bots, about treating automation as a core MSP operating strategy. Aarin describes how his automation focus accelerated around COVID by chaining PowerShell scripts, later expanding into Python, GUIs, and modular systems connected via RESTful APIs, with much of the computation running outside the RMM on servers (including SQL and Python) while the RMM remains mainly a monitoring and job-push layer. They discuss whether RMM is a “zombie product,” the ongoing role of PSA/ticketing as a system of record, and managing complexity through separate modules and staff literacy in Python/RPA. Aarin explains build-vs-buy decisions driven by ROI and fit, cites automated triage/dispatch with ~98% accuracy and shifting token costs, argues AI should augment rather than replace humans, and emphasizes documentation, playbooks, and focusing on operational “bad” anomalies. They also cover client tolerance for AI, limiting client-facing AI after hallucinated ticket notes, skepticism about voice AI, and concerns about AI economics and subsidies.This episode is brought to you by Opsleader Pro. A place for MSP owners and managers to get the systems and tools they need to build a stable and growing MSP. Part group coaching, part peer group, everything you need to run a successful MSP. (00:00) - Automation First Mindset (01:10) - Aaron Origin Story (05:04) - From Scripts to Platforms (05:41) - Beyond the RMM Beehive (08:35) - Is RMM a Zombie (12:14) - Managing Complexity Safely (14:33) - Build vs Buy ROI (19:39) - Token Costs and Pair Coding (23:49) - AI Security Reality Check (27:34) - Scaling with Playbooks (30:12) - Hunt the Bad Stuff (30:59) - Blueprints Before Automation (32:46) - Ticket Volume and Vision (33:32) - Saying No as Integrator (35:44) - Healthy Disagreement Dynamics (37:08) - Client Facing vs Backend AI (40:05) - AI Hallucinations and Guardrails (43:05) - Voice AI and Live Answer (46:06) - Costs and Subsidized AI Era (49:26) - Outcome First and RPA Focus (51:36) - Wrap Up and Thanks
Recorded live at PSConfEU 2026, Andrew sits down with returning guest Miriam Wiesner, Senior Security Researcher at Microsoft, for a wide-ranging conversation on PowerShell security, cookie-based attacks, and the evolving threat landscape. Miriam walks through her two conference talks — one on Microsoft Teams session cookie hijacking (a follow-up to her 2025 Entra ID cookie talk, complete with Cookie Monster branding and actual handcuffs), and a joint session with Stéphane van Gulick on using Microsoft Defender's Live Response feature for incident investigation. The conversation also covers the current state of PowerShell security, why sophisticated attackers are moving away from PowerShell, and why defenders who haven't enabled script block logging and AMSI are leaving easy wins on the table. On top of the technical deep dive, Miriam and Andrew get into the human side of the conference community — nerves before presenting, imposter syndrome, and why showing up is already half the battle. Key Takeaways: Cookie-based identity attacks are an active and growing threat. Microsoft Teams, SharePoint, and OneDrive share session cookies, meaning a single cookie theft can give an attacker broad access across your organization's collaboration tools — no re-authentication required. Sophisticated threat actors are moving away from PowerShell specifically because its security features work. Script block logging, AMSI, and Constrained Language Mode make PowerShell activity highly visible and detectable. If your org hasn't enabled these, you're handing attackers an easy path. Visibility beats prevention. You can't prevent what you can't see. Detection through proper logging is not a consolation prize — it's a core security strategy, and Microsoft Defender's Live Response feature gives teams a powerful way to investigate isolated endpoints without needing RDP or PowerShell remoting enabled. Guest Bio: Miriam Wiesner is a Senior Security Research Program Manager at Microsoft with over 15 years of experience in IT security, penetration testing, and security automation. She works on research behind Microsoft Defender and Sentinel and is the creator of widely used open source PowerShell security tools EventList and JEAnalyzer. Miriam is a sought-after speaker at major security and PowerShell conferences including Black Hat, PSConfEU, and MITRE ATT&CK Workshops. She's also the author of "PowerShell Automation and Scripting for Cybersecurity," published by Packt. Her conference speaker career started at PSConfEU 2018 and she's been a fixture of the community ever since. Resource Links Miriam's 2025 Cookies talk - https://www.youtube.com/watch?v=8xDcq0pPNPs Book – PowerShell Automation and Scripting for Cybersecurity (Packt): https://www.amazon.com/PowerShell-Automation-Scripting-Cybersecurity-Hacking/dp/1800566379 Miriam on LinkedIn: https://www.linkedin.com/in/miriamwiesner Miriam on X/Twitter: https://x.com/MiriamXyra Miriam's GitHub (EventList, JEAnalyzer, and more): https://github.com/miriamxyra Miriam's Website: https://miriamxyra.com Connect with Andrew: https://andrewpla.tech/links The PowerShell Podcast on YouTube: https://youtu.be/zxJOqcEwgWE
