0% found this document useful (0 votes)
7 views5 pages

PowerShell Lab for Cybersecurity Students

The lab introduces students to PowerShell scripting for security analysis, requiring them to write a script that analyzes Windows System Security Log events. Students must submit a lab report detailing their script, output, and the usefulness of PowerShell in cybersecurity, along with proper citations and appendices. The report should be 3-5 pages long, excluding title page and bibliography, and must adhere to specific formatting guidelines.

Uploaded by

BRIAN MULUTU
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
7 views5 pages

PowerShell Lab for Cybersecurity Students

The lab introduces students to PowerShell scripting for security analysis, requiring them to write a script that analyzes Windows System Security Log events. Students must submit a lab report detailing their script, output, and the usefulness of PowerShell in cybersecurity, along with proper citations and appendices. The report should be 3-5 pages long, excluding title page and bibliography, and must adhere to specific formatting guidelines.

Uploaded by

BRIAN MULUTU
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Extra Credit Lab: PowerShell Scripting for Security

Objective: To introduce students who attempt this lab with the Windows PowerShell scripting, you are

no way expected to be an expert in Powershell and you will be graded on your attempt. You must do the

following to complete this lab successfully:

1) Please review the RUBRIC and the Powershell 101 Tutorial (See the attached documents under

Module 3 Extra Credit Lab PowerShell Scripting). You can use the PowerShell tool on the SimSpace

Windows Hunt boxes, or you can download and install the PowerShell Scripting Environment (PSE)

onto your Windows, Linux, or Mac machine (Windows recommended). PSE comes pre-installed on

Windows 10. For other operating systems, make sure you research proper installation techniques at

[Link]

2) Write a script that analyzes the events in your windows System Security Log. To make the

lab easier, export your security log entries to a CSV file which will be used by the script to perform

the analysis. The script should count the number of success and failure audits

logged, provide the count associated with each, and the most common event ID.

3) The name of your script should be lastname_abc123_IS_3513_PS [Link]. When you run

the script It should be invoked by simply typing its name with no parameters. The CSV file should

also be in the directory from which your script executes. You can prove that your

script is working correctly by cross correlating the script output with the output from a common

spreadsheet program (i.e. Excel using filtering selections). I converted my CSV file

to an Excel sheet, added column labels, and filtered on the Audit field to make sure the spreadsheet

Audit counts equaled what the script produced.

4) The output for the script should be in the following example format:

Number of Audit Failures: 2469 failures of 19247 entries Most common Event ID:

5038

Number of Audit Successes: 16778 successes of 19247 entries Most common Event

ID: 4624

NOTE: The “Most common Event ID” may differ on your machine.

5) Prepare a lab report that shows your PS script and PS Script Output.

6) Please review the RUBRIC. Write a 3-5 page Lab Report explaining your PowerShell Script and the
steps taken to write it. Be sure to include screenshots. Also Discuss how PowerShell is Useful to a

Cybersecurity Professional. The Title page and APA Style Bibliography as well as the appendices do

not count in the 3-5 pages. Remember to Cite two sources (Author, Date).

GRADING: Please, Review the RUBRIC. This EC Lab report will be a minimum of minimum of 3 full

pages in length (single-spaced in font size 12, with page numbers) and contain a title page. The title page

does not count as one of the pages for the report. Figures (screenshots) can be used in the report but

will not count toward the page count and must be properly labeled. Figures are useful in showing you

completed certain tasks or produced the desired output. The required bibliography will not count as one

of the page requirements. If you use Appendices, they will not count as pages for the report. All

references and figures should be properly cited throughout the report. An electronic copy of the paper

will be submitted via Canvas for grading in .PDF format. Please make sure your last name and UTSA ID #

is on all items submitted and use the following file naming convention:

lastname_abc123_IS_3513_EC_PS_Scripting.pdf and :

lastname_abc123_IS_3513_Log_Entry.csv. Ensure you discuss Lab Report explaining your

