In a world where data security has become crucial, every company must regularly assess the health of its network infrastructure. The power of PowerShell, the command-line tool built into Windows, offers efficient ways to perform these audits. In this article, explore how five PowerShell scripts can help detect vulnerabilities and ensure your network’s security in a single day. These scripts not only analyze various aspects of your network but also strengthen your security posture against today’s cyber threats.
Checking Windows Firewall Status with PowerShell
Network protection often involves implementing an effective firewall. The following script checks the status of active firewall profiles on a Windows system. This first step is essential, as a poorly configured firewall can expose the network to attacks.
The Get-NetFirewallProfile script is used to display the status of various firewall profiles. This includes settings for domain, private, and public networks. Command: Get-NetFirewallProfile | Select-Object Name, Enabled Function:
- Displays the status (enabled or disabled) of each profile. Additionally, it is vital to list active firewall rules to ensure that only necessary connections are allowed. To do this, you can use the following script:
- Command: Get-NetFirewallRule | Where-Object { $_.Enabled -eq $true } | Select-Object DisplayName, Direction, Action
Function:
- Shows all enabled rules, including their direction (inbound or outbound) and their respective action. These two commands provide an overview of firewall configurations, a crucial element in preventing unauthorized access. By monitoring the firewall status, it is possible to anticipate threats and respond effectively to incidents.
- Firewall Profile State
Domain
| Enabled | Private |
|---|---|
| Disabled | Audience |
| Enabled | Analysis of network connections |
| Another fundamental aspect of security auditing is monitoring active network connections. Using the following script, administrators can identify suspicious connections that could compromise the system: | Order : |
Get-NetTCPConnection | Select-Object LocalAddress, LocalPort, RemoteAddress, RemotePort, State, OwningProcess
Function :
- Displays all TCP connections, allowing abnormal behavior to be detected. Analyzing these connections helps spot potential intrusions or malicious communications, which is vital for data integrity. All processes with active connections should be closely monitored to prevent attacks.
- https://www.youtube.com/watch?v=PIJIzePX8_M Windows Defender health monitoring
With online threats on the rise, it is imperative to ensure local defenses are in place. Windows Defender offers a basic level of protection, but its effectiveness depends on how it is configured and updated. The following script allows you to evaluate the status of the program:
Get-MpComputerStatus
Function :
- Shows details about Windows Defender status, including whether signatures are updated and whether real-time protection is enabled. Once the status of the software has been checked, it is also useful to list the installed software and spot any that could pose security risks.
- Software Name Version
Installation Date
| McAfee Antivirus | 21.0 | 01-02-2025 |
|---|---|---|
| Visual Studio | 16.7 | 05-15-2024 |
| Kaspersky | 20.0 | 01-01-2025 |
| It is recommended to maintain a software registry and regularly check their status to avoid any incompatibility or vulnerabilities. | User and group management | User control within an organization provides additional protection. PowerShell scripts can help manage local users and identify potentially compromised or unauthorized accounts. The following command will list all users: |
Command:
Get-LocalUser | Select-Object Name, Enabled, LastLogon
Function:
- Shows local users, their status (enabled or disabled), and their last logon date. Additionally, to check if there are members in the Administrators group, the following script is useful:
- Command: Get-LocalGroupMember -Group “Administrators”
Function:
- Lists members, ensuring that only authorized personnel have access to sensitive privileges. User Name Status
- Last Login Date Administrator
| Active | 20-03-2025 | User1 |
|---|---|---|
| Inactive | 15-02-2025 | Security Policy Management |
| Implementing good security policies for users allows you to effectively manage their access and actions. This includes updating passwords, training users on cybersecurity, and managing remote access. These measures are essential to prevent compromises and data leaks. | https://www.youtube.com/watch?v=HaV2da6hNuw | Analyzing Scheduled Tasks and Preventing Persistent Attacks |
Scheduled tasks can sometimes be used by attackers to establish persistent access to a system. Therefore, regular auditing of active tasks is necessary. The following script retrieves the scheduled tasks in the system:
Command:
Function:
Provides a list of tasks declared ready to run.
- Administrators should regularly review these tasks to identify and remove unauthorized or questionable ones. This can also ensure that no backdoors have been left inactive. Task Name
- Status Task 1
Ready
| Task 2 | Disabled |
|---|---|
| Assess Disk Security with BitLocker | Protecting data stored on a hard drive is a priority. BitLocker is an essential tool for encrypting disks on Windows systems. Ensuring it is enabled is a key step. The following script evaluates BitLocker status: |
| Command: | Manage-bde -status |
Function:
Displays whether the disk is encrypted or not.
- An encrypted disk significantly reduces the risk of data exposure in the event of theft or loss of equipment. This step, combined with proper user and login management, strengthens data defense. Disk BitLocker Status
- C: Encrypted
D:
| Unencrypted | https://www.youtube.com/watch?v=cHqnTMrwIFw |
|---|---|
| Best Practices for Ensuring Disk Security | It’s also important to follow regular audit procedures and take proactive measures, such as updating security software, auditing access, and training users on cybersecurity best practices. Together, these elements strengthen overall network security. |
| Solutions such as those offered by | Microsoft |
Cisco
,
Fortinet ,Palo Alto Networks ,Sophos ,Check Point ,Kaspersky ,McAfee ,CrowdStrike andIBM are all solid options to complement your PowerShell configurations.