Frank Lesniak joins Andrew Pla for a wide-ranging conversation that covers Frank's newly minted Microsoft MVP status, his journey through PowerShell, and what it looks like to build a real presence in the tech community. Frank talks through the pipeline struggles that tripped him up early on, how his VB Script and object-oriented background made the shift to PowerShell's object model feel disorienting, and how AI has quietly changed the way he approaches scripting today. The conversation takes a thoughtful turn as Andrew and Frank dig into impostor syndrome, the value of conference speaking, and how showing up consistently in the community compounds into a career. Frank also shares an update on DuPage Animal Friends, the nonprofit he serves, which supports one of the country's highest-performing open-admission animal shelters. Key Takeaways: The PowerShell pipeline is one of the most commonly cited stumbling blocks for newcomers, especially those coming from text-based scripting backgrounds. Learning to visualize what your objects look like at each stage of the pipeline, using tools like Get-Member, is a skill that pays dividends long term. Showing up at conferences and user groups, even when you feel underprepared, is how you build the reps that eventually make it feel natural. Frank's consulting background gave him a head start on presentation skills, and he's clear that no one is born polished. Community involvement and career growth are more connected than they might look from the outside. Engaging with people on GitHub, at events, and through open source creates a feedback loop that builds confidence and opens doors. Guest Bio: Frank Lesniak returns to The PowerShell Podcast, this time as a Microsoft MVP (Microsoft Azure, PowerShell). Frank is a Sr. Cybersecurity & Enterprise Technology Architect at West Monroe, where PowerShell runs through client work on corporate M&A: carve-outs, tenant-to-tenant migrations, identity consolidation, endpoint moves, and security posture improvement across Microsoft 365, Azure, Entra ID, Active Directory, Intune, Defender, and Windows. Beyond consulting, Frank speaks at technical conferences, mentors first-time speakers, and publishes open-source PowerShell standards and tooling, including PSStyleGuide, GloryRole, and PSConnMon. His public work threads least-privilege identity, cloud role mining, cross-platform observability, and high-quality AI-assisted development through standards, automated tests, and automated code quality reviews. Connect with Frank: https://linktr.ee/franklesniak Connect with Andrew: https://andrewpla.tech/links PSConnMon - PowerShell Network Monitoring - https://github.com/franklesniak/PSConnMon/ GloryRole - Automating Least-Privlege Azure and Entra ID Directory Roles - https://gloryrole.com PowerShell Style Guide - https://github.com/franklesniak/PSStyleGuide PowerShell Style Guide + Coding Agents Lightning Talk - https://github.com/devops-collective-inc/pshsummit26/tree/main/PowerShellStyleGuideForCodingAgentsAndHumans-Lesniak Coding Agent Accelerator Template Repo (Coming Soon!) - https://github.com/franklesniak/copilot-repo-template ProStateKit - the DSC v3-Intune Starter Kit - https://github.com/franklesniak/ProStateKit ProStateKit Promotional Commercial - https://www.youtube.com/watch?v=cA5vMH522F0 macOSLab - Automating Legit macOS VMs - https://github.com/franklesniak/macOSLab DuPage Animal Friends - https://www.dupageanimalfriends.org/ PDQ Discord: https://discord.gg/pdq The PowerShell Podcast: https://www.pdq.com/resources/the-powershell-podcast/ Previous episodes with Frank Lesniak: https://powershellpodcast.podbean.com/?s=Frank+Lesniak The PowerShell Podcast on YouTube: https://youtu.be/Eg-uEGaurmY
In this episode, host Andrew Pla sits down with Mark Littlefield, VP of Product at PDQ, for a wide-ranging conversation about product management, the PowerShell community, and what it looks like to deeply learn a technical domain when you're not coming from a traditional sysadmin background. Mark shares his journey from tech support to product management, what drew him to PDQ and the challenges facing IT admins, and what surprised him about PowerShell once he started paying close attention. The two also dig into the history behind PDQ Connect's PowerShell Scanner, how product teams learn from customers, the art of storytelling as a PM and sysadmin skill, and more. Key Takeaways: Product management and PowerShell automation share a core philosophy: solve problems at the root, not just on the surface. Whether you're writing a script or building a feature, the goal is to eliminate a challenge entirely rather than patch around it. Understanding your customer requires more than data — it requires immersion. Mark describes going deep into the sysadmin world through customer interviews, internal usage, and community engagement to truly understand the problems facing IT teams. Great storytelling is a transferable skill. Andrew draws a parallel between how Jeffrey Snover used the Monad Manifesto to get internal buy-in at