PowerShell Script and the steps taken to write it. Be sure to include screen shots. Also research and

discuss how PowerShell is Useful to a Cybersecurity Professional. The Title page and APA Style

Bibliography as well as the appendices do not count in the 3-5 pages. Remember to Cite two sources

(Author, Date). Addtionally, submit the CSV you used also. If you utilize SimSpace a screenshot is

sufficient. The items submitted should be in the following format: Your lab report must include an in

text citation from two sources minimum and those sources must be include in the bibliography. DO

NOT PLAGERIZE, using another authors work without citing (i.e Author Last name, Year Published) is

plagerism and you will be penalized if you plagerize. Please use the UTSA Style Guide to cite works and

construct your Bibliography. The John Peace Library has research assistants to assist you in finding

materials for this assignment. In your research you will find one peer reviewed source per tool (three

total) for Lab One and you will cite the sources within your write up in the (Author Last Name, Year

Published) format.
Begin your lab report with you experiences you encounter using PowerShell. It should be in black ink
and in12-pitch font. I would prefer Arial, Times New Roman, or Courier, but as long as it is legible, I am
flexible on the font type. The lab report will be arranged in paragraphs that are properly indented in
paragraph format. Ideally you should spend two pages describing your lab experience. After describing
your lab experience then you should research and discuss how PowerShell is Useful to a Cybersecurity
Professional.

If you have appendices (i.e., screenshot, graph, picture etc.) to help you reinforce a point in your lab
report, it should be on a separate page at the end of the lab report but before the bibliography, (See
Figure 1). By keeping them separate it will be easier to count your written pages so I do not have to
guess (I am a poor guesser). If you state a fact that is not common knowledge which you borrowed from
an outside source then you must cite it within the written portion of your lab report (Joyner, Rouse, and
Glatthorn, 2013). The following sentence is a quote form an article and I have cited it an example.
Cyber security is growing concern and is increasingly affecting the United States and the international
community (White, 2016). Make sure all your cited works are also located in your Bibliography or
Reference List. If your source doesn’t have an author or date published, find another source, please. Do
not cite Wikipedia but you can use it to find possible references based on your topic.

These lab reports will take time to complete properly but you are given four weeks for each one.
If you have questions, please bring them to class so I can give you clarity and purpose. This is not busy
work and I hope you will find the labs interesting and enjoyable. Please plan ahead because we have
limited SimSpace licenses and if your fellow classmates are using a machine select one that isn’t being
utilized. I highly encourage you to start your labs early in the cycle (especially lab two) as you cannot be
successful and start them on the last weekend.

Your research portion of the lab should employ techniques that include using the WHO, WHAT, WHEN,
WHY, HOW and HOW can be useful to a Cybersecurity Professional. You may be thinking to yourself
at this point that this is a cyber security course, not an English course. In order to be successful in cyber
security, you will need to know how to write policies, generate proposals, and write white pages. These
lab reports will help you to write better and be better prepared for the real world. Please review the
Rubric and use this template to help you get started with your lab report. I hope this helps, it is my first
attempt at a lab report template. If you have questions, please contact me by email or cell phone (210)
379-0266.

Appendices

Figure 1. Script Results


Figure 2. SecurityLog .csv File Output

The figure (screenshot, graph, picture, etc.) should be properly labeled and big enough that the reader
can see what you intend for them to view.

Bibliography

Adams, L. A. (2014). Research Ethics. Retrieved from


[Link]

Almeida, W. (2017). Wannacry timeline: How it happened and the industry response to ransomeware
attack.

Anney, V. N. (2014). Ensuring the quality of the findings of qualitative research: Looking at
trustworthiness criteria. Journal of Emerging Trends in Educational Research and Policy Studies
(JETERAPS), 5(2), 272-281.

Arghire, I. (2017). 4.2 billion records exposed in data breaches in 2016: Report. Security Week.

