Extra Credit Lab: PowerShell Scripting for Security
Objective: To introduce students who attempt this lab with the Windows PowerShell scripting, you are
no way expected to be an expert in Powershell and you will be graded on your attempt. You must do the
following to complete this lab successfully:
1) Please review the RUBRIC and the Powershell 101 Tutorial (See the attached documents under
Module 3 Extra Credit Lab PowerShell Scripting). You can use the PowerShell tool on the SimSpace
Windows Hunt boxes, or you can download and install the PowerShell Scripting Environment (PSE)
onto your Windows, Linux, or Mac machine (Windows recommended). PSE comes pre-installed on
Windows 10. For other operating systems, make sure you research proper installation techniques at
[Link]
2) Write a script that analyzes the events in your windows System Security Log. To make the
lab easier, export your security log entries to a CSV file which will be used by the script to perform
the analysis. The script should count the number of success and failure audits
logged, provide the count associated with each, and the most common event ID.
3) The name of your script should be lastname_abc123_IS_3513_PS [Link]. When you run
the script It should be invoked by simply typing its name with no parameters. The CSV file should
also be in the directory from which your script executes. You can prove that your
script is working correctly by cross correlating the script output with the output from a common
spreadsheet program (i.e. Excel using filtering selections). I converted my CSV file
to an Excel sheet, added column labels, and filtered on the Audit field to make sure the spreadsheet
Audit counts equaled what the script produced.
4) The output for the script should be in the following example format:
Number of Audit Failures: 2469 failures of 19247 entries Most common Event ID:
5038
Number of Audit Successes: 16778 successes of 19247 entries Most common Event
ID: 4624
NOTE: The “Most common Event ID” may differ on your machine.
5) Prepare a lab report that shows your PS script and PS Script Output.
6) Please review the RUBRIC. Write a 3-5 page Lab Report explaining your PowerShell Script and the
steps taken to write it. Be sure to include screenshots. Also Discuss how PowerShell is Useful to a
Cybersecurity Professional. The Title page and APA Style Bibliography as well as the appendices do
not count in the 3-5 pages. Remember to Cite two sources (Author, Date).
GRADING: Please, Review the RUBRIC. This EC Lab report will be a minimum of minimum of 3 full
pages in length (single-spaced in font size 12, with page numbers) and contain a title page. The title page
does not count as one of the pages for the report. Figures (screenshots) can be used in the report but
will not count toward the page count and must be properly labeled. Figures are useful in showing you
completed certain tasks or produced the desired output. The required bibliography will not count as one
of the page requirements. If you use Appendices, they will not count as pages for the report. All
references and figures should be properly cited throughout the report. An electronic copy of the paper
will be submitted via Canvas for grading in .PDF format. Please make sure your last name and UTSA ID #
is on all items submitted and use the following file naming convention:
lastname_abc123_IS_3513_EC_PS_Scripting.pdf and :
lastname_abc123_IS_3513_Log_Entry.csv. Ensure you discuss Lab Report explaining your
PowerShell Script and the steps taken to write it. Be sure to include screen shots. Also research and
discuss how PowerShell is Useful to a Cybersecurity Professional. The Title page and APA Style
Bibliography as well as the appendices do not count in the 3-5 pages. Remember to Cite two sources
(Author, Date). Addtionally, submit the CSV you used also. If you utilize SimSpace a screenshot is
sufficient. The items submitted should be in the following format: Your lab report must include an in
text citation from two sources minimum and those sources must be include in the bibliography. DO
NOT PLAGERIZE, using another authors work without citing (i.e Author Last name, Year Published) is
plagerism and you will be penalized if you plagerize. Please use the UTSA Style Guide to cite works and
construct your Bibliography. The John Peace Library has research assistants to assist you in finding
materials for this assignment. In your research you will find one peer reviewed source per tool (three
total) for Lab One and you will cite the sources within your write up in the (Author Last Name, Year
Published) format.
Begin your lab report with you experiences you encounter using PowerShell. It should be in black ink
and in12-pitch font. I would prefer Arial, Times New Roman, or Courier, but as long as it is legible, I am
flexible on the font type. The lab report will be arranged in paragraphs that are properly indented in
paragraph format. Ideally you should spend two pages describing your lab experience. After describing
your lab experience then you should research and discuss how PowerShell is Useful to a Cybersecurity
Professional.