Microsoft and how to use narrative to align teams and push ideas forward. Guest Bio: Mark Littlefield is the VP of Product at PDQ, where he leads product strategy and development for PDQ Connect and the broader PDQ product suite. With over 15 years of product management experience, Mark previously served as VP of Product Management at InsideSales.com, where he oversaw product management and design across the platform. He holds a Bachelor of Science in Information Systems with a focus on Business Intelligence from Utah Valley University and is based in Salt Lake City, Utah. Resource Links: PowerShell Event: https://www.pdq.com/save-time-with-powershell-pdq-connect/ PDQ Connect: https://www.pdq.com/pdq-connect/ PDQ PowerShell Scanners GitHub repository: https://github.com/pdqcom/PowerShell-Scanners The Monad Manifesto (Microsoft Learn): https://learn.microsoft.com/en-us/powershell/scripting/developer/monad-manifesto?view=powershell-7.5 Monad Manifesto blog post by Jeffrey Snover: https://devblogs.microsoft.com/powershell/monad-manifesto-the-origin-of-windows-powershell/ Mark Littlefield on LinkedIn: https://www.linkedin.com/in/mark-littlefield/ Connect with Andrew: https://andrewpla.tech/links PDQ Discord: https://discord.gg/pdq The PowerShell Podcast on YouTube: https://youtu.be/fo2V5LC-EZo
In the security news this week: FCC router bans and the hidden firmware update problem Why extending support timelines actually improves security Github supply chain concerns and the evolving SBOM ecosystem CRA and NIS2 compliance deadlines are getting very real The EU Cyber Resilience Act's 24-hour vulnerability disclosure requirement Security regulation: vertical vs horizontal compliance models Vehicle-to-load EV systems powering homes during outages Solar, batteries, AI farms, and the future economics of electricity Data centers consuming regional power grids BitLocker “Yellow Key” fallout and large-scale remediation challenges AI-generated PowerShell fixes and the rise of vibe scripting Linux kernel exploits, module jail, and default deny strategies Medical biometric data theft and why fingerprints are terrible passwords Interpol cybercrime operations across the MENA region OT security, connected vehicles, and accepting real-world risk The crew also discusses threat intelligence obligations under the CRA, the operational realities of patching at enterprise scale, the economics of secure-by-default systems, and why making security cheaper than insecurity might finally move the industry forward. Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-927
In the security news this week: FCC router bans and the hidden firmware update problem Why extending support timelines actually improves security Github supply chain concerns and the evolving SBOM ecosystem CRA and NIS2 compliance deadlines are getting very real The EU Cyber Resilience Act's 24-hour vulnerability disclosure requirement Security regulation: vertical vs horizontal compliance models Vehicle-to-load EV systems powering homes during outages Solar, batteries, AI farms, and the future economics of electricity Data centers consuming regional power grids BitLocker "Yellow Key" fallout and large-scale remediation challenges AI-generated PowerShell fixes and the rise of vibe scripting Linux kernel exploits, module jail, and default deny strategies Medical biometric data theft and why fingerprints are terrible passwords Interpol cybercrime operations across the MENA region OT security, connected vehicles, and accepting real-world risk The crew also discusses threat intelligence obligations under the CRA, the operational realities of patching at enterprise scale, the economics of secure-by-default systems, and why making security cheaper than insecurity might finally move the industry forward. Show Notes: https://securityweekly.com/psw-927
In the security news this week: FCC router bans and the hidden firmware update problem Why extending support timelines actually improves security Github supply chain concerns and the evolving SBOM ecosystem CRA and NIS2 compliance deadlines are getting very real The EU Cyber Resilience Act's 24-hour vulnerability disclosure requirement Security regulation: vertical vs horizontal compliance models Vehicle-to-load EV systems powering homes during outages Solar, batteries, AI farms, and the future economics of electricity Data centers consuming regional power grids BitLocker "Yellow Key" fallout and large-scale remediation challenges AI-generated PowerShell fixes and the rise of vibe scripting Linux kernel exploits, module jail, and default deny strategies Medical biometric data theft and why fingerprints are terrible passwords Interpol cybercrime operations across the MENA region OT security, connected vehicles, and accepting real-world risk The crew also discusses threat intelligence obligations under the CRA, the operational realities of patching at enterprise scale, the economics of secure-by-default systems, and why making security cheaper than insecurity might finally move the industry forward. Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-927
