Using PowerShell for Incident Response with Fernando Tomlinson
Listen to this Episode
Audio available

In this episode, we get to hear the perspective of someone who has been in the trenches of Incident Response. Fernando shared his experiences and methods for leveraging PowerShell during incidents. We talk about how the general perception of PowerShell Security has changed over the years and how PowerShell is now being publicly embraced by security organizations. Fernando told us about dealing with obfuscation and some of the most annoying techniques that he’s encountered. All this and more is covered in this episode jam-packed with security goodness.
Check out the video version here: https://www.youtube.com/watch?v=n8-AJGGIVaM
Guest Bio and links:
Fernando Tomlinson is a Principal Incident Response Consultant at Mandiant. He is active in the PowerShell community, speaking at conferences, and creating interactive PowerShell training platforms: Under the Wire and PoSh-Hunter. He is Retired U.S Army of 20 years and is a Purple Heart recipient. He teaches others as a Cybersecurity Adjunct Professor, Co-Authored the PowerShell Conference Book Volume 2, and blogs at cyberfibers.com.
https://twitter.com/Wired_Pulse
http://cyberfibers.com/wp-content/uploads/2017/09/PS-Cheat-Sheet.pdf
Cyber Fibers - My Location of Thoughts During a Buffer Overflow
Defensive and Offensive PowerShell security tactics (Fernando Tomlinson)
New Shell in Town: Adventures in using PowerShell on Linux by Fernando Tomlinson
Gaining 20/20 vision during an incident with PowerShell
New Shell in Town: Adventures in using PowerShell on Linux by Fernando Tomlinson
About the Authors
Andrew Pla
PowerShell MVP, podcast host, and Community Director of PowerShell Summit
I’m a technical educator and community builder. I’m a Microsoft PowerShell MVP, podcast host, speaker, and Community Director of PowerShell Summit. I also work at PDQ alongside sysadmins and IT pros every day.
Community isn’t just what I do. It’s where I get my energy. I genuinely light up when I see someone land a new job, level up a skill, or show up to their first conference. I love sharing that passion with others.
Every week I host a live podcast and stream on YouTube covering PowerShell, automation, and the humans behind the keyboards.
If you’re on your IT journey and need someone in your corner, you’re in the right place. Find more at andrewpla.tech/links.

Jordan Hammond
Long-time co-host of The PowerShell Podcast
Jordan Hammond was a long-time co-host of The PowerShell Podcast and a regular host of the PDQ streams.
