MIT Sloan AI Adoption: Build a Playbook That Drives Real Business ROI
Stuck in Tutorial Hell? Learn Backend Dev the Right Way
Overview
Google, IBM & Meta Certificates — All 10,000+ Courses at 40% Off
One annual plan covers every course and certificate on Coursera. 40% off for a limited time.
Get Full Access
Learn to investigate Windows processes using PowerShell for cybersecurity incident response and threat hunting in this 23-minute tutorial. Explore the fundamentals of what processes are and why analyzing them is crucial during live endpoint investigations, as malware must run as processes or hide within active processes during intrusions. Master legacy process enumeration techniques before progressing to modern PowerShell cmdlets like Get-Process for comprehensive process analysis. Understand the Filter Left Principle to optimize your queries and improve performance when investigating large numbers of processes. Practice filtering techniques using the PowerShell pipeline to narrow down suspicious processes and identify potential threats. Discover how to use Get-CimInstance for more detailed process information and advanced querying capabilities. Develop skills in decoding command lines to understand what processes are actually executing and identify potentially malicious activity. Gain practical knowledge of PowerShell commands and techniques that security analysts use during real-world incident response scenarios to quickly identify and analyze suspicious processes on Windows endpoints.
Syllabus
0:00 - Introduction
1:14 - What are Processes?
2:20 - Legacy Process Enumeration
5:58 - Get-Process
7:52 - The Filter Left Principle
9:55 - Filtering with the Pipeline
13:30 - Get-CimInstance
17:45 - Decoding Command Lines
20:28 - Conclusion
Taught by
The Cyber Mentor