It's PowerShell After Dark. Recorded live at the PowerShell & DevOps Global Summit in Bellevue, Washington, host Andrew Pla takes his mic to the hotel bar for a series of candid conversations with attendees. The episode features four guests: Josh Gratton, an OnRamp scholarship recipient whose career pivot to junior systems engineer was fueled by PowerShell and the podcast; Mark Go, a first-time Summit speaker and attendee; Craig Mileham, a fellow podcast listener and Summit first-timer working in higher ed IT; and Matt Zaske, a longtime community member, conference speaker, and IoT enthusiast who ran a Home Assistant lightning demo. What connects all four conversations is the same thread Andrew keeps pulling on: community makes everything better. Beginners belong here. Reach out. Take the risk. Start now. Key Takeaways: The OnRamp scholarship program is genuinely life-changing for early-career IT professionals. Josh Gratton's story, from service desk to systems engineer to Summit attendee, is a direct line from PowerShell to career transformation, and it started with applying for a scholarship he poured his heart into. Showing up in person changes something. Every guest in this episode described the in-real-life version of the PowerShell community as warmer, more welcoming, and more accessible than they expected. The gap between "online community" and "your people" closes fast when you're in the same room. Reaching out is not just encouraged, it's the move. Andrew makes the case clearly: the people who message him, who post in Discord, who ask questions in public, those are the ones he sees succeed. Suffering in silence is optional. So is waiting. Guest Bios: Josh Gratton is an IT professional who made a mid-career pivot from 15 years in a different field to the service desk, then leveraged PowerShell automation to earn a promotion to his company's systems engineering team. A 2026 OnRamp scholarship recipient, Josh attended his first PowerShell & DevOps Global Summit in Bellevue and left planning to present at a future Summit and bring a colleague along next year. Mark Go is an IT professional and active member of the PDQ Discord community who attended the 2026 PowerShell & DevOps Global Summit. He served as Andrew's cameraman during the Summit's After Dark session and is known in the community for his IoT work, including speaking at Summit. He's a returning podcast guest, Powershell Wednesday and Summit speaker. Mark brings a hardware-forward perspective to PowerShell, with interests in soldering and embedded systems. Craig Mileham is a PowerShell Podcast listener and Summit first-timer who works for an MSP in the higher ed space. He attended this year's Summit to absorb as much as possible and left energized to build internal tools for his help desk team and share what he learned at PowerShell Wednesday. This guy is really awesome Matt Zaske is an IT professional, conference speaker, and community member based in Minnesota. A regular presence at events like MMS, Matt is also an avid Home Assistant enthusiast who bridges the gap between PowerShell and IoT hardware. He ran a lightning demo at the 2026 Summit, taught attendees how to solder, and blogs regularly at mzonline.com. You can also find him on LinkedIn and Bluesky. 3d printing legend. GET ON HIS LEVEL Resource Links: PowerShell & DevOps Global Summit: https://www.powershellsummit.org OnRamp Program and Scholarship: https://www.powershellsummit.org/on-ramp/ The PowerShell Podcast on PDQ.com: https://www.pdq.com/resources/the-powershell-podcast/ PDQ Discord (Learn PowerShell channel): https://discord.gg/PDQ PDQ Careers: https://www.pdq.com/jobs/ Connect with Andrew Pla: https://andrewpla.tech/links Matt Zaske's Blog: https://www.mzonline.com The PowerShell Podcast on YouTube: https://youtu.be/Y_GDB0e8xHY
Jess Pomfret returns for her third appearance on the PowerShell Podcast and brings the same energy that keeps people coming back. She and Andrew cover a lot of ground, starting with her upcoming "Chase the Sun" charity cycling event where she'll attempt to ride 205 miles coast-to-coast across the UK in a single day, starting at sunrise on the longest day of the year and racing the sun to the finish line. It's a big undertaking, and she's riding to raise money for Momentum in Fitness, a charity her wife works for that brings fitness opportunities to older adults, kids in non-traditional school settings, and children with cancer. On the technical side, Jess makes the case for PowerShell splatting as an underrated beginner concept that makes code dramatically more readable. She walks through the idea of pulling parameters out of a long command line, organizing them into a hash table, and passing that hash table to the command instead. It's one of those things experienced scripters take for granted, but seeing it for the first time is genuinely useful. The conversation also gets into Desired State Configuration (DSC), where Andrew and Jess dig into what it is, how it works, and why it matters for sysadmins who want to maintain consistent configuration across their environments. Jess also opens up about