PowerShell Notes

There are two categories of PowerShell command:

  • External Command: For example, CMD commands, or programs launched from PowerShell. Output is in plain text. They run as separate processes to PowerShell.
  • Native Command: These are relatively easy to discover, as all can be listed within the PowerShell command line. These return objects, not just text. Commands have a naming convention and format.

Native commands typically follow this format:

Command-Name -Parameter Value

Searching for PowerShell Commands

We can get a list of native PowerShell commands with Get-Command. e.g.

Get-Command -Name *user*
Get-Command -Name *security*

We can also use -Verb and -Noun in addition to -Name.

The -Syntax option can be used to show the usage and parameters of a given command.

If more information is needed, help is provided by Get-Help. e.g.

Get-Help -Name *user*

PowerShell Help

The information about a command is presented in very much the same way as with the Linux command line, by default.

Get-Help [command]

or: [command] -?

More comprehensive information can be displayed by appending the following to the Get-Help command:

  • Examples
  • Detailed
  • Full
  • Online
  • ShowWindow

e.g.

Get-Help Get-Host -Full

In PowerShell ISE, the ‘-ShowWindow’ option will display the full help page in a new window.

We might want to update the help files. Use the ‘Update-Help’ command to do this.


Getting Execution Information

Sometimes we want information related to the execution of a .NET object and/or the errors returned. The following parameters are available:

  • Debug
  • ErrorAction
  • ErrorVariable
  • Verbose
  • WarningAction
  • WarningVariable

Adding the -WhatIf option to a command can tell us what would happen if the specified command is run.


Executing a Sequence of Commands

Obviously we can do this in PowerShell ISE. In the command line, we can specify a sequence of actions by inserting ‘;’ between each command.


Objects, Variables and Types

As with .NET programming, we’re dealing with strongly-typed objects. That is, everything we interact with has a type.

An object is structured data, and combines related things into a data model. It has properties and methods, both of which can be accessed using PowerShell.

Variables, as we already know, are regions of memory that exist within a process, into which data and objects can be stored during a session. There are a few native variables, such as ‘$Error’ and ’$?’.

To create a variable, and to read the value stored in it:

$myVariable = Get-Host
$myVariable

In addition, the following options can be used to manipulate variables:

New-Variable [name] -Value [value]
Clear-Variable -Name [name]
Remove-Variable -Name [name]

Pipelines

As with UNIX and Linux command lines, PowerShell enables us to pipe I/O between commands and files. Here we have a series of commands connected by at least one pipeline character (’|’), with input being passed from left to right. The difference here is that we’re passing objects, not text, and the data can be manipulated before it’s passed to a command.

e.g.

Get-Service | Export-Csv C:\temp\services.csv 

But the above is what we’d use to pass data from one command to another. If we want to send the output in ASCII format to a file, PowerShell enables that in the same way as on a Linux system, using ‘»’. e.g.

PS C:\Users\Emma> Get-Host >> C:\Users\Emma\Documents\myhost.txt

The data objects returned by a command can be queried:

  • Sort-Object
  • Select-Object
  • Group-Object
  • Measure-Object
  • Compare-Object