cybersecurity
education
€ EUR
  • $ USD
  • € EUR
  • #course
  • #livevirtualclass

PowerShell Advanced (PSA)

Live Virtual Class - Super Intensive Remote Training with Labs!
September 28, 2026, 9:00 am
Days
Hours
Min.
Sec.

During this intensive 2-day (14-hour) course, you will learn advanced techniques for securing and hardening PowerShell through enhanced visibility, application control, constrained execution, and least-privilege administration. Moreover, you will be able to:

    • Get the highest quality and unique learning experience – the class is limited to 20 participants by default.
    • Get the opportunity to interact with our world-renowned Experts.
    • Go through CQURE’s custom lab exercises and practice them after the course.
    • Receive a lifelong certification after completing the course!

 

(9:00am – 4:00pm CEST/CET Monday and Tuesday)

Original price was: €2730.Current price is: €2070. (TAX incl.*)

*Tax exemption available for eligible businesses

Why this course?

PowerShell is the most powerful management tool in the Windows ecosystem, which ironically makes it the weapon of choice for adversaries. This “Defender” focused course provides a deep understanding of the Attack Surface and the corresponding Defense Mechanisms.

The training begins with an “Offensive Primer,” where students execute real-world attack techniques (Obfuscation, Fileless execution, AMSI bypasses) to understand what they are up against. We then pivot to “Hardening,” implementing the gold standard of PowerShell security: Deep Visibility via Script Block Logging and Constraint via AppLocker/WDAC and Just Enough Administration (JEA).

The goal is to move the organization from a state of “Disable PowerShell” (which breaks management) to “Secure PowerShell” (which breaks the attacker).

PowerShell is the most powerful management tool in the Windows ecosystem, which ironically makes it the weapon of choice for adversaries. This “Defender” focused course provides a deep understanding of the Attack Surface and the corresponding Defense Mechanisms.

The training begins with an “Offensive Primer,” where students execute real-world attack techniques (Obfuscation, Fileless execution, AMSI bypasses) to understand what they are up against. We then pivot to “Hardening,” implementing the gold standard of PowerShell security: Deep Visibility via Script Block Logging and Constraint via AppLocker/WDAC and Just Enough Administration (JEA).

The goal is to move the organization from a state of “Disable PowerShell” (which breaks management) to “Secure PowerShell” (which breaks the attacker).

Pricing plan

We offer you pricing plan designed and adjusted to your specific needs and budget. Buy now or book your spot and pay later.

Course timeline

Course benefits

How our lessons look like

  • Key Takeaways
  • Lab
  • Prerequisites
  • Course materials
  • Unique exercises
  • Social & Network
  • Certification

Key Takeaways

  • Threat Anatomy: Understanding how attackers use PowerShell for “Living off the Land” (LotL) attacks and memory-resident malware.
  • De-Obfuscation & Detection: analyzing obfuscated code (Base64, XOR) and configuring Event ID 4104 (Script Block Logging) to strip away layers of concealment.
  • AMSI Internals: How the Antimalware Scan Interface works, how attackers try to break it, and how to monitor for AMSI tampering.
  • Language Modes: The critical difference between Full Language Mode and Constrained Language Mode (CLM) and how to enforce it using AppLocker or WDAC.
  • Just Enough Administration (JEA): Implementing the principle of Least Privilege by creating restricted endpoints that allow users to manage systems without Admin rights.

Lab

Red vs. Blue Cyber Range

A specialized environment where students first act as attackers to bypass default protections, and then switch roles to configure logging, CLM, and JEA to successfully neutralize their own previous attacks.

 

Prerequisites

  • Students should be comfortable reading complex scripts. You do not need to be a developer, but you must be able to look at a script and understand what it is doing to effectively analyze them.
  • A strong understanding of Windows security primitives is required.
  • Experience in managing a Windows Enterprise environment is highly recommended to understand the impact of hardening measures like AppLocker and JEA.

Course materials

During the course you will be provided with a bunch of materials such as lab exercises, presentations, intriguing articles and useful tools to make your tasks a little bit easier!