managing a packed schedule between her day job, speaking, podcasting, LinkedIn Learning courses, and serious bike training. Her answer is honest and relatable: she's still figuring it out, but Todoist and a very supportive partner help a lot. Key Takeaways: Splatting is one of the most readable improvements you can make to your PowerShell code. Instead of chaining parameters into one long command, you load them into a hash table and pass that to your command with an @ symbol. Cleaner to write, easier to read, and especially useful when you're sharing code on a screen. DSC lets you define what a system should look like and PowerShell handles the work of getting it (and keeping it) there. It's a mindset shift from scripting manual steps to declaring an end state, and it's particularly powerful in large environments where consistency matters. Having a support system is one of the most underrated factors in being able to sustain a high-output career alongside community contributions. Whether it's people around you who help carry the load or finding your people in the data and PowerShell communities, you can't do it alone indefinitely. Guest Bio: Jess Pomfret is a Data Platform Engineer and a dual Microsoft MVP. She's been working with SQL Server since 2011, is a maintainer on the dbatools open source project, co-host of the Finding Data Friends podcast, and a LinkedIn Learning instructor. She grew up in the south-west of England and now lives in the US. Outside of tech, she's an avid cyclist, padel player, and a devoted fan of proper football. Resource Links: Connect with Jess on LinkedIn: https://www.linkedin.com/in/jpomfret Connect with Andrew: https://andrewpla.tech/links Jess's blog: https://jesspomfret.com Support Jess's Chase the Sun ride for Momentum in Fitness: https://www.justgiving.com/page/jess-pomfret Finding Data Friends podcast on YouTube: https://www.youtube.com/@findingdatafriends/videos dbatools – PowerShell module for SQL Server automation: https://dbatools.io Jess's previous episode on the PowerShell Podcast (Ep. 164): https://powershellpodcast.podbean.com/e/from-proper-football-to-databases-with-jess-pomfret/ Jess's first appearance on the PowerShell Podcast: https://powershellpodcast.podbean.com/e/dbatools-with-jess-pomfret/ Join the PDQ Discord: https://discord.gg/pdq The PowerShell Podcast on YouTube: https://youtu.be/M2XvvCKs1Ls
Hello friends! Picking up the AI-automation series from a couple weeks back — here's another batch of scripts and integrations that have been giving me precious minutes (and sanity) back. Yes, I had to upgrade to Claude Max. No, I'm not trying to automate myself out of a job — just freeing up bandwidth for the more interesting parts of work/life. QuickBooks invoice automation: Got tired of the eight-factor login plus click-fest just to send a few invoices. Now I run a PowerShell menu — type the client name, pick the project, enter the amount, hit Enter — done in ~30 seconds. The QuickBooks dev onboarding (security questionnaire, IP allowlist) was actually a bigger time sink than the script itself. Password Pusher API integration: A menu-driven PowerShell script that prompts for a label, pops an Explorer window to grab the files, optionally adds a password, then auto-drafts the client email with the secure link filled in. A few minutes saved each time, a couple times a day — adds up to some nice time saved! Basecamp + Claude: Linked Basecamp into a Claude project so I can ask plain-English questions like "what personal project tasks are due this month?" or just voice-note a new task while I'm in the car. Honestly the biggest win is anxiety reduction — once it's in Claude, it's out of my always-simmering pressure cooker of a brain. Blumira agent auto-installer for the GOAD lab: I revert the GOAD lab to vanilla a couple times a week, which means re-installing Blumira agents constantly to show clients the attack/defense telemetry side. Wrote a Kali-side script that uses NetExec over WinRM to check each box for the Blumira service and push the installer if it's missing. (Tried SMB exec first, but escaping got wonky on the PowerShell one-liner.) Bonus: Blumira's dashboard auto-removes agents that haven't phoned home in 24 hours, which is a perfect fit for a lab that's constantly getting nuked. Auphonic + API for podcast production: This one's a little meta. Old workflow: record → drag into Hindenburg/GarageBand → manually line up intro and outro → noise reduction → export. New workflow: one terminal script that previews the first and last few seconds so I can trim silence, ships the audio to Auphonic via API, and returns a cleaned-up, levels-corrected MP3 plus a full transcript and auto-generated chapter markers. (If your podcast app supports chapters (like Downcast) pop open this episode or #720 and you'll see them.) Next step: pipe the transcript straight into Claude for a show notes first draft. One quick personal note before I run: my oldest son just landed an EMT job with a great Minnesota medical network, and is wrapping up paramedic school in a few months. I cried some happy dad tears today.