If you have appendices (i.e., screenshot, graph, picture etc.) to help you reinforce a point in your lab
report, it should be on a separate page at the end of the lab report but before the bibliography, (See
Figure 1). By keeping them separate it will be easier to count your written pages so I do not have to
guess (I am a poor guesser). If you state a fact that is not common knowledge which you borrowed from
an outside source then you must cite it within the written portion of your lab report (Joyner, Rouse, and
Glatthorn, 2013). The following sentence is a quote form an article and I have cited it an example.
Cyber security is growing concern and is increasingly affecting the United States and the international
community (White, 2016). Make sure all your cited works are also located in your Bibliography or
Reference List. If your source doesn’t have an author or date published, find another source, please. Do
not cite Wikipedia but you can use it to find possible references based on your topic.
These lab reports will take time to complete properly but you are given four weeks for each one.
If you have questions, please bring them to class so I can give you clarity and purpose. This is not busy
work and I hope you will find the labs interesting and enjoyable. Please plan ahead because we have
limited SimSpace licenses and if your fellow classmates are using a machine select one that isn’t being
utilized. I highly encourage you to start your labs early in the cycle (especially lab two) as you cannot be
successful and start them on the last weekend.
Your research portion of the lab should employ techniques that include using the WHO, WHAT, WHEN,
WHY, HOW and HOW can be useful to a Cybersecurity Professional. You may be thinking to yourself
at this point that this is a cyber security course, not an English course. In order to be successful in cyber
security, you will need to know how to write policies, generate proposals, and write white pages. These
lab reports will help you to write better and be better prepared for the real world. Please review the
Rubric and use this template to help you get started with your lab report. I hope this helps, it is my first
attempt at a lab report template. If you have questions, please contact me by email or cell phone (210)
379-0266.
Appendices
Figure 1. Script Results
Figure 2. SecurityLog .csv File Output
The figure (screenshot, graph, picture, etc.) should be properly labeled and big enough that the reader
can see what you intend for them to view.
Bibliography
Adams, L. A. (2014). Research Ethics. Retrieved from
[Link]
Almeida, W. (2017). Wannacry timeline: How it happened and the industry response to ransomeware
attack.
Anney, V. N. (2014). Ensuring the quality of the findings of qualitative research: Looking at
trustworthiness criteria. Journal of Emerging Trends in Educational Research and Policy Studies
(JETERAPS), 5(2), 272-281.
Arghire, I. (2017). 4.2 billion records exposed in data breaches in 2016: Report. Security Week.
Blakrishnaraja, N. (2018). The advantages of HIPAA compliance. Retrieved from
[Link]
Bromley, E., Mikesell, L., Jones, F., & Khodyakov, D. (2015). From subject to participant: Ethics and the
evolving role of community in health research. American Journal of Public Health, 105(5), 900-908.
doi:10.2105/AJPH.2014.302403.
Chaffin, J., Jones, S., Neville, S., & Pickard, J. (2017). NHS hackers used stolen cyber weapons from US spy
agency. Financial Times.
Joyner, R. L., Rouse, W.A., Glatthorn (2013). Writing the winning thesis or dissertation: A step by step
guide -3rd edition. London: Corwin.
White, J. (2016). Cyber Threats and Cyber Security: National Security Issues, Policy and Strategies.
Global Security Studies 7(4) 23-33. Retrieved from
[Link]
1944222X&AN=119212350&h=ggw6S3%2bGAMsltI%2fwOBfK4XuYdFIDR%2fRGIoYjynXPsFPk4uMoP3Mg
hh%2bW9BsWKTZkg3BELN7fvIi5wGUToMuzBQ%3d%3d&crl=c&resultNs=AdminWebAuth&resultLocal=E
rrCrlNotAuth&crlhashurl=[Link]%3fdirect%3dtrue%26profile%3dehost%26scope%3dsite%26authtyp
e%3dcrawler%26jrnl%3d1944222X%26AN%3d119212350
Some examples on how to create a bibliography. Sources should not be older than 10 years.