Unique exercises

To top it all of, the labs in which you will be practicing during the course will stay online for an extra 3 weeks so you may practice even more after the training is completed!

Social & Network

You will be granted access to our closed Discord community server where you will be able to share your thoughts with other IT specialists.

Certification

After finishing the course, you will be granted a CQURE Certificate of Completion. Please note that after completing the course you will also be eligible for CPE points!

Course syllabus

This Live Virtual Class consists of 8 Modules in terms of PowerShell Advanced. They include essential theory combined with individual practice during the exercises as well as loads of hands-on tools and real-case scenarios.

      • Module 1: The Dark Side of the Shell: Execution Policy myths. “Fileless” malware and Reflective DLL Injection techniques.
      • Module 2: Obfuscation Techniques: How attackers hide logic (String manipulation, Backticks, Encoding). Manual de-obfuscation strategies.
      • Module 3: Secure Coding for Admins: Protecting credentials. Avoiding “Injection” vulnerabilities in scripts. Using the SecretManagement module.
      • Module 4: Deep Visibility: Configuring Module Logging, Transcription, and the critical Script Block Logging. Integrating logs with SIEM.

Who is it for?

This is an advanced course on PowerShell for Cybersecurity Specialists.

Audience

Security Engineers, Blue Teamers, SOC Analysts, and Senior Administrators responsible for hardening Windows environments.

Recommendations

To fully benefit from this training, we recommend having a good hands-on experience in administering Windows infrastructure and at least 8 years experience in the field.

Exercises

All the exercises are based on Windows Server 2016 and 2019, Windows 10 and Kali Linux.

Platform and Technical Requirements

To participate in the course you need a stable internet connection. For best learning experience we also need you to have a webcam, headphones and a microphone. Open RDP port 3391 for the connection to the Lab environment is needed as well. We will setup a secure Zoom classroom for every day of the course – we will send you a safe link to join the conference by e-mail.

How to persuade your manager that this course is meaningful?

Investing in knowledge is one of the most worthy investment not only for us, but also for our environment. Learning new skills and insights in terms of cybersecurity may benefit with gaining awareness and as a result, may prevent falling a victim to cyber threats in the future.

Protects the Company

You will be the valuable element in regards to company’s safety – knowing about potential threats and ways of avoiding them may be incredibly useful in a daily company life.

Improves Employees skills

Not only your company will gain a specialist in terms of cybersecurity, but also you will unlock the door for expanding your skills horizon even further.

Boosts customer confidence

Completed course with personal certification may be the perfect advantage when it comes to business.

Helps comply with regulations

Knowledge is power—it helps navigate through complex regulatory landscapes. Keeping up-to-date with the latest cybersecurity regulations and standards ensures your company remains compliant, thus avoiding costly penalties and reputational damage.

Saves money in the long run

Who would have want to pay regularly for help in case of emergency data leakage in a company? It’s much better to educate the employees and prevent any cybersecurity risks.

Prepares for emerging threats

After our course, you will be educated in the possible threats and you will identify any suspicious activity online with ease.

Register now and learn from the best!

During this 14-hour super intensive training you will gain crucial cybersecurity knowledge and skills in terms of PowerShell Advanced. Moreover, you will be able to:

  • Get the highest quality and unique learning experience.
  • Get the opportunity to interact with our world-renowned Experts.
  • Go through CQURE’s custom lab exercises and practice them after the course.

Your Experts

This course is delivered by one of the greatest, world-renowned Cybersecurity Experts with practical knowledge from tons of successful projects, many years of real-world experience, great teaching skills and no mercy for misconfigurations or insecure solutions.

Jan

Marek

MVP, MCT, Microsoft Security Specialist

Jan Marek is a red teamer, security consultant and architect with more than 18 years of proven experience. His professional career includes training and speaking-related activities as well.

How can we help you?

Suggested searches

    Search history

      Popular searches:

      Not sure what course to look for?

      Mobile Newsletter Form