Paula Kingsley, a senior IT leader, longtime consultant, automation and PowerShell enthusiast, eight-time Microsoft MVP for Exchange Server, and happy generalist, joins Andrew for a wide-ranging conversation about her tech journey and what it actually looks like to grow from deep hands-on work into technology leadership. They kick things off with a topic near and dear to a lot of PowerShell folks: the ISE-to-VS Code migration. Paula was terrified of it, put it off for as long as she could, and now uses VS Code every single day. From there, the conversation opens up into what consulting taught her about solving problems, how being a generalist can be a genuine advantage, why documentation and communication matter as much as technical skill, and what it means to keep the human side of technology alive as you move up. Paula also drops some solid practical PowerShell wisdom along the way, from always including WhatIf support in your functions to the very important reminder that Get is safe and Set is something else entirely. Key Takeaways: Making the jump from ISE to VS Code feels daunting, but the move is absolutely worth it. The secret is forcing yourself to open it first and just leaving it open until the habit takes hold. Being a generalist isn't a weakness. The ability to see across systems, communicate up and down, and translate technical work into business outcomes is a real and undervalued skill. Always build yourself an escape route. WhatIf and ShouldProcess aren't just best practices, they're the difference between a confident deployment and a very bad afternoon. Guest Bio: Paula Kingsley is an outcome-driven senior IT leader, technology operations and engineering expert, eight-time Microsoft MVP for Exchange Server, and self-described happy generalist. Her path into tech started with a liberal arts degree and eventually led through boutique IT consulting, enterprise infrastructure, global production operations, automation, cloud, AI, and a deep appreciation for PowerShell. Paula has built her career around solving problems, simplifying workflows, removing friction, and helping technical teams work better at scale. She is senior enough to shape strategy and steer practices, still hands-on enough to fix things herself, and yes, she even likes regex. You can find her on GitHub as lanwench and on LinkedIn. Resource Links: Paula Kingsley on LinkedIn – https://www.linkedin.com/in/paulakingsley/ Paula Kingsley on GitHub – https://github.com/lanwench Connect with Andrew – https://andrewpla.tech/links/ PDQ Discord – https://discord.gg/pdq The PowerShell Podcast on YouTube: https://youtu.be/WLNVCW7S8BE
Hey friends! Today's another Tales of Pentest Pwnage! Quick tangent first on a couple side projects: I've got a music thing at quack.house (like the duck noise, not the drug) and a podcast with my dancer son Atticus at DadOfADancer.com. Speaking of Atticus — he just landed a spot in Master Ballet Academy's summer program in Phoenix, and I am a very proud dance dad over here. OK, on to the pentest: A weird runas quirk: If your AD test account password ends in a percent sign, runas seems to misbehave (Claude thinks Windows is interpreting the % as a variable delimiter). Workaround: runascs.exe, which wraps your tool launch with creds inline. Worked like a champ — notes over on the 7MinSec.wiki. Standard first pass: PingCastle for the AD overview, then Snaffler for share crawling, with Chimas as a nicer web UI for searching the Snaffler JSON. The "Snaffler missed something" moment: Snaffler is great but it primarily uses pattern matching, so manual review of interesting directories still matters. I found a PowerShell script with a funky obfuscation routine, fed it to Claude for context, tracked down the function definition, and ended up decrypting a local admin password. Going loud: SMB-sprayed that cred across the subnets → handful of machines popped → ran a deeper, targeted Snaffler against just those boxes → enumerated sessions and spotted a domain admin interactively logged in. Plan A fizzled: Wanted to pull off a favorite trick — sneak in via WinRM and queue a scheduled task as the logged-in DA (no password needed). WinRM was disabled. Oh fart. Plan B — the "trap" file: Dropped a malicious .library-ms file directly into the DA's desktop folder. No clicks required — just the desktop being open is enough to trigger an HTTP coercion to my evil box. (Caveat: I think you need a DNS record or computer object that the victim box trusts as "intranet zone.") The escalation: Had ntlmrelayx standing by, ready to relay to LDAP on a DC. The coerced auth fired the moment the "trap" file landed on disk. An interactive LDAP shell fired in the DA's context, and I used it to add my low-priv account to the Domain Admins group. Defense angles: Rather than chase each technique individually (LDAP signing, web client GPOs, library-ms neutralization, etc.), I like to back up to the systemic fixes that break the chain earlier. Big ones here: deploy LAPS so a single decrypted local admin password isn't a master key everywhere, and a thorough sweep for sensitive data and custom obfuscation routines hanging out on shares. Got thoughts on any of this? Shoot 'em over — I always love hearing how you'd have tackled things differently.