Blakrishnaraja, N. (2018). The advantages of HIPAA compliance. Retrieved from


[Link]

Bromley, E., Mikesell, L., Jones, F., & Khodyakov, D. (2015). From subject to participant: Ethics and the
evolving role of community in health research. American Journal of Public Health, 105(5), 900-908.
doi:10.2105/AJPH.2014.302403.
Chaffin, J., Jones, S., Neville, S., & Pickard, J. (2017). NHS hackers used stolen cyber weapons from US spy
agency. Financial Times.

Joyner, R. L., Rouse, W.A., Glatthorn (2013). Writing the winning thesis or dissertation: A step by step
guide -3rd edition. London: Corwin.

White, J. (2016). Cyber Threats and Cyber Security: National Security Issues, Policy and Strategies.
Global Security Studies 7(4) 23-33. Retrieved from
[Link]
1944222X&AN=119212350&h=ggw6S3%2bGAMsltI%2fwOBfK4XuYdFIDR%2fRGIoYjynXPsFPk4uMoP3Mg
hh%2bW9BsWKTZkg3BELN7fvIi5wGUToMuzBQ%3d%3d&crl=c&resultNs=AdminWebAuth&resultLocal=E
rrCrlNotAuth&crlhashurl=[Link]%3fdirect%3dtrue%26profile%3dehost%26scope%3dsite%26authtyp
e%3dcrawler%26jrnl%3d1944222X%26AN%3d119212350

Some examples on how to create a bibliography. Sources should not be older than 10 years.

Common questions

Powered by AI

Emphasizing proper citation and bibliography in lab reports is crucial to academic integrity, avoiding plagiarism, and fostering research skills. It encourages students to engage with existing literature and properly credit sources, reinforcing the ethical standards required in professional cybersecurity research and reporting .

The sources emphasize the critical role of documentation in both the learning and reporting processes by requiring detailed lab reports, citations, and bibliographies. This structured documentation not only demonstrates comprehension and correct script functionality but also instills professional practices necessary for real-world application and continuous learning .

Learning PowerShell scripting through labs prepares students for real-world cybersecurity challenges by teaching them how to automate and streamline security data analysis. This practical experience equips them with skills to quickly identify threats and anomalies, conduct efficient system audits, and develop customized security solutions that are immediately applicable in a professional setting .

PowerShell scripting significantly enhances a cybersecurity professional's ability to manage Windows system security logs by automating the process of analyzing logs for security events. Scripts can automatically count and categorize events, such as success and failure audits, and identify common event IDs, which streamlines the monitoring process and enhances the speed and accuracy of identifying potential security threats .

Manual verification of PowerShell script outputs with applications like Excel is recommended to ensure the script's accuracy. This cross-validation is crucial for identifying discrepancies between automated scripting outputs and manually filtered data, thereby confirming the reliability of the script .

PowerShell scripting can enhance the accuracy of a cybersecurity incident report by providing automated, precise log analysis that quickly identifies key metrics like the number of audit failures or successes and common event IDs. This automation minimizes human error and ensures consistent data interpretation across incidents .

PowerShell scripting teaches transferable skills such as automation, problem-solving, and data analysis, which are integral to broader cybersecurity operations. These skills help professionals automate routine tasks, analyze vast datasets efficiently, and develop robust scripts for security monitoring and threat management .

The effectiveness of a PowerShell script for cybersecurity should be evaluated based on its ability to automate accurate log analyses, its user-friendliness and error handling, speed and efficiency in processing data, and consistency of results with manual verification methods like spreadsheet cross-referencing .

Potential challenges include understanding the syntax and functionalities of PowerShell scripting, particularly if the student has no previous scripting experience. Additionally, new users might struggle with setting up the scripting environment correctly on non-Windows systems or ensuring the script accurately processes the CSV file for log analysis .

Best practices include ensuring scripts are executed without errors, properly processing input files like CSVs, using clear and consistent naming conventions, and validating script results by cross-referencing with manual data analyses in Excel. Documenting the script with a detailed lab report that includes screenshots, proper bibliography, and APA citations are also recommended .

You might also like