This episode of the PowerShell Podcast After Dark captures two candid bar-session conversations from the PowerShell and DevOps Global Summit, centered on community, career growth, and the real-world value of putting yourself out there. In the first segment, Josh Dearing talks about attending his first Summit, building PowerShell modules, learning from failure, and using automation to improve systems and processes in higher education. In the second, Jeff Wardlaw reflects on finally attending the event in person, the impact of meeting the people behind the tools and community, and the broader lessons around perspective, technical leadership, communication, and problem-solving. Across both conversations, the theme is clear, PowerShell is not just a toolset, it is a way into a generous technical community where curiosity, experimentation, and shared learning can meaningfully shape a career. The PowerShell Podcast on YouTube: https://youtu.be/NyT_A1hSH_M
Lucas Allman joins the PowerShell Podcast for a conversation that starts with practical beginner wins and builds into bigger questions about AI, learning, community, and career growth in IT. The episode covers hands-on PowerShell use cases like event logs, scheduled tasks, and writing functions directly in the terminal, then shifts into Lucas's experience as a first-time PowerShell Summit speaker and his evolving perspective on AI as a tool for both productivity and learning. It lands on a strong human note, with Lucas reflecting on impostor syndrome, keeping up with change, and why curiosity and community still matter just as much as technical skill. Key Takeaways: · Event logs are a great early PowerShell win. Lucas walks through using Get-WinEvent to explore logs, filter for errors, search messages, and troubleshoot faster without waiting on the Event Viewer GUI. He also shares a practical tip for reusing XML or XPath filters from Event Viewer inside PowerShell scripts. · You can do more from the terminal than most people realize. Lucas explains how he writes full functions directly in the interactive shell, then saves them with a custom helper function so good code does not disappear when the session closes. It is a simple idea, but it opens the door to faster experimentation and building tools in the flow of work. · AI is changing how technical people work, but not eliminating the need for judgment. A big part of the Summit discussion centered on using AI as a collaborator, not a replacement. Lucas argues that the real opportunity is to offload repetitive work, learn faster, and free up more time for higher-value problem solving, while still applying technical knowledge and critical thinking to the results. Guest Bio: Lucas Allman is an IT automation specialist with a passion for building practical, scalable solutions using PowerShell. With deep experience in endpoint management, configuration as code, and Microsoft cloud services like Intune and Graph API, Lucas focuses on making complex workflows maintainable, secure, and efficient. He's an advocate for knowledge sharing and enjoys helping others level up their scripting and automation skills through real-world examples and interactive problem-solving. He had ChatGPT write this bio and says it's close enough. Resource Links: · Lucas Allman website: https://lucasallman.com · Connect with Andrew: https://andrewpla.tech/links · PDQ Discord: https://discord.gg/PDQ · PowerShell.org GitHub organization: https://github.com/powershellorg The PowerShell Podcast on YouTube: https://youtu.be/kcjkCS0QN64
At the PowerShell and DevOps Global Summit, this after-dark bar session blends casual conversation with a real sense of why the event matters. Brian Quinn talks about returning for his second Summit, filling in PowerShell fundamentals, and bringing back practical skills like remoting, advanced functions, modules, testing, and version control to improve how his team handles identity and access management. Scott Lemonde reflects on what keeps drawing him back, not just the technical knowledge, but the community, the friendships, and the way Summit gives people confidence, perspective, and momentum in their careers. Across both conversations, the theme is clear: PowerShell is not just a tool, it is a shared journey of growth, automation, problem-solving, and finding your people in a field that can otherwise feel pretty isolating. See the PowerShell Podcast on YouTube: https://youtu.be/akrQSKoKjDI
This episode captures the energy of PowerShell Summit through two conversations, one with Gilbert Sanchez and one with Joshua Dearing. The discussion moves from open source maintenance and the future of PowerShell in AI workflows to the human side of technical communities, including burnout, neurodiversity, mentorship, and the value of showing up in person. It also highlights how PowerShell can change careers over time, not just by teaching syntax, but by opening doors to better communication, stronger community ties, and bigger technical thinking. Key Takeaways: · Community is often the unlock, not just the tooling. Both conversations reinforce that Summit's real value is the people, the hallway conversations, and the sense that learning gets easier when you have others around you who are willing to help. · Sustainable technical growth matters more than short bursts of output. Gilbert talks about burnout, open source maintenance, and creating healthier ways to contribute, while Andrew connects that to ADHD, mental health, and building a career that can last. · PowerShell is a starting point for much bigger opportunities. Joshua's story, from community member to module author, reflects a broader theme in the episode that small steps, taken consistently, can completely reshape what kind of work you can do and who you can become in the field. Guest Bio: Gilbert Sanchez is a Staff Software Development Engineer at Tesla, specifically working on PowerShell. Formerly known as "Señor Systems Engineer" at Meta. A loud advocate for DEI, DevEx, DevOps, and TDD. Resource Links: · PSake: https://psake.dev · Gilbert Sanchez links: https://links.gilbertsanchez.com · Gilbert Sanchez blog: https://gilbertsanchez.com Josh is a systems administrator with a philosophy degree and a helpdesk origin story. He's a speaker, open source contributor, creator of ModuleExplorer, and a PDQ Sysadmin Hall of Fame winner. He's a firm believer that the best script is the one you don't keep to yourself. · Joshua Dearing's website: https://dearing.dev The PowerShell Podcast on YouTube: https://youtu.be/XJAbZgOVMF4
With PowerShell + DevOps Global Summit 2026 opening this Monday, April 13th, this episode brings back one of the most respected names in the PowerShell community: Jeff Hicks. Andrew sits down with Jeff to dig into what makes the Summit special, the organic community that grew from those earliest events, and what it actually feels like to watch people go from struggling beginners to confident PowerShell practitioners. They also get into the big question hanging over everyone in IT right now: what does AI actually mean for the future of PowerShell professionals? Jeff shares his take on the "squishy bits" of scripting that AI still can't replicate, why learning the core PowerShell paradigm matters more than ever, and how he personally uses AI as a collaborator rather than a shortcut. It's a conversation about community, craft, and what it means to actually know your tools. Key Takeaways: Learn the foundation first, tools second. Jeff's consistent message over decades of teaching: don't start with Azure commands or specific modules. Start with the PowerShell paradigm — objects, the pipeline, managing at scale — and the rest becomes much easier to pick up over time. AI is a co-pilot, not a replacement. Jeff uses AI to get over specific technical hurdles, not to generate finished code. His concern isn't that AI will write bad scripts — it's that the next generation may skip the foundational learning that lets you recognize when AI gets it wrong. The PowerShell community is genuinely welcoming, and showing up matters. Whether it's Summit, a local user group, or Discord, getting into rooms with other PowerShell people can be a career changer. The hallway conversations are half the value. Guest Bio: Jeff Hicks is a veteran IT professional with 35 years of experience, a long-time Microsoft MVP, and one of the most recognized voices in the PowerShell community. He's the author and co-author of several foundational PowerShell books, a Pluralsight course creator, and the publisher of the premium newsletter Behind the PowerShell Pipeline. He's been teaching and writing about PowerShell since the very beginning and continues to focus on the human side of scripting — the parts that go beyond syntax and into craft. Resource Links: Jeff Hicks' hub (links to everything): https://jdhitsolutions.github.io Behind the PowerShell Pipeline (newsletter & book on Leanpub): https://leanpub.com/behind-the-pspipeline Jeff's Pluralsight courses: https://app.pluralsight.com/profile/author/jeff-hicks Connect with Andrew: https://andrewpla.tech/links PowerShell + DevOps Global Summit 2026 (April 13-16, Bellevue, WA): https://www.powershellsummit.org PDQ Discord (PowerShell scripting channel): https://discord.gg/pdq PowerShell Wednesday (weekly on PDQ's YouTube/Discord): https://www.youtube.com/watch?v=5vdfFswmREQ&list=PL1mL90yFExsix-L0havb8SbZXoYRPol0B&pp=0gcJCbcEOCosWNin The PowerShell Podcast on YouTube: https://youtu.be/ceB-3QGbvBA
Everyone's chasing the next big model drop.